Professional Documents
Culture Documents
Applicazioni Telematiche
Applicazioni Telematiche
Laboratorio
Applicazioni Telematiche
INFOCOM Dept
INFOCOM Dept
Why VLAN?
To limit broadcast and multicast traffic in the network.
VLAN: example
Vith VLAN
Two separeted Virtual LAN (Green and Red)
One Physical LAN (Gray)
One switch
Without VLAN
INFOCOM Dept
VLAN
IEEE 802.1Q standard defines two kinds of VLAN:
1. Port-based VLAN
Switch ports are explicitely assigned to a specifivc VLAN by means of the Port VLAN Identifier (PVID)
2. Protocol-based VLAN
Etherent frames are classified as belonging to a specific VLAN on the basis of the protocol they are carrying (Protocol Id) Each VLAN is a broadcast domain for a specific protocol
INFOCOM Dept
Port-based VLAN
VLAN 10 (PVID=10)
Port 1 Port 2 Port 3 Port 4
VLAN 20 (PVID=20)
Port 5 Port 6
Ports 1, 2, and 3 are assigned to VLAN 10 Ports 4, 5, and 6 are assigned to VLAN 20 Devices attached to ports belonging to different VLANs cannot communicate with each other
INFOCOM Dept
Definitions
Port VLAN Identifier (PVID): identifier that associates frames entering in a port of the switch to a specific VLAN
The PVID is used only if the frame is not a tagged frame
Tagged member: a port that is member of a specific VLAN from which frames are sent adding the TAG
VLAN Tagging
DA SA
VLAN
2 Bytes 2 Bytes
Payloa d
FCS
TPID
User Priority
TCI
CFI 1 bit VLAN ID 12 bits
3 bits
Switch1
Port 1 Port 2 Port 3 Port 4 Port 5 Port 6
Ethernet frames
Switch2
Port 1 Port 2 Port 3 Port 4 Port 5 Port 6
VLAN 20
VLAN 10
Ports 1,2,3 (4,5,6) of Switch1 (Switch2) are untagged members of VLAN 10 and have PVID=10
Ports 1,2,3 (4,5,6) of Switch2 (Switch1) are untagged members of VLAN 20 and have PVID=20
Ports 7 of both switches are Tagged members of both VLAN 10 and VLAN 20
Lab. Applicazioni Telematiche - Prof. Marco Listanti - A.A. 2011/2012
INFOCOM Dept
Port-based VLAN
prima
dopo
INFOCOM Dept
INFOCOM Dept
INFOCOM Dept
Trunk parameters
Native: specifies the native VLAN for that port when it is in trunk mode
Ex.: Switch(config-if)# switchport trunk native vlan 10 It menas PVID=10 and untagged member of VLAN 10
Untagged frames received on that port are classified as belonging to VLAN 10 Frames belonging to VLAN 10 are sent without the tag on that port
Allowed VLANs
If we want to limit allowed VLANs:
Delete all allowed VLANs with the command:
Switch(config-if)# switchport trunk allowed vlan none
Example: Scenario 1
To do
Configure the two switch so as to obtain the two VLANs (Green and Red) Assign addresses to PCs and the two Servers
INFOCOM Dept
Port 1
Port 3
Port 4
Port 2
Switch2
Port 9
To interconnect the two VLANs with each other and with the Internet we need a router with two physical interfaces attached to the same switch
Lab. Applicazioni Telematiche - Prof. Marco Listanti - A.A. 2011/2012
Switch1
Port 0 Port 1
Port 9
Port 2
Port 3
INFOCOM Dept
Port 1
Port 3 Port 9
Port 2
Switch2
In this way we connect just one interface of the router to the sitch configuring port 3 of Switch2 as a Trunk port for Green and Red VLANs
Lab. Applicazioni Telematiche - Prof. Marco Listanti - A.A. 2011/2012
Switch1
Port 0 Port 1
Port 9
Port 2
Port 3
INFOCOM Dept
Sub-interfaces on routers
The Router receives tagged frames on that interface
The physical interface must be divided in two logical su-interfaces belonging to two different IP sub-networks A physical Ethernet interface can be divided in several IP interfaces by using VLANs an sending tagged frames
INFOCOM Dept
Relay Entity
V-LAN V-LAN
IP
IP
IP
MAC PHY
V-LAN V-LAN
IP
IP
IP
MAC PHY
VLAN allows a physical interface to be split in several logical IP intefaces The Relay entity interconnects all IP interfaces performing the forwarding operation
INFOCOM Dept