You are on page 1of 10

LAN Local Area Networks

The issue with broadcast traffic in the LAN…


LAN Networks
ROUTER
External
Networks
ENG Default Gateway SALES Default Gateway
IP Address: 10.10.10.1 IP Address: 192.168.10.1

ENG PC3
IP Address: 10.10.10.12

Ethernet Switch

ENG PC1 ENG PC2 SALES PC1 SALES PC2


IP Address: 10.10.10.10 IP Address: 10.10.10.11 IP Address: 192.168.10.11 IP Address: 192.168.10.10
VLAN Virtual Local Area Networks

We can increase performance and security in the LAN by implementing


VLANs on our switches
VLANs segment the LAN into separate broadcast domains at layer 2
An access VLAN is configured on ports where an end host is plugged in
Only traffic for that specific VLAN will be sent out an access port
The configuration is all on the switch, the end host is not VLAN aware
VLAN Virtual Local Area Networks
ROUTER
ENG VLAN External
SALES VLAN ENG Default Gateway SALES Default Gateway
Networks

IP Address: 10.10.10.1 IP Address: 192.168.10.1

ENG PC3
IP Address: 10.10.10.12

Ethernet Switch

ENG PC1 ENG PC2 SALES PC1 SALES PC2


IP Address: 10.10.10.10 IP Address: 10.10.10.11 IP Address: 192.168.10.11 IP Address: 192.168.10.10
What about the links between switches?
ROUTER
ENG VLAN External
ENG Default Gateway
SALES VLAN IP Address: 10.10.10.10 SALES Default Gateway
Networks

IP Address: 192.168.10.1
ENG PC3
IP Address: 10.10.10.12

ENG PC1 SALES PC1


IP Address: 10.10.10.10 IP Address: 192.168.10.11

Ethernet Switch

SALES PC2 ENG PC2


IP Address: 192.168.10.10 IP Address: 10.10.10.11
Dot1Q Trunks
ROUTER
ENG VLAN External
ENG Default Gateway
SALES VLAN IP Address: 10.10.10.10 SALES Default Gateway
Networks

IP Address: 192.168.10.1
TRUNK
ENG PC3
IP Address: 10.10.10.12

ENG PC1 SALES PC1


IP Address: 10.10.10.10 IP Address: 192.168.10.11

Ethernet Switch

SALES PC2 ENG PC2


IP Address: 192.168.10.10 IP Address: 10.10.10.11
Dot1Q Trunks

Dot1Q trunks are configured on the links between switches where we


need to carry traffic for multiple VLANs
When the switch forwards the traffic to another switch, it tags it in the
layer 2 Dot1Q header with the correct VLAN
The receiving switch will only forward the traffic out ports that are in
that VLAN
Hypervisors ‐ VLAN Aware Hosts

End hosts are typically members of only one VLAN and are not VLAN
aware
A special case is virtualized hosts, where there are virtual machines in
different subnets on the host
In this case we need to trunk the VLANs down to the host
Hypervisors ‐ VLAN Aware Hosts
ROUTER
ENG VLAN External
SALES VLAN ENG Default Gateway SALES Default Gateway
Networks

IP Address: 10.10.10.1 IP Address: 192.168.10.1


TRUNK
Physical
Ethernet Switch
Trunk

Virtual Switch

ENG VM SALES VM
IP Address: 10.10.10.10 IP Address: 192.168.10.11

VMware Host

You might also like