Got it

Understanding of VLAN - VLAN Assignment

Latest reply: Oct 14, 2021 08:17:14 843 51 35 0 5

OBJECTIVE


The purpose of this post is to present an introduction to VLAN Assignment.


VLAN Assignment


VLANs can be assigned based on ports, MAC addresses, IP subnets, network protocols, and matching policies.


Table 1 describes differences between VLAN assignment modes.


VLAN Assignment Mode Principle AdvantageDisadvantage 
VLAN assignment based on port numbers

In this mode, VLANs are classified based on the numbers of ports on a switching device.


The network administrator configures a port default VLAN ID (PVID), that is, the default VLAN ID, for each port on the switching device. That is, a port belongs to a VLAN by default.


  • When a data frame reaches a port, it is marked with the PVID if the data frame carries no VLAN tag and the port is configured with a PVID.


  • If the data frame carries a VLAN tag, the switching device will not add a VLAN tag to the data frame even if

the port is configured with a PVID.


Different types of ports process VLAN frames in different manners.

It is simple to define VLAN members.VLANs must be re-configured when VLAN members change locations.
VLAN assignment based on MAC addresses

In this mode, VLANs are classified based on the MAC addresses of network interface cards (NICs). 


The network administrator configures the mappings between MAC addresses and VLAN IDs.


In this case, when a switching device receives an untagged packet, it searches the MAC-VLAN table for a VLAN tag to be added to the packet according to the MAC address of the packet.

When the physical locations of users change, you do not need to re-configure VLANs for the users.


This improves the security of users and increases the flexibility of user access.

  • This mode is applicable to only a simple networking environment where the NIC seldom changes.


  • In addition, all members on the network must be pre-defined.

VLAN assignment based on IP subnetsWhen receiving an untagged packet, a switching device adds a VLAN tag to the packet based on the IP address of the packet.

Packets sent from specified network segments or IP addresses are transmitted in specific VLANs. This decreases

burden on the network administrator and facilitates management.

This mode is applicable to the networking environment where users are distributed in an orderly manner and multiple users are on the same network segment.
VLAN assignment based on protocols

VLAN IDs are allocated to packets received on an interface according to the protocol (suite) type and encapsulation format of the packets. The network administrator configures the mappings between types of protocols and VLAN IDs.


In this case, when a switching device receives an untagged packet, it searches the Protocol-VLAN table for a VLAN tag to be added to the packet according to the protocol of the packet.

The classification of VLANs based on protocols binds the type of services to VLANs.


This facilitates management and maintenance.

  • The network administrator must initially configure the mappings between types of protocols and VLAN IDs.


  • The switch needs to analyze protocol address formats and convert between them. This slows down switch response.

VLAN assignment based on policies (MAC addresses, IP addresses, and interfaces)In this mode, VLANs are classified based on MAC addresses and IP addresses configured on switched and associated with VLANs. Only users matching a policy can be added to a specific VLAN. After users are added to the VLAN, if their IP addresses or MAC addresses are changed, they no longer belong to the VLAN.
  • Policy-based VLAN assignment is of high security. Do not change MAC addresses or IP addresses of users that have been added to VLANs based on MAC addresses and IP addresses.


  • Compared with other VLAN assignment modes, MAC address and IP address-based VLAN assignment has the highest priority.

Each policy needs to be manually configured.


Table 1 - Differences between VLAN assignment modes


If the switch supports multiple VLAN assignment modes, the priority is of policy-based VLAN assignment, MAC address-based VLAN assignment, IP subnet-based VLAN assignment, protocol-based VLAN assignment, and port-based VLAN assignment in a descending order.


  • MAC address-based VLAN assignment and IP subnet-based VLAN assignment have the same priority.


By default, MAC address-based VLAN assignment is preferentially adopted. Alternatively, you can run commands to change priorities of these two VLAN assignment modes to select a VLAN assignment mode.


  • Port-based VLAN assignment has the lowest priority and is the most common VLAN assignment mode.


  • Policy-based VLAN assignment has the highest priority and is the least useful VLAN assignment mode.


Figure 1 shows the process of classifying VLANs.


06-a

Figure 1 - Process of assigning VLAN




--- End

Vlada85
MVE Author Created Jun 6, 2021 18:17:06

Good article, thank you for sharing Understanding of VLAN - VLAN Assignment-3958999-1
View more
  • x
  • convention:

AliBinHussain
AliBinHussain Created Jun 7, 2021 16:16:04 (0) (0)
 
EL.BODO
EL.BODO Created Jun 7, 2021 16:40:28 (0) (0)
 
andersoncf1
andersoncf1 Created Jun 7, 2021 17:20:41 (0) (0)
Thanks friends  
lucian2003
lucian2003 Created Jun 8, 2021 01:00:41 (0) (0)
 
Good job and well done
View more
  • x
  • convention:

AliBinHussain
AliBinHussain Created Jun 7, 2021 16:15:56 (0) (0)
 
EL.BODO
EL.BODO Created Jun 7, 2021 16:40:12 (0) (0)
 
andersoncf1
andersoncf1 Created Jun 7, 2021 17:21:07 (0) (0)
Thanks  
Good
View more
  • x
  • convention:

Saqib123
Saqib123 Created Jun 7, 2021 16:01:10 (0) (0)
 
andersoncf1
andersoncf1 Created Jun 8, 2021 17:08:20 (0) (0)
thanks dear  
Nice
View more
  • x
  • convention:

Saqib123
Saqib123 Created Jun 7, 2021 16:01:18 (0) (0)
 
andersoncf1
andersoncf1 Created Jun 8, 2021 17:08:30 (0) (0)
thanks  
Good share
View more
  • x
  • convention:

Well done!
View more
  • x
  • convention:

well note
View more
  • x
  • convention:

well post
View more
  • x
  • convention:

IndianKid
Moderator Author Created Jun 7, 2021 05:53:57

good job, thanks for valuable info
View more
  • x
  • convention:

Comment

You need to log in to comment to the post Login | Register
Comment

Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " User Agreement."

My Followers

Login and enjoy all the member benefits

Login

Block
Are you sure to block this user?
Users on your blacklist cannot comment on your post,cannot mention you, cannot send you private messages.
Reminder
Please bind your phone number to obtain invitation bonus.