Monday, October 26, 2009

VLAN - HOW TO CONFIGURE MAC BASED VLAN

How mac based vlan works?

  • The table of mac address vs vlan is kept in a tftp server.
  • When one of the switches in your network is enabled as VMPS (Vlan Management Policy Server), it downloads the database from tftp.
  • When a laptop is connected to a port and when it sends the first frame, the switch to which it is connected will send a query (using Vlan Query Protocol) to the VMPS. The vmps checks its table and informs the vlan to which the laptop belongs.

 

Whether any switch can be enabled with VMPS?

  • No. Only certain high end switches like Cisco 5000 can be configured for vmps.
  • What is Switch based vmps?
  • In the above example, the vmps is configured in one of the switches. So it is switch based vmps. For that switch, it is an extra duty. It has to do the normal duty of switching also. So this method is having drawbacks. Instead you can go for "cisco secure user registration tool". In this case a separate server will function as vmps.

How Cisco URT works?

When users launch a Web browser, they are automatically redirected to the URT logon Web page.

If the user is successfully authenticated, he will be witched to the user-assigned VLAN. Users will be given the choice to authenticate to any LDAP or RADIUS domains .

By disallowing unregistered users or unregistered PCs, you can reduce the spread of viruses.

 

IP based vlan configuration screenshot

1 comment: