Custom Search

News World

Aug 31, 2009

(2) VLANS VIRTUAL LOCAL AREA NETWORKS OPERATION

CONFIGURATION PROCESS

A VLAN (Virtual Local Area Networks Operation )requires a series of configuration steps in order to begin operating. Cabletron Systems VLAN aware SmartSwitches do not default to VLAN mode, and the VLAN operation must be configured and activated through software management.

1. Defining a Virtual Local Area Networks Operation
A VLAN must exist and have a unique identity before any ports or rules can be assigned to it. The Administrator defines a VLAN by assigning it a unique identification number (the VLAN ID) and an optional name. The VLAN ID is the number that will identify data frames originating from,

and intended for, the ports that will belong to this new VLAN.

2. Assigning Ports to a Virtual Local Area Networks Operation
Now that a VLAN has been created, individual ports are given membership in the VLAN. This is accomplished through software management by associating a VLAN ID with each port on the VLAN aware switch. This combination of the switch port’s identification and the VLAN ID becomes the Port VLAN ID (PVID).

At the same time, the Administrator configures any needed trunk ports to consider themselves members of every VLAN. The configuration of trunk ports is very important in multiswitch VLAN configurations where VLAN membership applies to users across several switches.

3. Customizing the Virtual Local Area Networks Operation’s Forwarding List
Once the ports that will participate in the VLAN have been associated with a VLAN ID, the VLAN Forwarding List can be customized. The information in the Forwarding List tells the VLAN aware switch what ports are eligible to forward traffic for that particular VLAN.

4 Customizing the Port’s Egress List
When the VLAN Forwarding List is fully configured, the Egress List for each port may be customized if needed. The entries in the Egress List allow traffic classified into specific VLANs to be transmitted out the port.

5 Setting the Operational Mode
Once the VLANs are in place, the operation of the switch is dependent upon the method of operation specified by the Administrator. All port based VLAN switches can be set to one of two operational modes: Open and Secure. The mode configuration of a switch determines how the switch handles the frames that it receives.

Aug 30, 2009

(1) VLANS VIRTUAL LOCAL AREA NETWORKS OPERATION

This chapter describes the operation of a VLAN switch and discusses the operations that a VLAN switch performs in response to both normal and VLAN-originated network traffic.

DESCRIPTION

Port based VLAN operation is slightly different than the operation of traditional switched networking systems. These differences are due to the importance of keeping track of each transmission’s VLAN membership as it passes from switch to switch or from port to port within a switch.

VLAN COMPONENTS

Before describing the operation of a port based VLAN, it is important to understand the basic elements that are combined to make up an 802.1Q VLAN.

1. Stations

A station is any end unit that belongs to a network. In the vast majority of cases, stations are the computers through which the users access the network.

2. Switches

In order to configure a group of stations into a VLAN, the stations must be connected to VLAN aware switches. It is the job of the switch to classify received frames into VLAN memberships and transmit frames, according to VLAN membership, with or without a VLAN Tag Header.


VLANS VIRTUAL LOCAL AREA NETWORKS TERMS

To fully understand the operation and configuration of port based VLANs, it is essential to understand the meanings of several key terms.

VLAN ID

A unique number (between 1 and 4095) that identifies a particular VLAN.

VLAN Name

A 32-character alphanumeric name associated with a VLAN ID. The VLAN Name is intended to make user-defined VLANs easier to identify and remember.

Tag Header (VLAN Tag)

A field within a frame that identifies the VLAN the frame has been classified into. The Tag Header is inserted into the frame directly after the Source MAC address field. Twelve bits of the Tag Header are the VLAN ID. The remaining bits are other control information.

Tagged Frame

A data frame that contains a Tag Header. The Tag Header can be added to the data frame by a VLAN aware switch to any frame received from a port that is a member of a VLAN.

Untagged Frame

A data frame that does not have a Tag Header inserted into it.

Port VLAN ID (PVID)

An identification that encompasses a particular switch port’s identification (port 6, module 2) and that port’s VLAN membership. This identification is used to classify incoming untagged frames when they are received.

Default VLAN

The VLAN to which all ports are assigned upon initialization. The Default VLAN has a VLAN ID of 1.

Forwarding List

A list of the ports on a particular device that are eligible to transmit frames for a selected VLAN. The Forwarding List identifies what ports are associated with a single VLAN for frame transmission purposes.

Egress List

A per port list of all eligible VLANs that can be forwarded out one specific port and the frame format of transmissions for that port.The Egress List specifies what VLANs are associated with a single port for frame transmission purposes.

Filtering Database

A database structure within the switch that keeps track of the associations between MAC addresses, VLAN eligibilities, and interface (port) numbers. The Filtering Database is referred to when a VLAN aware switch makes a forwarding decision on a frame.

1Q Trunk

A connection between 802.1Q switches that passes only traffic with a VLAN Tag Header inserted in the frame.

1d Trunk

A connection from a switch that passes only untagged traffic.

Aug 29, 2009

BENEFITS AND RESTRICTIONS VLANS VIRTUAL LOCAL AREA NETWORKS

The primary benefit of the port based VLAN technology is the localization of traffic that it provides. This function can offer improvements in security and performance to stations assigned to a VLAN.

While the localization of traffic to VLANs can improve security and performance, it imposes some restrictions on network devices that participate in the VLAN. If a switch is operating in the “secure mode,” a group of users assigned to a single VLAN can communicate with one another freely, but cannot communicate with users on other VLANs without the services of a Network Layer (OSI Layer 3) routing device to make the connection between the VLANs. In the “open” mode, this restriction does not apply.

In order to set up a VLAN, all the network switch devices that are assigned to the VLAN must support the prestandard IEEE 802.1Q specification for port based VLANs. Before you attempt to implement a VLAN strategy, ensure that the switches under consideration support the 802.1Q specification.

IT Conversations

Moneycontrol Latest News

Latest new pages on Computer Hope

Latest from Infoworld

Door Lock

Door Lock Import Top Door Lock from China Contact Quality Manufacturers Now