PVLAN Promiscuous port not not forwarding packets to router.

Posted on 2013-06-19
Last Modified: 2016-11-23
Hello Experts,

I have a Dell Powerconnect 7024 connected downstream from a Sonicwall NSA 3500.
I'm attempting to setup a VMware host behind the Powerconnect and utilize Private Vlans to separate VMs.

Primary Private Vlan is 59
Isolate = 100
Community1 = 213
Community2 = 223

I believe I have the configuration below correct however none of my VM's can ping the gateway (

The Sonicwall router is plugged into interface Gi1/0/1 and my lab server is plugged into Gi1/0/12

My question is 2 part.

First question is any idea as to why I can't ping the firewall from my VM's? (I have them setup with a distributed switch and are in the primary vlan (59).

Second Question is it possible to have multiple secondary vlans on a single physical interface. For example could I have the isolate vlan and both my community vlan's utilize a single interface?

Here is my running configuration:

console#show running-config

!Current Configuration:
!System Description "PowerConnect 7024,, VxWorks 6.6"
!System Software Version
!System Operational Mode "Normal"
vlan 59,100,213,223
vlan 59
private-vlan primary
private-vlan association 100,213,223
vlan 100
private-vlan isolated
vlan 213
private-vlan community
vlan 223
private-vlan community
slot 1/0 2    ! PowerConnect 7024
--More-- or (q)uit
member 1 2    ! PCT7024
interface out-of-band
ip address
ip default-gateway
ip route 253
interface vlan 1
ip address
username "root" password ee940cf388b41e947b04a25aab769645 privilege 15 encrypted
ip ssh server
interface Gi1/0/1
switchport mode private-vlan promiscuous
switchport private-vlan mapping 59 100-250
interface Gi1/0/12
switchport mode private-vlan host
switchport private-vlan host-association 59 100
--More-- or (q)uit
snmp-server engineid local 800002a2035c260ad98a1e
snmp-server agent boot count 2
enable password ee940cf388b41e947b04a25aab769645 encrypted

Question by:kinetik20
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 3

Expert Comment

ID: 39260765
I come from the cisco world and dont deal with dell network gear much but heres at least some guidance...

In order for a physical interface to be a member of multiple vlans, it must a trunk port. A port tagged for access to a vlan can only be associated to one vlan. There is nothing in that config that clearly states either of those Gig interfaces are trunk ports (again not overly familiar with Dell nomenclature), so that may be your first hurdle (also an answer to your questions). Both interfaces would need to be configured as trunk ports if you want the vms from different vlans to reach the gateway.

Author Comment

ID: 39260792
In my research I've come across a lot of cisco pvlan info that has applied to the dell gear. The CLI is very very similar. Would you have an idea of how you would configure my above desired config for a cisco switch? Perhaps I can translate that into the dell gear.

Expert Comment

ID: 39260821
in the cisco world it would go something like:

conf t
int gig1/0/1
switchport mode trunk
switchport trunk allowed vlan <vlan number or range>

and you would perform the same thing on gig1/0/12
Don't Miss ATEN at InfoComm 2017!

Visit booth #2167 to see the  new ATEN VM3200 32 x 32 Modular Matrix Switch. Other highlights include the VE8950 4K HDMI Over IP Extender, VS1912 12-Port DP Video Wall Media Player  and VK2100 ATEN Control System. Register now with Free Pass Code ATEN288!


Author Comment

ID: 39260976
Well I tried trunking the ports but that did not work either.

Accepted Solution

iammorrison earned 500 total points
ID: 39260997
you also need to configure the interface on the sonic wall as a trunk, I should have included that

Author Closing Comment

ID: 39261155
Thank you. Turns out this is the case and the sonicwall does not support trunking. Any help finding a comparable Cisco firewall that would and support at least 25 ipsec vpn tunnels?

Expert Comment

ID: 39261293
Glad I could help! I would look into the Cisco ASA devices,  maybe the 5510 and move up from there if you require more horsepower!

Featured Post

Free Tool: Subnet Calculator

The subnet calculator helps you design networks by taking an IP address and network mask and returning information such as network, broadcast address, and host range.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Trouble adding ESXu host to vCenter 25 69
Clone Windows 95 1GB IDE drive onto 40GB IDE drive 29 105
i think i have the same error 16 87
I cant see screen 3 41
If we need to check who deleted a Virtual Machine from our vCenter. Looking this task in logs can be painful and spend lot of time, so the best way to check this is in the vCenter DB. Just connect to vCenter DB(default DB should be VCDB and using…
Giving access to ESXi shell console is always an issue for IT departments to other Teams, or Projects. We need to find a way so that teams can use ESXTOP for their POCs, or tests without giving them the access to ESXi host shell console with a root …
Teach the user how to configure vSphere clusters to support the VMware FT feature Open vSphere Web Client: Verify vSphere HA is enabled: Verify netowrking for vMotion and FT Logging is in place or create it: Turn On FT for a virtual machine: Verify …
After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

710 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question