Cisco: VLAN’s
What Is a VLAN?
A virtual LAN (VLAN) is a logical LAN, or a logical subnet. It defines
a broadcast domain. A physical subnet is a group of devices that shares
the same physical wire. A logical subnet is a group of switch ports
assigned to the same VLAN, regardless of their physical location in a
switched network.
Two types of VLANs are:
End-to-end VLAN—VLAN members are assigned by function
and can reside on different switches. They are used when hosts are
assigned to VLANs based on functions or workgroups, rather than
physical location. VLANs should not extend past the Building
Distribution submodule. Figure 2-1 shows end-to-end VLANs.
Local VLAN—Hosts are assigned to VLANs based on their location,
such as a floor in a building. A router accomplishes sharing
of resources between VLANs. This type is typically found in the
Building Access submodule. Figure 2-2 shows an example of local
VLANs.
Best Practices
VLAN networks need many of the same considerations that normal
Ethernet lines demand. For instance, VLANs should have one IP subnet.
By supplying consecutive subnets to VLANs, the routing advertisements
can be summarized (which has many benefits to convergence).
A stereotypical description of capacity requirements is possible. Access
ports are assigned to a single VLAN and should be Fast Ethernet or
faster. Ports to the distribution layer should be Gigabit Ethernet or
better. Core ports are Gigabit Etherchannel or 10-Gig Ethernet.
Remember that uplink ports need to be able to handle all hosts communicating
concurrently, and remember that although VLANs logically
separate traffic, traffic in different VLANs can still experience
contention with other VLANs when both VLANs travel over the same
trunk line.
Take into account the entire traffic pattern of applications found in your
network. For instance, Voice VLANs pass traffic to a remote Call
Manager. Multicast traffic has to communicate back to the routing
process and possibly call upon a Rendezvous Point.
Creating a VLAN in Global
Config Mode
VLANs must be created before they may be used. VLANs may be
created in global configuration mode or in VLAN database mode.
Creating VLANs in global configuration is easy—just identify the
VLAN number and name it!
(config)#vlan 12
(config-vlan)#name MYVLAN
Assigning Ports to VLANs
When statically assigning ports to VLANs, first make it an access port,
and then assign the port to a VLAN. At the interface configuration prompt:
(config-if)#switchport mode access
(config-if)#switchport access vlan 12
The commands are similar when using dynamic VLAN assignment. At
interface configuration mode:
(config-if)#switchport mode access
(config-if)#switchport access vlan dynamic
If you use dynamic, you must also enter the IP address of the VMPS
server at global configuration mode:
(config-if)#vmps server ip address
Verifying VLAN Configuration
To see a list of all the VLANs and the ports assigned to them, use the
command show vlan. To narrow down the information displayed, you
can use these keywords after the command: brief, id, vlan-number, or
name vlan-name:
ASW# show vlan brief
VLAN Name Status Ports
—— ———————————————— ————- ———————
————————
1 default active Fa0/1, Fa0/2, Fa0/3,
Fa0/10,Fa0/11,Fa0/12
20 VLAN0020 active Fa0/5,Fa0/6,Fa0/7
21 VLAN0021 active Fa0/8,Fa0/9
1002 fddi-default active
1003 trcrf-default active
1004 fddinet-default active
1005 trbrf-default active