Specifications
Configuring and Managing VLANs
4-14 Configuring and Managing Ports and VLANs
Configuring and Managing VLANs
Understanding VLANs in Enterasys Networks MSS
AvirtualLAN(VLAN)isaLayer2broadcastdomainthatcanspanmultiplewiredorwireless
LANsegments.EachVLANisaseparatelogicalnetworkand,ifyouconfigureIPinterfacesonthe
VLANs,MSStreatseachVLANasaseparateIPsubnet.
Onlynetworkportscanbepreconfiguredto
bemembersofoneormoreVLAN(s).Youconfigure
VLANsonaRoamAboutSwitch’snetworkportsbyconfiguringthemontheswitchitself.You
configureaVLANbyassigninganameandnetworkportstotheVLAN.Optionally,youcan
assignVLANtagvaluesonindividualnetworkports.Youcan
configuremultipleVLANsona
RoamAboutSwitch’snetworkports.Optionally,eachVLANcanhaveanIP address.
VLANsarenotconfiguredonwiredauthenticationports,becausetheVLANmembershipofthese
typesofportsisdetermineddynamicallythroughtheauthenticationandauthorizationprocess.
UserswhorequireauthenticationconnectthroughRoamAboutSwitch
portsthatareconfigured
forwiredauthenticationaccess.UsersareassignedtoVLANsautomaticallythrough
authenticationandauthorizationmechanismssuchas802.1X.
Bydefault,noneofaRoamAboutSwitch’sportsareinVLANs.Aswitchcannotforwardtrafficon
thenetworkuntilyouconfigureVLANsandaddnetworkportsto
thoseVLANs.
VLANs, IP Subnets, and IP Addressing
Generally,VLANsareequivalenttoIPsubnets.IfaRoamAboutSwitchisconnectedtothe
networkbyonlyoneIPsubnet,theswitchmusthaveatleastoneVLANconfigured.Optionally,
eachVLANcanhaveitsownIPaddress.However,notwoIPaddressesontheswitchcanbelong
tothe
sameIPsubnet.
YoumustassignthesystemIPaddresstooneoftheVLANs,forcommunicationsbetween
RoamAboutswitchesandforunsolicitedcommunicationssuchasSNMPtrapsandRADIUS
accountingmessages.AnyIPaddressconfiguredonaRoamAboutSwitchcanbeusedfor
managementaccessunlessexplicitly restricted.(For
moreinformationaboutthesystemIP
address,seeChapter 5,”ConfiguringandManagingIPInterfacesand Services”.)
Note: The CLI commands in this chapter configure VLANs on RoamAbout Switchnetwork ports. The
commands do not configure VLAN membership for wireless or wired authentication users. To assign
a user to a VLAN, configure the RADIUS Tunnel-Private-Group-ID attribute or the VLAN-Name
vendor specific attribute (VSA) for that user. (For more information, see Chapter 17, ”Configuring
AAA for Network Users”.)
Note: A wireless client cannot join a VLAN if the physical network ports on the RoamAbout Switchin
the VLAN are down. However, a wireless client that is already in a VLAN whose physical network
ports go down remains in the VLAN even though the VLAN is down.