VLANs, Trunks & QinQ

VLAN(Virtual Local Area Network)虛擬區域網路,用於在交換器上建立隔離的網路區段。

Physical Segment

Physical Segment

Frame Tagging

Frame Tagging

VLANs

VLAN 的主要功能:

  • Create separate L2 network segments
  • Isolated traffic isolation
  • Different networks (e.g., AWS Direct Connect VPCs)
  • Separate Broadcast Domains
VLANs

VLAN 特性

特性說明
Traffic Isolation不同 VLAN 間的流量完全隔離
Broadcast Domain每個 VLAN 是獨立的廣播域
Security提供網路區段的安全隔離
Flexibility無需實體佈線即可重新配置網路

VLANs 概念

  • Divides Switch Ports into isolated groups
  • Divides Switches into multiple “mini-switches”
  • Switches do all three actions within each VLAN
VLANs Concept

Multiple Switches

跨交換器的 VLAN 配置:

VLANs Multiple Switches