Chapter 3 Customization
Isolate Traffic and Users through VLANs
3-14
User Guide for the Catalyst Express 500 Switches
OL-8122-01
Using VLANs to Isolate Different Traffic Types
Isolating data traffic from delay-sensitive traffic, such as voice traffic, ensures the
quality of the voice transmission. In
Figure 3-6
, switch ports connected to the IP
phones belong to the Cisco-Voice VLAN, a special VLAN supported on the
switches. This VLAN automatically provides Voice over IP (VoIP) services on
these connections, meaning priority is given to voice traffic over regular IP data
traffic. Voice traffic from the phone and IP phone service requests to an IP PBX
server have priority over traffic from the desktop devices attached to the IP
phones.
To further isolate data traffic from voice traffic, data traffic from the attached
desktop devices can be assigned to a separate VLAN.
Using VLANs to Group Users
The network in
Figure 3-6
provides access to three types of network users: wired
employees, wireless (or mobile) employees, and wired and wireless company
visitors. Each user type requires different access levels to the company network.
VLANs and security policies on a router or Layer 3 switch can enforce privileges
and restrictions to different user types. In
Figure 3-6
:
•
VLAN 5 offers employee-level access to the company resources. This kind of
network access requires a direct connection to the specific switch ports.
•
Cisco-Guest VLAN offers Internet-only access to company visitors. Visitors
with wired or wireless connections to switch ports are assigned to this VLAN,
which automatically restricts guest access to only the Internet.
•
VLAN 9, which has one or more switch ports connected to the access point,
enforces security policies to identify the wireless user (for example, as
employee or a guest) and to determine what the user can do on the network
(for example, access only the Internet or access other network resources).
VLAN Types
The switch ships with a default VLAN to which each switch port initially belongs.
The switch supports a maximum of 32 VLANs, including the default VLAN.
Every VLAN is identified by its name and ID number. The default VLAN is
named default. During initial setup, you can assign the default VLAN ID. The ID
can be from 1 to 1001 where 1 is the default ID. After initial setup, you cannot
change the name or ID of the default VLAN.
Содержание 585-LRE - 585 LRE Customer Premise Equipment Bridge
Страница 4: ......
Страница 10: ...Contents x User Guide for the Catalyst Express 500 Switches OL 8122 01 ...
Страница 28: ...Chapter 1 Introduction When You Are Done 1 14 User Guide for the Catalyst Express 500 Switches OL 8122 01 ...
Страница 106: ...Chapter 5 Troubleshooting When You Are Done 5 12 User Guide for the Catalyst Express 500 Switches OL 8122 01 ...
Страница 114: ...Appendix A Reference Connector Specifications A 8 User Guide for the Catalyst Express 500 Switches OL 8122 01 ...
Страница 138: ...Index IN 14 User Guide for the Catalyst Express 500 Switches OL 8122 01 ...