12.07.2015 Views

Management Guide - Kamery IP

Management Guide - Kamery IP

Management Guide - Kamery IP

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

3Configuring the SwitchUntagged VLANs – Untagged (or static) VLANs are typically used to reducebroadcast traffic and to increase security. A group of network users assigned to aVLAN form a broadcast domain that is separate from other VLANs configured on theswitch. Packets are forwarded only between ports that are designated for the sameVLAN. Untagged VLANs can be used to manually isolate user groups or subnets.However, you should use IEEE 802.3 tagged VLANs with GVRP whenever possibleto fully automate VLAN registration.Automatic VLAN Registration – GVRP (GARP VLAN Registration Protocol)defines a system whereby the switch can automatically learn the VLANs to whicheach end station should be assigned. If an end station (or its network adapter)supports the IEEE 802.1Q VLAN protocol, it can be configured to broadcast amessage to your network indicating the VLAN groups it wants to join. When thisswitch receives these messages, it will automatically place the receiving port in thespecified VLANs, and then forward the message to all other ports. When themessage arrives at another switch that supports GVRP, it will also place thereceiving port in the specified VLANs, and pass the message on to all other ports.VLAN requirements are propagated in this way throughout the network. This allowsGVRP-compliant devices to be automatically configured for VLAN groups basedsolely on endstation requests.To implement GVRP in a network, first add the host devices to the required VLANs(using the operating system or other application software), so that these VLANs canbe propagated onto the network. For both the edge switches attached directly tothese hosts, and core switches in the network, enable GVRP on the links betweenthese devices. You should also determine security boundaries in the network anddisable GVRP on the boundary ports to prevent advertisements from beingpropagated, or forbid those ports from joining restricted VLANs.Note: If you have host devices that do not support GVRP, you should configure static oruntagged VLANs for the switch ports connected to these devices (as described in“Adding Static Members to VLANs (VLAN Index)” on page 3-226). But you can stillenable GVRP on these edge switches, as well as on the core switches in thenetwork.Port-based VLAN129 3 45 6 7 810 1112131415 1618193-220

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!