Professional Documents
Culture Documents
08 VLANPrinciplesand Configuration
08 VLANPrinciplesand Configuration
08 VLANPrinciplesand Configuration
and Configuration
Contents
1 What Is VLAN
2 VLAN Principles
3 VLAN Applications
Page 3 Copyright © 2020 Huawei Technologies Co., Ltd. All rights reserved.
Issues Facing a Traditional Ethernet
Layer 2 broadcast
domain
SW4 SW5
Unicast
frame PC2
SW6 SW7
Valid traffic
Junk traffic
(Note: This example assumes that the MAC address entry of PC2 exists in the
MAC address tables of SW1, SW3, and SW7 rather than SW2 and SW5.)
Page 4 Copyright © 2020 Huawei Technologies Co., Ltd. All rights reserved.
VLAN
VLAN
(multiple broadcast
domains)
SW4 SW5
Broadcast
frame PC2
SW6 SW7
Page 5 Copyright © 2020 Huawei Technologies Co., Ltd. All rights reserved.
Contents
1 What Is VLAN
2 VLAN Principles
• VLAN Identification
• VLAN Assignment
3 VLAN Applications
Page 6 Copyright © 2020 Huawei Technologies Co., Ltd. All rights reserved.
VLAN Implementation
1 2 3 4 5 5 4 3 2 1
Frame
Page 7 Copyright © 2020 Huawei Technologies Co., Ltd. All rights reserved.
VLAN Tag
• How does a switch identify the VLAN to which a received frame belongs?
VLAN Tag
Which VLAN does the
received frame belong SW2 • IEEE 802.1Q defines a 4-byte
to?
VLAN tag for Ethernet
20 frames, enabling switches to
identify the VLANs to which
VLAN 20 VLAN 10
Page 8 Copyright © 2020 Huawei Technologies Co., Ltd. All rights reserved.
VLAN Frame
Original Ethernet frame Destination Source Length/
MAC address MAC address Type Data FCS
(untagged frame)
Page 9 Copyright © 2020 Huawei Technologies Co., Ltd. All rights reserved.
VLAN Implementation
Tagged frame
Switch1 Switch2
Tagged frame
1 2 3 4 5 5 4 3 2 1
Page 11 Copyright © 2020 Huawei Technologies Co., Ltd. All rights reserved.
Contents
1 What Is VLAN
2 VLAN Principles
• VLAN Identification
• VLAN Assignment
3 VLAN Applications
Page 12 Copyright © 2020 Huawei Technologies Co., Ltd. All rights reserved.
VLAN Assignment Methods
• How are VLANs assigned on a network?
SW1
VLAN
Assignment VLAN 10 VLAN 20
Method
Interface-based
GE 0/0/1 and GE 0/0/3 GE 0/0/2 and GE 0/0/4
assignment
MAC address-based
MAC 1 and MAC 3 MAC 2 and MAC 4
assignment
IP subnet-based
10.0.1.* 10.0.2.*
assignment
Protocol-based
PC1 PC2 PC3 PC4 IP IPv6
assignment
10.0.1.1 10.0.2.1 10.0.1.2 10.0.2.2
MAC1 MAC2 MAC3 MAC4 Policy-based 10.0.1.* + GE 0/0/1 + 10.0.2.* + GE 0/0/2 + MAC
assignment MAC 1 2
Page 13 Copyright © 2020 Huawei Technologies Co., Ltd. All rights reserved.
Interface-based VLAN Assignment
路由器
10 SW1 SW2
Interface-based VLAN Assignment
PVID 1 PVID 1
• Principles
PVID 10 PVID 10 PVID 20 PVID 20
▫ VLANs are assigned based on interfaces.
Page 15 Copyright © 2020 Huawei Technologies Co., Ltd. All rights reserved.
MAC Address-based VLAN Assignment
Mapping Between MAC Addresses and
VLAN IDs on SW1
MAC Address VLAN ID MAC Address-based VLAN Assignment
MAC 1 10
MAC 2 10 • Principles
... ... ▫ VLANs are assigned based on the source
SW1 SW2 MAC addresses of frames.
10
• Mapping table
GE0/0/1 GE0/0/2
▫ Records the mapping between MAC
addresses and VLAN IDs.
Page 16 Copyright © 2020 Huawei Technologies Co., Ltd. All rights reserved.
Layer 2 Ethernet Interface Types
Interface Types
• Access interface
• Trunk interface
• Hybrid interface
Access Trunk
interface interface
Page 17 Copyright © 2020 Huawei Technologies Co., Ltd. All rights reserved.
Access Interface
Frame receiving Frame sending
Inside a switch Inside a switch Inside a switch Inside a switch
;
10 10 10 20
Page 18 Copyright © 2020 Huawei Technologies Co., Ltd. All rights reserved.
Trunk interface
防火墙 Frame receiving Frame sending
Inside a switch Inside a switch Inside a switch Inside a switch
10 10 10 20
After receiving an After receiving a tagged If the VLAN ID of the frame is If the VLAN ID of the frame is
untagged frame frame the same as the PVID of the different from the PVID of the
interface interface
Untagged Tagged
frame
10 frame
Page 19 Copyright © 2020 Huawei Technologies Co., Ltd. All rights reserved.
Example for Frame Processing on Access and Trunk Interfaces
• Describe how inter-PC access is implemented in this example.
10
SW1 SW2 Trunk Interfaces on SW1 and SW2
20
List of Permitted VLAN IDs
PVID 1 PVID 1
PVID 10 PVID 20 PVID 10 PVID 20 1
VLAN ID 10
20
Trunk Access
interface interface
Page 21 Copyright © 2020 Huawei Technologies Co., Ltd. All rights reserved.
Hybrid Interface
Frame receiving Frame sending
Inside a switch Inside a switch Inside a switch Inside a switch
10 10 10 20
After receiving an After receiving a tagged If the VLAN ID of the frame If the VLAN ID of the frame
untagged frame frame is in the list of VLAN IDs is in the list of VLAN IDs
permitted by the interface permitted by the interface
Untagged Tagged
frame
10 frame
Page 22 Copyright © 2020 Huawei Technologies Co., Ltd. All rights reserved.
Example for Frame Processing on Hybrid Interfaces
List of VLAN IDs Permitted by Interfaces on SW1
Port1 Port2 Port3
10
Untagged Untagged Tagged
SW1 20
SW2
Port 3 Port 3
PVID 1 PVID 1 1 1 10
VLAN VLAN VLAN
Port 1 Port 2 10 20 10
Port 1 ID ID ID
PVID 10 PVID 20
PVID 100 100 100 100
Port1 Port3
Untagged Tagged
PC1 PC2 Server
VLAN 10 VLAN 20 VLAN 100 1 10
VLAN
VLAN 10 20
ID
ID 20 100
Hybrid Interface
100
Page 24 Copyright © 2020 Huawei Technologies Co., Ltd. All rights reserved.
Summary
Access Interface Trunk Interface Hybrid Interface
Frame receiving Frame receiving Frame receiving
▫ Untagged frame: adds a tag with the VID ▫ Untagged frame: adds a tag with the VID ▫ Untagged frame: adds a tag with the VID
being the PVID of the interface and permits being the PVID of the interface and checks being the PVID of the interface and checks
the frame. whether the VID is in the list of permitted whether the VID is in the list of permitted
VLAN IDs. If yes, permits the frame. If not, VLAN IDs. If yes, permits the frame. If not,
▫ Tagged frame: checks whether the VID in the
discards it. discards it.
tag of the frame is the same as the PVID of
the interface. If they are the same, permits ▫ Tagged frame: checks whether the VID is in ▫ Tagged frame: checks whether the VID is in
the frame; otherwise, discards the frame. the list of permitted VLAN IDs. If yes, permits the list of permitted VLAN IDs. If yes, permits
the frame. If not, discards it. the frame. If not, discards it.
Page 25 Copyright © 2020 Huawei Technologies Co., Ltd. All rights reserved.
Contents
1 What Is VLAN
2 VLAN Principles
3 VLAN Applications
Page 26 Copyright © 2020 Huawei Technologies Co., Ltd. All rights reserved.
VLAN Planning
• VLAN assignment rules • Tips for VLAN assignment
▫ By service To improve VLAN ID continuity, you can
associate VLAN IDs with subnets during VLAN
▫ By department
assignment.
▫ By application
• Example for VLAN planning
Assume that there are three buildings: administrative building with offices, classrooms, and financing sections, teaching
building with offices and classrooms, and office building with offices and financing sections. Each building has one
access switch, and the core switch is deployed in the administrative building.
The following table describes the VLAN plan.
VLAN ID IP Address Segment Description
1 X.16.10.0/24 VLAN to which office users belong
2 X.16.20.0/24 VLAN to which the users of the financing department belong
3 X.16.30.0/24 VLAN to which classroom users belong
100 Y.16.100.0/24 VLAN to which the device management function belongs
Page 27 Copyright © 2020 Huawei Technologies Co., Ltd. All rights reserved.
Interface-based VLAN Assignment
• Applicable scenario:
Internet
▫ There are multiple enterprises in a building. These
enterprises share network resources to reduce costs. Router
Networks of the enterprises connect to different
interfaces of the same Layer 2 switch and access the
L3 Switch
Internet through the same egress device.
• VLAN assignment:
L2 Switch
▫ To isolate the services of different enterprises and
ensure service security, assign interfaces connected to
the enterprises' networks to different VLANs. In this
way, each enterprise has an independent network,
Enterprise 1 Enterprise 2 Enterprise 3
and each VLAN works as a virtual work group.
VLAN 2 VLAN 3 VLAN 4
Page 28 Copyright © 2020 Huawei Technologies Co., Ltd. All rights reserved.
MAC Address-based VLAN Assignment
• Applicable scenario:
▫ The network administrator of an enterprise Enterprise
Network
assigns PCs in the same department to the same
VLAN. To improve information security, the GE0/0/1
enterprise requires that only employees in the SW1
specified department be allowed to access specific
network resources.
GE0/0/3
• VLAN assignment:
▫ To meet the preceding requirement, configure
MAC address-based VLAN assignment on SW1,
preventing new PCs connected to the network PC1 PC2 PC3 PC4
001e-10dd-dd01 001e-10dd-dd02 001e-10dd-dd03 001e-10dd-dd04
from accessing the network resources.
VLAN 10
Page 29 Copyright © 2020 Huawei Technologies Co., Ltd. All rights reserved.
Contents
1 What Is VLAN
2 VLAN Principles
3 VLAN Applications
Page 30 Copyright © 2020 Huawei Technologies Co., Ltd. All rights reserved.
Basic VLAN Configuration Commands
1. Create one or more VLANs.
This command creates a VLAN and displays the VLAN view. If the VLAN to be created already exists, this
command directly displays the VLAN view.
• The value of vlan-id is an integer ranging from 1 to 4094.
Page 31 Copyright © 2020 Huawei Technologies Co., Ltd. All rights reserved.
Basic Access Interface Configuration Commands
In the interface view, set the link type of the interface to access.
In the interface view, configure a default VLAN for the interface and add the interface to the VLAN.
• vlan-id: specifies an ID for the default VLAN. The value is an integer ranging from 1 to 4094.
Page 32 Copyright © 2020 Huawei Technologies Co., Ltd. All rights reserved.
Basic Trunk Interface Configuration Commands
In the interface view, set the link type of the interface to trunk.
In the interface view, configure a default VLAN for the trunk interface.
Page 33 Copyright © 2020 Huawei Technologies Co., Ltd. All rights reserved.
Basic Hybrid Interface Configuration Commands
1. Set the link type of an interface.
In the interface view, set the link type of the interface to hybrid.
In the interface view, add the hybrid interface to specified VLANs in untagged mode.
In the interface view, add the hybrid interface to specified VLANs in tagged mode.
Page 34 Copyright © 2020 Huawei Technologies Co., Ltd. All rights reserved.
Contents
1 What Is VLAN
2 VLAN Principles
3 VLAN Applications
Page 35 Copyright © 2020 Huawei Technologies Co., Ltd. All rights reserved.
Case1:Configuring Interface-based VLAN Assignment
Page 36 Copyright © 2020 Huawei Technologies Co., Ltd. All rights reserved.
Creating VLANs
Page 37 Copyright © 2020 Huawei Technologies Co., Ltd. All rights reserved.
Configuring Access and Trunk Interfaces
Configure access interfaces and add the
interfaces to corresponding VLANs.
[SW1] interface GigabitEthernet 0/0/1
SW1 SW2
GE0/0/3 GE0/0/3 [SW1-GigabitEthernet0/0/1] port link-type access
PVID 1 PVID 1 [SW1-GigabitEthernet0/0/1] port default vlan 10
[SW1]display vlan
SW1 SW2 The total number of vlans is : 3
GE0/0/3 GE0/0/3
PVID 1 PVID 1 -------------------------------------------------------------------------------
U: Up; D: Down; TG: Tagged; UT: Untagged;
MP: Vlan-mapping; ST: Vlan-stacking;
GE0/0/1 GE0/0/2 GE0/0/1 GE0/0/2
PVID 10 PVID 20 PVID 10 PVID 20 #: ProtocolTransparent-vlan; *: Management-vlan;
-------------------------------------------------------------------------------
VID Type Ports
-------------------------------------------------------------------------------
1 common UT:GE0/0/3(U) ……
10 common UT:GE0/0/1(U)
TG:GE0/0/3(U)
PC1 PC2 PC3 PC4 20 common UT:GE0/0/2(U)
VLAN 10 VLAN 20 VLAN 10 VLAN 20 TG:GE0/0/3(U)
……
Page 39 Copyright © 2020 Huawei Technologies Co., Ltd. All rights reserved.
Case2:Configuring Interface-based VLAN Assignment
Page 40 Copyright © 2020 Huawei Technologies Co., Ltd. All rights reserved.
Configuring Hybrid Interfaces (1)
SW1 configuration:
SW1 SW2
GE0/0/3 GE0/0/3
PVID 1 PVID 1 [SW1] vlan batch 10 20 100
[SW1] interface GigabitEthernet 0/0/1
GE0/0/1 GE0/0/2
PVID 10 PVID 20 GE0/0/1 [SW1-GigabitEthernet0/0/1] port link-type hybrid
PVID 100 [SW1-GigabitEthernet0/0/1] port hybrid pvid vlan 10
[SW1-GigabitEthernet0/0/1] port hybrid untagged vlan 10 100
[SW1-GigabitEthernet0/0/1] interface GigabitEthernet 0/0/2
[SW1-GigabitEthernet0/0/2] port link-type hybrid
[SW1-GigabitEthernet0/0/2] port hybrid pvid vlan 20
[SW1-GigabitEthernet0/0/2] port hybrid untagged vlan 20 100
PC1 PC2 Server
VLAN 10 VLAN 20 VLAN 100 [SW1-GigabitEthernet0/0/2] interface GigabitEthernet 0/0/3
[SW1-GigabitEthernet0/0/3] port link-type hybrid
[SW1-GigabitEthernet0/0/3] port hybrid tagged vlan 10 20 100
Page 41 Copyright © 2020 Huawei Technologies Co., Ltd. All rights reserved.
Configuring Hybrid Interfaces (2)
Page 42 Copyright © 2020 Huawei Technologies Co., Ltd. All rights reserved.
Verifying the Configuration
[SW1]display vlan
The total number of vlans is : 4
SW1 GE0/0/3 GE0/0/3
SW2 -----------------------------------------------------------------------------------------
PVID 1 PVID 1 U: Up; D: Down; TG: Tagged; UT: Untagged;
MP: Vlan-mapping; ST: Vlan-stacking;
GE0/0/1 GE0/0/2
PVID 10 PVID 20 GE0/0/1 #: ProtocolTransparent-vlan; *: Management-vlan;
PVID 100 -----------------------------------------------------------------------------------------
VID Type Ports
-----------------------------------------------------------------------------------------
1 common UT:GE0/0/1(U) GE0/0/2(U) GE0/0/3(U) ……
10 common UT:GE0/0/1(U)
TG:GE0/0/3(U)
20 common UT:GE0/0/2(U)
PC1 PC2 Server
TG:GE0/0/3(U)
VLAN 10 VLAN 20 VLAN 100
100 common UT:GE0/0/1(U) GE0/0/2(U)
TG:GE0/0/3(U)
……
Page 43 Copyright © 2020 Huawei Technologies Co., Ltd. All rights reserved.
Basic VLAN Configuration Commands
1. Associate a MAC address with a VLAN.
Page 44 Copyright © 2020 Huawei Technologies Co., Ltd. All rights reserved.
Example for Configuring MAC Address-based VLAN
Assignment
• Networking requirements:
Enterprise
Network ▫ The network administrator of an enterprise assigns PCs in
the same department to the same VLAN. To improve
GE0/0/1
information security, the enterprise requires that only
SW1
employees in the department be allowed to access the
network resources of the enterprise.
GE0/0/3
Page 45 Copyright © 2020 Huawei Technologies Co., Ltd. All rights reserved.
Creating a VLAN and Associating MAC Addresses with the VLAN
[SW1] vlan 10
[SW1-vlan10] mac-vlan mac-address 001e-10dd-dd01
[SW1-vlan10] mac-vlan mac-address 001e-10dd-dd02
[SW1-vlan10] mac-vlan mac-address 001e-10dd-dd03
PC1 PC2 PC3
[SW1-vlan10] quit
001e-10dd-dd01 001e-10dd-dd02 001e-10dd-dd03
VLAN 10
Page 46 Copyright © 2020 Huawei Technologies Co., Ltd. All rights reserved.
Adding Interfaces to the VLAN and Enabling
MAC Address-based VLAN Assignment
Page 47 Copyright © 2020 Huawei Technologies Co., Ltd. All rights reserved.
Verifying the Configuration
Page 48 Copyright © 2020 Huawei Technologies Co., Ltd. All rights reserved.
Summary
• This course describes the VLAN technology, including the functions, identification,
assignment, data exchange, planning, application, and basic configuration of
VLANs.
• The VLAN technology can divide a physical LAN into multiple broadcast domains
so that network devices in the same VLAN can directly communicate at Layer 2,
while devices in different VLANs cannot.
Page 51 Copyright © 2020 Huawei Technologies Co., Ltd. All rights reserved.