For large-scale networks, our usual practice of IP planning is to divide VLANs, because dividing VLANs has many benefits, which facilitates management and improves the security of the entire network. Of course, in addition to dividing VLAN there are other methods? The answer is yes, that is port isolation. These two methods are the most used in ip planning. In this issue, we will learn more about VLAN division and port isolation.
VLAN division
When faced with many IP addresses, our common method is to divide VLANs. The role of VLANs is to isolate broadcasts. The same VLAN is in a broadcast domain. Port isolation is to isolate different ports of the same VLAN. Use a three-layer switch to divide vlans, so that vlans can communicate with each other.
The main advantages of VLAN :
Restrict the broadcast domain. The broadcast domain is restricted to one VLAN, which improves network processing capabilities.
Enhance the security of the local area network. The advantage of VLAN is that the broadcast and unicast traffic within the VLAN will not be forwarded to other VLANs, which helps to control network traffic, reduce equipment investment, simplify network management, and improve network security.
Flexible construction of virtual working groups. VLANs can be used to divide different users into different working groups, and users in the same working group do not have to be limited to a certain fixed physical range, and network construction and maintenance are more convenient and flexible.
Port isolation
As we mentioned above, VLAN is a good solution for networks. In addition to VLAN, port isolation can also be used. Users can add different ports to different VLANs, but this will waste limited VLAN resources. The port isolation function can be used to achieve isolation between ports in the same VLAN. The user only needs to add the port to the isolation group to realize the isolation of the Layer 2 data between the ports in the isolation group. Port isolation is generally used in the intranet.Isolated ports can not communicate with each other,so it provides the user a safer solution of network.
In short:The role of VLAN is to isolate broadcasts. The same VLAN is in a broadcast domain. Port isolation is to isolate different ports in the same VLAN.
Access Port vs Trunk Port vs Hybrid Port
We know that different network segments need to be forwarded through routing to communicate.PCs between different VLANs on the same network segment cannot communicate with each other. In fact, this is not absolute. After understanding the various labels of VLAN, we can realize the data intercommunication of different network segments without routing.
The switch port has three working modes, named Access, Hybrid, and Trunk.
Access type ports can only belong to one VLAN, and are generally used to connect to a computer port.
Trunk type ports can allow multiple VLANs to pass, and can receive and send packets of multiple VLANs. They are generally used for ports connected between switches.
Hybrid type ports can allow multiple VLANs to pass through, can receive and send packets from multiple VLANs, and can be used to connect between switches or to connect to a user’s computer.
When the Hybrid port and Trunk port receive data, the processing method is the same. The only difference is when sending data: Hybrid port can allow multiple VLANs packets to be sent without tag, while Trunk port only allows default tagged VLAN message to be sent without tag.