Professional Documents
Culture Documents
VLAN Ramirez Vallejo Villacres Guerra
VLAN Ramirez Vallejo Villacres Guerra
Integrantes:
Brayan Ramírez
Luis Vallejo
Juan Villacrés
José Guerra
Introduction
The Local Area Network (LAN) we once knew starts to take a different shape.
Each VLAN created on a switch is a separate network. This means that a separate
broadcast domain is created for each VLAN that exists. Network broadcasts, by default,
are filtered from all ports on a switch that are not members of the same VLAN and this is
why VLANs are very common in today's large network as they help isolate network
segments between each other.
2
Objectives
General purpose:
Specific objectives:
3
4
How VLAN Works?
5
Traffic from multiple VLANs can traverse a link that interconnects two switches by using
VLAN tagging. A VLAN tag is a unique identifier that indicates the VLAN to which a frame
belongs. A VLAN tag is included in the header of every frame sent by an end-station on a
VLAN.
On receiving a tagged frame, the switch inspects the frame header and, based on the
VLAN tag, identifies the VLAN. The switch then forwards the frame to the destination in the
identified VLAN. If the destination MAC address is unknown, the switch limits the flooding
of the frame to ports that belong to the identified VLAN.
6
For example, in this figure, if a member of VLAN
10 on Floor 1 sends a frame for a member of
VLAN 10 on Floor 2, Switch 1 inspects the frame
header for the VLAN tag (to determine the VLAN)
and the destination MAC address. The
destination MAC address is not known to Switch
1.
7
Tipes of VLANs
Management VLAN
A best practice is to set up a separate VLAN for management traffic like monitoring,
system logging, SNMP, and other potentially sensitive management tasks. In addition
to the security benefits, this ensures that bandwidth for management will be available
even when user traffic is high.
8
Data VLAN
Also known as a user VLAN, the data VLAN is designated only for user-generated data.
How you group your data VLANs (such as by department or workgroup, for example) will
depend on your organization’s structure and business processes.
Voice VLAN
If your organization uses voice over IP (VoIP), you’ll want to have a separate voice VLAN.
This will preserve bandwidth for other applications and ensure VoIP quality.
9
Default VLAN
This can refer to one of two types. Typically, the default VLAN refers to the one that all of
the ports on a device belong to when it is switched on. On most switches, this default is
VLAN 1 and should be changed for security reasons.
Native VLAN
The native VLAN is the one into which untagged traffic will be put when it’s received on a
trunk port. This makes it possible for your VLAN to support legacy devices or devices that
don’t tag their traffic like some wireless access points and simply network attached
devices.
10
Benefits
Performance
11
Simplified Administration
Most of the Network costs are result of adding, moving and changing users. If a user is
moved within a VLAN, reconfiguration of routers is unnecessary. In addition, depending on
the type of VLAN, other administrative work can be reduced or eliminated.
Reduced Costs
VLAN's can be used to create broadcast domains which eliminate the need for expensive
routers.
12
Security
VLAN's can also be used to control broadcast domains, set up firewalls, restrict access,
and inform the network manager of an intrusion
13
VLAN Trunking Protocol
14
VTP opera en 3 modos distintos:
VTP Client
VTP Server VTP Client Transparen
t
15
VTP Server
Modo por
defecto
Crear,
Autenticacion
eliminar o
MD5
modificar
Configuració
Debe existir 1
n Switch
servidor al
mismo
menos
domino
16
VTP Client
No puede crear,
Sincronizar esta SMS VTP
eliminar o
información. recibidos.
modificar Vlans.
17
Cliente VTP Transparente
18
Dominio del VTP
Router o Switch
capa 3 define
Publicaciones VTP
limite de cada
dominio.
19
Publicaciones del VTP
Distribuir y sincronizar
Configuraciones
Jerarquía de publicaciones
de la VLAN
20
Depuración del VTP
21
Enlace Troncal
22
23
Detalles de Trama 802.1Q.
24
Verification problems with VLANs
Inconsistencies of the native VLAN: The ports are configured with different native VLAN
Inconsistencies the trunking mode: A trunk port is configured with trunk mode "off" link and
the other with the mode "active" trunk.
VLAN and IP subnets: End user devices configured with incorrect IP addresses will not have
network connectivity.
VLAN trunking permittedThe list of allowed VLAN on a trunk has not been updated with
current requirements link VLAN trunk.
25
Drawbacks of Vlans
Proprietary solutions.
Standardizing up.
26
Routing between VLANs
27
Routing between VLANs
28
Routing between VLANs
29
Process
Each VLAN is its own subnet and broadcast domain, which means that frames broadcast
onto the network are only switched between the ports within the same VLAN.
30
En una red tradicional que utiliza VLAN múltiples para segmentar el tráfico de la red en
dominios de broadcast lógicos, el enrutamiento se realiza mediante la conexión de
diferentes interfaces físicas del router a diferentes puertos físicos del switch
31
Enrutador
Las subinterfaces son interfaces virtuales múltiples, asociadas a una interfaz física. Estas
interfaces están configuradas en software en un router configurado en forma
independiente.
32
El router realiza el enrutamiento entre VLAN al aceptar el tráfico etiquetado de la VLAN
en la interfaz troncal proveniente del switch adyacente y enrutar en forma interna entre
las VLAN, mediante subinterfaces.
33
El Switch capa 3 realiza el enrutamiento entre VLAN al aceptar el tráfico etiquetado de
la VLAN en la interfaz SVI para cada vlan.
34
Conclusions
The use of vlan’s is very important in the management of network, this concept
allows us to distribute the necessary IPs to each of the devices in the network.
Therefore, it is important to know how to route the packets within that network, and
how the hosts communicate according to their needs.
Implementing routing between networks is very easy, assigning a LAN interface to
the VLAN router, then enabling them to communicate and finally a device that
commutes the packets.
It is important to know that the entanglement between networks is not supported by
very old series of routers, such as the past 1600, 1700 and 2500. In contrast, the
current ones already allow it, taking into account that the number is limited, and if
there are more interfaces For routing that VLAN, you can use additional protocols
such as 802.10q or use a superior switch.
35
Bibliography
Íñigo, G. J., Barceló, O. J. M., & Cerdà, A. L. (2008). Estructura de redes de computadores. Retrieved from
http://bibliotecavirtual.ups.edu.ec:2619
Anderson, E. (7 de 10 de 2010). severfault.com. Obtenido de
https://serverfault.com/questions/188350/how-do-vlans-work
Muso. (14 de Junio de 2018). Descripcion General del VTP. Obtenido de Descripcion General del VTP:
http://musso.blogspot.com/
36