Chapter 10 Interface
Figure 130 Example: Before VLAN
A
B
C
In this example, there are two physical networks and three departments A, B, and C. The physical networks are connected to hubs, and the hubs are connected to the router.
Alternatively, you can divide the physical networks into three VLANs.
Figure 131 Example: After VLAN
A
B
Each VLAN is a separate network with separate IP addresses, subnet masks, and gateways. Each VLAN also has a unique identification number (ID). The ID is a
•Traffic inside each VLAN is
•Traffic between VLANs (or between a VLAN and another type of network) is
This approach provides a few advantages.
•Increased performance - In VLAN 2, the extra switch should route traffic inside the sales department faster than the router does. In addition, broadcasts are limited to smaller, more logical groups of users.
•Higher security - If each computer has a separate physical connection to the switch, then broadcast traffic in each VLAN is never sent to computers in another VLAN.
| 197 |
ZyWALL USG 1000 User’s Guide | |
|
|