For added security I am migrating out network to use PVLANs. My question is given standard VLAN (192.168.0.0/24) can I designate a few ports as isolated\promiscuous while still having the others work normally. I would like to test things using a few hosts as opposed to potentially bricking the whole network. There are also hundreds of hosts to migrate so I might not be able to do it all in one setting.
Take a look at this:
http://www.cisco.com/en/US/i/100001-200000/180001-190000/182001-183000/182773.jpg
Imagine the top port as a promisc port (which it is), and the two left-most ones as isolated ports (which they are). Now instead of assigning community ports to the four rightmost ports I would like to simply leave them in the VLAN without any PVLAN parameters. Can this be done?