Background of MUX VLANMUX VLAN (Multiplex VLAN) provides a mechanism for controlling network resources through VLAN. In an enterprise network, enterprise employees and enterprise customers can access the enterprise's servers. For an enterprise, it is hoped that internal employees can communicate with each other, while enterprise customers are isolated and cannot access each other. In order to make all users able to access the enterprise server, you can configure inter-VLAN communication. If the enterprise is large and has a large number of users, you must assign VLANs to users who cannot access each other, which not only consumes a large number of VLAN IDs, but also increases the workload of network administrators and the amount of maintenance. The Layer 2 traffic isolation mechanism provided by MUX VLAN enables internal employees of an enterprise to communicate with each other, while enterprise customers are isolated from each other. Basic ConceptsMUX VLAN is divided into Principal VLAN and Subordinate VLAN, and Subordinate VLAN is further divided into Separate VLAN and Group VLAN.
Application ScenarioAccording to the MUX VLAN feature, enterprises can use Principal port to connect to enterprise servers, Separate port to connect to enterprise customers, and Group port to connect to enterprise employees. In this way, both enterprise customers and enterprise employees can access enterprise servers, while enterprise employees can communicate with each other, enterprise customers cannot communicate with each other, and enterprise customers and enterprise employees cannot visit each other. For aggregation layer devices, you can create a VLANIF interface for the Principal VLAN. The IP address of the VLANIF interface can be used as the gateway address of the host or server. As shown in the following figure, configuring MUX VLAN on the aggregation device Switch1 can flexibly implement isolation or intercommunication of access traffic. MUX VLAN Configuration Commands(1) Configure the principal VLAN in the MUX VLAN: Configure the VLAN as a MUX VLAN, that is, a Principal VLAN. If the specified VLAN has been used for a Principal VLAN, then the VLAN cannot be used in the configuration of a Super-VLAN or Sub-VLAN. (2) Configure the Group VLAN in the Subordinate VLAN: A maximum of 128 group VLANs can be configured under one principal VLAN. (3) Configure Separate VLAN in Subordinate VLAN: Only one separate VLAN can be configured under a principal VLAN. The VLAN IDs of the group VLAN and separate VLAN in the same MUX VLAN cannot be the same. (4) Enable the MUX VLAN function on the interface: Enable the MUX VLAN function on the interface. The negotiation-auto and negotiation-desirable interfaces do not support the port mux-vlan enable configuration. MUX VLAN Configuration ExampleNetwork diagram for configuring MUX-VLAN In an enterprise network, all employees can access the enterprise's servers. However, the enterprise hopes that some employees can communicate with each other, while other employees are isolated and cannot access each other. Configuration RoadmapThe configuration roadmap is as follows:
Procedure(1) Create VLAN2, VLAN3, and VLAN4: (2) Configure Group VLAN and Separate VLAN in MUX VLAN: (3) Configure the interface to join the VLAN and enable the MUX VLAN function: |
<<: A brief discussion on WebSocket interface testing
In the previous issue of k8s-Service Mesh Practic...
【51CTO.com original article】 Normal 0 7.8 磅 0 2 f...
dwidc (Dawang Data) is the site of Shaanxi Securi...
Image source: Visual China Among China's thre...
[Beijing, China, February 8, 2018] On February 8,...
[[386495]] This article is reprinted from the WeC...
On March 8, Beijing time, Xunlei released its una...
Python is a high-level programming language with ...
VMISS is a foreign hosting service provider regis...
Smart systems have become an increasingly common ...
According to public data, the scale of layoffs at...
[51CTO.com original article] On December 18, 2019...
The day before yesterday, we shared the product i...
Once upon a time, Telnet was my favorite remote l...