VLANs
Overview |
The "LAN Switching" chapter discussed problems inherent(yang berhubungan) in a LAN and possible solutions to improve(memajukan) LAN performance(daya guna). You learned about the advantages and disadvantages of using bridges, switches, and routers for LAN segmentation and the effects of switching, bridging, and routing on network throughput. Finally, you briefly(singkat) learned about the benefits of Fast Ethernet and virtual local-area networks (VLANs). This chapter provides an introduction to VLANs and switched internetworking, compares traditional shared LAN configurations with switched LAN configurations, and discusses the benefits of using a switched VLAN architecture.
Washington Project: VLANs As you begin the chapter on VLANs, think about why VLANs are being introduced. Also think about how, where, and when you might want to use VLANs at an elementary school site. |
3.1 VLANS | |
3.1.1 Existing shared LAN configurations | |
A VLAN is a logical grouping of devices or users that can be grouped by function, department, or application, regardless(tanpa memperhatikan) of their physical segment location. VLAN configuration is done at the switch via software. VLANs are not standardized and require(membutuhkan) the use of proprietary(pemilik) software from the switch vendor. A typical LAN is configured according to the physical infrastructure(prasarana) it is connecting. Users are grouped based on their location in relation to the hub they are plugged in to and how the cable is run to the wiring closet. The router interconnecting each shared(bersama sama) hub typically(khususnya) provides segmentation and can act as a broadcast firewall. The segments created by switches do not. Traditional LAN segmentation does not group users according to their workgroup association or need for bandwidth. Therefore, they share the same segment and contend(berjuang) for the same bandwidth, although(walaupun) the bandwidth requirements(perlu) may vary(berubah ubah) greatly by workgroup or department. | |
3.2 Segmentation with Switching Architectures | |
3.2.1 Grouping geographically separate users into network-wide virtual topologies | |
LANs are increasingly(meluas) being divided(dibagi) into workgroups connected via common backbones to form VLAN topologies. VLANs logically segment(membagi) the physical LAN infrastructure(rangka dasar) into different subnets (or broadcast domains for Ethernet). Initial VLAN implementations(pelaksanaan) offered(diberikan) a port-mapping(pemetaan) capability(mampu) that established(membuat) a broadcast domain between a default group of devices. Current(sekarang) network requirements demand(menuntut) VLAN functionality that covers(mencakup) the entire network. This approach(tiba) to VLANs allows you to group geographically separate users in networkwide virtual topologies. VLAN configurations group users by logical association(gabungan) rather than(lebih lagi) physical location. The majority(sebagian besar) of the networks currently(sekarang) installed provide(memberikan) very limited logical segmentation. Users are commonly grouped based on connections to the shared hub and the router ports between the hubs. This topology provides segmentation only between the hubs, which are typically located on separate floors, and not between users connected to the same hub. This imposes(penentuan) physical constraints(membatasi) on the network and limits how users can be grouped. A few shared-hub architectures have some grouping capability, but they restrict(membatasi) how you configure logically defined(ditetapkan) workgroups. | |
3.2.2 Differences between traditional switched LAN and VLANs |
In a LAN that utilizes(menggunakan) LAN switching devices, VLAN technology is a cost-effective and efficient way of grouping network users into virtual workgroups regardless(tanpa memperhatikan) of their physical location on the network. The graphic shows the difference between LAN and VLAN segmentation. Some of the main differences are as follows:
Using VLAN technology, you can group switch ports and their connected users into logically defined workgroups, such as the following:
You can group these ports and users into workgroups on a single switch or on connected switches. By grouping ports and users together across multiple switches, VLANs can span(menjangkau) single-building infrastructures, interconnected buildings, or even wide-area networks (WANs). |
3.2.3 The transport of VLANs across backbones |
Important to any VLAN architecture is the ability to transport VLAN information between interconnected switches and routers that reside(terletak) on the corporate(hubungan) backbone. These transport capabilities:
The backbone commonly acts as the collection point for large volumes of traffic(lalu lintas). It also carries end-user VLAN information and identification between switches, routers, and directly attached(diberikan) servers. Within the backbone, high-bandwidth, high-capacity links are typically chosen to carry the traffic throughout the enterprise(perusahaan). |
3.2.4 The role(peranan) of routers in VLANs |
The traditional role of a router is to provide firewalls, broadcast management and route processing and distribution. While VLAN switches take on some of these tasks, routers still remain(tetap) vital in VLAN architectures because they provide connected routes between different VLANs. They also connect to other parts of the network that are either(tiap) logically segmented with the more traditional subnet approach(menjelang) or require(membutuhkan) access to remote sites across wide-area links. Layer 3 communication, either embedded(disimpan) in the switch or provided externally, is an integral(utuh) part of any high-performance(daya guna) switching architecture. You can cost-effectively integrate(menggabungkan) external routers into the switching architecture by using one or more high-speed backbone connections. These are typically(khusus) Fast Ethernet, or ATM connections, and they provide benefits by:
VLAN architecture not only provides logical segmentation, but, with careful(teliti) planning, it can greatly enhance(menambah) the efficiency of a network. |
3.2.5 How frames are used in VLANs |
Switches are one of the core(inti) components of VLAN communications. Each switch has the intelligence(kecerdasan) to make filtering(penyaring) and forwarding decisions by frame, based on VLAN metrics defined by network managers. The switch can also communicate this information to other switches and routers within the network. The most common approaches(menemui) for logically grouping users into distinct(berbeda) VLANs are frame filtering and frame identification (frame tagging(label)). Both of these techniques look at the frame when it is either received or forwarded by the switch. Based on the set of rules defined by the administrator, these techniques determine where the frame is to be sent, filtered, or broadcast. These control mechanisms can be centrally administered (with network management software) and are easily implemented throughout(diseluruh) the network. In their early days, VLANs were filter-based and they grouped users based on a filtering table. This model did not scale well because each frame had to be referenced to a filtering table. Frame tagging(label) uniquely(khusus) assigns(memberikan) a VLAN ID to each frame. The VLAN IDs are assigned to each VLAN in the switch configuration by the switch administrator. This technique was chosen by the Institute of Electrical and Electronic Engineers (IEEE) standards group because of its scalability. Frame tagging is gaining(mendapat) recognition(pengenalan) as the standard trunking(batang tubuh) mechanism; in comparison(perbandingan) to frame filtering, it can provide a more scalable solution to VLAN deployment that can be implemented campus-wide. IEEE 802.1q states that frame tagging is the way to implement VLANs. VLAN frame tagging is an approach(jalan) that has been specifically developed for switched communications. Frame tagging places a unique identifier in the header of each frame as it is forwarded throughout (disepanjang)the network backbone. The identifier(pengenalan) is understood(dimengerti) and examined(diperiksa) by each switch prior(utama) to any broadcasts or transmissions(pengiriman) to other switches, routers, or end-station devices. When the frame exits the network backbone, the switch removes the identifier before the frame is transmitted to the target end station. Frame identification functions at Layer 2 and requires little processing or administrative overhead(tambahan). |
3.3 VLAN Implementation | |
3.3.1 The relationship between ports, VLANs, and broadcasts | |
A VLAN makes up a switched network that is logically segmented by functions, project teams, or applications, without regard(memperhatikan) to the physical location of users. Each switch port can be assigned(ditempatkan) to a VLAN. Ports assigned to the same VLAN share broadcasts. Ports that do not belong to that VLAN do not share these broadcasts. This improves(penambahan) the overall(keseluruhan) performance(daya guna) of the network. The following sections discuss three VLAN implementation methods that can be used to assign a switch port to a VLAN. They are:
| |
3.3.2 Why port-centric VLANs make an administrator's job easier |
In port-centric VLANs, all the nodes connected to ports in the same VLAN are assigned to the same VLAN ID. The graphic shows VLAN membership by port, which make an administrator's job easier and the network more efficient because:
|
3.3.3 Static VLANs |
Static VLANs are ports on a switch that you statically assign(ditempatkan) to a VLAN. These ports maintain(memelihara) their assigned VLAN configurations until you change them. Although static VLANs require the administrator to make changes, they are secure(aman), easy to configure, and straightforward(terus terang) to monitor. Static VLANs work well in networks in which moves are controlled and managed(diatur). |
3.3.4 Dynamic VLANs |
Dynamic VLANs are ports on a switch that can automatically determine their VLAN assignments(tugas).
In this lab you will work with Ethernet Virtual Local Area Networks or VLANs. VLANs can be used to separate groups of users based on function rather than physical location.
In this lab you will work with Virtual Local Area Networks (VLANs). You will console into the switch and view the menu options available to manage VLANs and will check the current(sekarang) VLAN configuration. |
3.4 Benefits of VLANs | |
3.4.1 How VLANs make additions, moves, and changes easier | |
Companies are continuously(terus menerus) reorganizing(mereorganisasi). On average, 20% to 40% of the workforce physically moves every year. These moves, additions, and changes are one of a network manager's biggest headaches(persoalan) and one of the largest expenses(biaya) related(dihubungkan) to managing(mengurus) the network. Many moves require recabling, and almost all moves require new station addressing and hub and router reconfigurations. VLANs provide an effective mechanism for controlling these changes and reducing(pengurangan) much of the cost associated with hub and router reconfigurations. Users in a VLAN can share the same network address space(tempat) (that is, the IP subnet), regardless(tanpa memperhatikan) of their location. When users in a VLAN are moved from one location to another, as long as they remain(tetap) within the same VLAN and are connected to a switch port, their network addresses do not change. A location change can be as simple as plugging a user into a port on a VLAN-capable(mampu) switch and configuring the port on the switch to that VLAN. VLANs are a significant(penting) improvement (kemajuan) over(diatas) the typical(khusus) LAN-based techniques used in wiring closets because they require less rewiring, configuration, and debugging. Router configuration is left intact(utuh); a simple move for a user from one location to another does not create any configuration modifications in the router if the user stays in the same VLAN. | |
3.4.2 How VLANs help control broadcast activity |
Broadcast traffic occurs in every network. Broadcast frequency(sering) depends on the types of applications, the types of servers, the amount(banyaknya) of logical segmentation, and how these network resources are used. Although applications have been fine-tuned(distem) over the past few years to reduce the number of broadcasts they send out, new multimedia applications are being developed that are broadcast and multicast intensive. You need to take preventive(pencegahan) measures(tindakan) to ensure against broadcast-related problems. One of the most effective measures is to properly(sebaiknya) segment the network with protective firewalls that, as much as possible, prevent(mencegah) problems on one segment from damaging other parts of the network. Thus(jadi), although one segment may have excessive(terlalu banyak) broadcast conditions, the rest(sisa) of the network is protected with a firewall commonly provided by a router. Firewall segmentation provides reliability(tahan uji) and minimizes the overhead of broadcast traffic, allowing for greater throughput of application traffic. When no routers are placed between the switches, broadcasts (Layer 2 transmissions) are sent to every switched port. This is commonly referred to as a flat(rata) network, where there is one broadcast domain across the entire network. The advantage of a flat network is that it can provide both low-latency and high-throughput performance and it is easy to administer. The disadvantage is that it increases(memperluas) vulnerability(mudah kena serang) to broadcast traffic across all switches, ports, backbone links, and users. VLANs are an effective mechanism for extending firewalls from the routers to the switch fabric (struktur)and protecting the network against potentially(sanggup) dangerous broadcast problems. Additionally, VLANs maintain all the performance benefits of switching. You create firewalls by assigning(menentukan) switch ports or users to specific VLAN groups both within single switches and across multiple connected switches. Broadcast traffic within one VLAN is not transmitted outside the VLAN. Conversely(sebaliknya), adjacent(berbatasan) ports do not receive(menerima) any of the broadcast traffic generated(dihasilkan) from other VLANs. This type of configuration substantially (banyaj) reduces(mengurangi) the overall(keseluruhan) broadcast traffic, frees bandwidth for real(nyata) user traffic, and lowers the overall vulnerability(kena serangan) of the network to broadcast storms(badai). The smaller the VLAN group, the smaller the number of users affected(dipengaruhi) by broadcast traffic activity within the VLAN group. You can also assign VLANs based on the application type and the number of applications broadcasts. You can place users sharing a broadcast-intensive application in the same VLAN group and distribute(menyalurkan) the application across the campus. |
3.4.3 How VLANs can improve network security |
The use of LANs has increased at a very high rate(harga) over the past several years. As a result, LANs often have confidential(rahasia), mission-critical data moving across them. Confidential(rahasia) data requires security through access restriction(batasan). One problem of shared LANs is that they are relatively easy to penetrate(ditembus). By plugging in to a live port, an intrusive user has access to all traffic within the segment. The larger the group, the greater the potential access. One cost-effective and easy administrative technique to increase security is to segment the network into multiple broadcast groups that allows the network manager to:
Implementing this type of segmentation is relatively straightforward(terus terang). Switch ports are grouped together based on the type of applications and access privileges(istimewa). Restricted(batas) applications and resources are commonly placed in a secured(dijamin) VLAN group. On the secured(terlindungi) VLAN, the switch restricts access into the group. Restrictions can be placed based on station addresses, application types, or protocol types. You can add more security enhancements(peningkatan) by using access control lists, which will be discussed in a later chapter. These are especially(utama) useful when communicating between VLANs. On the secured VLAN, the router restricts access to the VLAN as configured on both switches and routers. You can place restrictions on station addresses, application types, protocol types, or even by time of day. |
3.4.4 How VLANs can save money |
Over(diatas) the past several years, network administrators have installed a significant(penting) number of hubs. Many of these devices are being replaced with newer switching technologies. Because network applications require more dedicated(persembahan) bandwidth and performance(hasil) directly(ditunjukkan) to the desktop, these hubs still perform(menyelenggarakan) useful functions in many existing installations. Network managers save money by connecting existing hubs to switches. Each hub segment connected to a switch port can be assigned to only one VLAN. Stations that share a hub segment are all assigned to the same VLAN group. If an individual station needs to be reassigned(ditempatkan kembali) to another VLAN, the station must be relocated(dipindahkan) to the corresponding hub. The interconnected switch fabric(susunan) handles the communication between the switching ports and automatically determines the appropriate(tepat) receiving segments. The more the shared hub can be broken into smaller groups, the greater the microsegmentation and the greater the VLAN flexibility for assigning individual users to VLAN groups. By connecting hubs to switches, you can configure hubs as part of the VLAN architecture. You can also share traffic and network resources directly attached(diberikan) to switching ports with VLAN designations(penunjukan).
In this lab you will learn to display information about current Switch Firmware, learn about switch memory and update options, and how to use a TFTP Server to update a switch to a new version of the Firmware software.
In this lab you will work with Ethernet Virtual Local Area Networks or VLANs. VLANs can be used to separate groups of users based on function rather than physical location. Normally all of the ports on a switch are in the same default VLAN 1. This lab introduces multi-switch VLANs using trunking. |
No comments:
Post a Comment