Qtech QSW-2900-24T4-AC [72/209] Super vlan

Qtech QSW-2900-24T-AC [72/209] Super vlan
4-70
4.6 Super VLAN
With the development of networks, network address resource has become more and more scarce. The concept
of Super VLAN was introduced to save the IP address space. Super VLAN is also named as VLAN aggregation. A
super VLAN involves multiple sub-VLANs. It has a VLAN interface with an IP address, but no physical ports can be
added to the super VLAN. A sub-VLAN can has physical ports added but has no IP address and VLAN interface. All
ports of sub-VLANs use the VLAN interfaces IP address of the super VLAN. Packets cannot be forwarded between
sub-VLANs at Layer 2.
If Layer 3 communication is needed from a sub-VLAN, it will use the IP address of the super VLAN as the
gateway IP address. Thus, multiple sub-VLANs share the same gateway address and thereby save IP address
resource.
The local Address Resolution Protocol (ARP) proxy function is used to realize Layer 3 communications
between sub-VLANs and between sub-VLANs and other networks. It works as follows: after creating the super
VLAN and the VLAN interface, enable the local ARP proxy function to forward ARP response and request packets.
Caution: SuperVLAN is only supported in the QSW-3900, please refer to the
http://www.qtech.ru
4.7 Isolate-User-VLAN
The isolate-user-VLAN adopts a two-tier VLAN structure. In this approach, two types of VLANs,
isolate-user-VLAN and secondary VLAN, are configured on the same device.
The isolate-user-VLAN is mainly used for upstream data exchange. An isolate-user-VLAN can have multiple
secondary VLANs associated to it. The upstream device only knows the isolate-user-VLAN, how the secondary
VLANs are working is not its concern. In this way, network configurations are simplified and VLAN resources are
saved.
Secondary VLANs are used for connecting users. Secondary VLANs are isolated from each other on Layer 2.
To allow users from different secondary VLANs under the same isolate-user-VLAN to communicate with each other,
you can enable ARP proxy on the upstream device to realize Layer 3 communication between the secondary VLANs.
One isolate-user-VLAN can have multiple secondary VLANs, which are invisible to the corresponding
upstream device.
As illustrated in the following figure, the isolate-user-vlan function is enabled on Switch B. VLAN 10 is the
isolate-user-VLAN, and VLAN 2, VLAN 5, and VLAN 8 are secondary VLANs that are mapped to VLAN 10 and
are invisible to Switch A.
QSW-2900
QSW-3500
` ` `
VLAN 2 VLAN 5 VLAN 8
VLAN 10

Содержание

Скачать