Afrikaans
Akan
Albanian
Amharic
Arabic
Armenian
Azerbaijani
Basque
Belarusian
Bemba
Bengali
Bihari
Bosnian
Breton
Bulgarian
Cambodian
Catalan
Cebuano
Cherokee
Chichewa
Chinese (Simplified)
Chinese (Traditional)
Corsican
Croatian
Czech
Danish
Dutch
English
Esperanto
Estonian
Ewe
Faroese
Filipino
Finnish
French
Frisian
Ga
Galician
Georgian
German
Greek
Guarani
Gujarati
Haitian Creole
Hausa
Hawaiian
Hebrew
Hindi
Hmong
Hungarian
Icelandic
Igbo
Indonesian
Interlingua
Irish
Italian
Japanese
Javanese
Kannada
Kazakh
Kinyarwanda
Kirundi
Kongo
Korean
Krio (Sierra Leone)
Kurdish
Kurdish (Soranรฎ)
Kyrgyz
Laothian
Latin
Latvian
Lingala
Lithuanian
Lozi
Luganda
Luo
Luxembourgish
Macedonian
Malagasy
Malay
Malayalam
Maltese
Maori
Marathi
Mauritian Creole
Moldavian
Mongolian
Myanmar (Burmese)
Montenegrin
Nepali
Nigerian Pidgin
Northern Sotho
Norwegian
Norwegian (Nynorsk)
Occitan
Oriya
Oromo
Pashto
Persian
Polish
Portuguese (Brazil)
Punjabi
Quechua
Romanian
Romansh
Runyakitara
Russian
Samoan
Scots Gaelic
Serbian
Serbo-Croatian
Sesotho
Setswana
Seychellois Creole
Shona
Sindhi
Sinhalese
Slovak
Slovenian
Somali
Spanish
Spanish (Latin American)
Sundanese
Swahili
Swedish
Tajik
Tamil
Tatar
Telugu
Thai
Tigrinya
Tonga
Tshiluba
Tumbuka
Turkish
Turkmen
Twi
Uighur
Ukrainian
Urdu
Uzbek
Vietnamese
Welsh
Wolof
Xhosa
Yiddish
Yoruba
Zulu
Welcome back in this section we're going to look at villans or virtual local area networks.
We are going to virtualize our infrastructure.
Virtualization is a big topic today with companies such as V.M. way of virtualizing servers but villans
have been around for many years and in a similar way we are going to be virtualizing our switches with
one physical switch is virtually multiple switches.
This is not full virtualization.
We are just virtualizing the local area networks on that specific switch.
So I want to give you an overview of villans and how they operate.
We need to talk about trunking protocols like a two to one q and a cell wall into switch link.
I want to explain virtual trunking protocol or VTB which allows us to create villans on a single switch
and have that information propagated to other switches in the topology.
The DP can be a very useful protocol but can be extremely dangerous and has caused a lot of problems.
Cisco engineers over the years and these days a lot of us will just turn it off and never use it because
of its inherent dangers.
Now an incorrectly designed network or poorly designed network has multiple issues in a simple typology
as an example.
We have a switch with a hub.
This is a single broadcast domain.
So if this host a started broadcasting that broadcast would be received by everyone.
Now that may not be a problem but if the Knicks start jabbering in other words sending out broadcast
off the broadcast of the broadcast it can flood through the entire network and cause a lot of issues
as every device in the network needs to process that broadcast.
This issue exponentially increases as the number of hosts on the network increases more and more hosts
are sending broadcasts more and more hosts are affected by those broadcasts and thus broadcast should
be contained or limited as far as possible.
This is an example of a poorly designed network.
If the central switch went down it would affect all devices and the typology.
No host would be able to communicate with each other because all communication needs to go via the single
device which is now a single point of failure.
Broadcasts once again will fly throughout the network.
The broadcast is received on all links and will consume the bandwidth on every single link in this apology.
Once again every single device has to process that broadcast and it CPQ will be interrupted by the broadcast
continuous broadcasts will slow down the entire network.
Because of the way mac address tables work traffic going to the unit costs address where the MAC address
is not learned by the switches will also be flooded throughout the typology multi costs are treated
in the same way as broadcasts by most laity switches so multi-course will be flooded throughout the
network and affect all devices at poorly designed network may be disorganized and poorly documented
and easily identified traffic flows which make support maintenance and problem resolution.
Very time consuming and very difficult.
You also have the issue of security.
If this host on the left hand side is in marketing and the host on the right hand side is in the accounts
department the person in marketing has access to that machine across the network because security might
not be implemented properly.
It becomes very difficult to manage a poorly designed network so what is a virtual LAN or villain a
villain is essentially a single broadcast domain or logical subnet or logical network.
You could say it's a group of hosts with a common set of requirements attached to the same broadcast
domain regardless of where they are physically located.
You are able to group multiple devices together logically rather than physically.
So it is possible to span a subnet or Villon across multiple switches even though that's not recommended
today.
You can design a villain structure that allows you to group together stations or hosts that are segmented
logically by functions project teams and other types of applications.
Once again without regard to physical location.
So some of the advantages of villans include segmentation where you segment or separate users based
on function.
For instance the sales department will go into specific villain and the accountancy Department will
go into different violent it's very flexible with our changing physical cabling you can move the user
from one villain to another.
It also provides security because users are insipidly lands and they have to traverse a layer 3 device
like a Raptor to get from one villain to another on the router you could implement access lists to control
which users have access to various villains.
We'll be talking a lot about access lists later of course.
But for now I understand that it gives you the ability to enhance security by separating users these
days.
Villans also have other advantages specifically when implementing voice over IP.
You can put your IP phones into separate a villain to your workstations and therefore provide a better
quality of service to the IP phones.
So implementing villans has many advantages in modern networks today.
Something that I find that always confuses people is the difference between a physical topology and
a logical topology.
You need to change your paradigm and no longer think about the physical topology of the network but
draw they envision what the logical topology looks like.
The logical typology will be very different to the physical topology as soon as villans are implemented.
So he has an example of what a physical typology may look like.
You have four physical machines connected to a single physical switch on Portes 0 1 0 2 0 3 and 0 4.
So that's the physical topology However logically we can put interfaces into different villans.
So all you need to do is go into the interface and I'll show you the commands in a moment and you put
that interface into a specific plan.
Let's say for argument's sake to read the land now the lands on switches are configured with numbers
but often when we discuss villans we talk about colors to try and differentiate between the villains
and make it easier to understand.
So assume for the moment that PC a and PCD have been put into the red Villon like typing commands on
the switch ports PCB and PCC have been put into the green V land.
Please note that the hosts are oblivious to what's happened.
As the administrator have just gone onto the switch and changed the villain that the port belongs to
by default all ports belong to Villon one on Cisco switches but by using a single command you can move
that port to a separate Thielen.
So once again the physical topology looks as follows.
But you've just got to imagine that these PCs on separate villans have a when looking at the logical
topology things are dramatically different PCJ and PCD are in the red villaine on switch DCC and PC
be on the green villaine logically there are two separate switches or two separate land.
Here we have virtualise the Allen infrastructure and created two separate local area networks.
These networks cannot communicate with each other from a layer to point of view.
The plans are implemented at laity and the only way to move from one villain to another is to go via
a layer 3 device such as a router remember please.
A billion is a separate logical subnet or separate broadcast domain.
If a sent a broadcast that broadcasts would only be received by d if C sent a broadcast that broadcasts
would only be received by B which is very different with all the devices on the same Bil'in or same
physical switch.
Once again ports can be put into a villain using different mechanisms for the moment just a that use
the administrator statically put the port into the of the land.
So going back to our physical view of the topology and this topology we're not going to use Forty-Eight
but Mac addresses because I want to simplify what's going on.
So just assume that these numbers a b c and d are the Mac addresses of these devices.
When a sends a broadcast that broadcast will be forwarded to the switch with a source address of a and
the destination will contain x.
In other words broadcast when that frame hits the switch the switch will make a note of which villaine
that code belongs to.
So that frame is internally tagged with the red villain.
Please note the PC is oblivious to what's going on.
The PC just sees this link as standard Ethernet and doesn't understand the concept of violence.
I'm going to digress just for a second.
The architecture switches very Cisco documents like this one explaining the architecture of a 6500 switch.
So for example looking at the different Jessies and different line cards and different supervisors.
This document will explain how the architecture is set up.
The detail of this is totally out of the scope of the course but it's just to try and explain a little
bit about what happens behind the scenes.
One of the things that they explain in the document is the day in the life of a packet going through
a hundred.
And in this example they've got centralized forwarding so they'll explain how a package will arrive
on an interface and based on different application specific integrated circuits or A-6 how that packet
will flow from the ingress port to an a great sport going via the database on the back plane of the
switch.
You can learn more about the actual flow of the packet through the switch by going and looking at documents
like this.
All I want you to realize is that the architecture of different switches work differently.
And if you want to look at the internals of a switch there are really good documents on Cisco's Web
site explaining how packets flow through a switch for this cause we are going to explain it as follows.
When the frame arrives on this port it's internally tagged with a red Villon that frame is then copied
to all other ports on the switch.
However that broadcast will not be forwarded.
Out of this port because the port is in a different Villon to the original frame the frame will also
not be forwarded.
Out of this port 0 3 because the frame is in a different villain to the port.
However on this port the frame will be forwarded out because the villain number or color is the same.
Please note only the original frame is sent out of the port.
No internal tagging leaves the switch.
The PCs once again are oblivious to any tagging or changing of frames.
So the frame leaves the switch and arrives at PCD in its original form.
Source addresses a destination address as a broadcast.
So physically we have one switch here but logically PCIe can only send traffic to PCD not to PCB or
PCC.
They are on a separate the land or separate logical switch.
If you try to send a unit cost to see so the source addresses say in the frame and the destination address
is C which is this PC on the green line.
That frame would be sent to the switch as a standard.
Ethan at frame.
Now we are assuming here that is somehow learnt the Mac address of C..
So he is sending a frame directly to see normally he wouldn't even be able to learn that Mac address.
So in this example the person on a could be up to no good.
The frame arrives at the switch and the switch tags the frame internally with the red villaine that
frame is copied to all ports on the switch.
Now once again that depends on the switch architecture.
So let's just assume for the moment that that's what's going to happen on the specific switch.
Now the central async checks the Mac address table and sees that C can be found in port 0 3.
So their central A-6 sends a flush message to the other ports to remove the copies of the frame.
So the frame is only available on port 0 3.
However just before sending out the frame the Port Vila and Kallos checked against the frame.
The frame is a red villaine frame because it arrived on a red port.
But this is a Green the line interface so the frame is not transmitted and is dropped so the frame never
gets to PCC.
Therefore am not able to access the green line.
Logically A is separated from C and from a later point of view there is no connection between the red
line and the green V land.
As mentioned previously the only way to get from one villain to another is to traverse a layer 3 device
such as a router and as there is no rot in the example the traffic is totally separated.
Now he has a slightly more complicated example.
He is still in the red line but is connected to switch 1 D is in the red villaine that is in this case
connected to switch to CS in the green villin connected to switch t and B is in the green the line connected
to switch 1.
A special type of link is required between the two switches so that they can communicate any information
between them and that is known as a trunk port.
This interface will run at trunking protocol so that any information can be transmitted from one switch
to another.
The two trunking protocols that are used are ISIL or into switch link an editor the one key now ISIL
was a Cecka proprietary protocol and tends not to be used today.
Or one.
Q The industry standard is the protocol of choice for communicating the information between switches
across trunking ports.
Now once again it's important to remember what the physical topology looks like.
Which is as follows.
And then the logical topology which looks like this.
Is connected to switch one PCCs connected to switch to.
They're all in the red Villon PCBs connected to switch one and PCD is connected to switch 2.
But they're on the green villain so there's logical separation between the devices across the two switches
physically please remember there are only two switches in this topology.
But logically we are creating four switches with the Readville and separated from the green Bil'in and
the switches are linked using a trunking interface.
So trunking once again allows multiple villains to traverse a single physical link.
The two protocols are Ed. one.
Q The Industry Standard which tends to be used today and ISIL which was Cisco's proprietary method which
tends not to be used in todays environments.
Cisco IP phones for example do not support ICL and a lot of news switches do not provide support for
ISIL.
So in this course we are going to concentrate on a two to one key and attitude or one Q frame is different
to a standard Ethan it frame stented Ethan it frame would look something like this.
You have a destination field a source field a length or ether type field.
You have the data and then you have the frame checked sequence and edit 2.1 one frame has a full byte
tag inserted into the header between the source address field and the ether top or length field because
the frame has been altered.
The frame check sequence is pre-computed and replaced in the modified frame.
The tag consists of two main parts the tag protocol identifier which is set to 0 6 8 1 0 0 to identify
this as an actual E to the one tag frame and thus allow switches and devices to distinguish an editor
or one cue frame from untagged frames.
This is 16 bits in length or two bytes.
The remaining two bytes will 16 bits is split as follows three bits represent the priority or priority
code point which is a three bit field used to prioritize certain traffic types over others.
This is used very heavily in quality of service where for instance a decimal value of five is used to
represent voice.
The canonical format identifier will see if y was used in the old days or compatibility between Ethernet
and Token Ring networks.
It's very unlikely that you're going to use that today.
And the important piece is the villain identify which is a 12 bit field specifying the Wii LAN to which
this frame belongs.
A value of zero would mean that this frame does not belong to any villain.
It's because of this field that switches are able to communicate the veel and number to each other.
It is 12 bits in size which allows for 4000 ninety 96 villans to be created in an 8 to 1 environment.
You can work that out as follows.
Two to the power of 12 equals 4000 a 96.
So in theory 4000 a 96 villans could be configured on an ADA to the one key switch switches however
do not necessarily support that number of villans.
Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.