ã¿ã° VLAN ã䜿ãå Žåã¯ããŒãã«ãã©ã³ã¯ããŒã (trunk port)ãšããèšå®ãå ¥ããå¿ èŠããããŸãããã©ã³ã¯ããŒãã§ã¯ãªãããŒãã¯ã¢ã¯ã»ã¹ããŒã (access port)ãšåŒã³ãŸããä»åã¯ãã® 2 çš®é¡ã®ããŒãã説æããŸãã
ã¢ã¯ã»ã¹ããŒããšãã©ã³ã¯ããŒã
ã¢ã¯ã»ã¹ããŒããšã¯ãVLAN 察å¿ã®ã¹ã€ããã§ã1 ã€ã® VLAN ã®ã¿æå±ããŠããããŒãã§ããäžèšã®å³ã§èšããšã端æ«ãå·®ãã£ãŠããè²ä»ãã®ããŒãã®ããšã§ããã¢ã¯ã»ã¹ããŒãã¯åžžã«ã¿ã°ãç¡ã (untag ãšèšããŸã) ç¶æ ã§ããã¢ã¯ã»ã¹ããŒãã®æ¥ç¶ãã¢ã¯ã»ã¹ãªã³ã¯ãšèšããŸãã
äŸãã° gigabitEthernet 0/1 ããŒãã« VLAN 10 ãèšå®ããå ŽåãCisco Catalyst ã§ããã°ä»¥äžã®ããã«ãªããŸãã
(config)# interface gigabitEthernet 0/1 (config-if)# switchport mode access (config-if)# switchport access vlan 10
äžæ¹ããã©ã³ã¯ããŒããšã¯ãã¿ã° VLAN ã䜿ããè€æ° VLAN ãæå±ããŠããããŒãã§ãã
å çšã®å³ã§èšããšãL3 ã¹ã€ãããš L2 ã¹ã€ããã®éã®é»è²ã®æ¥ç¶ããŒãã§ããL3 ã¹ã€ãããL2 ã¹ã€ãããšãã«ãã©ã³ã¯ããŒãã§ããã©ã³ã¯ããŒãåå£«ãæ¥ç¶ããŸãããã®æ¥ç¶ããã©ã³ã¯ãªã³ã¯ãšèšããŸãã
äŸãã° gigabitEthernet 0/24 ããŒãã«ãã©ã³ã¯ããŒããèšå®ããå ŽåãCisco Catalyst ã§ããã°ä»¥äžã®ããã«ãªããŸãã
(config)# interface gigabitEthernet 0/24 (config-if)# switchport mode trunk
ããã ãã ãšå šãŠã® VLAN ããã®ããŒãããæµããŠãããŸããäŸãã° VLAN10, 20 ã ããæµãããå Žåã¯ä»¥äžã³ãã³ããæã¡ãŸãã
(config-if)# switchport trunk allowed vlan 10, 20
ãŸããããšãã远å ã§ VLAN 999 ãå ããããšãªã£ãå Žåã¯ä»¥äžã³ãã³ããæã¡ãŸãã
(config-if)# switchport trunk allowed vlan add 999
ãã® add ããã£ããå¿ããŠããŸããšå€§å€ãªããšã«ãªããŸããVLAN 10 ãš 20 ãç¹ãããªããªãã999 ã ããç¹ããããã«ãªããŸãã®ã§æ³šæãå¿ èŠã§ããadd ãã€ããã°æ¢åã®ãã©ã³ã¯èšå® VLAN ã®éä¿¡æãçºçãããã«è¿œå ãå¯èœã§ãã
Native VLAN
ãã©ã³ã¯ããŒãã«ã¯ Native VLANãšããæŠå¿µããããŸãããããŠãã®ã¹ã€ããã§ã¯ããã©ã«ãã§ VLAN 1 ã Native VLANã«ãªã£ãŠããŸãã
ãã©ã³ã¯ããŒãã§ã¿ã°ç¡ã (untag) ã®éä¿¡ãåä¿¡ããå ŽåãNative VLAN ãšããŠåŠçãããŸãã
Native VLAN ã 1 ãã 10 ã«å€æŽãããå ŽåãCisco Catalyst ã®å Žåã¯ä»¥äžã³ãã³ããæã¡ãŸãã
(config-if)# switchport trunk native vlan 10
ãŸããNative VLAN ãã¿ã°ä»ãã§éåä¿¡ããããå Žåã¯ä»¥äžã³ãã³ããæã¡ãŸããã€ãŸãå šãŠã® VLAN ã§ã¿ã°ãä»ããèšå®ã§ãã
(config)# vlan dot1q tag native
Native VLAN ã«èšå®ãã VLAN ID ã«ã€ããŠã(æ¬æ¥ untag ã§ããã¹ãã ã)ã¿ã° VLAN ã§ãã¬ãŒã ãåä¿¡ãããšããåãå ¥ãããç Žæ£ãããããšããã®ã¯ãNW æ©åšã®ä»æ§ã«ãã£ãŠãŸã¡ãŸã¡ã§ãã
ãã©ã³ã¯ããŒãã« PC (ãããã¯ã¢ã¯ã»ã¹ããŒã)ãæ¥ç¶ãã
ãã©ã³ã¯ããŒãã¯åºæ¬çã«ã¯ãã©ã³ã¯ããŒãåå£«ãæ¥ç¶ããŸããã€ãŸãã倧æµã¯ VLAN 察å¿ã¹ã€ããåå£«ãæ¥ç¶ããã®ã§ãããå®ã¯ VLAN é察å¿ã® PC ãã¹ã€ãããæ¥ç¶ãããšãNative VLAN ã ãã«ã¯æ¥ç¶ã§ããŸãã
ãªã®ã§ãããã©ã³ã¯ããŒãã« VLAN 察å¿ã¹ã€ãããæ¥ç¶ããŠãããã©ãäžãäž VLAN 察å¿ã¹ã€ãããå£ãããšãã§ã VLAN 100 ã ãã¯äœ¿ãããïŒããšããæã¯VLAN 100 ã Native VLAN ã«ããã°ããã®ã§ãããã©ã³ã¯ããŒãã« PC çŽçµã§ããHUB ãä»ããŠã Native VLAN ã ãã¯éä¿¡ã§ããŸãã
äžå³ã¯ãL2 ã¹ã€ãã#1ãš#2ã§ VLAN 100, 200, 300 ã trunk ããŒãã§æ¥ç¶ããéãL2 ã¹ã€ãã#2ãå£ãããšãã§ããVLAN 100 ã ãã¯éä¿¡ãç¶ç¶ããããå Žåã®äŸã瀺ããŠããŸããäŸã§ã¯ VLAN 察å¿ã®ã¹ã€ããã HUB ã«çœ®ãæããŠããŸãããL2 ã¹ã€ãã#1ã« PC ãçŽçµããŠãåé¡ãããŸããã
ã¿ã° VLAN ãš MTU å€
L3 ã¹ã€ããã® VLAN ã€ã³ã¿ãã§ãŒã¹ã§ã¯ MTU å€ã¯ããã©ã«ãã§ 1500 Byte ãšãªã£ãŠããŸããã¿ã°ãä»ãã Ethernet ãã¬ãŒã 㯠4 Byte å¢ããŠããŸããããã®å Žåã¯åé¡ãããŸãããL3 ã¹ã€ããã®å éšçãªåããšããŠã¯ãã¿ã° VLAN ã¯åä¿¡ããã¿ã€ãã³ã°ã§ã¿ã°ãå€ããŠã«ãŒãã£ã³ã°çã®åŠçããããã®ã§ãæ°ã«ããªããŠããã®ã§ãã
ãã ããQ-in-Qãšãã£ãæè¡ã§ã¿ã°ã 2 ã€ä»ããæ§æãšãªããšãMTU å€ã¯ã¹ã€ããåŽã§ 4 Byte åå¢ãããªããš(ããã㯠PC åŽã§ 4 Byte åæžãããªããš) ãã©ã°ã¡ã³ããŒã·ã§ã³ïŒDF bit ãããå Žåã¯ããããïŒãçºçããŠããŸããŸãã
ãããåé¿ããããã«ãCatalyst L3 ã¹ã€ããã§ä»¥äžã³ãã³ããæã¡ãŸãã
(config)# system mtu 1504
ããã«ãããã©ã°ã¡ã³ããŒã·ã§ã³ãããããã¯åé¿ã§ããŸãããã ããOSPF ã䜿ã£ãŠããå Žå㯠MTU å€ã察åã«ãŒã¿ãšåäžãããªããš EXSTART ç¶æ ã§æ¢ãŸããDBD æ å ±ã®äº€æãåºæ¥ãŸããããªã®ã§ãåãã MTU ã倿Žãããã以äžã® MTU å€ã®éããç¡èŠããã³ãã³ãã§å¯ŸåŠããŸãã
(config-if)# ip ospf mtu-ignore
IT/ã€ã³ãã©ãšã³ãžãã¢ã®å°äœãšã¹ãã«åäžã®ããã«



ããªããæé·ã®æ¥ã ãæ©ããŸãããã«ã
ã³ã¡ã³ã
綺éºãªãµã€ããäœã£ãŠããã ããããããšãããããŸãã
ãã€ããã®ãµã€ããèŠãŠãå匷ãããŠããã ããŠããŸãã
untag vlan 10 , tag vlan 20 ã§ãèšå®ãããŠãã
hybrid ããŒãã®å Žåã
ããã«ãæ®éã®ããœã³ã³ãæ¥ç¶ãããš
vlan 10 ãšããŠãéä¿¡å¯èœ ã«ãªã
ãšããèªèã§è¯ãã§ããããïŒ
ãã€ãã芧ããã ãããããšãããããŸãïŒ
ã¯ãããã®èªèã§å€§äžå€«ã§ããïŒ
ãŸããªã«ãåãããªãããšãšããããŸãããæ°è»œã«ã³ã¡ã³ãäžããïœ
ãã€ããã®ãµã€ããèŠãŠãå匷ãããŠããã ããŠããŸãã
untag vlan 10 , tag vlan 20 ã§ãèšå®ãããŠããHybrid ããŒãã«ã
NICã«ãŒã 1ã€ã ãã§ãè€æ°ã»ã°ã¡ã³ãã®IPã¢ãã¬ã¹ãèšå®(VLANèšå®ïŒ
ãããŠãããµãŒããæ¥ç¶ãããå Žåã
ãµãŒã NICã«ãŒã â- Hybrid ããŒã ã®
LANã±ãŒãã«äžã«ã¯ãVLANã¿ã° ãä»ãããã±ããã
æµããŠããã®ã§ããããïŒ
ãµãŒãã®VLANèšå®ã¯ã©ã®ããã«ãªã£ãŠããæ³å®ã§ããïŒ
vlan10(untag)ã«è€æ°IPãä»ããŠããã®ã§ããã°ãvlan20ãšã®éä¿¡ãã§ããŸããã
vlan10(untag)ã«1ã€ã®IPãvlan20ã«1ã€ã®IPãä»ããŠããã®ã§ããã°éä¿¡ã«åé¡ã¯ãªãã¯ãã§ãã
åããããã解説ããããšãããããŸãã
ãäžå³ã¯ãL2 ã¹ã€ãã#1ãš#2ã§ ã»ã»ãã®äžå³ã衚瀺ãããŠããªãã®ã§äžæãªéšåããããŸãããNativeã«èšå®ããVLANãTrunkã«èšå®ããäºã¯å¯èœãªã®ã§ããããïŒ
ãã®å Žåãã¹ã€ããããéä¿¡ããã該åœVLANå®ãŠãã¬ãŒã ã«ã¿ã°ã¯ä»äžãããªãã®ã§ããããïŒ
yosshiãã
ã³ã¡ã³ãããããšãããããŸãããã¿ãŸãããå³ã衚瀺ãããªãã®ã¯ããµã€ãã®èšå®ã®åé¡ã§ãããä»ã¯è¡šç€ºãããŠããããšæããŸãã®ã§ã確èªäžããã
èãæ¹ãšããŠã¯ããã©ã³ã¯ããŒãã®ãªãã§ã1ã€ã®vlanã ããnativeã«èšå®å¯èœã§ãnativeã«ããvlanã«ã¯ããèªèã®éããã¿ã°ãä»ããŸãããã€ãŸããã¹ã€ããããéä¿¡ããã該åœVLANå®ãŠãã¬ãŒã ã«ã¿ã°ã¯ä»äžãããŸããã
ãåçããããšãããããŸãã
ãŸã å³ã¯è¡šç€ºãããŠããªãããã§ãããã
ä»åã®äŸã§ã¯vlan100ã¯ãallowed vlanãã®äžã«ã¯èšå®ãããŠããªããšããèªèã§ããããã§ããããïŒ
vlan100ãnativeã«ããallowed vlanãã«ãèšå®ãããŠããããšæããïŒã§ããã
allowed vlanã«ãèšå®ã¯å¿ èŠã§ãããããã¯éä¿¡ãèš±å¯ããvlanãæå®ããŸãã
native vlanã¯ã¿ã°ãã€ããªãvlanãæå®ããŸãã®ã§è»žãç°ãªããŸãã
vlanã®èšå®ã«èºããŠããã¡ãã®ãµã€ãã§å匷ãããŠããã ããŠããŸãã
VLAN察å¿ã®ã«ãŒã¿ãŒã«ãŠ
ããŒã1(untag) VLAN1,PVID1
ããŒã2(untag) VLAN3,PVID3
ããŒã3(tag) VLAN1,VLAN3,PVID1
ã§èšå®ããããããã«VLANãèšå®ããŠããªãPCãæ¥ç¶ããå Žå
ããŒã3ã®PC(192.168.0.200)ã¯ããŒã1ã®PC(192.168.0.100)ãšéä¿¡å¯èœãšæã£ãŠããã®ã§ãããæ£ããã§ããããã
ããã°ãã¯ãã³ã¡ã³ãããããšãããããŸãã
ã¯ããããã§åã£ãŠãŸããã现ãã話ã§ããµãããã㯠/24 ã§ãããïŒ
ããšãæ¥ç¶PCã¯Windowsã§ãããïŒäžæçã« Windows ãã¡ã€ã¢ãŠã©ãŒã«ããŠã£ã«ã¹å¯Ÿçãœãããåã£ãŠè©ŠããŠã¿ãŠãã ããã
ãåçããããšãããããŸãã
ãµããããã¯ãã¹ãŠ/24ã§ããã¢ã³ããŠã£ã«ã¹ããã¡ã€ã¢ãŠã©ãŒã«åã£ãŠãé§ç®ã§ããâŠ
ããšããšã¯ãã«ãŒã¿ãŒããæç·ã§ç¡ç·APãã€ãªãã§wifi䜿ãããšããŠããã®ã§ãããwifiã«ã€ãªãã§ããããã䜿ããâŠ
ã«ãŒã¿ãŒã«çŽæ¥PCã€ãªãã§ãããã調ã¹ããšãã©ããã¿ã°ç¡ãã匟ããŠãæãã§âŠ
ç§ã®PVIDã«ã€ããŠã®èªèãééã£ãŠããã®ããšäžå®ã§ããã
ã¡ãŒã«ãŒã«åŒ·æ°ã§åãåããããŠã¿ãŸããããããšãããããŸãã
ã¡ãªã¿ã«ã«ãŒã¿ãŒã¯asusã®BRT-AC828ã§ãã
Native VLANèšå®æã®åäœã«ã€ããŠã®çè§£ã®ããããæç€ºãããããé¡ãããããŸãã
ãNative VLAN ã«èšå®ãã VLAN ID ã«ã€ããŠã(æ¬æ¥ untag ã§ããã¹ãã ã)ã¿ã° VLAN ã§ãã¬ãŒã ãåä¿¡ãããšããåãå ¥ãããç Žæ£ãããããšããã®ã¯ãNW æ©åšã®ä»æ§ã«ãã£ãŠãŸã¡ãŸã¡ã§ãããšãããŸããç Žæ£ããã®ã¯çŽåŸåºæ¥ãã®ã§ãããåãå ¥ããæ©åšä»æ§ããããšããã®ãçè§£åºæ¥ãŸããã
ãšããã®ããåä¿¡ãã¬ãŒã ã«ã¿ã°ãä»äžãããŠãããšããããšã¯å¯Ÿåæ©åšã¯trunkããŒãã§ãäžã€åä¿¡åŽè£ 眮ïŒAæ©åšãšããŸãïŒã§èšå®ãããŠããNativeVLANãšã¯ç°ãªãIDãNativeãšããŠèšå®ãããŠããããšæããŸãã
éæ¹åã§Aæ©åšããå¯Ÿåæ©åšã«éä¿¡ããéã¯Nativeèšå®ãããVLANã¯ã¿ã°ãä»äžãããªããšæããŸãã®ã§ïŒå¯Ÿåè£ çœ®ã¯ã¿ã°ããã§åä¿¡ããå¿ èŠãããããïŒãçµå±éä¿¡ã¯æãç«ããªãã®ã§ã¯ãšæãã®ã§ãããèªèééã£ãŠãããŸãã§ããããïŒ
ããã¯ããªãç¹æ®ãªã±ãŒã¹ãªã®ã§ããŸãçå£ã«æããªããŠããã§ãã
äŸãã°juniperã§ã¯ãã¹ã€ããã³ã°ããããã±ãããšæ©åšã®èªçºãã±ãããšã§ã¿ã°ãšã¢ã³ã¿ã°ãåãããã±ãŒã¹ããããŸãã
https://kb.juniper.net/InfoCenter/index?page=content&id=KB17419&actp=METADATA
ä»ã«ã䌌ããããªã±ãŒã¹ãçšã«ãããŸãããç§ã人çã§2åããééããŠãªãã§ããã
ãããã¯ãŒã¯èšèšãé£èªããŠããããã®ãµã€ããæèŠãããŠé ããŸããã
ãææã®çšãããããé¡ãèŽããŸãã
L2ã¹ã€ããå·ŠãšL2ã¹ã€ããäžãL3ã¹ã€ãããä»ããçŽæ¥æ¥ç¶ãããšããŸãã
L2ã¹ã€ããå·Šã«ã¯ã
ãgigabitEthernet0/1:VLAN10ãgigabitEthernet0/2:VLAN20ãgigabitEthernet0/3:VLAN999ã
gigabitEthernet0/24:ãã©ã³ã¯ããŒã(èš±å¯VLAN:10,20,999ãNativeVLAN:100)ã
ã®èšå®ãè¡ããŸãã
L2ã¹ã€ããäžã«ã¯ã
ãgigabitEthernet0/24:ãã©ã³ã¯ããŒã(èš±å¯VLAN10,20,100,999ãNative VLAN100)ãã®èšå®ãè¡ãã
L2ã¹ã€ããäžã«æ¥ç¶ããŠããPCãžL2ã¹ã€ããå·Šã®VLAN10,20,999ããã®ãã¹ãŠã®éä¿¡ãå¯èœãšããããã
L2ã¹ã€ããäžãž
ãgigabitEthernet0/1ïœ0/3ãHybridããŒããšããŠãNativeVLAN:100ãUntaggedVLAN:10,20,999,100ã
ã®èšå®ãè¡ãã°äžèšéä¿¡ãå¯èœãšæã£ãŠããã®ã§ãããéä¿¡ã§ããŸããã§ããã
L2ã¹ã€ããäžã®gigabitEthernet0/1ïœ0/3ã®NativeVLANãVLAN10ã«èšå®ãããšL2ã¹ã€ããå·Šã®VLAN10ããã®éä¿¡ã¯å¯èœã
NativeVLANãVLAN20ã«èšå®ãããšL2ã¹ã€ããå·Šã®VLAN20ããã®éä¿¡ã¯å¯èœãšãªããŸãã
ãL2ã¹ã€ããäžã«æ¥ç¶ããŠããPCãžL2ã¹ã€ããå·Šã®VLAN10,20,999ããã®ãã¹ãŠã®éä¿¡ãå¯èœãšããããã
ãå®çŸããã«ã¯L2ã¹ã€ããäžãžã©ã®ãããªèšå®ãè¡ãã°ãããå¿ãããã¯ããããŸããïŒ
é·æã§ç³ãèš³ããããŸãããããããããé¡ãèŽããŸãã
ããã«ã¡ã¯ã
æåã ãã ãšã©ãããŠãå šå®¹ãææ¡ã§ããŸãããããææã®èšå®ã¯ã§ããªããšæããŸãã
VLANãèšå®ããªãããšããã®ã1ã€ã®è§£æ±ºçã§ããããããããŠããããããšã¯ããã©ã€ããŒãVLANãã«è¿ãæ°ãããŸãããããã§ããïŒ
https://milestone-of-se.nesuke.com/nw-advanced/nw-security/private-vlan/
ãåçããããšãããããŸãã
説æãåããã«ãããªã£ãŠããŸãç³ãèš³ããããŸããã
ãã£ãããéãããã©ã€ããŒãVLANãã«è¿ãæ°ãããŸãã
ãªã³ã¯
ã®ããã©ã€ããŒãVLANã®trunkã®çš®é¡ãã®å³ã§ãããšã
PC#3ã»PC#4ã®VLAN102ãšPC#5ã»PC#6ã®VLAN103ããã®è€æ°ã®VLANãã
察ååŽã¹ã€ããã®NASã»Printerãžã¢ã¯ã»ã¹å¯èœãšãããã
ãšããããšã§ããã