Chapter1VLANConguration
ItconnectstwodevicesthatcanidentifyVLANtagsandcar-
riesseveralVLAN’sservices.Ittransmitstaggedframesonly
toseveralVLANs.Themostcommontrunklinkistheonebe-
tweentwoVLANswitches.
3.HybridLink
Ittransmitsbothtaggedanduntaggedframes.Foragiven
VLAN,however ,itonlytransmitsframesofthesametype.
DefaultVLAN
ZXR105900EhasadefaultVLANinitially,whichhasthefollowing
features:
�VLANIDas1
�VLANnameasVLAN0001
�Allportsincluded
�Untaggedbydefaultonallports
PVLAN
Toimprovenetworksecurity,messagesamongdifferentusersshall
beseparated.ThetraditionalmethodistoassignaVLANtoeach
user .Themethodhasobviouslimitation,whichcanbeseenfrom
thefollowingaspects:
1.Atpresent,IEEE802.1Qstandardsupportsutmost4094
VLANs,whichlimitsthenumberofusersandnetworkexpan-
sion.
2.EachVLANcorrespondstooneIPsubnet,sovastdividedsub-
netswillcausethewasteofIPaddresses.
3.PlanningandmanagementtoamassofVLANsandIPsubnets
isextremelycomplicated.
PVLAN(PrivateVLAN)technologyisdevelopedtosolvetheseprob-
lems.
PVLANdividestheportsinVLANintothreetypes:theportcon-
nectingtotheuseriscalledIsolatePort,theportconnectingtoa
groupofusersthatneedinterconnectionandintercommunication
iscalledCommunityPortandtheportconnectingtotheupstream
routeriscalledPromiscuousPort.Theisolatedportcommunicates
withthepromiscuousportonly,butnotwithanyotherisolated
portorcommunityport.Communityportcancommunicatewith
promiscuousportandanyothercommunityport,butnotwithiso-
latedport.ThusportsinthesameVLANareseparated.Theuser
whoconnectswithisolatedportcanonlycommunicatewithits
defaultgateway,theuserwhoconnectscommunityportcanin-
terconnectandintercommunicate.Networksecurityisensured.
ZXR105900Esupports20PVLANgroups,eachgrouphavingcus-
tomizedisolatedportsandatmost256isolatedports,16commu-
nityportsand8promiscuousports.
CondentialandProprietaryInformationofZTECORPORATION3