Hi Lyndidon
Thanks for your help. You assisted me to solve my problem so I will accept
your post as a solution, but here are some comments
1) Private vlan feature (primary + secondary/community ones) work fine without no-local-switching
option. AJEX instructor guide has no place where no-local-switching is mentioned;
AJEX lab guide just says to configure no-local-switching without telling what it does;
it is actually not needed in that lab setup. But this option is indeed required for
isolated vlans to work properly.
2) Access ports in the primary vlan (if you have more than one) are not
"isolated" from each other before you configure no-local-switching.
Before:
{master:0}[edit]
lab@exA-1# show vlans
v12-13 {
vlan-id 300;
interface {
ge-0/0/12.0;
ge-0/0/13.0;
}
isolation-id 600;
}
{master:0}[edit]
lab@exA-1# run show vlans
Name Tag Interfaces
__pvlan_v12-13_isiv__ 600
None
default
None
v12-13 300
ge-0/0/12.0*, ge-0/0/13.0*
(and I can ping between ports);
After:
{master:0}[edit]
lab@exA-1# set vlans v12-13 no-local-switching
{master:0}[edit]
lab@exA-1# commit
warning: Isolation-id configured with no pvlan_trunk associated with primary vlan v12-13.
configuration check succeeds
commit complete
{master:0}[edit]
lab@exA-1# run show vlans
Name Tag Interfaces
__pvlan_v12-13_ge-0/0/12.0__
ge-0/0/12.0*
__pvlan_v12-13_ge-0/0/13.0__
ge-0/0/13.0*
__pvlan_v12-13_isiv__ 600
None
default
None
v12-13 300
ge-0/0/12.0*, ge-0/0/13.0*
and ping does not go between ports - they are indeed isolated (and have separate
internal vlan assigned).
Any other comments welcome.