Professional Documents
Culture Documents
10-Switching & VLANs
10-Switching & VLANs
6/8/2011
Agenda
Address Learning
Forwarding
Filtering
Spanning Tree Protocol
Forwarding/Filtering
Loop Avoidance
6/8/2011
ADDRESS LEARNING
Table is initially
Empty
1
2
aaaa
dddd
bbbb
4
1
cccc
6/8/2011
2
3
bbbb
4
1
3
cccc
dddd
MAC Address
I want to send to
cccc
aaaa
aaaa
2
bbbb
dddd
cccc
6/8/2011
MAC Address
aaaa
2
aaaa
bbbb
3
4
cccc
1
3
cccc
dddd
Reply to
aaaa
MAC Address
aaaa
2
aaaa
bbbb
3
4
cccc
1
dddd
3
cccc
Reply to
aaaa
6/8/2011
aaaa
Port
MAC Address
aaaa
dddd
bbbb
cccc
1
dddd
bbbb
3
cccc
LAYER 2 FORWARDING
6/8/2011
aaaa
I want to
send to
bbbb
1.
Port
MAC Address
aaaa
dddd
bbbb
cccc
bbbb
dddd
cccc
2. Finds it
3. Forward Frame out ONLY the
associated port
Port
MAC Address
aaaa
dddd
bbbb
cccc
aaaa
I want to
send to
bbbb
bbbb
dddd
cccc
2
6/8/2011
MAC Address
aaaa, dddd
aaaa
bbbb
cccc
bbbb
Hub
dddd
3
cccc
4
6/8/2011
Port
MAC Address
aaaa, dddd
2
3
bbbb
cccc
bbbb
Hub
dddd
I dont need to
do anything
cccc
LOOP AVOIDANCE
6/8/2011
10
6/8/2011
11
6/8/2011
Switches:
Bridges:
Cutthrough
Store-andforward
Store-andforward
12
6/8/2011
Cut-through Switching
The fastest way to forward frames
Looks at only the first 6 bytes (destination
MAC address) before forwarding
No error checking
Destination
MAC Address
Rest of Frame
Forwarding Decision
Fragment-free Switching
Waits for the first 64 bytes before forwarding
Catches most collisions
Limited error checking
Destination
MAC Address
64
Bytes
Rest of Frame
Forwarding Decision
13
6/8/2011
Store-and-Forward Switching
Slower but more reliable than the cut-through
Reads entire frame and performs a CRC check
If CRC check fails discard frame
Complete Frame
CRC
Forwarding Decision
Review
Address Learning
Forwarding
Filtering
Spanning Tree Protocol
Frame Switching
14
6/8/2011
15
6/8/2011
Port mirroring
Port authentication
16
6/8/2011
Bridging Function
Breakup Collision Domain
Address Learning
Bridges
Switches
Forwarding
Filtering
Loop Avoidance
Switches
17
6/8/2011
18
6/8/2011
IP Camera
IP
Telephone
Wireless AP
(with Power
Injector)
19
6/8/2011
20
6/8/2011
Broadcast Frames
Broadcast Storms
21
6/8/2011
22
6/8/2011
Spanning-Tree Operation
One root bridge per broadcast domain.
One root port per nonroot bridge.
One designated port per segment.
23
6/8/2011
Bridge
Priority
MAC
Address
24
6/8/2011
Management and
support challenges
Possible security
vulnerabilities
25
6/8/2011
26
6/8/2011
VLAN Operation
Access
Access
10
11
12
VLAN 1
27
6/8/2011
VLAN 1
VLAN 15
VLAN 10
10
11
12
VLAN 33
VLAN 1
VLAN 10
VLAN 15
10
11
12
VLAN 33
VLAN 1
28
6/8/2011
VLAN TRUNKING
29
6/8/2011
802.1Q Trunking
802.1Q Frame
16-Bits
3-Bits
12-Bits
30
6/8/2011
IDS
31
6/8/2011
Denied
Allowed
Minicomputer
Authentication
Server
32
6/8/2011
802.1x
Authentication
Server
802.1x
Supplicant
Minicomputer
Review
Basic Layer-2 Switching
Advance Switch Features
Power over Ethernet
The Spanning Tree Protocol
VLAN and VLAN Trunking
Port mirroring
Port authentication
33