You are on page 1of 8

NP0995.

qxd 12/8/97 11:10 AM Page 1

Virtual LANs
Flexible network segmentation for high-speed LANs

Intel Networking Information Series

For today’s networking professionals who need fast,

concise information to help them understand new

technologies that can make their networks more

efficient and cost-effective.


NP0995.qxd 12/8/97 11:10 AM Page 2

Virtual LANs

Contents
Executive Summary 3

The Need for VLANs 4

VLANs: A Semi-Technical Discussion 5

An Industry-Wide VLAN Standard 6

The Intel VLAN Solution 6

Summary and Conclusion 7

For More Information 7

Glossary of Terms 7

2
NP0995.qxd 12/8/97 11:10 AM Page 3

Virtual LANs

Executive designed, administered and managed. of the technology and the large number
Summary And since VLANs are software-based, of proprietary implementations have
Few people experience the rapid changes they allow the network structure to created confusion in the marketplace.
of today’s business environment more quickly and easily adapt to the addition, Some industry pundits have charged
than Information Technology (IT) relocation or reorganization of nodes. that VLANs may eventually become
managers. Employees move, business No longer does each change require a unnecessary as routing becomes faster
operations are restructured and new tech- visit to the wiring closet. and high-bandwidth technologies such
nologies emerge. All of these changes as Fast Ethernet and Gigabit Ethernet
Equally important, VLANs help meet
add pressure to networks already straining emerge. They also note a slow, industry-
performance needs by segmenting the net-
under the requirements of more users, wide trend toward protocols that depend
work more effectively. Unlike standard
more powerful workstations and more less upon broadcast traffic.
switching, they restrict the dissemination of
demanding applications. broadcast as well as node-to-node traffic, These changes may, to some extent,
Virtual LANs (VLANs) can help IT so the burden of extraneous traffic is reduce the importance of VLAN solutions
managers adapt to these changes more reduced throughout the network. Security in the future, but they won’t eliminate
easily and effectively, while increasing can also be improved. Since all packets many of the key advantages of the tech-
overall network performance. By offering traveling between VLANs may also pass nology. And VLANs offer an immediate
a highly flexible means of segmenting a through a router, standard router-based and cost-effective solution to several very
corporate network, VLANs reduce the security measures can be implemented real networking challenges – a solution that
performance bottlenecks that occur when to restrict access as needed. can be integrated into existing networks
traditional backbone routers can’t meet without costly overhauls. The potential
Despite the advantages of a well-
the demands of fast, switched networks. benefits should not be ignored.
designed VLAN solution, the newness
A VLAN is a group of PCs, servers
and other network resources that behave
The VLAN Solution
as if they were connected to a single,
network segment – even though they Printer

may not be. For example, all marketing Hub

personnel may be spread throughout


a building. Yet if they are all assigned to
a single VLAN, they can share resources Switch

and bandwidth as if they were connected 3rd Floor


Marketing
to the same segment (see Figure 1). Engineering Printer
The resources of other departments can Administration

be invisible to the marketing VLAN Switch

members, accessible to all, or accessible


only to specified individuals, at the IT 2nd Floor
manager’s discretion.
This logical grouping of network Router
nodes helps free IT managers from the
restrictions of their existing network WAN Switch
design and cabling infrastructure. Ist Floor
It offers a fundamental improvement
in the ease with which LANs can be Figure 1: VLANs allow highly flexible, efficient network segmentation, enabling users and resources to be
grouped logically, without regard to physical location.

3
NP0995.qxd 12/8/97 11:10 AM Page 4

Virtual LANs

The Need the nodes within the network) or multicast


Benefits of VLANs
for VLANs traffic (packets that are distributed to a
By the 1980’s, most networks consisted group of nodes). Flexible network segmentation
Users and resources that communicate most
of a simple, hierarchical arrangement in As networks have grown and traffic has frequently with each other can be grouped into
common VLANs, regardless of physical location.
which multiple, shared-media networks increased, IT managers have been forced Each group’s traffic is largely contained within the
were connected by a router (see Figure 2). to segment their networks into more and VLAN, reducing extraneous traffic and improving
the efficiency of the whole network.
With their sophisticated packet handling, more switched subnets to meet increasing Simple management
routers allowed communication between performance demands. With these changes, The addition of nodes, as well as moves and
other changes, can be dealt with quickly
networks when necessary, while effectively broadcast and multicast traffic have placed and conveniently from the management console
segmenting traffic so that large shared a greater burden on network bandwidth. rather than the wiring closet.
networks were not swamped by excessive In the worst case scenario, broadcast Increased performance
VLANs free up bandwidth by limiting node-to-node
traffic. Unfortunately, traditional routers traffic can spiral out of control, creating and broadcast traffic throughout the network.
were slow, complicated and expensive. broadcast storms that can bring down Better use of server resources
With a VLAN-enabled adapter, a server can be a
As the need for faster networks emerged, the network. member of multiple VLANs. This reduces the need
a new solution was needed. to route traffic to and from the server.
As switched networks have become
Enhanced network security
Switches spearheaded the next more common, routers have continued to VLANs create virtual boundaries that can only be
evolution of network structure. By crossed through a router. So standard, router-based
exist within the network. But they’ve been security measures can be used to restrict access
segmenting the network and providing forced toward the periphery, where speed to each VLAN as required.
dedicated bandwidth where needed, is generally less critical.
they greatly increased performance,
VLANs offer an effective solution to between switched networks, and eliminate
while reducing cost and complexity
swamped routers and broadcast storms. the danger of broadcast storms. With these
(see Figure 3). However, traditional
By limiting the distribution of broadcast, advantages, VLANs revive many of the
switches segment only unicast, or
multicast and unicast traffic, they can key advantages of LAN routing, but with
node-to-node, traffic. Unlike routers,
help free up bandwidth, reduce the need greater flexibility, performance, simplicity
they do not limit broadcast traffic
for expensive and complicated routing and affordability.
(packets that are addressed to all

A Traditional Fully Routed Network A Standard Switched Network

Corporate
Corporate LAN Router
LAN Router WAN

Servers
Hub Hub Hub Switch
Switch

Hub
Hub

Hub
Hub

PCs PCs PCs

PCs
PCs
Server Server Server

PCs
PCs

Figure 2: Traditional LAN routers segment the network and provide logical Figure 3: Standard switches are much faster than routers and provide dedicated
structure, but are slow, complicated and expensive. bandwidth where needed, but are vulnerable to broadcast storms.

4
NP0995.qxd 12/8/97 11:10 AM Page 5

Virtual LANs

VLANs: A Semi-Technical Discussion


In general, there are three basic models However, assigning VLAN membership Another important distinction between
for determining and controlling how to each MAC address can be a time con- VLAN implementations is the method
a packet gets assigned to a VLAN. suming task. Also, a single MAC address used to indicate membership when a
Port-based VLANs – In this imple- cannot easily be a member of multiple packet travels between switches. Two
mentation, the administrator assigns VLANs. This can be a significant limitation, methods exist – implicit and explicit.
each port of a switch to a VLAN. For making it difficult to share server resources Implicit – VLAN membership is
example, ports 1-3 might be assigned between more than one VLAN. (Although indicated by the MAC address. In this
to the Sales VLAN, ports 4-6 to the a MAC address can theoretically be assigned case, all switches that support a particular
Engineering VLAN and ports 7-9 to to multiple VLANs, this can cause serious VLAN must share a table of member
the Administrative VLAN (see Figure 4). problems with existing bridging and MAC addresses.
The switch determines the VLAN routing, producing confusion in switch
Explicit – A tag is added to the packet
membership of each packet by noting forwarding tables.)
to indicate VLAN membership. Cisco
the port on which it arrives. Layer 3 (or protocol)-based VLANs – ISL and the IEEE 802.1q VLAN
When a user is moved to a different port With this method, the VLAN membership specifications both use this method.
of the switch, the administrator can simply of a packet is based on protocols (IP, IPX,
To summarize, when a packet enters
reassign the new port to the user’s old Netbios, etc.) and Layer 3 addresses. This
its local switch, the determination of its
VLAN. The network change is then is the most flexible method and provides
VLAN membership can be port-based,
completely transparent to the user, and the most logical grouping of users. An IP
MAC-based or protocol-based. When
the administrator saves a trip to the wiring subnet or an IPX network, for example,
the packet travels to other switches, the
closet. However, this method has one can each be assigned their own VLAN.
determination of VLAN membership
significant drawback. If a repeater is Additionally, protocol-based membership
for that packet can be either implicit
attached to a port on the switch, all of allows the administrator to assign non-
(using the MAC address) or explicit
the users connected to that repeater routable protocols, such as Netbios or
(using a tag that was added by the first
must be members of the same VLAN. DECNET, to larger VLANs than routable
switch). Port-based and protocol-based
protocols like IPX or IP. This maximizes
MAC address-based VLANs – VLANs use explicit tagging as their
the efficiency gains that are possible
The VLAN membership of a packet in preferred indication method. MAC-based
with VLANs.
this case is determined by VLANs are almost
its source or destination always implicit.
MAC address. Each
Port-Based VLANs
The bottom line is
switch maintains a table Switch that the IEEE 802.1q
Marketing
of MAC addresses and Engineering
specification is going
Administration
their corresponding to support port-based
1 2 3 4 5 6 7 8 9
VLAN memberships. membership and
A key advantage of explicit tagging,
this method is that the so these will be
switch doesn’t need the default VLAN
to be reconfigured model in the future.
when a user moves to
a different port.

Figure 4: In a Port-based VLAN, each port of a switch can be assigned to a particular VLAN.

5
NP0995.qxd 12/8/97 11:10 AM Page 6

Virtual LANs

An Industry-Wide The Intel adapters. Both port-based and MAC


VLAN Standard VLAN Solution address-based VLANs will be supported
Many vendors have already developed A proprietary VLAN solution can using an implicit model. Explicit tagging
their own proprietary VLAN solutions provide significant benefits. But once the will be also be supported using both the
and products. Although these can provide IEEE specifications have been finalized, shared and independent models. This
significant benefits, an industry standard most future networking products will be support for multiple implementations
is clearly needed to ease the confusion designed to support and extend that new will make it as easy as possible for IT
and make the benefits of VLANs more industry standard. So a standards-based managers to create their own VLAN
accessible to IT managers. VLAN solution is more likely to retain solutions, and help ensure compatibility
and extend its value as your network with other VLAN implementations
At present, the IEEE is still working within their network.
grows and you incorporate new products
on the 802.1q specification, which will
and technologies. Flexible VLAN support is only
help ensure the interoperability of VLAN
implementations between switches and Intel currently offers network adapters one way in which Intel switches and
NICs from different vendors. Ratification that are hardware-compatible with the adapters help ensure maximum per-
of 802.1q is expected in the spring of 1998, upcoming IEEE VLAN specifications. formance and adaptability in changing
but products based on the specification Once the specifications are ratified, simple network environments. (For more infor-
will start to appear on the market in early software upgrades will be available by mation, see the Adaptive Technology
1998. A second IEEE specification, 802.1p, disk or from the Intel Web page to estab- and Layer 3 Switching briefs in the
defines the use of priority bits, which are lish compliance. Adapters that support Intel Network Information Series,
part of the explicit VLAN tag as defined this simple upgrade path include: FaxBack 1758 and 1769.)
in 802.1q. Intel’s support for emerging VLAN
■ Intel EtherExpressTM Server Adapter
There are two different VLAN technologies derives naturally from
■ Intel EtherExpress PRO/100
models which will both be specified Intel’s commitment to delivering high-
PCI Adapter
in the 802.1q specification: the shared performance connectivity solutions to
■ Intel EtherExpress PRO/100+
model and the independent model. PCs and servers.
PCI Adapter
Both are explicit tagging implementa- Intel now offers a complete line of
Since the industry standards are not
tions. They will generally work together, industry-leading networking products
yet finalized, Intel switches currently
but problems can arise. Specifically, if and network management software.
support a proprietary VLAN solution,
you have a bridge router in your net- All offer high-performance, cost-
using the MAC address-based method
work, you would probably do well to effective networking solutions, designed
with Layer 3 extensions. This is an
adopt the independent model. If not, to empower users at the desktop while
extremely flexible approach, enabling
either option would work. Some switches easing the burden on IT managers.
an efficient, high-performance VLAN
will support both models, but you must
solution. The Intel EtherExpress Intel has also played a leading role
choose one when configuring the switch
PRO/100 Server Adapter compliments in shifting the industry toward simplified
for your network.
the implementation in Intel switches PC and server management. The Wired
with its support for Cisco’s proprietary for Management (WfM) initiative was
ISL VLAN protocol. launched by Intel in September of 1996.
In the future, Intel intends to offer One result of this wide-ranging effort
strong support for the IEEE VLAN is the Wired for Management Baseline
specifications in both switches and Specification. This defacto industry
standard is already helping to make

6
NP0995.qxd 12/8/97 11:10 AM Page 7

Virtual LANs

the next generation of networked PCs Intel’s current VLAN solution offers For More
easier to manage and support. The goal a highly flexible approach, using explicit Information
is nothing less than a network of PCs tagging so that each node can be assigned Visit Intel on the World Wide Web
that can be fully managed from a to multiple VLANs. In future switches at http://www.intel.com/network
central location. and adapters, Intel will provide multiple for more information on Intel’s
VLAN solutions to better meet the complete line of LAN adapters,
Intel is strongly committed to devel-
specific needs of individual networks, switches and other high-performance
oping and supporting other industry-wide
while also supporting the upcoming networking solutions.
standards as well, through cooperation
IEEE specifications.
with other key vendors and standards
organizations. Because in today’s het-
erogenous networking environments,
Glossary of Terms
a solution can only be cost-effective if
it interoperates readily with existing Broadcast – Network traffic that is disseminated to all the nodes on a shared-
components and software. To safeguard media segment
your investment, Intel continually tracks Explicit model – VLAN membership is indicated by adding a tag to each packet
and supports trends and specifications
Implicit model – VLAN membership is determined by examining information
relating to VLANs and other emerging
that already exists within each packet (the MAC address)
networking technologies.
Independent Model – One of two explicit VLAN models specified in the
IEEE 802.1q specification
Summary and
Layer 3 (or protocol)-based VLANs – Each packet’s protocol or Layer 3 addressing
Conclusion
is examined individually by the switch to determine VLAN membership
By segmenting the corporate network
MAC Address-based VLANs – VLAN membership is determined by the MAC
with a new level of flexibility, VLANs
address of each individual node
offer a fundamental improvement to
the network by working to simplify Multicast – Network traffic that is disseminated to selected nodes

management, while increasing Node – Each of the individual computers or other devices on a network
performance and enhancing security. Packet – A chunk of data bits and associated information, including source address
Desktops, servers and other network and destination address, formatted for transmitting from one node to another
resources can be organized according Port-based VLANs – Each port of a switch is assigned to a particular VLAN
to the needs of the business, rather
Router – A device that connects two networks at the Network Layer (Layer 3) of the
than the restrictions of the wiring closet.
OSI model; operates like a bridge, but also can choose routes through a network
VLANs also address the limitations Segmentation – The division of a network into separate shared-media subnets
of standard switch segmentation by
Shared Model – One of two explicit VLAN models specified in the IEEE 802.1q
containing broadcast as well as node-to-
specification
node traffic. This helps eliminate router
bottlenecks and reduces the danger of Switch – A device that connects multiple network segments at the Data Link Layer
(Layer 2) of the OSI model. They operate more simply and at higher speeds than routers.
broadcast storms. Also, as a software-
based solution, VLANs allow IT Unicast – Network traffic between two nodes
managers to adapt more easily to the VLAN – Virtual LAN; a logical grouping of network nodes that act as if they are
inevitable network changes that occur connected to a single, shared-media network
in a fast-paced business environment.

7
NP0995.qxd 12/8/97 11:10 AM Page 8

Intel Services
Intel PC & LAN Products Customer Information and Support Phone Numbers
or find us on the World Wide Web at http://www.intel.com/network

NORTH AMERICAN SERVICE CENTER: OREGON, USA ASIA-PACIFIC SERVICE CENTER: SINGAPORE††

Intel BBS 1-503-264-7999 Product Information +65-735-3811
FaxBack* 1-800-525-3019 or 503-264-6835 Technicians +65-831-1311 Hours: 05:00 – 15:00
Product Information 1-800-538-3373 or 503-264-7354
Technicians ASIA-PACIFIC SERVICE CENTER: HONG KONG††
Network and ProShare®
Product Information +65-735-3811
Conferencing/Video Products 1-916-377-7000
Technicians +852-2-844-4456 Hours: 05:00 – 15:00
CPU, OverDrive® Processors
and Math Processors 1-800-321-4044
ASIA-PACIFIC SERVICE CENTER: KOREA††
Phone Hours: 7:00 – 5:00 M-W, F
7:00 – 3:00 Th (US Pacific Time) Product Information +65-735-3811
Technicians +822-767-2595 Hours: 05:00 – 15:00
EUROPEAN SERVICE CENTRE: SWINDON, UK
ASIA-PACIFIC SERVICE CENTER: TAIWAN††
Intel BBS† +44-1793-432-955
FaxBack +44-1793-432-509 Product Information +65-735-3811
Product Information +44-1793-431-155 Technicians +886-2-718-9915 Hours: 05:00 – 15:00
Technicians Hours (British Time)
English +44-1793-404-900 (08:00 – midnight) JAPAN SERVICE CENTER: TSUKUBA, JAPAN††
French +44-1793-404-988 (08:00 – 17:00, Tu 08:00 – 16:00) Product Information and Technicians
German +44-1793-404-777 (08:00 – 17:00, Tu 08:00 – 16:00) Network and ProShare
Italian +44-1793-404-141 (08:00 – 17:00, Tu 08:00 – 16:00) Conferencing/Video Products +81-298-47-0800
OverDrive Processors and Math Processors 03-5454-1886
ASIA-PACIFIC SERVICE CENTER: SYDNEY, AUSTRALIA†† Hours: 09:00 – 17:00 M-F
Product Information +61-2-9937-5800

Technicians +1-800-649-931 Hours: 05:00 – 15:00 modem settings: 8-N-1, up to 14.4Kbps
††
Or contact your dealer or distributor.

NOTE: Call our FaxBack service and order document #9089 for a current list of phone numbers.

CUSTOMER SUPPORT
Intel Customer Support Services offers a broad selection of programs including extended phone support, upgrades, parts replacement, on-site
services and installation. For more information, contact us on the World Wide Web at http://support.intel.com or call 800-538-3373, ext. 276.
Service and availability may vary by country.

FOR ALL OTHER INTERNATIONAL SALES MAILING ADDRESS


AND TECHNICAL SUPPORT QUESTIONS
North American Service Center
Contact your local dealer or distributor or call the North Intel Customer Support
American Service center at +1-503-264-7354. JF3-333
5200 NE Elam Young Parkway
SUPPORT FILES ON THE INTERNET Hillsboro, OR 97124-6497
Support information for Intel Brand products is available USA
on the Internet for downloading by Anonymous FTP and European Service Centre
for viewing or downloading on the World Wide Web. Branded Products Support Centre
World Wide Web address (URL) Intel Corporation (UK), Ltd.
Corporate: http://www.intel.com Pipers Way
Customer Support: http://support.intel.com Swindon, Wiltshire
Intel FTP Server England SN3 1RJ
Hostname: ftp.intel.com
File directory location: /pub/support/enduser_reseller
(For FTP Server access instructions, order document #9051)

© Intel Corporation, 1997.


NP0995 * Third party trademarks are the property of their respective owners. Please Recycle.

You might also like