
4.
Web Management
AirLive AirMax4GW User’s Manual
38
Port-based VLAN is a group of ports on an Ethernet or Virtual APs of Wired or
Wireless Gateway that form a logical LAN segment. Following is an example. In
SMB or a company, administrator schemes out 4 segments, Lobby, Lab &
Servers, Office and VoIP & IPTV. In a Wireless Gateway, administrator can
configure Lobby segment with VLAN ID 4. The VLAN group includes Port-4 and
VAP-8 (SSID: Guest) with NAT mode and DHCP-3 server equipped. He also
configure Lab & Servers segment with VLAN ID 3. The VLAN group includes
Port-3 with NAT mode and DHCP-2 server equipped. However, he configure
Office segment with VLAN ID 2. The VLAN group includes Port-2 and VAP-1
(SSID: Staff) with NAT mode and DHCP-1 server equipped. At last, administrator
also configure VoIP & IPTV segment with VLAN ID 11. The VLAN group includes
Port-1 with bridge mode to WAN interface as shown at following diagram.
Above is the general case for 4 Ethernet LAN ports in the gateway. But the device
has only one Ethernet LAN port. So, there is only one VLAN group in the device.
But it also supports two different kinds of application for the Port-based VLAN
tagging, NAT or Bridge.
•
Tag-based VLAN Tagging for Location-free Departments
Tag-based VLAN function can group Ethernet port, Port-1, and WiFi Virtual
Access Points, VAP-1 ~ VAP-8, together with different VLAN tags for deploying
department subnets in Intranet. All packet flows can carry with different VLAN
tags even at the same physical Ethernet port for Intranet. These flows can be
directed to different destination because they have differentiated tags. The
approach is very useful to group some hosts in different geographic location to
be a same department.
Tag-based VLAN is also called a VLAN Trunk. The VLAN Trunk collects all
packet flows with different VLAN IDs from Router device and delivers them in
the Intranet. VLAN membership in a tagged VLAN is determined by VLAN ID
information within the packet frames that are received on a port. Administrator
can further use a VLAN switch to separate the VLAN trunk to different groups
based on VLAN ID. Following is an example. In SMB or a company, administrator
schemes out 3 segments, Lobby & Restaurant, Lab & Meeting Rooms and
Office. In a Security VPN Gateway, administrator can configure Lobby &
Restaurant segment with VLAN ID 12. The VLAN group is equipped with
DHCP-3 server to construct a 192.168.12.x subnet. He also configure Lab &