ZXR10 8900E series Core Switch Product Description
8
© 2013ZTE CORPORATION. All rights reserved.
ZTE Confidential Proprietary
Each VLAN is logically like one independent LAN. All frame traffic in one VLAN is limited
to the VLAN. Cross-VLAN access is made through L3 forwarding which will improve
network performance and reduce the entire traffic in physical LAN.
VLAN reduces network broadcast storm and increases network security and centralized
management control.
ZXR10 8900E supports 802.1Q VLAN. The untagged packet can be added with VLAN
tag based on subnet, protocol and port to support a wide variety of VLAN features.
According to 802.1Q VLAN protocol, 12-bit VLAN is limit to 4096 in number, which affect
some actual applications. 8900E has four extension modes: QinQ, PVLAN, VLAN
translation, and L3-related Super VLAN.
3.1.2.1
PVLAN
Private VLAN is a mechanism that provides additional Layer 2 traffic isolation between
ports within a regular VLAN. This feature places constrains on traffic flow between
specific ports in a VLAN. For instance, in an enterprise network, client ports can
communicate with server ports, but not among each other.
Private VLAN is port based and it can be enabled through PVLAN_ENABLE field in
PORT_TABLE for each port. There are three types of private VLAN ports:
Promiscuous port—a promiscuous port can communicate with all interfaces,
including the community and isolated ports within a private VLAN.
Isolated port—an isolated port has complete Layer 2 separation from all other ports
within the same private VLAN except for the promiscuous ports. Private VLANs
block all traffic to isolated ports except traffic from promiscuous ports. Traffic
received from an isolated port is forwarded only to promiscuous ports.
Community port—Community ports communicate among themselves and with the
promiscuous ports. These interfaces are isolated at Layer 2 from all other interfaces
in other communities or isolated ports within their private VLAN.
PVLAN can effectively ensure the communication security of network data. The user is
connected only to his default gateway. Without several VLAN and IP subnets, one
PVLAN can provide the connection with L2 data communication security. All users can
access PVLAN to connect default gateway without any access to other users in the
PVLAN. PVLAN ensure that the ports in one VLAN do not communicate with each other,
but the services can go through Trunk port. Thus, the users in one VLAN will not affect
each other because of service broadcast.
PVLAN does not need protocol message. It can be statically configure in ZXR10 8900E.
Summary of Contents for ZXR10 8900E series
Page 1: ...Operator Logo ZXR10 8900E series Core Switch Product Description ...
Page 2: ......
Page 10: ......