VLAN For Networking
VLAN For Networking
VLAN For Networking
Virtual LANs
Layer 2 switched network is referred to
as a flat network topology with single
broadcast domain.
To overcome single broadcast domain
switched networks can be subdivided
into Virtual LANs (VLANs)
By definition, a VLAN is a single
broadcast domain.
ALTTC/ DX Faculty
Virtual LANs
In a VLAN, computers are assigned to
LAN segments by software.
VLANs are often faster and provide
more flexible network management
than traditional LAN and BN designs.
They are also more complex and so
far usually used for larger networks.
The two basic designs are single
switch and multi-switch VLANs.
ALTTC/ DX Faculty
VLAN 100
VLAN 200
VLAN 400
VLAN 300
VLAN 300
VLAN 400
VLAN 100
ALTTC/ DX Faculty
Multi-switch VLANs
VLANs in separate locations can be possible by MultiSwitch VLANs interconnected by Trunk Links
The two ways to implement multi-switch VLANs:
Proprietary protocols are used to envelope the
Ethernet frame (ISL)
which is then sent to its destination switch, where the
Ethernet packet is released and sent to its destination
computer.
Multi-switch VLANs
VLAN 200
VLAN 100
VLAN 300
VLAN 200
VLAN 100
VLAN 300
Trunk Links
ALTTC/ DX Faculty
VLAN Membership
When a VLAN is provided at an access
layer switch, an end user must have
some means to gain membership to it.
Two membership methods exist on
Cisco Catalyst switches:
Static VLANs and
Dynamic VLANs.
ALTTC/ DX Faculty
Static VLANs
Static VLANs offer port-based
membership, where switch ports are
assigned to specific VLANs.
End user devices become members in a
VLAN based on which physical switch port
they are connected to.
VLAN Trunks
At the access layer, end user devices
connect to switch ports (a single VLAN)
Intervention of an additional Layer 3
router/switch is needed to communicate
between the VLANs
A trunk link, however, can transport more
than one VLAN through a single switch
port.
Trunk links are most beneficial when
switches are connected to other switches or
switches are connected to routers.
ALTTC/ DX Faculty
10
VLAN Tagging
VLAN Tagging is used when a link needs to
carry traffic for more than one VLAN.
The packet is then forwarded to the
appropriate switches or routers based on the
VLAN identifier and MAC address through a
trunk link after adding a tag.
This is known as a trunk link or VLAN
trunking.
Upon reaching the destination Switch the
VLAN ID is removed from the packet by the
adjacent switch and forwarded to the
attached device.
ALTTC/ DX Faculty
11
VLAN Tagging
ALTTC/ DX Faculty
12
VLAN Tagging
No VLAN Tagging
VLAN Tagging
13
VLAN Tagging
There are two major methods of
frame tagging,
Cisco proprietary Inter-Switch Link (ISL)
and
IEEE 802.1Q.
14
VLAN Tagging
ISL
Ethernet Frame
1500 bytes plus 18 byte header (1518
bytes)
IEEE 802.1Q
SA and DA
MACs
ALTTC/ DX Faculty
802.1q
Tag
Type/Length
Field
CRC
New
CRC
15
16
17
18
IEEE 802.1Q
SA and DA
MACs
802.1q
Tag
Type/Length
Field
19
20
Trunking operation
or 802.1Q
21
Non-Trunk Links
Trunk Link
Non-Trunk Links
22
Dynamic VLANs
Dynamic VLANs are used to provide
membership based on the MAC address of
an end user device.
When a device is connected to a switch
port, the switch must query a database to
establish VLAN membership.
A network administrator must assign a
VLAN using the database of a VLAN
Membership Policy Server (VMPS).
Dynamic VLANs allow a great deal of
flexibility and mobility for end users,
ALTTC/ DX Faculty
23
ALTTC/ DX Faculty
24
VTP Modes
Server Mode
VTP-Servers can create, modify, and delete VLANs
and other configuration parameters for the entire
VTP domain;
This information is propagated to the VTP clients in
that same domain.
Client Mode
A VTP client cannot create, change, or delete
VLANs, nor can it save VLAN configurations in
nonvolatile memory (NVRAM).
Transparent Mode
VTP transparent mode is used when a switch does
not need or want to participate in VTP, but is willing
to pass VTP advertisements to other switches.
ALTTC/ DX Faculty
25
26
VTP pruning
ALTTC/ DX Faculty
27
VTP pruning
VTP pruning makes more efficient use of
trunk bandwidth by reducing unnecessary
flooded traffic.
When a Catalyst switch has a port
associated with a VLAN, the switch sends
an advertisement to its neighbor switches
that it has active ports on that VLAN.
The neighbors keep this information,
enabling them to decide if flooded traffic
from a VLAN should use a trunk port or not.
ALTTC/ DX Faculty
28
VTP pruning
ALTTC/ DX Faculty
29
Inter-VLAN Routing
30
10.10.0.11/16
10.20.0.22/16
10.10.0.1/16
10.20.0.1/16
31
32
10.10.0.11/16
10.20.0.22/16
Trunk Link
10.1.0.1/16
10.10.0.1/16
10.20.0.1/16
ALTTC/ DX Faculty
33
Management VLAN
By default, all Ethernet interfaces on
Cisco switches are on VLAN 1.
Notice that User VLANs have been
configured for VLANs other than VLAN
1.
The management VLAN refers to a
separate VLAN for your switches and
routers.
This helps ensure access to these
devices when another VLAN is
experiencing problems.
ALTTC/ DX Faculty
34
ALTTC/ DX Faculty
35