User's Manual Part 1
Configuring Network Settings
114 Check Point Safe@Office User Guide
you can easily transfer a member of one division to another division without
rewiring your network, by simply reassigning them to the desired VLAN.
The Safe@Office appliance supports the following VLAN types:
• Tag-based
In tag-based VLAN you use one of the gateway’s ports as a 802.1Q VLAN
trunk, connecting the appliance to a VLAN-aware switch. Each VLAN behind
the trunk is assigned an identifying number called a “VLAN ID”, also referred
to as a "VLAN tag". All outgoing traffic from a tag-based VLAN contains the
VLAN's tag in the packet headers. Incoming traffic to the VLAN must contain
the VLAN's tag as well, or the packets are dropped. Tagging ensures that traffic
is directed to the correct VLAN.
Figure 10: Tag-based VLAN