You are on page 1of 15

VLAN

What Do We Mean by
Bandwidth Management?
Brings back router-oriented benefits into our networks
while improving upon router deficiencies
• Classic router benefits
– Broadcast containment and policy
Enforcement (security)
• Classic router deficiencies
– Change management
– Complex administration
– Cost
• How?
• Layer 3 handling, VLANs, routing, filtering, ...
VLANs for Bandwidth Allocation
There’s More to VLAN Technology than Tagging

Logical
Management Views

Level of
Configuration
Automation

Membership
Defines Membership Policies
Criteria

Spanning
Explicit and Implicit
Boxes
Policy-Based Virtual LANs
Backbone LAN • Defines membership policies
• Flexible VLAN policy definition
– Port grouping
– MAC address grouping
– Protocol grouping
– Application control
• Mature technology

Port Group Protocol Group

Address Groups
Protocol-Based VLAN Definitions
• VLANs defined by
existing paradigms
– Layer 3 ID,
NetBIOS layer 2 simplicity
IPX • Support for routable and
Subnet 2
non-routable protocols
IP – IP subnet, AppleTalk, IPX,
Subnet 1 Subnet 4 Subnet 7 DECnet, NetBIOS,
Netbeui, XNS, SNA,
Vines, X.25, and Wildcard
• Non-proprietary
implementation
How Does Routing Fit In?
Q: Why?
A1: You can’t flatten a network overnight
A2: Routing allows directed unicasts to traverse VLANs

Routing R
Bridging 1 2 3 4

VLAN-B
IP Subnet A =

VLAN-A
Where Should the Router Reside?
• Inside the Switch: Multinetting, Per-port
configuration, ASIC+RISC preprocessing,
no Hops, no links, lower cost
• Outside the Switch: More routing protocols
Internal External
Routing R Router R
Bridging 1 2 B 3 4

Switch 5
1 2 B 3 4

VLAN-A VLAN-B

VLAN-A VLAN-B
Routing/VLAN Structure
Routing • Logical protocol-based
R
Engine VLAN engines

158.101.20.X 158.101.10.X
• Route between VLANs
– IP, IPX, Appletalk
VLAN Engine VLAN Engine
• Switch within VLANs
Switching
Engine S S • Flexibly combined with
other definition options
MAC MAC MAC • ASIC accelerated
158.101.20.1 158.101.10.2 158.101.10.1
158.101.20.2 158.101.20.3
Using Protocol-Based VLANs
to Allocate Bandwidth
Broadcast Containment
IP-Based
Fileservers
Support
AppleTalk,
but isolate it

VLANs vs. Filters


AT Network • VLAN Advantage
– Protocol dependent
– Less maintenance
IP Subnet A IP Subnet A • Address filter advantage
– Simple, clear

AppleTalk Must Be
Supported on a Majority-IP LAN
User Benefits
• Support required protocols
• Optimize response time for other protocols
Using Protocol-Based VLANs to
Allocate Bandwidth
Broadcast Firewalls
IP-Based
Fileservers
Support
AppleTalk,
but isolate it
VLANs vs. Filters
• VLAN advantage
NetBIOS – Easily span boxes
– Protocol dependent
• Port group
IP Subnet A IP Subnet A filter advantage
– Simple, clear

Test Lab
Generating NetBIOS Traffic
User Benefits
• Improved application and desktop response time
• Reduce exposure to lab broadcast storms
Using Protocol-Based VLANs
to Enforce Policy
Restricted Subnet Access
Engineering Server;
IP subnet B
HR Server;
IP Subnet A

Only Members of VLANs vs. Filters


“IP Subnet A” VLAN IP Subnet A • VLAN advantage
can Access HR Server – Protocol dependent
– Less maintenance

IP Subnet B
• Address group
IP Subnet A filter advantage
– Tighter security
IP Subnet B

User Benefits
• Policy enforcement for secure access
Using Protocol-Based VLANs to Ease
the Adds/Moves/Change Problem
Moving an IP Device - No Station Reconfiguration

9
9
7 5 4
IP Subnet A
IP Subnet A

IP Subnet B

IP Subnet B
User Needs to Move
Across Building
User Benefit
• No workstation changes needed
VLANs on the Backplane

Inter swich Link (ISL)

RISC
Relationship between VLANs and ELANs
• ELANs are simply another switch port
– ELANs are flat, fast and simple, but suffer the same
broadcast issues as
• Bandwidth issues addressed by same techniques
– Filters, VLANs, IP Multicasting, Integral Routing
• VLANs particularly sensible in ATM
– Each ELAN is a “Virtual” path to begin with
– ELAN configuration is flexible
– ELANs are meant to be parallel
• The same issues driving high function switching
apply to (LANE-based) ATM networks
TELSYS

You might also like