ZyXEL Communications VES-1616 manual Port-based Vlan across multiple switches

Page 28

ZyXEL

VES-1616/24FA-5x Series Support Notes

Port-based VLAN across multiple switches

Port-based VLAN is specific only to the switch on which it was created. Thus, port-based VLAN cannot cross multiple switches. The following figure shows an MTU network example. For network security, subscribers are isolated from each other except for the gateway. There are two switches, Switch-2 and Switch-3, that support port-based VLAN and an uplink to a non-port-based VLAN switch, Switch-1.

For Switch-2, ports 1, 2, and 3 are allowed to communicate with uplink port 4, but not with other ports.

zSwitch-2 VLAN 1 member port: port 1 and port 4

zSwitch-2 VLAN 2 member port: port 2 and port 4

zSwitch-2 VLAN 3 member port: port 3 and port 4

For Switch-3, ports 2, 3, and 4 are allowed to communicate with uplink port 1, but not with other ports.

zSwitch-3 VLAN 1 member port: port 2 and port 1

zSwitch-3 VLAN 2 member port: port 3 and port 1

zSwitch-2 VLAN 3 member port: port 4 and port 1

Host A cannot communicate with Host B due to the port-based VLAN implementation on Switch-2. Host C cannot communicate with Host D due to the port-based VLAN implementation on Switch-3. However, the uplink ports on both Switch-2 and Switch-3 connect to the non- VLAN Switch-1. Hosts A and B is able to communicate with Hosts C and D through the non-VLAN switch because port-based VLAN cannot cross multiple switches.

To provide security between switches, you must install another port-based VLAN switch for the uplink. Each port on the uplink switch also should be separated into different VLANs, except for the port connection to the gateway. So subscribers can only connect to the gateway for Internet access but not communicate with each other.

All contents copyright 2008 ZyXEL Communications Corporation.

27

Image 28
Contents VES-1616/24FA-5x Series Vdsl Switch ZyXEL VES-1616/24FA-5x Series Support Notes Classifier & Policy rule setup on your Switch Switch Management and Maintenance Firmware UpgradeRestore a Configuration File ZyXEL Backing Up a Configuration File Load Factory Defaults General Networking Dhcp Relay Option 82 ApplicationSwitch settings Network Port Dhcp Server Dhcp ClientIP Commander setup ZyXEL ZyXEL ZyXEL Enter a name and description for the new rule ZyXEL Next select Dhcp Option in the Keywords field An Add Dhcp Option Rule screen displays ZyXEL Click Next in the screen that displays ZyXEL ZyXEL You can choose to enable Ddns service on the Dhcp server Click Finish to complete the rule creation Separating a physical network into multiple Virtual networks Case Port-based Vlan definition Port-based Vlan across multiple switches ZyXEL PC Z ZyXEL ZyXEL Configuring the Switch Using the CLI Tag-based Vlan Overview ZyXEL Ingress Process Forwarding ProcessVID Vlan ID Egress Process VEES-1616/24FA-5x Series Support Notes Answer ZyXEL Configuration screen for switch 2 is shown as follows ZyXEL ZyXEL Vlan Stacking Overview Company XX branch Company YY branchSwitch a Switch BSwitch C Switch DSwitch H ZyXEL ZyXEL ZyXEL ZyXEL ZyXEL ZyXEL ZyXEL ZyXEL ZyXEL ZyXEL ZyXEL ZyXEL Network Scenario ZyXEL ZyXEL ZyXEL ZyXEL IP Multicasting Configuring Igmp snooping in your switch IgmpCPE ZyXEL Overview of MVR Dynamic Mode Compatible mode Join OperationLeave Operation Immediate Leave OperationConfiguration via Web ZyXEL ZyXEL ZyXEL ZyXEL Setting, and activate the Igmp Snooping VES-1616FA-54config# vlanVES-1616FA-54config-vlan# fixed VES-1616FA-54config#igmpsnoopingTriple play Application Vlan IDZyXEL ZyXEL ZyXEL ZyXEL ZyXEL ZyXEL ZyXEL ZyXEL ZyXEL Vlan ID ZyXEL ZyXEL ZyXEL Broadcast storm Filtering Database Instability Select a root bridge Select a designated port on each segment ZyXEL Switching security MAC Limit ZyXEL Setting up 802.1x Radius Authentication ZyXEL ZyXEL ZyXEL Classifier & Policy rule setup on your Switch ZyXEL ZyXEL Centralized Management Introduction to SNMPc and NetAtlas System Architecture EMS Overview Adding a new device in SNMPc Map Object Properties Read/Write Access Mode Read/write Community Device Selection Rootmap FAQ ZyXEL Using the Web Configurator ZyXEL