SlideShare a Scribd company logo
Lesson 04: Analyzing Inter-VLAN
Routing


Overview
◦ Routing is the process of determining where to send data packets destined for
addresses outside of the network.
◦ Routers gather and maintain routing information to enable the transmission and receipt
of data packets.
◦ For traffic to cross from one VLAN to another, a Layer 3 process is necessary.



Understanding Inter-VLAN Routing
◦ Inter-VLAN communication occurs between broadcast domains via a Layer 3 device.
◦ In a VLAN environment, frames are switched only between ports within the same
broadcast domain.
◦ VLANs perform network partitioning and traffic separation at Layer 2.
◦ Inter-VLAN communication cannot occur without a Layer 3 device, such as a router.
◦ This process uses IEEE 802.1Q to enable trunking on a router subinterface. See the
following diagram for a VLAN-to-VLAN overview.
VLAN-to-VLAN Overview

Obtained from Cisco.com.

Router on a Stick
◦ The diagram illustrates a router attached to a core switch.
◦ The configuration between a router and a core switch is sometimes referred to as a
router on a stick.
◦ The router can receive can receive packets on one VLAN and forward them to another
VLAN.
◦ To perform inter-VLAN routing functions, the router must know how to reach all
interconnected VLANs.
◦ There must be a separate connection on the router for each VLAN, or you must enable
802.1Q trunking on those connections.
◦ The router already knows about directly connected networks.
◦ The router must learn routes to networks to which it is not directly connected.
Overview of Subinterfaces
◦ To support 802.1Q trunking, you must subdivide the physical Fast Ethernet interface of
the router into multiple, logical, addressable interfaces, one per VLAN.
◦ The resulting logical interfaces are called Subinterfaces.
◦ Without this subdivision, you would to dedicate a separate physical interface to each
VLAN.



Example: Subinterfaces

Obtained from Cisco.com.

◦ In the figure, the FastEthernet0/0 interface is divided multiple subinterfaces:




FastEthernet0/0.1
FastEthernet0/0.2
FastEthernet0/0.3
Configuring Inter-VLAN Routing

Obtained from Cisco.com.



Example: Inter-VLAN routing with 802.1Q
◦

In the figure, the fastEthernet0/0 interface is divided into multiple subinterfaces.

◦

Each subinterface represents the router in each of the VLANs for which it routes, except in the native
VLAN (in this example there is only one subinterface).

◦

The 802.1Q native VLAN frames do not carry a tag.

◦

The native VLAN here is represented by the major interface of the trunk; therefore the FastEthernet0/0
interface has an IP address in the native VLAN address space.
Example: Inter-VLAN routing with 802.1Q
continues…
◦ Use the encapsulation dot1q vlan identifier IOS command (where vlan identifier is the
VLAN number) on each subinterface to enable 802.1Q encapsulation trunking.
◦ The subinterface number does not have to be the same as the VLAN
number, however, management is easier when the two numbers are the same.
◦ Alternatively, the native VLAN can be configured on a subinterface by using the
encapsulation dot1Q vlan identifier native IOS command on the subinterface.
◦ Ensure that the VLAN assigned as the native VLAN matches the native VLAN on the
switch to which the router connects.
Inter-VLAN Routing Using an Internal Router


Internal Router Using a Core 6500 Multilayer switch
◦
◦

Your organization’s Core 6500 switch employs Multilayer Switch Feature Card (MSFC) for inter-VLAN
routing.

◦



While inter-VLAN routing with a router on a tick uses an external router, your own organization
accomplishes the same VLAN routing functionality using a router built in to the Core 6500 switch.

In your organization, the router for inter-VLAN routing resides as a module inside the Core 6500 switch.

Example: Inter-VLAN routing with 802.1Q on a 6500
◦

The is no needs for subinterfaces for inter-VLAN routing in this environment

◦

To configure inter-VLAN routing on your Core 6500 environment you need to do the following:











You need to create a VLAN management interface on the Core 6500 switch to be used as the default
gateway for switches in the vtp client mode.
Assign an IP address to the management interface.
For switches in the vtp client mode, create inter-VLAN routing based on the Core management VLAN ID.
Assign a unique management IP address to each switch on the campus network that are trunking.
Use the Core management IP address as the default gateway for all other switches in the organization.
Configure uplink interfaces as trunking interfaces.
Use encapsulation dot1q.
Use native VLAN 100
Set uplink interface modes to trunk
The following diagram figure show an overview of the process:
Inter-VLAN Routing Using an Internal Router
Lesson 04: Wrap-up


Summary
◦ Inter-VLAN routing using a router on a stick
utilizes an external router to pass traffic between
VLANs.
◦ Inter-VLAN routing using a Core 6500 switch
utilizes an internal to pass traffic between VLANs
◦ A router on a stick is configured with a
subinterface for each VLAN (except possibly for
the native VLAN) and 802.1Q trunk
encapsulation.

More Related Content

What's hot

Cap6 intervlan routing
Cap6   intervlan routingCap6   intervlan routing
Cap6 intervlan routing
Hector Camba Lainez
 
Vlans (virtual local area networks)
Vlans (virtual local area networks)Vlans (virtual local area networks)
Vlans (virtual local area networks)
Kanishk Raj
 
Lab 6.4.1 InterVLAN routing
Lab 6.4.1 InterVLAN routingLab 6.4.1 InterVLAN routing
Lab 6.4.1 InterVLAN routing
Muhd Mu'izuddin
 
VLAN (Virtual Local Area Network)
VLAN (Virtual Local Area Network)VLAN (Virtual Local Area Network)
VLAN (Virtual Local Area Network)
NetProtocol Xpert
 
vlan
vlanvlan
LAN Switching and Wireless: Ch4 - VLAN Trunking Protocol (VTP)
LAN Switching and Wireless: Ch4 - VLAN Trunking Protocol (VTP)LAN Switching and Wireless: Ch4 - VLAN Trunking Protocol (VTP)
LAN Switching and Wireless: Ch4 - VLAN Trunking Protocol (VTP)
Abdelkhalik Mosa
 
VLAN Network for Extreme Networks
VLAN Network for Extreme NetworksVLAN Network for Extreme Networks
VLAN Network for Extreme Networks
Dani Royman Simanjuntak
 
Tn 310 vlan-trunking
Tn 310 vlan-trunkingTn 310 vlan-trunking
Tn 310 vlan-trunking
sali Ibrahimu
 
Vlans and inter vlan routing
Vlans and inter vlan routingVlans and inter vlan routing
Vlans and inter vlan routing
Mohammedseleim
 
At8000 s configurando vla_ns
At8000 s configurando vla_nsAt8000 s configurando vla_ns
At8000 s configurando vla_nsNetPlus
 
Vlan
VlanVlan
Vlan Types
Vlan TypesVlan Types
Vlan Types
IT Tech
 
What is a VLAN?
What is a VLAN?What is a VLAN?
What is a VLAN?
NetProtocol Xpert
 
Vlans
VlansVlans
Vlans1 2d
 
Cap4 implementing vtp
Cap4   implementing vtpCap4   implementing vtp
Cap4 implementing vtp
Hector Camba Lainez
 
Benefits of vlan
Benefits of vlanBenefits of vlan
Benefits of vlan
Logitrain
 

What's hot (20)

Ccna3 mod9-vtp
Ccna3 mod9-vtpCcna3 mod9-vtp
Ccna3 mod9-vtp
 
Cap6 intervlan routing
Cap6   intervlan routingCap6   intervlan routing
Cap6 intervlan routing
 
CCNA- part 9 vlan
CCNA- part 9 vlanCCNA- part 9 vlan
CCNA- part 9 vlan
 
Vlans (virtual local area networks)
Vlans (virtual local area networks)Vlans (virtual local area networks)
Vlans (virtual local area networks)
 
Lab 6.4.1 InterVLAN routing
Lab 6.4.1 InterVLAN routingLab 6.4.1 InterVLAN routing
Lab 6.4.1 InterVLAN routing
 
VLAN (Virtual Local Area Network)
VLAN (Virtual Local Area Network)VLAN (Virtual Local Area Network)
VLAN (Virtual Local Area Network)
 
vlan
vlanvlan
vlan
 
LAN Switching and Wireless: Ch4 - VLAN Trunking Protocol (VTP)
LAN Switching and Wireless: Ch4 - VLAN Trunking Protocol (VTP)LAN Switching and Wireless: Ch4 - VLAN Trunking Protocol (VTP)
LAN Switching and Wireless: Ch4 - VLAN Trunking Protocol (VTP)
 
VLAN Network for Extreme Networks
VLAN Network for Extreme NetworksVLAN Network for Extreme Networks
VLAN Network for Extreme Networks
 
Tn 310 vlan-trunking
Tn 310 vlan-trunkingTn 310 vlan-trunking
Tn 310 vlan-trunking
 
Vlans and inter vlan routing
Vlans and inter vlan routingVlans and inter vlan routing
Vlans and inter vlan routing
 
At8000 s configurando vla_ns
At8000 s configurando vla_nsAt8000 s configurando vla_ns
At8000 s configurando vla_ns
 
Vlan
VlanVlan
Vlan
 
Vlan Types
Vlan TypesVlan Types
Vlan Types
 
What is a VLAN?
What is a VLAN?What is a VLAN?
What is a VLAN?
 
Vlans
VlansVlans
Vlans
 
Vlan
Vlan Vlan
Vlan
 
Vlan
VlanVlan
Vlan
 
Cap4 implementing vtp
Cap4   implementing vtpCap4   implementing vtp
Cap4 implementing vtp
 
Benefits of vlan
Benefits of vlanBenefits of vlan
Benefits of vlan
 

Viewers also liked

A2 advanced portfolio production diary template 2013 to 2014
A2 advanced portfolio production diary template 2013 to 2014A2 advanced portfolio production diary template 2013 to 2014
A2 advanced portfolio production diary template 2013 to 2014emilykgrimshaw
 
Promoción del turismo en el salvador
Promoción del turismo en el salvadorPromoción del turismo en el salvador
Promoción del turismo en el salvador
Wilber Rivas
 
Good, Fast, or Cheap.
Good, Fast, or Cheap. Good, Fast, or Cheap.
Good, Fast, or Cheap.
Liana Underwood
 
JongwingsDesignPortfolio2016
JongwingsDesignPortfolio2016JongwingsDesignPortfolio2016
JongwingsDesignPortfolio2016
Jongwings
 
Pendekatan saintifik ilmiah
Pendekatan saintifik ilmiahPendekatan saintifik ilmiah
Pendekatan saintifik ilmiah
Joe Zidane
 
Foniя records
Foniя recordsFoniя records
Foniя recordsbordunihor
 
Git - распределенная система контроля версий
Git - распределенная система контроля версийGit - распределенная система контроля версий
Git - распределенная система контроля версий
Oleg Poyaganov
 
Where i’m from
Where i’m fromWhere i’m from
Where i’m fromronn2
 
Almacenaje
Almacenaje Almacenaje
Almacenaje
Kike Anampa Vilchez
 
Automatic weather station
Automatic weather stationAutomatic weather station
Automatic weather station
sgmlab360
 
Where to start when you dont know where to start
Where to start when you dont know where to startWhere to start when you dont know where to start
Where to start when you dont know where to start
Liana Underwood
 
Charles darwin viaje de un naturalista
Charles darwin   viaje de un naturalistaCharles darwin   viaje de un naturalista
Charles darwin viaje de un naturalista
Jonathan Aranda Alavarado
 
catalogo
catalogocatalogo
catalogo
litus13
 
In what ways does my media product represent particular social groups?
In what ways does my media product represent particular social groups?In what ways does my media product represent particular social groups?
In what ways does my media product represent particular social groups?
JodieNiamh287
 
Media technologies
Media technologiesMedia technologies
Media technologies
elizaeagles
 
DOM E-5064 09102015
DOM E-5064 09102015DOM E-5064 09102015
DOM E-5064 09102015
samir_bhowmik
 
PM Reston Managing Stakeholders by Robert Godbey
PM Reston Managing Stakeholders by Robert GodbeyPM Reston Managing Stakeholders by Robert Godbey
PM Reston Managing Stakeholders by Robert Godbey
Liana Underwood
 

Viewers also liked (20)

A2 advanced portfolio production diary template 2013 to 2014
A2 advanced portfolio production diary template 2013 to 2014A2 advanced portfolio production diary template 2013 to 2014
A2 advanced portfolio production diary template 2013 to 2014
 
Promoción del turismo en el salvador
Promoción del turismo en el salvadorPromoción del turismo en el salvador
Promoción del turismo en el salvador
 
Good, Fast, or Cheap.
Good, Fast, or Cheap. Good, Fast, or Cheap.
Good, Fast, or Cheap.
 
JongwingsDesignPortfolio2016
JongwingsDesignPortfolio2016JongwingsDesignPortfolio2016
JongwingsDesignPortfolio2016
 
Pendekatan saintifik ilmiah
Pendekatan saintifik ilmiahPendekatan saintifik ilmiah
Pendekatan saintifik ilmiah
 
:-
:-:-
:-
 
Foniя records
Foniя recordsFoniя records
Foniя records
 
Git - распределенная система контроля версий
Git - распределенная система контроля версийGit - распределенная система контроля версий
Git - распределенная система контроля версий
 
Where i’m from
Where i’m fromWhere i’m from
Where i’m from
 
Almacenaje
Almacenaje Almacenaje
Almacenaje
 
Automatic weather station
Automatic weather stationAutomatic weather station
Automatic weather station
 
Sephoraulta
SephoraultaSephoraulta
Sephoraulta
 
Evaluation question 4
Evaluation question  4Evaluation question  4
Evaluation question 4
 
Where to start when you dont know where to start
Where to start when you dont know where to startWhere to start when you dont know where to start
Where to start when you dont know where to start
 
Charles darwin viaje de un naturalista
Charles darwin   viaje de un naturalistaCharles darwin   viaje de un naturalista
Charles darwin viaje de un naturalista
 
catalogo
catalogocatalogo
catalogo
 
In what ways does my media product represent particular social groups?
In what ways does my media product represent particular social groups?In what ways does my media product represent particular social groups?
In what ways does my media product represent particular social groups?
 
Media technologies
Media technologiesMedia technologies
Media technologies
 
DOM E-5064 09102015
DOM E-5064 09102015DOM E-5064 09102015
DOM E-5064 09102015
 
PM Reston Managing Stakeholders by Robert Godbey
PM Reston Managing Stakeholders by Robert GodbeyPM Reston Managing Stakeholders by Robert Godbey
PM Reston Managing Stakeholders by Robert Godbey
 

Similar to IT0527 Inter-VLAN Routing

VIRTUAL LANS
VIRTUAL LANSVIRTUAL LANS
VIRTUAL LANSanilinvns
 
Day 5 VIRTUAL LANS
Day 5 VIRTUAL LANSDay 5 VIRTUAL LANS
Day 5 VIRTUAL LANS
anilinvns
 
Lecture_Network Design, InterVlan Routing and Trunking_.pptx
Lecture_Network Design, InterVlan Routing and Trunking_.pptxLecture_Network Design, InterVlan Routing and Trunking_.pptx
Lecture_Network Design, InterVlan Routing and Trunking_.pptx
SaqibAhmedKhan4
 
VLAN
VLANVLAN
vlaN.pptgfggdfgdrgsegtrgthyrtewgsrdhftjf
vlaN.pptgfggdfgdrgsegtrgthyrtewgsrdhftjfvlaN.pptgfggdfgdrgsegtrgthyrtewgsrdhftjf
vlaN.pptgfggdfgdrgsegtrgthyrtewgsrdhftjf
peterhaile1
 
mod8-VLANs.ppt
mod8-VLANs.pptmod8-VLANs.ppt
mod8-VLANs.ppt
SAROORNAGARCMCORE
 
Virtual Local Area Network
Virtual Local Area NetworkVirtual Local Area Network
Virtual Local Area Network
Atakan ATAK
 
Chapter 8 .vlan.pdf
Chapter 8 .vlan.pdfChapter 8 .vlan.pdf
Chapter 8 .vlan.pdf
manojkumar595505
 
VLANs_Module_3.pptx
VLANs_Module_3.pptxVLANs_Module_3.pptx
VLANs_Module_3.pptx
BOURY1
 
Chapter 16 : inter-vlan routing
Chapter 16 : inter-vlan routingChapter 16 : inter-vlan routing
Chapter 16 : inter-vlan routing
teknetir
 
intervlan routing using different m.pptx
intervlan routing using different m.pptxintervlan routing using different m.pptx
intervlan routing using different m.pptx
Rexious Huka
 
Chapter 05 - Inter-VLAN Routing
Chapter 05 - Inter-VLAN RoutingChapter 05 - Inter-VLAN Routing
Chapter 05 - Inter-VLAN Routing
Yaser Rahmati
 
KPUCC-Rs instructor ppt_chapter5_final
KPUCC-Rs instructor ppt_chapter5_finalKPUCC-Rs instructor ppt_chapter5_final
KPUCC-Rs instructor ppt_chapter5_final
Fisal Anwari
 
CCNAv5 - S2: Chapter5 Inter Vlan Routing
CCNAv5 - S2: Chapter5 Inter Vlan RoutingCCNAv5 - S2: Chapter5 Inter Vlan Routing
CCNAv5 - S2: Chapter5 Inter Vlan Routing
Vuz Dở Hơi
 
CCNA R&S-10-Implementing Ethernet Virtual LANs
CCNA R&S-10-Implementing Ethernet Virtual LANsCCNA R&S-10-Implementing Ethernet Virtual LANs
CCNA R&S-10-Implementing Ethernet Virtual LANs
Amir Jafari
 
CCNA- Router on stick, VLAN and Trunking
CCNA- Router on stick, VLAN and TrunkingCCNA- Router on stick, VLAN and Trunking
CCNA- Router on stick, VLAN and Trunking
Rafat Khandaker
 
Vlan configuration in medium sized network
Vlan configuration in medium sized networkVlan configuration in medium sized network
Vlan configuration in medium sized network
Arnold Derrick Kinney
 
Mod8 vlans
Mod8 vlansMod8 vlans
Mod8 vlans
Mohan Kumaresan
 
CCNA_RSE_Chp6.pptx
CCNA_RSE_Chp6.pptxCCNA_RSE_Chp6.pptx
CCNA_RSE_Chp6.pptx
santosh Kumar
 
VLAN chapters for networking CCNA_RSE_Chp6.pptx
VLAN chapters for networking CCNA_RSE_Chp6.pptxVLAN chapters for networking CCNA_RSE_Chp6.pptx
VLAN chapters for networking CCNA_RSE_Chp6.pptx
muhammadFaheem656405
 

Similar to IT0527 Inter-VLAN Routing (20)

VIRTUAL LANS
VIRTUAL LANSVIRTUAL LANS
VIRTUAL LANS
 
Day 5 VIRTUAL LANS
Day 5 VIRTUAL LANSDay 5 VIRTUAL LANS
Day 5 VIRTUAL LANS
 
Lecture_Network Design, InterVlan Routing and Trunking_.pptx
Lecture_Network Design, InterVlan Routing and Trunking_.pptxLecture_Network Design, InterVlan Routing and Trunking_.pptx
Lecture_Network Design, InterVlan Routing and Trunking_.pptx
 
VLAN
VLANVLAN
VLAN
 
vlaN.pptgfggdfgdrgsegtrgthyrtewgsrdhftjf
vlaN.pptgfggdfgdrgsegtrgthyrtewgsrdhftjfvlaN.pptgfggdfgdrgsegtrgthyrtewgsrdhftjf
vlaN.pptgfggdfgdrgsegtrgthyrtewgsrdhftjf
 
mod8-VLANs.ppt
mod8-VLANs.pptmod8-VLANs.ppt
mod8-VLANs.ppt
 
Virtual Local Area Network
Virtual Local Area NetworkVirtual Local Area Network
Virtual Local Area Network
 
Chapter 8 .vlan.pdf
Chapter 8 .vlan.pdfChapter 8 .vlan.pdf
Chapter 8 .vlan.pdf
 
VLANs_Module_3.pptx
VLANs_Module_3.pptxVLANs_Module_3.pptx
VLANs_Module_3.pptx
 
Chapter 16 : inter-vlan routing
Chapter 16 : inter-vlan routingChapter 16 : inter-vlan routing
Chapter 16 : inter-vlan routing
 
intervlan routing using different m.pptx
intervlan routing using different m.pptxintervlan routing using different m.pptx
intervlan routing using different m.pptx
 
Chapter 05 - Inter-VLAN Routing
Chapter 05 - Inter-VLAN RoutingChapter 05 - Inter-VLAN Routing
Chapter 05 - Inter-VLAN Routing
 
KPUCC-Rs instructor ppt_chapter5_final
KPUCC-Rs instructor ppt_chapter5_finalKPUCC-Rs instructor ppt_chapter5_final
KPUCC-Rs instructor ppt_chapter5_final
 
CCNAv5 - S2: Chapter5 Inter Vlan Routing
CCNAv5 - S2: Chapter5 Inter Vlan RoutingCCNAv5 - S2: Chapter5 Inter Vlan Routing
CCNAv5 - S2: Chapter5 Inter Vlan Routing
 
CCNA R&S-10-Implementing Ethernet Virtual LANs
CCNA R&S-10-Implementing Ethernet Virtual LANsCCNA R&S-10-Implementing Ethernet Virtual LANs
CCNA R&S-10-Implementing Ethernet Virtual LANs
 
CCNA- Router on stick, VLAN and Trunking
CCNA- Router on stick, VLAN and TrunkingCCNA- Router on stick, VLAN and Trunking
CCNA- Router on stick, VLAN and Trunking
 
Vlan configuration in medium sized network
Vlan configuration in medium sized networkVlan configuration in medium sized network
Vlan configuration in medium sized network
 
Mod8 vlans
Mod8 vlansMod8 vlans
Mod8 vlans
 
CCNA_RSE_Chp6.pptx
CCNA_RSE_Chp6.pptxCCNA_RSE_Chp6.pptx
CCNA_RSE_Chp6.pptx
 
VLAN chapters for networking CCNA_RSE_Chp6.pptx
VLAN chapters for networking CCNA_RSE_Chp6.pptxVLAN chapters for networking CCNA_RSE_Chp6.pptx
VLAN chapters for networking CCNA_RSE_Chp6.pptx
 

Recently uploaded

Pushing the limits of ePRTC: 100ns holdover for 100 days
Pushing the limits of ePRTC: 100ns holdover for 100 daysPushing the limits of ePRTC: 100ns holdover for 100 days
Pushing the limits of ePRTC: 100ns holdover for 100 days
Adtran
 
みなさんこんにちはこれ何文字まで入るの?40文字以下不可とか本当に意味わからないけどこれ限界文字数書いてないからマジでやばい文字数いけるんじゃないの?えこ...
みなさんこんにちはこれ何文字まで入るの?40文字以下不可とか本当に意味わからないけどこれ限界文字数書いてないからマジでやばい文字数いけるんじゃないの?えこ...みなさんこんにちはこれ何文字まで入るの?40文字以下不可とか本当に意味わからないけどこれ限界文字数書いてないからマジでやばい文字数いけるんじゃないの?えこ...
みなさんこんにちはこれ何文字まで入るの?40文字以下不可とか本当に意味わからないけどこれ限界文字数書いてないからマジでやばい文字数いけるんじゃないの?えこ...
名前 です男
 
National Security Agency - NSA mobile device best practices
National Security Agency - NSA mobile device best practicesNational Security Agency - NSA mobile device best practices
National Security Agency - NSA mobile device best practices
Quotidiano Piemontese
 
GraphRAG is All You need? LLM & Knowledge Graph
GraphRAG is All You need? LLM & Knowledge GraphGraphRAG is All You need? LLM & Knowledge Graph
GraphRAG is All You need? LLM & Knowledge Graph
Guy Korland
 
20240609 QFM020 Irresponsible AI Reading List May 2024
20240609 QFM020 Irresponsible AI Reading List May 202420240609 QFM020 Irresponsible AI Reading List May 2024
20240609 QFM020 Irresponsible AI Reading List May 2024
Matthew Sinclair
 
PCI PIN Basics Webinar from the Controlcase Team
PCI PIN Basics Webinar from the Controlcase TeamPCI PIN Basics Webinar from the Controlcase Team
PCI PIN Basics Webinar from the Controlcase Team
ControlCase
 
Securing your Kubernetes cluster_ a step-by-step guide to success !
Securing your Kubernetes cluster_ a step-by-step guide to success !Securing your Kubernetes cluster_ a step-by-step guide to success !
Securing your Kubernetes cluster_ a step-by-step guide to success !
KatiaHIMEUR1
 
GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using Deplo...
GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using Deplo...GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using Deplo...
GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using Deplo...
James Anderson
 
Removing Uninteresting Bytes in Software Fuzzing
Removing Uninteresting Bytes in Software FuzzingRemoving Uninteresting Bytes in Software Fuzzing
Removing Uninteresting Bytes in Software Fuzzing
Aftab Hussain
 
20240607 QFM018 Elixir Reading List May 2024
20240607 QFM018 Elixir Reading List May 202420240607 QFM018 Elixir Reading List May 2024
20240607 QFM018 Elixir Reading List May 2024
Matthew Sinclair
 
Microsoft - Power Platform_G.Aspiotis.pdf
Microsoft - Power Platform_G.Aspiotis.pdfMicrosoft - Power Platform_G.Aspiotis.pdf
Microsoft - Power Platform_G.Aspiotis.pdf
Uni Systems S.M.S.A.
 
GraphSummit Singapore | Graphing Success: Revolutionising Organisational Stru...
GraphSummit Singapore | Graphing Success: Revolutionising Organisational Stru...GraphSummit Singapore | Graphing Success: Revolutionising Organisational Stru...
GraphSummit Singapore | Graphing Success: Revolutionising Organisational Stru...
Neo4j
 
Mind map of terminologies used in context of Generative AI
Mind map of terminologies used in context of Generative AIMind map of terminologies used in context of Generative AI
Mind map of terminologies used in context of Generative AI
Kumud Singh
 
Climate Impact of Software Testing at Nordic Testing Days
Climate Impact of Software Testing at Nordic Testing DaysClimate Impact of Software Testing at Nordic Testing Days
Climate Impact of Software Testing at Nordic Testing Days
Kari Kakkonen
 
DevOps and Testing slides at DASA Connect
DevOps and Testing slides at DASA ConnectDevOps and Testing slides at DASA Connect
DevOps and Testing slides at DASA Connect
Kari Kakkonen
 
RESUME BUILDER APPLICATION Project for students
RESUME BUILDER APPLICATION Project for studentsRESUME BUILDER APPLICATION Project for students
RESUME BUILDER APPLICATION Project for students
KAMESHS29
 
GridMate - End to end testing is a critical piece to ensure quality and avoid...
GridMate - End to end testing is a critical piece to ensure quality and avoid...GridMate - End to end testing is a critical piece to ensure quality and avoid...
GridMate - End to end testing is a critical piece to ensure quality and avoid...
ThomasParaiso2
 
Alt. GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using ...
Alt. GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using ...Alt. GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using ...
Alt. GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using ...
James Anderson
 
Observability Concepts EVERY Developer Should Know -- DeveloperWeek Europe.pdf
Observability Concepts EVERY Developer Should Know -- DeveloperWeek Europe.pdfObservability Concepts EVERY Developer Should Know -- DeveloperWeek Europe.pdf
Observability Concepts EVERY Developer Should Know -- DeveloperWeek Europe.pdf
Paige Cruz
 
Monitoring Java Application Security with JDK Tools and JFR Events
Monitoring Java Application Security with JDK Tools and JFR EventsMonitoring Java Application Security with JDK Tools and JFR Events
Monitoring Java Application Security with JDK Tools and JFR Events
Ana-Maria Mihalceanu
 

Recently uploaded (20)

Pushing the limits of ePRTC: 100ns holdover for 100 days
Pushing the limits of ePRTC: 100ns holdover for 100 daysPushing the limits of ePRTC: 100ns holdover for 100 days
Pushing the limits of ePRTC: 100ns holdover for 100 days
 
みなさんこんにちはこれ何文字まで入るの?40文字以下不可とか本当に意味わからないけどこれ限界文字数書いてないからマジでやばい文字数いけるんじゃないの?えこ...
みなさんこんにちはこれ何文字まで入るの?40文字以下不可とか本当に意味わからないけどこれ限界文字数書いてないからマジでやばい文字数いけるんじゃないの?えこ...みなさんこんにちはこれ何文字まで入るの?40文字以下不可とか本当に意味わからないけどこれ限界文字数書いてないからマジでやばい文字数いけるんじゃないの?えこ...
みなさんこんにちはこれ何文字まで入るの?40文字以下不可とか本当に意味わからないけどこれ限界文字数書いてないからマジでやばい文字数いけるんじゃないの?えこ...
 
National Security Agency - NSA mobile device best practices
National Security Agency - NSA mobile device best practicesNational Security Agency - NSA mobile device best practices
National Security Agency - NSA mobile device best practices
 
GraphRAG is All You need? LLM & Knowledge Graph
GraphRAG is All You need? LLM & Knowledge GraphGraphRAG is All You need? LLM & Knowledge Graph
GraphRAG is All You need? LLM & Knowledge Graph
 
20240609 QFM020 Irresponsible AI Reading List May 2024
20240609 QFM020 Irresponsible AI Reading List May 202420240609 QFM020 Irresponsible AI Reading List May 2024
20240609 QFM020 Irresponsible AI Reading List May 2024
 
PCI PIN Basics Webinar from the Controlcase Team
PCI PIN Basics Webinar from the Controlcase TeamPCI PIN Basics Webinar from the Controlcase Team
PCI PIN Basics Webinar from the Controlcase Team
 
Securing your Kubernetes cluster_ a step-by-step guide to success !
Securing your Kubernetes cluster_ a step-by-step guide to success !Securing your Kubernetes cluster_ a step-by-step guide to success !
Securing your Kubernetes cluster_ a step-by-step guide to success !
 
GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using Deplo...
GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using Deplo...GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using Deplo...
GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using Deplo...
 
Removing Uninteresting Bytes in Software Fuzzing
Removing Uninteresting Bytes in Software FuzzingRemoving Uninteresting Bytes in Software Fuzzing
Removing Uninteresting Bytes in Software Fuzzing
 
20240607 QFM018 Elixir Reading List May 2024
20240607 QFM018 Elixir Reading List May 202420240607 QFM018 Elixir Reading List May 2024
20240607 QFM018 Elixir Reading List May 2024
 
Microsoft - Power Platform_G.Aspiotis.pdf
Microsoft - Power Platform_G.Aspiotis.pdfMicrosoft - Power Platform_G.Aspiotis.pdf
Microsoft - Power Platform_G.Aspiotis.pdf
 
GraphSummit Singapore | Graphing Success: Revolutionising Organisational Stru...
GraphSummit Singapore | Graphing Success: Revolutionising Organisational Stru...GraphSummit Singapore | Graphing Success: Revolutionising Organisational Stru...
GraphSummit Singapore | Graphing Success: Revolutionising Organisational Stru...
 
Mind map of terminologies used in context of Generative AI
Mind map of terminologies used in context of Generative AIMind map of terminologies used in context of Generative AI
Mind map of terminologies used in context of Generative AI
 
Climate Impact of Software Testing at Nordic Testing Days
Climate Impact of Software Testing at Nordic Testing DaysClimate Impact of Software Testing at Nordic Testing Days
Climate Impact of Software Testing at Nordic Testing Days
 
DevOps and Testing slides at DASA Connect
DevOps and Testing slides at DASA ConnectDevOps and Testing slides at DASA Connect
DevOps and Testing slides at DASA Connect
 
RESUME BUILDER APPLICATION Project for students
RESUME BUILDER APPLICATION Project for studentsRESUME BUILDER APPLICATION Project for students
RESUME BUILDER APPLICATION Project for students
 
GridMate - End to end testing is a critical piece to ensure quality and avoid...
GridMate - End to end testing is a critical piece to ensure quality and avoid...GridMate - End to end testing is a critical piece to ensure quality and avoid...
GridMate - End to end testing is a critical piece to ensure quality and avoid...
 
Alt. GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using ...
Alt. GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using ...Alt. GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using ...
Alt. GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using ...
 
Observability Concepts EVERY Developer Should Know -- DeveloperWeek Europe.pdf
Observability Concepts EVERY Developer Should Know -- DeveloperWeek Europe.pdfObservability Concepts EVERY Developer Should Know -- DeveloperWeek Europe.pdf
Observability Concepts EVERY Developer Should Know -- DeveloperWeek Europe.pdf
 
Monitoring Java Application Security with JDK Tools and JFR Events
Monitoring Java Application Security with JDK Tools and JFR EventsMonitoring Java Application Security with JDK Tools and JFR Events
Monitoring Java Application Security with JDK Tools and JFR Events
 

IT0527 Inter-VLAN Routing

  • 1. Lesson 04: Analyzing Inter-VLAN Routing  Overview ◦ Routing is the process of determining where to send data packets destined for addresses outside of the network. ◦ Routers gather and maintain routing information to enable the transmission and receipt of data packets. ◦ For traffic to cross from one VLAN to another, a Layer 3 process is necessary.  Understanding Inter-VLAN Routing ◦ Inter-VLAN communication occurs between broadcast domains via a Layer 3 device. ◦ In a VLAN environment, frames are switched only between ports within the same broadcast domain. ◦ VLANs perform network partitioning and traffic separation at Layer 2. ◦ Inter-VLAN communication cannot occur without a Layer 3 device, such as a router. ◦ This process uses IEEE 802.1Q to enable trunking on a router subinterface. See the following diagram for a VLAN-to-VLAN overview.
  • 2. VLAN-to-VLAN Overview Obtained from Cisco.com. Router on a Stick ◦ The diagram illustrates a router attached to a core switch. ◦ The configuration between a router and a core switch is sometimes referred to as a router on a stick. ◦ The router can receive can receive packets on one VLAN and forward them to another VLAN. ◦ To perform inter-VLAN routing functions, the router must know how to reach all interconnected VLANs. ◦ There must be a separate connection on the router for each VLAN, or you must enable 802.1Q trunking on those connections. ◦ The router already knows about directly connected networks. ◦ The router must learn routes to networks to which it is not directly connected.
  • 3. Overview of Subinterfaces ◦ To support 802.1Q trunking, you must subdivide the physical Fast Ethernet interface of the router into multiple, logical, addressable interfaces, one per VLAN. ◦ The resulting logical interfaces are called Subinterfaces. ◦ Without this subdivision, you would to dedicate a separate physical interface to each VLAN.  Example: Subinterfaces Obtained from Cisco.com. ◦ In the figure, the FastEthernet0/0 interface is divided multiple subinterfaces:    FastEthernet0/0.1 FastEthernet0/0.2 FastEthernet0/0.3
  • 4. Configuring Inter-VLAN Routing Obtained from Cisco.com.  Example: Inter-VLAN routing with 802.1Q ◦ In the figure, the fastEthernet0/0 interface is divided into multiple subinterfaces. ◦ Each subinterface represents the router in each of the VLANs for which it routes, except in the native VLAN (in this example there is only one subinterface). ◦ The 802.1Q native VLAN frames do not carry a tag. ◦ The native VLAN here is represented by the major interface of the trunk; therefore the FastEthernet0/0 interface has an IP address in the native VLAN address space.
  • 5. Example: Inter-VLAN routing with 802.1Q continues… ◦ Use the encapsulation dot1q vlan identifier IOS command (where vlan identifier is the VLAN number) on each subinterface to enable 802.1Q encapsulation trunking. ◦ The subinterface number does not have to be the same as the VLAN number, however, management is easier when the two numbers are the same. ◦ Alternatively, the native VLAN can be configured on a subinterface by using the encapsulation dot1Q vlan identifier native IOS command on the subinterface. ◦ Ensure that the VLAN assigned as the native VLAN matches the native VLAN on the switch to which the router connects.
  • 6. Inter-VLAN Routing Using an Internal Router  Internal Router Using a Core 6500 Multilayer switch ◦ ◦ Your organization’s Core 6500 switch employs Multilayer Switch Feature Card (MSFC) for inter-VLAN routing. ◦  While inter-VLAN routing with a router on a tick uses an external router, your own organization accomplishes the same VLAN routing functionality using a router built in to the Core 6500 switch. In your organization, the router for inter-VLAN routing resides as a module inside the Core 6500 switch. Example: Inter-VLAN routing with 802.1Q on a 6500 ◦ The is no needs for subinterfaces for inter-VLAN routing in this environment ◦ To configure inter-VLAN routing on your Core 6500 environment you need to do the following:           You need to create a VLAN management interface on the Core 6500 switch to be used as the default gateway for switches in the vtp client mode. Assign an IP address to the management interface. For switches in the vtp client mode, create inter-VLAN routing based on the Core management VLAN ID. Assign a unique management IP address to each switch on the campus network that are trunking. Use the Core management IP address as the default gateway for all other switches in the organization. Configure uplink interfaces as trunking interfaces. Use encapsulation dot1q. Use native VLAN 100 Set uplink interface modes to trunk The following diagram figure show an overview of the process:
  • 7. Inter-VLAN Routing Using an Internal Router
  • 8. Lesson 04: Wrap-up  Summary ◦ Inter-VLAN routing using a router on a stick utilizes an external router to pass traffic between VLANs. ◦ Inter-VLAN routing using a Core 6500 switch utilizes an internal to pass traffic between VLANs ◦ A router on a stick is configured with a subinterface for each VLAN (except possibly for the native VLAN) and 802.1Q trunk encapsulation.