What Is a VLAN?
LAN Segmentation
Cisco 1710 Security Router Software Configuration Guide
3-2
A VLAN can be thought of as a broadcast domain that exists within a defined set
of switches. A VLAN consists of a number of end systems, either hosts or network
equipment (such as bridges and routers), connected by a single bridging domain.
The bridging domain is supported on various pieces of network equipment; for
example, LAN switches that operate bridging protocols between them with a
separate bridge group for each VLAN.
VLANs are created to provide the segmentation services traditionally provided by
routers in LAN configurations. VLANs address scalability, security, and network
management. Routers in VLAN topologies provide broadcast filtering, security,
address summarization, and traffic flow management. None of the switches
within the defined group will bridge any frames, not even broadcast frames,
between two VLANs. Several key issues need to be considered when designing
and building switched LAN internetworks:
•
LAN Segmentation
Security
•
•
Broadcast Control
Performance
•
Network Management
•
•
Communication Between VLANs
VLANs allow logical network topologies to be overlaid onto the physical
switched infrastructure such that any arbitrary collection of LAN ports can be
combined into an autonomous user group or community of interest. The
technology logically segments the network into separate Layer 2 broadcast
domains whereby packets are switched between ports designated to be within the
same VLAN. By containing traffic originating on a particular LAN only to other
LANs in the same VLAN, switched virtual networks avoid wasting bandwidth, a
drawback inherent to traditional bridged and switched networks in which packets
are often forwarded to LANs with no need for them. Implementation of VLANs
also improves scalability, particularly in LAN environments that support
broadcast- or multicast-intensive protocols and applications that flood packets
throughout the network.
Figure 3-1
illustrates the difference between traditional physical LAN
segmentation and logical VLAN segmentation.
Chapter 3
Overview of Routing Between Virtual LANs
78-12696-01