User manual

Table Of Contents
Chapter1VLANConguration
ItconnectstwodevicesthatcanidentifyVLANtagsandcar-
riesseveralVLAN’sservices.Ittransmitstaggedframesonly
toseveralVLANs.Themostcommontrunklinkistheonebe-
tweentwoVLANswitches.
3.HybridLink
Ittransmitsbothtaggedanduntaggedframes.Foragiven
VLAN,however ,itonlytransmitsframesofthesametype.
DefaultVLAN
ZXR105900/5200hasadefaultVLANinitially,whichhasthefol-
lowingfeatures:
VLANIDas1
VLANnameasVLAN0001
Allportsincluded
Untaggedbydefaultonallports
PVLAN
Toimprovenetworksecurity,messagesamongdifferentusersshall
beseparated.ThetraditionalmethodistoassignaVLANtoeach
user .Themethodhasobviouslimitation,whichcanbeseenfrom
thefollowingaspects:
1.Atpresent,IEEE802.1Qstandardsupportsutmost4094
VLANs,whichlimitsthenumberofusersandnetworkexpan-
sion.
2.EachVLANcorrespondstooneIPsubnet,sovastdividedsub-
netswillcausethewasteofIPaddresses.
3.PlanningandmanagementtoamassofVLANsandIPsubnets
isextremelycomplicated.
PVLAN(PrivateVLAN)technologyisdevelopedtosolvetheseprob-
lems.
PVLANdividestheportsinVLANintothreetypes:theportcon-
nectingtotheuseriscalledIsolatePort,theportconnectingtoa
groupofusersthatneedinterconnectionandintercommunication
iscalledCommunityPortandtheportconnectingtotheupstream
routeriscalledPromiscuousPort.Theisolatedportcommunicates
withthepromiscuousportonly,butnotwithanyotherisolated
portorcommunityport.Communityportcancommunicatewith
promiscuousportandanyothercommunityport,butnotwithiso-
latedport.ThusportsinthesameVLANareseparated.Theuser
whoconnectswithisolatedportcanonlycommunicatewithits
defaultgateway,theuserwhoconnectscommunityportcanin-
terconnectandintercommunicate.Networksecurityisensured.
ZXR105900/5200supports20PVLANgroups,eachgrouphaving
customizedisolatedportsandatmost256isolatedports,16com-
munityportsand8promiscuousports.
CondentialandProprietaryInformationofZTECORPORATION3