RUGGEDCOM ROX II
CLI User Guide
Chapter 8
Layer 2
Native VLAN
303
Section 8.5.1.2
Native VLAN
Each port is assigned a native VLAN number, the Port VLAN ID (PVID). When an untagged frame ingresses a port, it
is associated with the port's native VLAN.
By default, when a switch transmits a frame on the native VLAN, it sends the frame untagged. The switch can be
configured to transmit tagged frames on the native VLAN.
Section 8.5.1.3
Edge and Trunk Port Types
Each port can be configured as an edge or trunk port.
An edge port attaches to a single end device, such as a PC or Intelligent Electronic Device (IED). An edge port
carries traffic on the native VLAN.
Trunk ports are part of the network and carry traffic for all VLANs between switches. Trunk ports are automatically
members of all VLANs configured in the switch.
The switch can 'pass through' traffic, forwarding frames received on one trunk port out of another trunk port. The
trunk ports must be members of all VLANs that the 'pass through' traffic is part of, even if none of those VLANs are
used on edge ports.
Frames transmitted out of the port on all VLANs other than the port's native VLAN are always sent tagged.
NOTE
It may be desirable to manually restrict the traffic on the trunk to a specific group of VLANs. For
example, when the trunk connects to a device, such as a Layer 3 router, that supports a subset of the
available LANs. To prevent the trunk port from being a member of the VLAN, include it in the VLAN's
Forbidden Ports list.
For more information about the Forbidden Ports list, refer to
Section 8.5.1.5, “Forbidden Ports List”
.
Port Type
VLANs Supported
PVID Format
Usage
Untagged
VLAN Unaware Networks
: All frames are sent and received without
the need for VLAN tags.
Edge
1 (Native)
Configured
Tagged
VLAN Aware Networks
: VLAN traffic domains are enforced on a
single VLAN.
Trunk
All Configured
Tagged or Untagged
switch-to-Switch Connections
: VLANs must be manually created and
administered, or can be dynamically learned through GVRP.
Multiple-VLAN End Devices
: Implement connections to end devices
that support multiple VLANs at the same time.
Section 8.5.1.4
Ingress Filtering
Ingress filtering is a method of verifying that inbound packets arriving at a network originate from the source they
are expected to be from, before entry (or ingress) is granted.
When ingress filtering is enabled, the switch verifies any tagged frame arriving at a port. When the port is not a
member of the VLAN with which the frame is associated, the frame is dropped. When ingress filtering is disabled,
Summary of Contents for RUGGEDCOM ROX II
Page 2: ...RUGGEDCOM ROX II CLI User Guide ii ...
Page 4: ...RUGGEDCOM ROX II CLI User Guide iv ...
Page 39: ...RUGGEDCOM ROX II CLI User Guide Table of Contents xxxix 19 5 VLANs 752 ...
Page 40: ...Table of Contents RUGGEDCOM ROX II CLI User Guide xl ...
Page 46: ...Preface RUGGEDCOM ROX II CLI User Guide xlvi Customer Support ...
Page 170: ...Chapter 5 System Administration RUGGEDCOM ROX II CLI User Guide 124 Deleting a Scheduled Job ...
Page 256: ...Chapter 6 Security RUGGEDCOM ROX II CLI User Guide 210 Enabling Disabling a Firewall ...
Page 402: ...Chapter 11 Wireless RUGGEDCOM ROX II CLI User Guide 356 Managing Cellular Modem Profiles ...