Thursday, September 18, 2008

VLANs

VLANs


 

Overview

 

The "LAN Switching" chapter discussed problems inherent(yang berhubungan) in a LAN and possible solutions to improve(memajukan) LAN performance(daya guna). You learned about the advantages and disadvantages of using bridges, switches, and routers for LAN segmentation and the effects of switching, bridging, and routing on network throughput. Finally, you briefly(singkat) learned about the benefits of Fast Ethernet and virtual local-area networks (VLANs).

This chapter provides an introduction to VLANs and switched internetworking, compares traditional shared LAN configurations with switched LAN configurations, and discusses the benefits of using a switched VLAN architecture.


Threaded Case Study

Washington Project: VLANs

As you begin the chapter on VLANs, think about why VLANs are being introduced. Also think about how, where, and when you might want to use VLANs at an elementary school site.


 


 

3.1 VLANS

3.1.1 Existing shared LAN configurations 

A VLAN is a logical grouping of devices or users that can be grouped by function, department, or application, regardless(tanpa memperhatikan) of their physical segment location. VLAN configuration is done at the switch via software. VLANs are not standardized and require(membutuhkan) the use of proprietary(pemilik) software from the switch vendor.

A typical LAN is configured according to the physical infrastructure(prasarana) it is connecting. Users are grouped based on their location in relation to the hub they are plugged in to and how the cable is run to the wiring closet. The router interconnecting each shared(bersama sama) hub typically(khususnya) provides segmentation and can act as a broadcast firewall. The segments created by switches do not. Traditional LAN segmentation does not group users according to their workgroup association or need for bandwidth. Therefore, they share the same segment and contend(berjuang) for the same bandwidth, although(walaupun) the bandwidth requirements(perlu) may vary(berubah ubah) greatly by workgroup or department.


 


 

3.2 Segmentation with Switching Architectures

3.2.1 Grouping geographically separate users into network-wide virtual topologies 

LANs are increasingly(meluas) being divided(dibagi) into workgroups connected via common backbones to form VLAN topologies. VLANs logically segment(membagi) the physical LAN infrastructure(rangka dasar) into different subnets (or broadcast domains for Ethernet).
Broadcast frames(susunan) are switched only between ports within the same VLAN.

Initial VLAN implementations(pelaksanaan) offered(diberikan) a port-mapping(pemetaan) capability(mampu) that established(membuat) a broadcast domain between a default group of devices. Current(sekarang) network requirements demand(menuntut) VLAN functionality that covers(mencakup) the entire network. This approach(tiba) to VLANs allows you to group geographically separate users in networkwide virtual topologies. VLAN configurations group users by logical association(gabungan) rather than(lebih lagi) physical location.

The majority(sebagian besar) of the networks currently(sekarang) installed provide(memberikan) very limited logical segmentation. Users are commonly grouped based on connections to the shared hub and the router ports between the hubs. This topology provides segmentation only between the hubs, which are typically located on separate floors, and not between users connected to the same hub. This imposes(penentuan) physical constraints(membatasi) on the network and limits how users can be grouped. A few shared-hub architectures have some grouping capability, but they restrict(membatasi) how you configure logically defined(ditetapkan) workgroups.


 

3.2.2 Differences between traditional switched LAN and VLANs 

In a LAN that utilizes(menggunakan) LAN switching devices, VLAN technology is a cost-effective and efficient way of grouping network users into virtual workgroups regardless(tanpa memperhatikan) of their physical location on the network. The graphic shows the difference between LAN and VLAN segmentation. Some of the main differences are as follows:

  • VLANs work at Layer 2 and Layer 3 of the OSI reference model.
  • Communication between VLANs is provided by Layer 3 routing.
  • VLANs provide a method of controlling network broadcasts.
  • The network administrator assigns(menentukan) users to a VLAN.
  • VLANs can increase network security by defining which network nodes can communicate with each other.

Using VLAN technology, you can group switch ports and their connected users into logically defined workgroups, such as the following:

  • Coworkers in the same department
  • A cross-functional product team
  • Diverse(bermacam) user groups sharing the same network application or software

You can group these ports and users into workgroups on a single switch or on connected switches. By grouping ports and users together across multiple switches, VLANs can span(menjangkau) single-building infrastructures, interconnected buildings, or even wide-area networks (WANs).


 

3.2.3 The transport of VLANs across backbones 

Important to any VLAN architecture is the ability to transport VLAN information between interconnected switches and routers that reside(terletak) on the corporate(hubungan) backbone. These transport capabilities:

  • remove the physical boundaries(batas) between users
  • increase the configuration flexibility of a VLAN solution when users move
  • provide(menyediakan) mechanisms for interoperability between backbone system components.

The backbone commonly acts as the collection point for large volumes of traffic(lalu lintas). It also carries end-user VLAN information and identification between switches, routers, and directly attached(diberikan) servers. Within the backbone, high-bandwidth, high-capacity links are typically chosen to carry the traffic throughout the enterprise(perusahaan).


 

3.2.4 The role(peranan) of routers in VLANs 

The traditional role of a router is to provide firewalls, broadcast management and route processing and distribution. While VLAN switches take on some of these tasks, routers still remain(tetap) vital in VLAN architectures because they provide connected routes between different VLANs. They also connect to other parts of the network that are either(tiap) logically segmented with the more traditional subnet approach(menjelang) or require(membutuhkan) access to remote sites across wide-area links. Layer 3 communication, either embedded(disimpan) in the switch or provided externally, is an integral(utuh) part of any high-performance(daya guna) switching architecture.

You can cost-effectively integrate(menggabungkan) external routers into the switching architecture by using one or more high-speed backbone connections. These are typically(khusus) Fast Ethernet, or ATM connections, and they provide benefits by:

  • Increasing the throughput between switches and routers
  • Consolidating(menggabungkan) the overall(keseluruhan) number of physical router ports required for communication between VLANs

VLAN architecture not only provides logical segmentation, but, with careful(teliti) planning, it can greatly enhance(menambah) the efficiency of a network.


 

3.2.5 How frames are used in VLANs 

Switches are one of the core(inti) components of VLAN communications. Each switch has the intelligence(kecerdasan) to make filtering(penyaring) and forwarding decisions by frame, based on VLAN metrics defined by network managers. The switch can also communicate this information to other switches and routers within the network.

The most common approaches(menemui) for logically grouping users into distinct(berbeda) VLANs are frame filtering and frame identification (frame tagging(label)). Both of these techniques look at the frame when it is either received or forwarded by the switch. Based on the set of rules defined by the administrator, these techniques determine where the frame is to be sent, filtered, or broadcast. These control mechanisms can be centrally administered (with network management software) and are easily implemented throughout(diseluruh) the network.

In their early days, VLANs were filter-based and they grouped users based on a filtering table. This model did not scale well because each frame had to be referenced to a filtering table. Frame tagging(label) uniquely(khusus) assigns(memberikan) a VLAN ID to each frame. The VLAN IDs are assigned to each VLAN in the switch configuration by the switch administrator. This technique was chosen by the Institute of Electrical and Electronic Engineers (IEEE) standards group because of its scalability. Frame tagging is gaining(mendapat) recognition(pengenalan) as the standard trunking(batang tubuh) mechanism; in comparison(perbandingan) to frame filtering, it can provide a more scalable solution to VLAN deployment that can be implemented campus-wide. IEEE 802.1q states that frame tagging is the way to implement VLANs.

VLAN frame tagging is an approach(jalan) that has been specifically developed for switched communications. Frame tagging places a unique identifier in the header of each frame as it is forwarded throughout (disepanjang)the network backbone. The identifier(pengenalan) is understood(dimengerti) and examined(diperiksa) by each switch prior(utama) to any broadcasts or transmissions(pengiriman) to other switches, routers, or end-station devices. When the frame exits the network backbone, the switch removes the identifier before the frame is transmitted to the target end station. Frame identification functions at Layer 2 and requires little processing or administrative overhead(tambahan).


 


 

3.3 VLAN Implementation

3.3.1 The relationship between ports, VLANs, and broadcasts

A VLAN makes up a switched network that is logically segmented by functions, project teams, or applications, without regard(memperhatikan) to the physical location of users. Each switch port can be assigned(ditempatkan) to a VLAN. Ports assigned to the same VLAN share broadcasts. Ports that do not belong to that VLAN do not share these broadcasts. This improves(penambahan) the overall(keseluruhan) performance(daya guna) of the network. The following sections discuss three VLAN implementation methods that can be used to assign a switch port to a VLAN. They are:

  • port-centric
  • static
  • dynamic


 

3.3.2 Why port-centric VLANs make an administrator's job easier 

In port-centric VLANs, all the nodes connected to ports in the same VLAN are assigned to the same VLAN ID. The graphic shows VLAN membership by port, which make an administrator's job easier and the network more efficient because:

  • Users are assigned by port.
  • VLANs are easily administered.
  • It provides increased security between VLANs.
  • Packets do not "leak"(bocor) into other domains.


 

3.3.3 Static VLANs 

Static VLANs are ports on a switch that you statically assign(ditempatkan) to a VLAN. These ports maintain(memelihara) their assigned VLAN configurations until you change them. Although static VLANs require the administrator to make changes, they are secure(aman), easy to configure, and straightforward(terus terang) to monitor. Static VLANs work well in networks in which moves are controlled and managed(diatur).


 

3.3.4 Dynamic VLANs

Dynamic VLANs are ports on a switch that can automatically determine their VLAN assignments(tugas).
Dynamic VLAN functions are based on MAC addresses, logical addressing, or protocol type of the data packets. When a station is initially(pertama) connected to an unassigned(tidak ditentukan) switch port, the appropriate(tepat) switch checks the MAC address entry(masuk) in the VLAN management database and dynamically configures the port with the corresponding(cocok) VLAN configuration. The major benefits(keuntungan) of this approach(jalan) are less administration within the wiring closet when a user is added or moved and centralized(dipusat) notification(pemberitahuan) when an unrecognized user is added to the network. Typically(khusus), more administration is required up front to set up the database within the VLAN management software and to maintain an accurate(teliti) database of all network users.


Lab Activity


 

In this lab you will work with Ethernet Virtual Local Area Networks or VLANs. VLANs can be used to separate groups of users based on function rather than physical location.


 


 


Lab Activity

In this lab you will work with Virtual Local Area Networks (VLANs). You will console into the switch and view the menu options available to manage VLANs and will check the current(sekarang) VLAN configuration.


 


 

3.4 Benefits of VLANs

3.4.1 How VLANs make additions, moves, and changes easier

Companies are continuously(terus menerus) reorganizing(mereorganisasi). On average, 20% to 40% of the workforce physically moves every year. These moves, additions, and changes are one of a network manager's biggest headaches(persoalan) and one of the largest expenses(biaya) related(dihubungkan) to managing(mengurus) the network. Many moves require recabling, and almost all moves require new station addressing and hub and router reconfigurations.

VLANs provide an effective mechanism for controlling these changes and reducing(pengurangan) much of the cost associated with hub and router reconfigurations. Users in a VLAN can share the same network address space(tempat) (that is, the IP subnet), regardless(tanpa memperhatikan) of their location. When users in a VLAN are moved from one location to another, as long as they remain(tetap) within the same VLAN and are connected to a switch port, their network addresses do not change. A location change can be as simple as plugging a user into a port on a VLAN-capable(mampu) switch and configuring the port on the switch to that VLAN.

VLANs are a significant(penting) improvement (kemajuan) over(diatas) the typical(khusus) LAN-based techniques used in wiring closets because they require less rewiring, configuration, and debugging. Router configuration is left intact(utuh); a simple move for a user from one location to another does not create any configuration modifications in the router if the user stays in the same VLAN.


 

3.4.2 How VLANs help control broadcast activity 

Broadcast traffic occurs in every network. Broadcast frequency(sering) depends on the types of applications, the types of servers, the amount(banyaknya) of logical segmentation, and how these network resources are used. Although applications have been fine-tuned(distem) over the past few years to reduce the number of broadcasts they send out, new multimedia applications are being developed that are broadcast and multicast intensive.

You need to take preventive(pencegahan) measures(tindakan) to ensure against broadcast-related problems. One of the most effective measures is to properly(sebaiknya) segment the network with protective firewalls that, as much as possible, prevent(mencegah) problems on one segment from damaging other parts of the network. Thus(jadi), although one segment may have excessive(terlalu banyak) broadcast conditions, the rest(sisa) of the network is protected with a firewall commonly provided by a router. Firewall segmentation provides reliability(tahan uji) and minimizes the overhead of broadcast traffic, allowing for greater throughput of application traffic.

When no routers are placed between the switches, broadcasts (Layer 2 transmissions) are sent to every switched port. This is commonly referred to as a flat(rata) network, where there is one broadcast domain across the entire network. The advantage of a flat network is that it can provide both low-latency and high-throughput performance and it is easy to administer. The disadvantage is that it increases(memperluas) vulnerability(mudah kena serang) to broadcast traffic across all switches, ports, backbone links, and users.

VLANs are an effective mechanism for extending firewalls from the routers to the switch fabric (struktur)and protecting the network against potentially(sanggup) dangerous broadcast problems. Additionally, VLANs maintain all the performance benefits of switching.

You create firewalls by assigning(menentukan) switch ports or users to specific VLAN groups both within single switches and across multiple connected switches. Broadcast traffic within one VLAN is not transmitted outside the VLAN. Conversely(sebaliknya), adjacent(berbatasan) ports do not receive(menerima) any of the broadcast traffic generated(dihasilkan) from other VLANs. This type of configuration substantially (banyaj) reduces(mengurangi) the overall(keseluruhan) broadcast traffic, frees bandwidth for real(nyata) user traffic, and lowers the overall vulnerability(kena serangan) of the network to broadcast storms(badai).

The smaller the VLAN group, the smaller the number of users affected(dipengaruhi) by broadcast traffic activity within the VLAN group. You can also assign VLANs based on the application type and the number of applications broadcasts. You can place users sharing a broadcast-intensive application in the same VLAN group and distribute(menyalurkan) the application across the campus.


 

3.4.3 How VLANs can improve network security 

The use of LANs has increased at a very high rate(harga) over the past several years. As a result, LANs often have confidential(rahasia), mission-critical data moving across them. Confidential(rahasia) data requires security through access restriction(batasan). One problem of shared LANs is that they are relatively easy to penetrate(ditembus). By plugging in to a live port, an intrusive user has access to all traffic within the segment. The larger the group, the greater the potential access. One cost-effective and easy administrative technique to increase security is to segment the network into multiple broadcast groups that allows the network manager to:

  • Restrict(membatasi) the number of users in a VLAN group
  • Prevent(mencegah) another user from joining(keikutsertaan) without first receiving approval(persetujuan) from the VLAN network management application
  • Configure all unused ports to a default low-service VLAN

Implementing this type of segmentation is relatively straightforward(terus terang). Switch ports are grouped together based on the type of applications and access privileges(istimewa). Restricted(batas) applications and resources are commonly placed in a secured(dijamin) VLAN group. On the secured(terlindungi) VLAN, the switch restricts access into the group. Restrictions can be placed based on station addresses, application types, or protocol types.

You can add more security enhancements(peningkatan) by using access control lists, which will be discussed in a later chapter. These are especially(utama) useful when communicating between VLANs. On the secured VLAN, the router restricts access to the VLAN as configured on both switches and routers. You can place restrictions on station addresses, application types, protocol types, or even by time of day.


 

3.4.4 How VLANs can save money 

Over(diatas) the past several years, network administrators have installed a significant(penting) number of hubs. Many of these devices are being replaced with newer switching technologies. Because network applications require more dedicated(persembahan) bandwidth and performance(hasil) directly(ditunjukkan) to the desktop, these hubs still perform(menyelenggarakan) useful functions in many existing installations. Network managers save money by connecting existing hubs to switches.

Each hub segment connected to a switch port can be assigned to only one VLAN. Stations that share a hub segment are all assigned to the same VLAN group. If an individual station needs to be reassigned(ditempatkan kembali) to another VLAN, the station must be relocated(dipindahkan) to the corresponding hub. The interconnected switch fabric(susunan) handles the communication between the switching ports and automatically determines the appropriate(tepat) receiving segments. The more the shared hub can be broken into smaller groups, the greater the microsegmentation and the greater the VLAN flexibility for assigning individual users to VLAN groups. By connecting hubs to switches, you can configure hubs as part of the VLAN architecture. You can also share traffic and network resources directly attached(diberikan) to switching ports with VLAN designations(penunjukan).


 


Lab Activity

In this lab you will learn to display information about current Switch Firmware, learn about switch memory and update options, and how to use a TFTP Server to update a switch to a new version of the Firmware software.


 


 


Lab Activity


 

In this lab you will work with Ethernet Virtual Local Area Networks or VLANs. VLANs can be used to separate groups of users based on function rather than physical location. Normally all of the ports on a switch are in the same default VLAN 1. This lab introduces multi-switch VLANs using trunking.


 

Summary

 

Now that you completed this chapter, you should have a firm understanding of the following:

  • An Ethernet switch is designed to physically segment a LAN into individual collision domains.
  • A typical LAN is configured according to the physical infrastructure(prasarana) it connects.
  • In a LAN that uses LAN switching devices, VLAN technology is a cost-effective and efficient way of grouping network users into virtual workgroups, regardless (tanpa memperhatikan)of their physical location on the network.
  • VLANs work at Layer 2 and Layer 3 of the OSI reference model.
  • Important to any VLAN architecture is the ability to transport VLAN information between interconnected switches and routers that reside(terletak) on the corporate(berhubungan) backbone.
  • The problems associated with shared LANs and switches are causing traditional LAN configurations to be replaced with switched VLAN networking configurations.
  • The most common approaches(menemui) for logically grouping users into distinct(jelas) VLANs are frame filtering, frame tagging, and frame identification.
  • There are three main types of VLANs: port-centric VLANs, static VLANs, and dynamic VLANs.
  • VLANs provide the following benefits:
    • They reduce administration costs related to solving problems associated with moves, additions, and changes.
    • They provide controlled broadcast activity.
    • They provide workgroup and network security.
    • They save money by using existing hubs.


 


 


Threaded(urutan) Case Study

 
 

Washington School District(daerah) Project Task: User Requirements, Site Maps, Handling Graphics

After this chapter, you will continue studying the TCS Overview for the Washington School District Network Design Project, focusing on the LAN requirements. You should begin work on your school site wiring diagrams (physical topologies). And you will need to learn some basics about graphics file formats and graphics manipulation. You need to complete the following tasks:

  1. Familiarize yourself with the LAN sections (and User Counts) of the TCS Overview , including any activities your Instructor assigns.
  2. Individually, begin working on your site wiring diagrams. Then discuss them as a group.
  3. Understand the different graphic file formats involved in how your Instructor wants you to submit your Web-based TCS Solutions.
  4. Apply the CCNA Certification Exam Learning Objectives to your specific design. This will require a paragraph on how the learning objectives relate to your design. Learning objectives can be grouped together for the purpose of explanation(keterangan). In this way, you will be studying for the CCNA Certification Exam as you work through the case study.

CCNA Certification Exam Learning Objectives (*** are explicit CCNA Exam objectives; unmarked are knowledge assumed by the exam):

VLANs

No comments: