ImplementingVLANsandTrunks
Medium-SizedSwitchedNetworkConstruction
IssuesinaPoorlyDesignedNetworkUnboundedfailuredomainsLargebroadcastdomainsLargeamountofunknown
MACunicasttrafficUnboundedmulticasttrafficManagementand
supportchallengesPossiblesecurity
vulnerabilities
VLANOverviewVLAN=BroadcastDomain=LogicalNetwork(Subnet)SegmentationFlexibilitySecurity
DesigningVLANsforanOrganizationVLANdesignmusttakeintoconsiderationtheimplementation
ofahierarchicalnetworkaddressingscheme.Thebenefitsofhierarchicaladdressingare:EaseofmanagementandtroubleshootingMinimizationoferrorsReducednumberofroutingtableentries
GuidelinesforApplyingIP
AddressSpaceAllocateoneIPsubnetperVLAN.AllocateIPaddressspacesincontiguousblocks.
NetworkTrafficTypesTraffictypestoconsider
whendesignatingVLANs:NetworkmanagementIPtelephonyIPMulticastNormaldataScavengerclass
AdvantagesofVoiceVLANsPhonessegmentedin
separatelogicalnetworksPrividesnetwork
segmentation
andcontrolAllowsadministrators
tocreateand
enforceQoSLetsadministrators
addandenforce
securitypolicies
VLANOperation
802.1QTrunking
802.1QFrame
UnderstandingNativeVLANs
ISLEncapsulationFramesencapsulatedwithISLheaderandCRCSupportformanyVLANs(1024)VLANfieldBPDUbit
VLANMembershipModes
VTPFeatures
Cannotcreate,
change,ordelete
VLANsSendsand
forwards
advertisementsSynchronizesCreateVLANsModifyVLANsDeleteVLANsSendsandforwards
advertisementsSynchronizesCreatelocalVLANsonlyModifylocalVLANsonlyDeletelocalVLANsonlyForwardsadvertisementsDoesnot
synchronizeVTPModes
VTPOperationVTPadvertisementsaresentasmulticastframes.VTPserversandclientsaresynchronizedtothe
latestrevisionnumber.VTPadvertisementsaresentevery5minutesor
whenthereisachange.
VTPPruning
ConfiguringVLANsandTrunksConfigureandverifyVTP.Configureandverify802.1Qtrunks.CreateormodifyaVLAN