Solved

VLAN , VLAN Tagging how it works

Posted on 2013-01-08
12
635 Views
Last Modified: 2013-01-26
Hello Experts,

 I am not familiar with Networking concepts , but I need to understand how this VLAN stuff works between switches ?

Below are my questions

1. Can I assign multiple VLAN to a single port in a switch? If yes then how the traffic will be recongised?

2. Do we need to connect the device to a switch port according to the VLAN in which they belong?

3. How the VLAN Traffic will travel between switches?

I will be asking more question depending on the responses :)

Thanks.,

_Prashant_
0
Comment
Question by:Prashant Girennavar
  • 3
  • 2
  • 2
  • +4
12 Comments
 
LVL 18

Accepted Solution

by:
fgasimzade earned 167 total points
Comment Utility
1. Yes, you can assign multiple vlans to a single switch port. This is called a trunk port (cisco). Trunk ports are basically used to extend vlans from one switch to another.  A packet, which is going through a trunk port is tagged with vlan id it was originated from.

Note that ordinary PCs will not be able to see the LAN if you connect them to a trunk port - they can not understand tagged packets.

2. Yes, you connect PCs, printers or IP phones to an access ports, which are configured with appropriate VLAN

3. See point 1.
0
 
LVL 9

Assisted Solution

by:gt2847c
gt2847c earned 333 total points
Comment Utility
1. Can I assign multiple VLAN to a single port in a switch? If yes then how the traffic will be recongised?
If the switch supports VLAN configurations and the port is properly configured, yes. Switches commonly use the 802.1Q Ethernet frame which includes the VLAN tag (Cisco also has a proprietary format).  A VLAN aware switch will read the 802.1Q VLAN tag and forward the traffic as configured.

2. Do we need to connect the device to a switch port according to the VLAN in which they belong?
If the device does not support VLAN tagging its own traffic, then yes, you will need to assign the desired VLAN to the port so that traffic from that device will exist in the proper Layer 2 network.  Standalone servers will not generally tag their own traffic.  Virtual host systems will often allow VLAN tagging.

3. How the VLAN Traffic will travel between switches?
Ports on the switch are configured to accept 802.1Q traffic.  In Cisco terminology these are known as trunk ports.  Trunk ports allow VLAN tagged traffic to be sent between systems and switches.
0
 
LVL 3

Expert Comment

by:Tm-L
Comment Utility
I have limited knowledge within this field so will answer to the best of my abilities:

1: Yes you can, i believe the traffic is controlled by the switches as its switch technology so its the switch that has to handle and control the VLANs

2: you tag ports with the VLAN that the port has access to and so the device that you then connect via this port will have access to the VLAN. so you could tag a switch 50/50 with 2 VLANs, VLAN1 and VLAN2 for example with half the ports of going to each, these device would then be contain to the VLAN that the ports are tagged with. In this instance VLAN1 will be for manager devices and VLAN2 for lower level user devices. the devices are held within the VLANs that they are suited to and as you will wire them meaning there will be no cross talk between the two VLANs so management devices will not see or talk to lower level user devices.

now to add to the mix we have VLAN3, VLAN3 in this example holds the servers with the file servers, mail servers, default gateway etc. VLAN3 has been tagged on every port on the previously mentioned switch. this means that although we have VLAN1 & VLAN2 that are self-contained, we now are allowing both sets of devices access to VLAN3 which holds various servers that both groups need to have access two whilst not having access to one another and keeping the traffic separate so there will be no interactions between the lower level user devices and the management devices unless its through VLAN3 devices.

3: the VLAN traffic will travel through the network fabric you are using as any normal data would, the different being that you have tagged ports and VLANs so the switches route data accordingly there shouldn't be anything special needed between the switch more so then you would normally cable/fibre connect them. but ofcourse the bigger the bandwidth between switches and switches to devices the better.
0
 

Expert Comment

by:AncoPostma
Comment Utility
Hello _Prashant_ ,

1. You can assign multiple VLAN's to a single port. For example, a server can access multiple vlans. Also, all ports are member of VLAN1, the management vlan.

2. You assign vlans to ports, this is the easiest way. You can also assign vlans to MAC addresses, but this is not recommended.

3. VLAN information will be shared among the switches by a vlan management protocol. You can also tag the frames if an edge switch doesn't support vlans.

Best practice: create vlans, assign ports, use vlan switches.
0
 
LVL 5

Expert Comment

by:dallensworth
Comment Utility
Others have already explained this pretty well above.  If you want additional detail here is a pretty good video on the topic.

http://www.youtube.com/watch?v=jHw7OUqcg-g
0
 
LVL 9

Expert Comment

by:Sandeep Gupta
Comment Utility
Can I assign multiple VLAN to a single port in a switch? If yes then how the traffic will be recongised?

if you have L3 switch then you can create subinterface ..depened upon your vlans.

ex:

int gi0/0

int gi0/0.1
int gi0/0.2
int gi0/0.3
----and soon

at each subinteface you have to define your vlan id with dot1q trunk.
0
Threat Intelligence Starter Resources

Integrating threat intelligence can be challenging, and not all companies are ready. These resources can help you build awareness and prepare for defense.

 
LVL 10

Author Comment

by:Prashant Girennavar
Comment Utility
Thanks for the explination,

 I still have some questions.

Say for eg , I have 48 port switch wehre I have defined 0-24 ports are VLAN1 (For Voice) and 25-46(for data) ,

 Now IF I connect the IP Phone to port number 32(which is a dataport) how this will work? I am pretty sure , we need not remember VLAN Ports here?

What is the concept behind this?

Regards,
_Prashant_
0
 
LVL 5

Expert Comment

by:dallensworth
Comment Utility
If your using traditional IP phones on a cisco switch the following should work to accomplish what you want:  

interface GigabitEthernet32
 switchport access vlan 25
 switchport mode access
 switchport voice vlan 1


The voice vlan option allows for access ports to also carry the voice traffic.  Many times people will run a drop for the phone and then the phone supports a port out to the pc which saves on total number of drops.

There is more configuration that can be done than what is above but you can follow this link for details:

http://www.cisco.com/en/US/docs/switches/lan/catalyst3550/software/release/12.1_19_ea1/configuration/guide/swvoip.html#wp1034062
0
 
LVL 18

Expert Comment

by:fgasimzade
Comment Utility
If you pluf your ip phone into the data vlan the phone will obtain ip address from data subnet.  Everything depends on the subnets configured for each vlan
0
 
LVL 10

Author Comment

by:Prashant Girennavar
Comment Utility
If it gets the ip address from data VLAN (I belive it will be in Data VLAN) , then how it will contact other IP phones , Since the IP phone will only talk on their VLAN.

Correct me if I am wrong here.

Thanks,

_Prashant_
0
 
LVL 18

Expert Comment

by:fgasimzade
Comment Utility
You need a router or a layer 3 switch to communicated between different vlans (subnets)
0
 
LVL 9

Assisted Solution

by:gt2847c
gt2847c earned 333 total points
Comment Utility
IP Phones with data port capability generally have to be configured to use a specific VLAN.  This can be done, manually, via DHCP/BootP option or through a config file supplied via TFTP or FTP.  When the phone boots and gets the configuration, it should use the assigned VLAN to request its IP address.  In the config dallensworth provided above, the switch port is configured to allow untagged traffic to use VLAN 25 and the phone to use VLAN1.  If the phone is properly configured to use VLAN1, then it will pick up an address from the correct VLAN and be able to communicate with your other phones.  If the phone uses DHCP or a TFTP config file, it may get its initial IP from the data VLAN, then move itself to the correct VLAN and get a new IP address...
0

Featured Post

What Security Threats Are You Missing?

Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

Join & Write a Comment

Suggested Solutions

This tutorial will go through the steps required to write a script that will back up the configuration settings of a HP-ProCurve switch. You will need to get the following things to follow this tutorial: Telnet Scripting Tool e.g. TST10.exe …
Please see preceding article here: http://www.experts-exchange.com/Networking/Operating_Systems/A_11209-Root-Bridge-Election.html Figure 1 After Root Bridge has been elected, then what?..... Let's start by defining a Root Port in la…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

771 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

13 Experts available now in Live!

Get 1:1 Help Now