
Switching on the AR440S, AR441S and AR450S 3-9
Software Release 2.6.6
C613-03079-00 REV A
The packet handling rules are that:
■ If an untagged frame arrives at a port, a VID is assigned to the frame
according to the ingress port’s VLAN membership as an untagged port.
The VID is then used when the packet is processed.
■ If an untagged frame is switched to a tagged port the frame has a VLAN
tag inserted into it before the frame is transmitted. The VID used in the tag
is the VID assigned to the frame at the ingress port.
■ If an untagged frame arrives at a tagged-only port the packet is dropped.
■ If a tagged frame is switched to an untagged port the frame has the VLAN
tag removed before it is transmitted.
■ If a tagged frame arrives at a port which is not a member of the VLAN
specified by the VID in the frame’s VLAN tag the frame is accepted or
dropped according to the port’s Ingress Filtering rules.
■ If a tagged frame arrives at a port with a VID that is unknown to the switch
the frame is dropped.
Eth interfaces on the router can also apply a VLAN tag to frames that they
transmit. For more information, see VLAN Tagging on Eth Interfaces on
page 12-28 of Chapter 12, Internet Protocol (IP).
VLAN Membership using VLAN Tags
Switch ports can belong to many VLANs as tagged ports. Therefore, when the
VLAN tag is used to determine which VLAN a packet belongs to, it is simple
to:
■ Share network resources, such as servers and printers, across several
VLANs
■ Configure VLANs that span several routers
For tagged ports, the router uses the VID of incoming frames, and the frame’s
destination field to switch traffic through a VLAN aware network. Frames are
only transmitted on ports belonging to the required VLAN. Other vendors’
VLAN aware devices on the network can be configured to accept traffic from
one or more VLANs. A VLAN-aware server can be configured to accept traffic
from many different VLANs, and then return data to each VLAN without
mixing or leaking data into the wrong VLANs.
Figure 3-2 on page 3-10 shows a network configured with VLAN tagging.
Table 3-4 on page 3-10 shows the VLAN membership. The server on port 2 on
Router A belongs to both the admin and marketing VLANs. The two routers are
connected through port 5 on Router A and port 3 on Router B, which belong to
both the marketing VLAN and the training VLAN, so devices on both VLANs
can use this link.
Komentáře k této Příručce