l LANÀº single broadcast domain, LAN»óÀÇ ¸ðµç ÄÄÇ»ÅͰ¡ broadcast ÆÐŶÀ» ¹ÞÀ½À¸·Î¼ traffic ¹ß»ý
l LAN»ó¿¡¼ router¸¦ »ç¿ëÇϸé broadcast°¡ ¾ÈµÊ
l router´Â bridge³ª switch¿¡ ºñÇØ ºñ½Ó
l VLANÀº broadcast trafficÀ» Á¦ÇÑÇÏ´Â ´ë¾ÈÀ¸·Î ³ª¿È
l LANÀ» ´Ù¸¥ broadcast domain·Î ³í¸®ÀûÀ¸·Î segmentÇϵµ·Ï ÇÏ´Â °Í
l ³×Æ®¿÷À» ¼ºê³Ý ´ÜÀ§·Î ³ª´²¼ °¢ ¼ºê³Ý¿¡ ¼ÓÇÑ Àåºñµé°£¿¡¸¸ Åë½ÅÀÌ °¡´ÉÇϵµ·Ï ÇØÁÜ
l IP ¼ºê³ÝÀ» ¸¸µë
l ´Ù¸¥ VLAN¿¡ ¼ÓÇÑ È£½ºÆ® °£¿¡ Åë½ÅÀ» ÇÏ·Á¸é ¹Ýµå½Ã ¶ó¿ìÅ͸¦ °ÅÃÄ¾ß ÇÔ
l IEEE 802.1Q : Layer 1, 2 VLAN¸¸ Á¤ÀÇ
l the maximum number of VLAN : 4094 (0, 0xFFF are reserved), ½ºÀ§Ä¡¿¡ µû¶ó VLAN Table À¯ÁöÇÏ´Â ¸Þ¸ð¸®¿Í °ü·ÃÇÏ¿© ÁÖ·Î Dynamic/Static VLAN node °³¼ö¸¦ 256°³¸¦ Áö¿øÇÏ´Â °ÍÀÌ ¸¹À½
l IEEE 802.1Q¸¦ ¿ÏÀüÈ÷ Áö¿øÇϱâ À§ÇØ GARP(Generic Attribute Registration Protocol) °ú GVRP(GARP VLAN Registration Protocol) ÇÊ¿ä
l VLAN by port°¡ ÁÖ·Î »ç¿ëµÊ : Port-based VLAN
l VLANÀÇ µ¿ÀÛÀ» ÀÌÇØÇϱâ À§ÇØ ÇÊ¿äÇÑ °Íµé : VLAN ŸÀÔ, VLAN»óÀÇ deviceµé°£ÀÇ connection type, filtering database, tagging, VLAN ½Äº°ÇÏ´Â process
l Untagged frames, Priority-tagged frames, VLAN-tagged frames
l Untagged/Priority-tagged frames
- VLANÁ¤º¸ ¾øÀ½
- mac address, layer 3 protocol idµîÀ¸·Î ºÐ·ù
l VLAN-tagged frame
- VID¸¦ °¡Áø tag header¸¦ °¡Áö°í ÀÖÀ½
- VID·Î ºÐ·ù
- VLANÀ» ±¸ºÐÇϱâ À§ÇÏ¿© ÀÌ´õ³ÝÇÁ·¹ÀÓ¿¡ ¼Û½Å³ëµå°¡ ¼ÓÇÑ VLANÁ¤º¸(tag)¿¡ ´ëÇÑ Á¤º¸¸¦ »ðÀÔÇÏ´Â ¹æ½Ä
- ÁÖ·Î ¿©·¯ °³ÀÇ ½ºÀ§Ä¡°¡ ¿¬°áµÇ¾î ÀÖ´Â ´ÙÁß ½ºÀ§Ä¡ ³×Æ®¿÷¿¡¼ ½ºÀ§Ä¡ °£¿¡ µ¿ÀÏÇÑ VLANÀ» °øÀ¯ÇÒ ¶§ ÁÖ·Î »ç¿ë
- ½ºÀ§Ä¡°¡ ¿· ½ºÀ§Ä¡¿¡°Ô µ¥ÀÌŸ¸¦ ³Ñ±æ¶§ ¼Û½Å³ëµå°¡ ¼ÓÇÑ VLAN Á¤º¸(tag)°¡ Ãß°¡µÈ ÇÁ·¹ÀÓ(tagged frame)À» ³Ñ±ä´Ù. ±×·¯¸é ¹ÞÀº ½ºÀ§Ä¡°¡ tag¸¦ »©°í ¸ñÀûÁö·Î º¸³½´Ù.
- ethernet frame tag header : tag protocol id(2 bytes) + tag control information(2 bytes)
- tag control information : user priority(3 bit) + CFI(Canonical format indicator, 1 bit) + VID(VLAN ID, 12 bits)
l VLAN-aware device
- tagged frameÀ» ÀÌÇØÇÒ ¼ö ÀÖ´Â µð¹ÙÀ̽º(½ºÀ§Ä¡, ¶ó¿ìÅÍ, PCµî)
- VLAN-aware device·Î µ¥ÀÌŸ¸¦ º¸³»´Â °æ¿ì¿¡´Â VLAN id¸¦ µ¥ÀÌŸ¿¡ ºÙ¿©¼ º¸³½´Ù.
l VLAN-unaware device
- tagged frameÀ» ÀÌÇØÇÏÁö ¸øÇÏ´Â µð¹ÙÀ̽º
- VLAN-unaware device·Î µ¥ÀÌŸ¸¦ º¸³»´Â °æ¿ì¿¡´Â VLAN id¾øÀÌ µ¥ÀÌŸ¸¸ º¸³½´Ù.
l Ingress rules : ¹ÞÀº frame ºÐ·ùÇϱâ À§ÇØ Àû¿ë
- VID°¡ frame¿¡ Àֳľø³Ä¿¡ µû¶ó, VID¿¡ µû¶ó
l egress rules : ¾î¶² port frameÀÌ ¾î¶² formatÀ¸·Î Àü¼ÛµÉÁö.
l explicit tagging
- bridge°¡ µ¥ÀÌŸ¸¦ ¹ÞÀ¸¸é ±× µ¥ÀÌŸ°¡ ¾î´À VLAN¿¡¼ ¿Â°ÇÁö VLAN id·Î µ¥ÀÌŸ¿¡ tag¸¦ ºÎħ
l implicit tagging
- data´Â tagµÇÁö ¾ÊÁö¸¸ ¾î´À Æ÷Æ®·Î ¹Þ¾Ò´ÂÁö, MACÀÌ ¹ºÁöµîÀ» º¸°í ¾î´À VLAN¿¡¼ ¿Â°ÇÁö ¾Ï
- implicit taggingÀ» À§ÇØ ¾î´À Çʵ尡 taggingÀ» À§ÇØ »ç¿ëµÇ´ÂÁö¿Í VLAN»çÀÌÀÇ mappingÀ» À§ÇÑ database À¯Áö
- ¿¹ : port·Î taggingµÈ´Ù¸é ¾î¶² port°¡ ¾î¶² VLAN¿¡ ¼ÓÇÏ´ÂÁö¿¡ ´ëÇÑ database ÇÊ¿ä
l Layer 1 VLAN - Membership by port : port1=vlan1, port2=vlan1
l Layer 2 VLAN - membership by MAC address : 001122334455=vlan1, 223344556677 : vlan2, ...
l Layer 2 VLAN - membership by protocol type : ip=vlan1, ipx=vlan2
l Layer 3 VLAN - membership by IP subnet address : 23.2.24=vlan1, 26.21.35=vlan2
l Higher layer VLAN - application : ftp=vlan1, telnet=vlan2
l Trunk link : ¸ðµç deviceµéÀº VLAN-aware, trunk link»óÀÇ ¸ðµç ÇÁ·¹ÀÓµéÀº Ưº°ÇÑ Çì´õ°¡ ºÎÂøµÈ´Ù(tagged frame)
l Access link : VLAN-aware bridgeÀÇ Æ÷Æ®¿¡ VLAN-unware device¸¦ ºÙÀÎ °Í. access link»óÀÇ ¸ðµç frameÀº implicitly tagged(untagged)
l Hybrid Link
l Forwarding process : filtering database, bridge portÀÇ »óÅ¿¡ µû¶ó
l learning process : source address, VID¸¦ º¸¾Æ¼ filtering database, port state °»½Å
l filtering database : filter information À¯Áö, destination Mac address¿Í VID¿¡ µû¶ó forwardÇÒ Æ÷Æ®
l ÀýÂ÷ : frame ¹ÞÀ½ --> learning process¿¡¼ ingress ruls, port status¸¦ ÂüÁ¶ÇÏ¿© filtering database °»½Å
l LAN»óÀÇ ¸ðµç bridge´Â °°Àº database¸¦ À¯ÁöÇØ¾ß ÇÑ´Ù - GVRP(GARP VLAN Registration Protocol)ÀÌ¿ë : GARP = Generic Attribute Registration Protocol
l filtering database : static entries(°ü¸®ÀÚ°¡ Á÷Á¢ VLAN Á¤º¸ »ðÀÔ), dynamic entries(GARPµîÀ¸·Î ¾Ë°ÔµÈ VLAN Á¤º¸)
l Ãʱ⿡´Â VLAN id = 1 , ¸ðµç Æ÷Æ®°¡ ¼ÓÇØ ÀÖÀ½
l vlan x°³±îÁö °¡´É
l vlanÀÌ Ãß°¡µÉ¶§¸¶´Ù ÇØ´ç IP¿Í MacÀÌ Á¤ÇØÁü(macÀÇ °æ¿ì, ¸¶Áö¸· ÀÚ¸®°¡ id°ªÀ¸·Î µÇ´Â °Í °°À½)
l IVL(°¢ VLANÀÌ °¢°¢ forwarding mac table À¯Áö, ±×·¡¼ Á»´õ º¸¾È¿¡ °Çϸç VLANµé°£¿¡ µ¥ÀÌÅͰ¡ Á÷Á¢ÀûÀ¸·Î forward µÉ ¼ö ¾øÀ½), SVL(¸ðµç VLANÀÌ ÇϳªÀÇ forwarding mac table »ç¿ë, º¸¾È¿¡ ´ú ¹Î°¨ÇÏ°í ¸ðµç Æ÷Æ®¿¡ ´ëÇÑ mac tableÀÌ °°ÀÌ ÀÖÀ¸¹Ç·Î VLANµé°£¿¡ forwardingÀÌ °¡´É)
l Default VLANÀÇ ID´Â 1
l VLAN table¿¡ ÀÖ´Â °¢ VLAN Á¤º¸´Â static(»ç¿ëÀÚ°¡ Á÷Á¢ ÀÔ·ÂÇÑ VLAN Á¤º¸)°ú Dynamic(GVRP¸¦ ÅëÇÏ¿© ¾Ë°ÔµÈ VLAN Á¤º¸)·Î ³ª´¶´Ù.
l °°Àº Protocol typeÀ» °¡Áø VLANÀº port¸¦ °øÀ¯ÇÒ ¼ö ¾ø´Ù. ´Ü Protocol typeÀÌ ´Ù¸£¸é port¸¦ °øÀ¯ÇÒ ¼ö ÀÖ´Ù(¿¹: IP Protocol typeÀ» °¡Áø VLAN 1ÀÌ port1~3À¸·Î ÇϳªÀÇ VLAN Çü¼º, IP Protocol typeÀ» °¡Áø VLAN 2´Â port 1~3À» °¡Áú ¼ö ¾ø´Ù. ´Ü IPX Protocol typeÀ» °¡Áø VLAN 2´Â port 1~3À» °¡Áú ¼ö ÀÖ´Ù)
l VLAN »ý¼º : vlan À̸§, Id, style(port, mac, protocol, ...), stp on/off, ip address, subnet
l VLAN¿¡ port ÇÒ´ç : vlanÀ̸§, ÇÒ´çÇÒ portµé
l VLAN »ý¼º : VLAN À̸§, Member ports, VLAN ID
l ±âŸ : VLAN Host Setting(ip, gateway, subnet, default vlanÀº ¹Ýµå½Ã ÀÖ¾î¾ß Çϳª ±×·¸Áö ¾Ê´Ù¸é ¾ø¾îµµ µÈ´Ù)
l »ý¼º : vlan name, vlan id, portµé, status(enable/disable)
ÇØ´ç vlan id¿¡ Æ÷ÇԵǾ ¾ÈµÇ´Â Æ÷Æ®µé(GVRPµîÀ¸·Î ¿ä±¸µÇ´õ¶óµµ)
tagged portµé(ÇØ´ç Æ÷Æ®¿¡ ¿¬°áµÈ °ÍÀÌ VLANȣȯÀåºñÀÎ °æ¿ì, ÀÌ´õ³Ý ÇÁ·¹ÀÓ¿¡ tag°¡ Ç×»ó Æ÷ÇԵǾî ÀÖÀ½)
l º¸±â : vlan name, id, portµé, learned by static/dynamic
l GARP ¼³Á¤ : port id, join time, leave time, leave all time, port join GARP(enable/disable) - Æ÷Æ®º°·Î GARP »ç¿ë¿©ºÎ °áÁ¤(ÀÌ Æ÷Æ®¿¡¼ µé¾î¿À´Â GVRP´Â enable/disable ?)
*
GVRP
- ÀÌ ±â´ÉÀº ¾ø¾îµµ µÈ´Ù. ÇÏÁö¸¸ ¾øÀ¸¸é °ü¸®ÀÚ°¡ °ü·ÃµÈ ¸ðµç ½ºÀ§Ä¡¿¡ Á¤º¸¸¦ ¼öµ¿À¸·Î ¼³Á¤ÇØ¾ß ÇÏ´Â ºÎ´ãÀÌ ÀÖ´Ù.
- Switch¿¡¼´Â °¢ Æ÷Æ®º°·Î GVRP PDU¸¦ ¹Þ¾ÒÀ» ¶§ ¾î¶»°Ô ÇÒ°ÍÀÎÁö °áÁ¤ÇÏ´Â ¼³Á¤ÀÌ ÇÊ¿ä(enable/disable), °æ¿ì¿¡ µû¶ó °¢ Æ÷Æ®º° ¼³Á¤ÀÌ ¾Æ´Ï¶ó ½ºÀ§Ä¡ ÀüüÀûÀ¸·Î GVRP ¼³Á¤À» ¾î¶»°Ô ÇÒ °ÍÀÎÁö ¼³Á¤ÇÒ ¼öµµ ÀÖÀ½
- Enable : GVRP PDU¸¦ ¹Þ¾Æ¼ ó¸®ÇÏ¿© ÀÌ Æ÷Æ®¸¦ ÅëÇÏ¿© Ÿ ½ºÀ§Ä¡·ÎºÎÅÍ VLAN Group Á¤º¸°¡ ³Ñ¾î¿À¸é LearnÇϰڴٴ ÀǹÌ, ÀÌ °æ¿ì ¼ÒÇÁÆ®¿þ¾îÀûÀ¸·Î ó¸®ÇØ¾ß Çϸç, GVRP PDU¸¦ ¹Þ¾Æ¼ CPU¿¡°Ô ³Ñ°ÜÁÖ¸é(Packet Driver) GVRP Protocol ó¸® ¸ðµâÀÌ ÀÚüÀûÀ¸·Î ó¸®Çؼ ½ºÀ§Ä¡ ³» and/or ÀÚü¿¡ ÀÖ´Â VLAN Table¿¡ learnÇÑ VLAN Á¤º¸¸¦ dynamicÀ¸·Î ¼³Á¤ÇØ¾ß ÇÑ´Ù.
- Disable : BlockÀÇ ÀǹÌ, GVRP PDU¸¦ ¹Þ¾Æµµ ó¸®ÇÏÁö ¾Ê°Ú´Ù´Â ÀǹÌ
- ¡°Show gvrp¡±¶ó´Â ¸í·É¿¡ ÀÇÇØ ¸ðµç Æ÷Æ®¿¡ ´ëÇÏ¿© GVRP enable/disable(ȤÀº block/learning)ÀÌ ³ªÅ¸³²
- GVRP¸¦ ¹Þ´Â Port´Â ÇØ´ç GVRP°¡ ÀüÇÏ´Â ¸ðµç VLAN GroupÀÇ Member°¡ µÈ´Ù.
- GVRP¸¦ ¼Û¼ö½Å ÇÏ´Â Port´Â tagged memberÀ̾î¾ß ÇÑ´Ù.
l GVRP Propagation
1) GVRP°¡ ½ºÀ§Ä¡¿¡¼ enableµÉ ¶§, ½ºÀ§Ä¡´Â ¸ðµç Ports·Î GVRP packetsÀ» º¸³½´Ù. GVRP PacketsÀº ±× ½ºÀ§Ä¡°¡ ¾Ë°í ÀÖ´Â ¸ðµç VLAN Á¤º¸¸¦ advertiseÇÑ´Ù.(Default VLAN Á¦¿Ü)
2) GVRP enabled ½ºÀ§Ä¡°¡ GVRP packetÀ» ¹ÞÀ» ¶§, GVRP PacketÀÌ ³Ñ¾î¿À´Â Âʰú ¿¬°áµÇ¾î PacketÀ» ¹Þ´Â Port´Â advertisedµÈ ¸ðµç VLANsÀÇ member°¡ µÈ´Ù. ±×¸®°í ³Ñ°Ü¹ÞÀº ¸ðµç VLAN Á¤º¸¸¦ ´Ù½Ã ¸ðµç Ports·Î advertisingÀ» ÇÑ´Ù(´Ü, ±× GVRP Á¤º¸¸¦ ¹ÞÀº Æ÷Æ®´Â Á¦¿Ü)
¿¹)



* ±âŸ
