8‐PortGigabitWeb‐SmartSwitch
23|Page
5 VLAN
AVirtualLocalAreaNetwork(VLAN)isanetworktopologyconfiguredaccordingtoalogicalschemerather
thanthephysicallayout.VLANcanbeusedtocombineanycollectionofLANsegmentsintoan
autonomoususergroupthatappearsasasingleLAN.VLANalsologicallysegmentsthenetworkinto
differentbroadcastdomainssothatpacketsareforwardedonlybetweenportswithintheVLAN.Typically,
aVLANcorrespondstoaparticularsubnet,althoughnotnecessarily.VLANcanenhanceperformanceby
conservingbandwidth,andimprovesecuritybylimitingtraffictospecificdomains.AVLANisacollection
ofendnodesgroupedbylogicinsteadofphysicallocation.Endnodesthatfrequentlycommunicatewith
eachotherareassignedtothesameVLAN,regardlessofwheretheyarephysicallyonthenetwork.
Logically,aVLANcanbeequatedtoabroadcastdomain,becausebroadcastpacketsareforwardedtoonly
membersoftheVLANonwhichthebroadcastwasinitiated.TheIntellinet8‐PortGigabitWeb‐Smart
SwitchsupportsthreetypesofVLANs.
Port‐basedVLANs
Port‐basedVLANlimitstrafficthatflowsintoandoutofswitchports.Thus,alldevicesconnectedtoaport
aremembersoftheVLAN(s)theportbelongsto,whetherthereisasinglecomputerdirectlyconnectedto
aswitch,oranentiredepartment.Onport‐basedVLANs,NICsdonotneedtobeabletoidentify802.1Q
tagsinpacketheaders.NICssendandreceivenormalEthernetpackets.Ifthepacket'sdestinationlieson
thesamesegment,communicationstakeplaceusingnormalEthernetprotocols.Eventhoughthisis
alwaysthecase,whenthedestinationforapacketliesonanotherswitchport,VLANconsiderationscome
intoplaytodecideifthepacketisdroppedbytheSwitchordelivered.
IEEE802.1QVLANs
IEEE802.1Q(tagged)VLANsareimplementedontheSwitch.802.1QVLANsrequiretagging,which
enablesthemtospantheentirenetwork(assumingallswitchesonthenetworkareIEEE802.1Q‐
compliant).VLANsallowanetworktobesegmentedinordertoreducethesizeofbroadcastdomains.All
packetsenteringaVLANwillonlybeforwardedtothestations(overIEEE802.1Qenabledswitches)that
aremembersofthatVLAN,andthisincludesbroadcast,multicastandunicastpacketsfromunknown
sources.VLANscanalsoprovidealevelofsecuritytoyournetwork.IEEE802.1QVLANswillonlydeliver
packetsbetweenstationsthataremembersoftheVLAN.Anyportcanbeconfiguredaseithertaggingor
untagging.TheuntaggingfeatureofIEEE802.1QVLANallowsVLANstoworkwithlegacyswitchesthat
don'trecognizeVLANtagsinpacketheaders.ThetaggingfeatureallowsVLANtospanmultiple802.1Q‐
compliantswitchesthroughasinglephysicalconnectionandallowsSpanningTreetobeenabledonall
portsandworknormally.
Somerelevantterms:
Tagging‐Theactofputting802.1QVLANinformationintotheheaderofapacket.
Untagging‐Theactofstripping802.1QVLANinformationoutofthepacketheader.