D-Link DGS-3048 [60/147] Ingress filtering
![D-Link DGS-3048 [60/147] Ingress filtering](/views2/1043638/page60/bg3c.png)
DGS-3048 Gigabit Ethernet Switch Manual
48
Port VLAN ID
Packets that are tagged (are carrying the 802.1Q VID information) can be transmitted from one 802.1Q compliant network
device to another with the VLAN information intact. This allows 802.1Q VLANs to span network devices (and indeed, the
entire network, if all network devices are 802.1Q compliant).
Unfortunately, not all network devices are 802.1Q compliant. These devices are referred to as tag-unaware. 802.1Q devices
are referred to as tag-aware.
Prior to the adoption of 802.1Q VLANs, port-based and MAC-based VLANs were in common use. These VLANs relied
upon a Port VLAN ID (PVID) to forward packets. A packet received on a given port would be assigned that port's PVID
and then be forwarded to the port that corresponded to the packet's destination address (found in the Switch's forwarding
table). If the PVID of the port that received the packet is different from the PVID of the port that is to transmit the packet,
the Switch will drop the packet.
Within the Switch, different PVIDs mean different VLANs (remember that two VLANs cannot communicate without an
external router). So, VLAN identification based upon the PVIDs cannot create VLANs that extend outside a given Switch
(or Switch stack).
Every physical port on a Switch has a PVID. 802.1Q ports are also assigned a PVID, for use within the Switch. If no
VLANs are defined on the Switch, all ports are then assigned to a default VLAN with a PVID equal to 1. Untagged packets
are assigned the PVID of the port on which they were received. Forwarding decisions are based upon this PVID, in so far as
VLANs are concerned. Tagged packets are forwarded according to the VID contained within the tag. Tagged packets are
also assigned a PVID, but the PVID is not used to make packet forwarding decisions, the VID is.
Tag-aware Switches must keep a table to relate PVIDs within the Switch to VIDs on the network. The Switch will compare
the VID of a packet to be transmitted to the VID of the port that is to transmit the packet. If the two VIDs are different, the
Switch will drop the packet. Because of the existence of the PVID for untagged packets and the VID for tagged packets,
tag-aware and tag-unaware network devices can coexist on the same network.
A Switch port can have only one PVID, but can have as many VIDs as the Switch has memory in its VLAN table to store
them.
Because some devices on a network may be tag-unaware, a decision must be made at each port on a tag-aware device before
packets are transmitted - should the packet to be transmitted have a tag or not? If the transmitting port is connected to a tag-
unaware device, the packet should be untagged. If the transmitting port is connected to a tag-aware device, the packet
should be tagged.
Tagging and Untagging
Every port on an 802.1Q compliant Switch can be configured as tagging or untagging.
Ports with tagging enabled will put the VID number, priority and other VLAN information into the header of all packets that
flow into and out of it. If a packet has previously been tagged, the port will not alter the packet, thus keeping the VLAN
information intact. The VLAN information in the tag can then be used by other 802.1Q compliant devices on the network to
make packet-forwarding decisions.
Ports with untagging enabled will strip the 802.1Q tag from all packets that flow into and out of those ports. If the packet
doesn't have an 802.1Q VLAN tag, the port will not alter the packet. Thus, all packets received by and forwarded by an
untagging port will have no 802.1Q VLAN information. (Remember that the PVID is only used internally within the
Switch). Untagging is used to send packets from an 802.1Q-compliant network device to a non-compliant network device.
Ingress Filtering
A port on a Switch where packets are flowing into the Switch and VLAN decisions must be made is referred to as an ingress
port. If ingress filtering is enabled for a port, the Switch will examine the VLAN information in the packet header (if present)
and decide whether or not to forward the packet.
If the packet is tagged with VLAN information, the ingress port will first determine if the ingress port itself is a member of
the tagged VLAN. If it is not, the packet will be dropped. If the ingress port is a member of the 802.1Q VLAN, the Switch
then determines if the destination port is a member of the 802.1Q VLAN. If it is not, the packet is dropped. If the destination
port is a member of the 802.1Q VLAN, the packet is forwarded and the destination port transmits it to its attached network
segment.
If the packet is not tagged with VLAN information, the ingress port will tag the packet with its own PVID as a VID (if the
port is a tagging port). The Switch then determines if the destination port is a member of the same VLAN (has the same
Содержание
- D link dgs 3048 managed 48 port gigabit ethernet switch 1
- Manual 1
- Table of contents 4
- Intended readers 8
- Notes notices and cautions 8
- Preface 8
- Safety cautions 9
- Safety instructions 9
- General precautions for rack mountable products 10
- Safety instructions continued 11
- Battery handling reminder 12
- Protecting against electrostatic discharge 12
- Features 13
- Introduction 13
- Management 13
- Performance features 13
- Desktop or shelf installation 15
- Installation 15
- Packing list 15
- Unpacking and setup 15
- Power on 16
- Rack installation 16
- External redundant power system 17
- Power failure 17
- Front panel 18
- Identifying external components 18
- Rear panel 18
- Side panels 18
- Led indicators 19
- Connecting the switch 20
- Switch to end node 20
- Switch to hub or switch 20
- Switch to core router switch 21
- Command line console interface through the serial port 22
- Connecting the console port rs 232 dce 22
- Introduction to switch management 22
- Management options 22
- Snmp based management 22
- Web based management interface 22
- First time connecting to the switch 23
- Password protection 24
- Ip address assignment 25
- Snmp settings 25
- Connecting devices to the switch 27
- Introduction 28
- Login to web manager 28
- Web based network management 28
- Area 3 30
- Areas of the user interface 30
- Web based user interface 30
- Switch information 31
- Administration 33
- Switch information 33
- Ip address 34
- Port configuration 35
- Port settings 35
- Port description 37
- User accounts 37
- Admin and user privileges 39
- Port mirroring 40
- System log settings 41
- Sntp settings 42
- Time setting 42
- Time zone and dst 44
- Tftp services 46
- Download firmware 47
- Snmp manager 48
- Snmp view table 48
- Snmp group table 49
- Snmp user table 50
- Snmp community table 52
- Snmp host table 53
- Snmp engine id 54
- Snmp trap configuration 54
- L2 features 56
- Notes about vlans on the dgs 3048 56
- Understanding ieee 802 p priority 56
- Vlan description 56
- Ieee 802 q vlans 57
- Q vlan tags 58
- Ingress filtering 60
- Port vlan id 60
- Tagging and untagging 60
- Default vlans 61
- Vlan and trunk groups 61
- Vlan status 61
- Static vlan entry 62
- Gvrp port settings 65
- Link aggregation 67
- Igmp snooping 69
- Current igmp snooping group entries 70
- Static router port entries 70
- Forwarding and filtering 72
- Unicast forwarding 72
- Multicast forwarding 73
- S mstp 74
- Spanning tree 74
- Edge port 75
- Port transition states 75
- W rapid spanning tree 75
- D 802 w 802 s compatibility 76
- P2p port 76
- Stp bridge global settings 76
- Stp port settings 78
- Mst configuration identification 79
- Mstp port information 82
- Advantages of qos 83
- Understanding qos 83
- Bandwidth control 85
- P default priority 86
- Traffic control 86
- P user priority 87
- Qos scheduling mechanism 88
- Qos output scheduling 89
- Port access entity 90
- Security 90
- X port based access control 90
- Authentication server 91
- Authenticator 91
- Authentication process 92
- Client 92
- Port based network access control 93
- X authenticator parameter 93
- Radius server 97
- Access authentication control 98
- Trusted host 98
- Application authentication settings 99
- Authentication server host 99
- Login method lists 101
- Enable method lists 103
- Configure local enable password 104
- Configuration 105
- Secure socket layer ssl 105
- Secure shell ssh 106
- Ssh algorithm 107
- Ssh configuration 107
- Cpu utilization 110
- Monitoring 110
- Port utilization 111
- Packets 112
- Received rx 112
- Umb cast rx 113
- Transmitted tx 114
- Router port 116
- Session table 116
- Mac address 117
- Port access control 117
- Radius authentication 117
- Igmp snooping forwarding 119
- Igmp snooping group 119
- Switch history log 120
- Reboot system 121
- Save changes 121
- Logout 122
- Appendix 123
- Technical specifications 123
- Cable lengths 125
- Glossary 126
- All countries and regions excluding usa 129
- Limitation of liability 129
- Warranties exclusive 129
- Warranty and registration information 129
- Wichtige sicherheitshinweise 129
- Hardware 130
- Limited warranty 130
- Software 130
- Fcc statement this equipment has been tested and found to comply with the limits for a class a digital device pursuant to part 15 of the fcc rules these limits are designed to provide reasonable protection against harmful interference in a commercial installation this equipment generates uses and can radiate radio frequency energy and if not installed and used in accordance with the instructions may cause harmful interference to radio communication however there is no guarantee that interference will not occur in a particular installation operation of this equipment in a residential environment is likely to cause harmful interference to radio or television reception if this equipment does cause harmful interference to radio or television reception which can be determined by turning the 132
- Equipment off and on the user is encouraged to try to correct the interference by one or more of the following measures 133
- Product registration 134
- Ce emi class a warning 135
- Copyright statement 135
- D link europe limited product warranty 135
- General terms 135
- Geographical scope of the limited product warranty 135
- Limitation of product warranty 135
- Limited product warranty period 135
- Trademarks 135
- Performance of the limited product warranty 136
- Product type product warranty period 136
- Warrantor 136
- Www dlink com 136
- Allgemeine bedingungen 137
- D link europe limited produktgarantie 137
- Einschränkung der garantie 137
- Laufzeit der eingeschränkten garantie 137
- Produkttyp gewährleistungslaufzeit 137
- Räumlicher geltungsbereich der eingeschränkten garantie 137
- Die vorstehende garantie wurde in die deutsche sprache aus dem englischen übersetzt bei abweichungen zwischen der englischen version und der deutschen übersetzung gelten die bestimmungen der englischen version 138
- Garantiegeber 138
- Leistungsumfang der eingeschränkten garantie 138
- Www dlink com 138
- Conditions générales 139
- D link europe a limité la garantie des produits 139
- Etendue géographique de la garantie produit limitée 139
- Limitation de la garantie produit 139
- Période de garantie produit limitée 139
- Type de produit période de garantie 139
- Exécution de la garantie produit limitée 140
- Garant 140
- Www dlink co uk 140
- Cobertura geográfica de la garantía limitada del producto 141
- Condiciones generales 141
- Garantía limitada del producto d link europa 141
- Limitación de la garantía del producto 141
- Período de la garantía limitada del producto 141
- Tipo de producto período de garantía del producto 141
- Garante 142
- Uso de la garantía limitada del producto 142
- Www dlink co uk 142
- Ambito geografico della garanzia limitata 143
- D link europe termini di garanzia dei prodotti 143
- Generalità 143
- Limitazione della garanzia 143
- Periodo di garanzia 143
- Tipo de producto período de garantía del producto 143
- Prestazioni della garanzia limitata 144
- Www dlink co uk 144
- D link office information 145
- Offices 145
Похожие устройства
- Sony MS-HX32B/K1 ET4 Инструкция по эксплуатации
- Sony Cyber-Shot DSC-T900 Инструкция по эксплуатации
- LG D2343P-BN Инструкция по эксплуатации
- Panasonic KX-F50 Инструкция по эксплуатации
- D-Link DGS-3204 Инструкция по эксплуатации
- Sony Cyber-Shot DSC-T90 Инструкция по эксплуатации
- Sony SF4N4 Инструкция по эксплуатации
- LG E2242TC-BN Инструкция по эксплуатации
- Sharp SJ-P64M Инструкция по эксплуатации
- D-Link DGS-3208F Инструкция по эксплуатации
- Sony Cyber-Shot DSC-T9 Инструкция по эксплуатации
- LG Flatron IPS236V-PN LED Инструкция по эксплуатации
- Sony SF8N4 Инструкция по эксплуатации
- D-Link DGS-3208TG Инструкция по эксплуатации
- Sony SF-8NX/T1 ET4 Инструкция по эксплуатации
- Sony Cyber-Shot DSC-T77 Инструкция по эксплуатации
- LG E2411T-BN Инструкция по эксплуатации
- D-Link DGS-3224TG Инструкция по эксплуатации
- Sony SF16N4 Инструкция по эксплуатации
- LG Flatron E2341T-BN LED Инструкция по эксплуатации