Afrikaans
Akan
Albanian
Amharic
Arabic
Armenian
Azerbaijani
Basque
Belarusian
Bemba
Bengali
Bihari
Bosnian
Breton
Bulgarian
Cambodian
Catalan
Cebuano
Cherokee
Chichewa
Chinese (Simplified)
Chinese (Traditional)
Corsican
Croatian
Czech
Danish
Dutch
English
Esperanto
Estonian
Ewe
Faroese
Filipino
Finnish
French
Frisian
Ga
Galician
Georgian
German
Greek
Guarani
Gujarati
Haitian Creole
Hausa
Hawaiian
Hebrew
Hindi
Hmong
Hungarian
Icelandic
Igbo
Indonesian
Interlingua
Irish
Italian
Japanese
Javanese
Kannada
Kazakh
Kinyarwanda
Kirundi
Kongo
Korean
Krio (Sierra Leone)
Kurdish
Kurdish (Soranî)
Kyrgyz
Laothian
Latin
Latvian
Lingala
Lithuanian
Lozi
Luganda
Luo
Luxembourgish
Macedonian
Malagasy
Malay
Malayalam
Maltese
Maori
Marathi
Mauritian Creole
Moldavian
Mongolian
Myanmar (Burmese)
Montenegrin
Nepali
Nigerian Pidgin
Northern Sotho
Norwegian
Norwegian (Nynorsk)
Occitan
Oriya
Oromo
Pashto
Persian
Polish
Portuguese (Brazil)
Punjabi
Quechua
Romanian
Romansh
Runyakitara
Russian
Samoan
Scots Gaelic
Serbian
Serbo-Croatian
Sesotho
Setswana
Seychellois Creole
Shona
Sindhi
Sinhalese
Slovak
Slovenian
Somali
Spanish
Spanish (Latin American)
Sundanese
Swahili
Swedish
Tajik
Tamil
Tatar
Telugu
Thai
Tigrinya
Tonga
Tshiluba
Tumbuka
Turkish
Turkmen
Twi
Uighur
Ukrainian
Urdu
Uzbek
Vietnamese
Welsh
Wolof
Xhosa
Yiddish
Yoruba
Zulu
So let’s do a test
what happens if we move one of these ports into a different VLAN?
Now earlier when I was doing this test I had some problem in GNS3.
So what I’m gonna do is I’m gonna shut g0/2 down and g0/3.
So the only interfaces that are now up are 0/0 and 0/1
in this topology, just to start with a simple network to make a point.
So those interfaces are up, up the other interfaces are down.
What I'll also do actually is to shutdown any other interfaces
to make sure the things converge quicker. 10
So I'll shut down that range and this range of interfaces 11
sh ip int brief also shut down gigabit 3/0 - 3 12
So sh ip interface brief 13
All our interfaces are shutdown except for those 2 interfaces 14
so gigabit 0/0, gigabit 0/1 15
Is router 1 able to ping router 2? 16
Yes it is but if we put this interface gigabit 0/1 into VLAN 2 17
what will happen with the pings? 18
So switchport access vlan 2 19
now before I present here, notice the ping succeeds I'll repeat this 100 times. 20
And then hit enter on the switchport access VLAN command. 21
Notice the pings are starting to time out 22
so as soon as I moved the port from 1 VLAN to another 23
the devices are not able to communicate with each other. 24
sh spanning tree shows that 25
gigabit 0/1 is still in the learning phase of Spanning Tree 26
so we'll wait for a while for Spanning Tree to converge and then do the test again. 27
But what I’d like you to see is this, 2 devices were in the same subnet 28
and at the same VLAN and they were able to ping each other 29
as soon as we moved one port to different VLAN 30
they were no longer able to ping each other. 31
Spanning Tree is forwarding on the VLAN 2 on port gigabit 0/1 32
it’s also forwarding on gigabit 0/0 on VLAN 1. 33
So if we use the sh spanning tree summary command 34
we can see that VLAN 1 is forwarding 35
VLAN 2 is forwarding, there are no blocking ports 36
yet router 1 is not able to ping router 2 37
and router 2 is not able to ping router 1. 38
Because they are in separate VLANs. 39
Is router 2 aware that it’s in a separate VLAN? 40
The answer is no because no tagging information 41
or no VLAN information is gonna being sent on this port it’s an access port. 42
So we just a standard Ethernet frames. 43
There is no VLAN port information transmitted 44
on any of the frames going out on that port. 45
Now to prove this. 46
Let’s add some IP addresses into switch 1 47
so interface vlan 1 ip address 10.1.1. 48
Let’s make it 254 and then interface vlan 2 ip address 10.1.2.254 49
for the mask, now need to no shut both of those 50
so go back to vlan 1 and no shut it. 51
So these are layer 3 Switch Virtual Interfaces on the switch. 52
we are basically creating a layer 3 IP address 53
on the switch for the relevant VLAN 54
so as an example, this switch can ping router 1 on VLAN 1 55
it lost the first ping because of ARP 56
but switch 1 can ping router 1 57
it can’t ping router 2 because router 2 58
needs to be configured with the right IP address for VLAN 2 59
but before I do that notice when I do a capture on that port 60
traffic from the switch to the router is untagged 61
it's a standard Ethernet frame IP traffic 62
there is no tagging at all and as a last test 63
what I’ll do is configure router 2 64
so interface f0/0 ip address 10.1.2.2 65
so I’ve moved it from 1 subnet to another. 66
Ping 2.2 the switch can ping router 2 on this port. 67
Is the traffic tagged? So do the ping again. 68
Filter for ICMP traffic, notice there is no tagging information at all. 69
It’s just standard Ethernet. 70
So what is the summary of this test? 71
Their PCs in the topology are unaware of VLAN traffic 72
these are access ports or untagged ports. 73
In other words 802.1Q tagging is not used on these ports. 74
Can router 1 ping router 2? 75
so cannot ping 10.1.2.2 76
at the moment it won’t be able to 77
because the routers don’t have default routes configured. 78
So I’m gonna turn off IP routing 79
on this routers to turn them into PCs with dumb devices 80
and type IP default gateway 81
and in this case the default gateway router 2 82
will be this IP address on router 1 83
no IP routing that’s a command that turns an expensive router 84
into a dumb device IP default gateway 10.1.1.254 85
so router 1 has a default gateway configured. 86
Can it ping its default gateway? 87
Yes it can, can it ping router 2? 88
At the moment it can and the reason why is that 89
on these switches IP routing is configured by default. 90
However, if I type no IP routing which is true on a lot of switches. 91
The pings will not succeed because the switch is not doing Inter-VLAN routing. 92
To enable Inter-VLAN routing on a layer 3 switch such as this 93
or a physical switch you need the IP routing command 94
to route between the VLANs. 95
So to prove this on router 2 96
I’ll do a debug ip icmp so we can see if ICMP traffic is getting to the router. 97
Do the ping again and notice there are the echo replies 98
we can do something similar on router 1 and there are the echo replies. 99
debug ip packet will give us low information 100
I repeat this only once so we'll send 1 ping 101
which succeeded over there 102
and what you can see is the packet was routed out of the router 103
and sent to the destination as an IP packet. 104
So in other words, this end devices connected to a switch 105
are unaware that the switch is using VLANs. 106
The configuration of the switches as follows. 107
sh run int g0/0 108
that port is using default config which 109
which means that it’s an access port in VLAN 1 110
gigabit 0/2 is an access port in VLAN 2. 111
IP routing is enabled and we’ve configured layer 3 IP addresses 112
on the 2 VLANs to allow the switch to route between their 2 VLANs 113
configured which in turn allows router 1 and router 2 114
to communicate with each other. 115
Now if router 1 and router 3 are put into the same VLAN 116
and router 2 and router 4 are put into the same VLAN. 117
That kind of information needs to be communicated 118
from 1 switch to another using 802.1Q 119
So this port needs to be configured as a trunk port 120
so let’s prove that and then configure it.
Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.