Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations gkittelson on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

PVLAN - web and database server

Status
Not open for further replies.

d1900233

MIS
May 21, 2009
2
US
Lets's say I create a VLAN for a DMZ with 3 servers: a web server , a database server, and an email server. I want to use PVLANs to isolate the three servers so they can not communicate with each other. However, the one exception is that the web server does need to connect to the database server to execute database queries on port 1433.

1)Can PVLANs allow certain ports to be accessible within a PVLAN like in this example?

2)If so does ACLs control this type of filtering on a PVLAN?

3)Where can I find reliable documentation on the subject, preferably on a Cisco website?

Thanks in advance.

 
I'm not all that knowledgeable with pvlans but I would think you would have to put the webserver and the database server in the same pvlan and exclude them from the other servers of the dmz.
 
1)Can PVLANs allow certain ports to be accessible within a PVLAN like in this example?
No. It is all or nothing
2)If so does ACLs control this type of filtering on a PVLAN?
You can combine VACLs (VLAN ACL's) to the PVLANs to make this work
3)Where can I find reliable documentation on the subject, preferably on a Cisco website?
Keep in mind that there aren't many different switches that can implement PVLANs so make sure that yours can. Check out this Cisco doc:


I hate all Uppercase... I don't want my groups to seem angry at me all the time! =)
- ColdFlame (vbscript forum)
 
unclerico,

Thanks for your help but I am a little confused. You said to the first question that its "all or nothing". Then your answer to the second question seemed to contradict your first answer. What do you mean by "make this work"? What is "this"?

Thanks
 
PVLANs by themselves allow for all or nothing access to resources on the same PVLAN. When you combine PVLANs with VACLs then you can get the functionality you are looking for. "Make this work" means getting the functionality that you are looking for.

I hate all Uppercase... I don't want my groups to seem angry at me all the time! =)
- ColdFlame (vbscript forum)
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top