User manual

C
HAPTER
6
| VLAN Configuration
IEEE 802.1Q VLANs
– 94 –
ES-2000 Series
network devices or the host at the other end of the connection supports
VLANs. Then assign ports on the other VLAN-aware network devices along
the path that will carry this traffic to the same VLAN(s). However, if you
want a port on this switch to participate in one or more VLANs, but none of
the intermediate network devices nor the host at the other end of the
connection supports VLANs, then you should add this port to the VLAN as
an untagged port.
N
OTE
:
VLAN-tagged frames can pass through VLAN-aware or VLAN-
unaware network interconnection devices, but the VLAN tags should be
stripped off before passing it on to any end-node host that does not
support VLAN tagging.
Figure 46: VLAN Compliant and VLAN Non-compliant Devices
VLAN Classification – When the switch receives a frame, it classifies the
frame in one of two ways. If the frame is untagged, the switch assigns the
frame to an associated VLAN (based on the default VLAN ID of the
receiving port). But if the frame is tagged, the switch uses the tagged
VLAN ID to identify the port broadcast domain of the frame.
Port Overlapping – Port overlapping can be used to allow access to
commonly shared network resources among different VLAN groups, such
as file servers or printers. Note that if you implement VLANs which do not
overlap, but still need to communicate, you can connect them by enabled
routing on this switch.
Untagged VLANsUntagged VLANs are typically used to reduce
broadcast traffic and to increase security. A group of network users
assigned to a VLAN form a broadcast domain that is separate from other
VLANs configured on the switch. Packets are forwarded only between ports
that are designated for the same VLAN. Untagged VLANs can be used to
manually isolate user groups or subnets.
Forwarding Tagged/Untagged Frames
If you want to create a small port-based VLAN for devices attached directly
to a single switch, you can assign ports to the same untagged VLAN.
However, to participate in a VLAN group that crosses several switches, you
should create a VLAN for that group and enable tagging on all ports.
VA
VA: VLAN Aware
VU: VLAN Unaware
VA
tagged frames
VA VUVA
tagged
frames
untagged
frames