VLAN

Reference: [์ฑ…] IT ์—”์ง€๋‹ˆ์–ด๋ฅผ ์œ„ํ•œ ๋„คํŠธ์›Œํฌ ์ž…๋ฌธ

1. What is VLAN?

  • ๋ฌผ๋ฆฌ์  ๋ฐฐ์น˜์™€ ์ƒ๊ด€์—†์ด LAN์„ ๋…ผ๋ฆฌ์ ์œผ๋กœ ๋ถ„ํ• , ๊ตฌ์„ฑํ•˜๋Š” ๊ธฐ์ˆ 

    • ํ•œ ๋Œ€์˜ Switch๋ฅผ ์—ฌ๋Ÿฌ๊ฐœ์˜ VLAN์œผ๋กœ ๋ถ„ํ• ํ•  ์ˆ˜ ์žˆ๋‹ค

      • ๋ณ„๋„์˜ switch ์ฒ˜๋Ÿผ ๋™์ž‘ํ•œ๋‹ค

  • ๊ธฐ์—…์—์„œ์˜ ๋ถ€์„œ๋ณ„ ๋„คํŠธ์›Œํฌ ๋ถ„ํ•  ๋ฐ ์Šค๋งˆํŠธํฐ, PC ๋“ฑ ๋‹ค์ˆ˜์˜ ๋‹จ๋ง์ด ๋„คํŠธ์›Œํฌ์— ์—ฐ๊ฒฐ๋จ์— ๋”ฐ๋ผ ๋„คํŠธ์›Œํฌ ๋ถ„ํ• ์ด ์ค‘์š”ํ•˜๋‹ค

    • ๋„คํŠธ์›Œํฌ ๋ถ„ํ• ์ด ํ•„์š”ํ•œ ์ด์œ 

      1. ๊ณผ๋„ํ•œ broadcast๋กœ ์ธํ•œ ๋‹จ๋ง๋“ค์˜ ์„ฑ๋Šฅ ์ €ํ•˜

      2. ๋ณด์•ˆ ํ–ฅ์ƒ์„ ์œ„ํ•œ ์ฐจ๋‹จ ์šฉ๋„

      3. ์„œ๋น„์Šค ์„ฑ๊ฒฉ์— ๋”ฐ๋ฅธ ์ •์ฑ… ์ ์šฉ

  • VLAN์„ ๋‚˜๋ˆ„๋ฉด ํ•˜๋‚˜์˜ ์žฅ๋น„๋ฅผ ์„œ๋กœ ๋‹ค๋ฅธ network๋ฅผ ๊ฐ–๋„๋ก ๋…ผ๋ฆฌ์ ์œผ๋กœ ๋ถ„ํ• ํ•œ ๊ฒƒ์ด๋ฏ€๋กœ Unicast ๋ฟ๋งŒ ์•„๋‹ˆ๋ผ Broadcast ๋„ VLAN ๊ฐ„์— ํ†ต์‹ ํ•  ์ˆ˜ ์—†๋‹ค

    • ๋งŒ์•ฝ VLAN ๊ฐ„์˜ ํ†ต์‹ ์ด ํ•„์š”ํ•˜๋‹ค๋ฉด, ์„œ๋กœ ๋‹ค๋ฅธ network ๊ฐ„์˜ ํ†ต์‹ ์ด๋ฏ€๋กœ 3๊ณ„์ธต ์žฅ๋น„์˜ ๋„์›€์ด ํ•„์š”ํ•˜๋‹ค

  • VLAN์„ ์‚ฌ์šฉํ•˜๋ฉด ๋ฌผ๋ฆฌ์  ๊ตฌ์„ฑ๊ณผ ์ƒ๊ด€์—†์ด network๋ฅผ ๋ถ„๋ฆฌํ•  ์ˆ˜ ์žˆ๊ณ , ๋ฌผ๋ฆฌ์ ์œผ๋กœ ๋‹ค๋ฅธ ์ธต์— ์žˆ๋Š” ๋‹จ๋ง์ด ํ•˜๋‚˜์˜ VLAN์„ ์‚ฌ์šฉํ•ด ๋™์ผํ•œ network๋กœ ๋ฌถ์„ ์ˆ˜ ์žˆ๋‹ค

    • ๋ถ„๋ฆฌ๋œ ๋‹จ๋ง ๊ฐ„์—๋Š” 3๊ณ„์ธต ์žฅ๋น„๋ฅผ ํ†ตํ•ด ํ†ต์‹ ํ•˜๊ฒŒ ๋œ๋‹ค

2. Types of VLANS

VLAN ํ• ๋‹น ๋ฐฉ์‹์—๋Š” port ๊ธฐ๋ฐ˜์˜ VLAN๊ณผ MAC ์ฃผ์†Œ ๊ธฐ๋ฐ˜์˜ VLAN์ด ์žˆ๋‹ค

Port Based VLAN

  • VLAN์ด ์ฒ˜์Œ ๋„์ž…๋˜์—ˆ์„ ๋•Œ๋Š” switch๊ฐ€ ๊ณ ๊ฐ€์˜€๊ณ  ์—ฌ๋Ÿฌ hub๋ฅผ ๋ฌถ๋Š” ์—ญํ• ์„ switch๊ฐ€ ๋‹ด๋‹นํ–ˆ์œผ๋ฏ€๋กœ switch๋ฅผ ๋ถ„ํ• ํ•ด ์—ฌ๋Ÿฌ network์— ์‚ฌ์šฉํ•˜๋Š” ๊ฒƒ์ด VLAN ๊ธฐ๋Šฅ์„ ์ ์šฉํ•˜๋Š” ๋ชฉ์ ์ด์—ˆ๋‹ค

    • ์ด๋ ‡๊ฒŒ switch์˜ ์œ„์น˜๋ฅผ ๋…ผ๋ฆฌ์ ์œผ๋กœ ๋ถ„ํ• ํ•ด ์‚ฌ์šฉํ•˜๋Š” ๊ฒƒ์ด ๋ชฉ์ ์ธ VLAN์„ Port Based VLAN ์ด๋ผ๊ณ  ๋ถ€๋ฅธ๋‹ค

      • ์šฐ๋ฆฌ๊ฐ€ ์ผ๋ฐ˜์ ์œผ๋กœ ์–ธ๊ธ‰ํ•˜๋Š” ๋Œ€๋ถ€๋ถ„์˜ VLAN์€ Port Based VLAN์ด๋‹ค

    • ์–ด๋–ค ๋‹จ๋ง์ด ์ ‘์†ํ•˜๋“ ์ง€ switch์˜ ํŠน์ • port์— VLAN์„ ํ• ๋‹นํ•˜๋ฉด ํ• ๋‹น๋œ VLAN์— ์†ํ•˜๊ฒŒ ๋œ๋‹ค

  • Port Based VLAN์œผ๋กœ ์„ค์ •๋œ switch์—์„œ VLAN ์„ค์ • ๊ธฐ์ค€์€ Switch์˜ port ์ด๋‹ค

    • ex)

      • AA PC๊ฐ€ 1๋ฒˆ port์— ์—ฐ๊ฒฐ๋˜๋ฉด VLAN 10์— ์†ํ•˜๊ณ , 4๋ฒˆ port์— ์—ฐ๊ฒฐ๋˜๋ฉด VLAN 20์— ์†ํ•œ๋‹ค

Mac Based VLAN

  • ์‚ฌ์šฉ์ž๋“ค์˜ ์ž๋ฆฌ ์ด๋™์ด ๋งŽ์•„์ง€๋ฉด์„œ MAC Address๋ฅผ ๊ธฐ๋ฐ˜์œผ๋กœ ํ•œ Mac Based VLAN์ด ๊ฐœ๋ฐœ๋˜์—ˆ๋‹ค

    • Mac Based VLAN์„ ์‚ฌ์šฉํ•˜๋ฉด ์œ ์„  ์‚ฌ์šฉ์ž๊ฐ€ ์ด๋™ํ•˜๋”๋ผ๋„ ๊ฐ™์€ VLAN์— ํ• ๋‹น๋œ๋‹ค

  • Switch์˜ ๊ณ ์ • port์— VLAN์„ ํ• ๋‹นํ•˜๋Š” ๊ฒƒ์ด ์•„๋‹ˆ๋ผ switch์— ์—ฐ๊ฒฐ๋˜๋Š” ๋‹จ๋ง์˜ MAC Address๋ฅผ ๊ธฐ๋ฐ˜์œผ๋กœ VLAN์„ ํ• ๋‹นํ•˜๋Š” ๊ธฐ์ˆ ์ด๋‹ค

  • ๋‹จ๋ง์ด ์—ฐ๊ฒฐ๋˜๋ฉด, ๋‹จ๋ง์˜ MAC Address๋ฅผ ์ธ์‹ํ•œ switch๊ฐ€ ํ•ด๋‹น port๋ฅผ ์ง€์ •๋œ VLAN์œผ๋กœ ๋ณ€๊ฒฝํ•œ๋‹ค

    • ๋‹จ๋ง์— ๋”ฐ๋ผ VLAN ์ •๋ณด๊ฐ€ ๋ฐ”๋€” ์ˆ˜ ์žˆ์–ด Dynamic VLAN์ด๋ผ๊ณ ๋„ ๋ถ€๋ฅธ๋‹ค

  • Mac Based VLAN์˜ VLAN ํ• ๋‹น ๊ธฐ์ค€์€ PC์˜ MAC์ฃผ์†Œ์ด๋‹ค

    • ex)

      • AA PC๋Š” ์–ด๋–ค switch์˜ ์–ด๋–ค port์— ์ ‘์†ํ•˜๋”๋ผ๋„ ๋™์ผํ•œ VLAN์ด ํ• ๋‹น๋œ๋‹ค

3. How VLAN Works (Trunk/Access)

  • Port Based VPN ์—์„œ๋Š” Switch์˜ ๊ฐ port์— ๊ฐ๊ฐ ์‚ฌ์šฉํ•  VLAN์„ ์„ค์ •ํ•˜๋Š”๋ฐ, ํ•œ ๋Œ€์˜ switch์— ์—ฐ๊ฒฐ๋˜๋”๋ผ๋„ ์„œ๋กœ ๋‹ค๋ฅธ VLAN์ด ์„ค์ •๋œ prot ๊ฐ„์—๋Š” ํ†ต์‹ ํ•  ์ˆ˜ ์—†๋‹ค

    • VLAN์ด ๋‹ค๋ฅด๋ฉด ๋ณ„๋„์˜ ๋ถ„๋ฆฌ๋œ switch์— ์—ฐ๊ฒฐ๋œ ๊ฒƒ๊ณผ ๊ฐ™์œผ๋ฏ€๋กœ VLAN ๊ฐ„ ํ†ต์‹ ์ด ๋ถˆ๊ฐ€๋Šฅํ•˜๋‹ค

      • ์„œ๋กœ ๋‹ค๋ฅธ VLAN ๊ฐ„ ํ†ต์‹ ์„ ์œ„ํ•ด์„œ๋Š” router์™€ ๊ฐ™์€ 3๊ณ„์ธต ์žฅ๋น„๋ฅผ ์‚ฌ์šฉํ•ด์•ผ ํ•œ๋‹ค

        • VLAN์œผ๋กœ ๊ตฌ๋ถ„๋œ network์—์„œ๋Š” broadcast์ธ ARP Request๊ฐ€ ๋‹ค๋ฅธ VLAN์œผ๋กœ ์ „๋‹ฌ๋  ์ˆ˜ ์—†์œผ๋ฏ€๋กœ 3๊ณ„์ธต ์žฅ๋น„๋ฅผ ์ด์šฉํ•ด ํ†ต์‹ ํ•ด์•ผ ํ•œ๋‹ค

  • Switch port์— VLAN์„ ์„ค์ •ํ•˜์—ฌ network๋ฅผ ๋ถ„๋ฆฌํ•˜๋ฉด ๋ฌผ๋ฆฌ์ ์œผ๋กœ switch๋ฅผ ๋ถ„๋ฆฌํ•  ๋•Œ๋ณด๋‹ค ํšจ์œจ์ ์œผ๋กœ ์žฅ๋น„๋ฅผ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๋‹ค

    • VLAN ๋ถ„๋ฆฌ๋Š” ๋‹ค์ˆ˜์˜ ๋…ผ๋ฆฌ์ ์ธ switch๋ฅผ ๋งŒ๋“œ๋Š” ํšจ๊ณผ๊ฐ€ ์žˆ๋‹ค

  • ์—ฌ๋Ÿฌ ๊ฐœ์˜ VLAN์ด ์กด์žฌํ•˜๋Š” ์ƒํ™ฉ์—์„œ switch๋ฅผ ์„œ๋กœ ์—ฐ๊ฒฐํ•ด์•ผ ํ•˜๋Š” ๊ฒฝ์šฐ์—๋Š” ๊ฐ VLAN ๋ผ๋ฆฌ ํ†ต์‹ ํ•˜๋ ค๋ฉด VLAN ๊ฐœ์ˆ˜๋งŒํผ port๋ฅผ ์—ฐ๊ฒฐํ•ด์•ผ ํ•œ๋‹ค

    • VLAN์ด ๋ถ„ํ• ๋œ switch๋Š” ๋ฌผ๋ฆฌ์ ์ธ ๋ณ„๋„์˜ switch๋กœ ์ทจ๊ธ‰๋œ๋‹ค

    • ex)

      • Switch ํ•˜๋‚˜์— 3๊ฐœ์˜ VLAN์ด ๊ตฌ์„ฑ๋˜์–ด ์žˆ๋Š” ๊ฒฝ์šฐ, ๊ฐ VLAN์ด switch ๊ฐ„์— ํ†ต์‹ ํ•˜๋ ค๋ฉด 3๊ฐœ์˜ port๊ฐ€ ํ•„์š”ํ•˜๋‹ค

        • VLAN์„ ๋” ๋งŽ์ด ์‚ฌ์šฉํ•˜๋Š” ์ค‘/๋Œ€ํ˜• network์—์„œ ์ด๋ ‡๊ฒŒ VLAN๋ณ„๋กœ port๋ฅผ ์—ฐ๊ฒฐํ•˜๋ฉด ์žฅ๋น„ ๊ฐ„์˜ ์—ฐ๊ฒฐ๋งŒ์œผ๋กœ๋„ ๋งŽ์€ port๊ฐ€ ๋‚ญ๋น„๋œ๋‹ค

    • ์ด ๋ฌธ์ œ๋ฅผ ํ•ด๊ฒฐํ•˜๊ธฐ ์œ„ํ•ด VLAN Tag ๊ธฐ๋Šฅ์ด ๋“ฑ์žฅํ–ˆ๋‹ค!

Tagged Port (Trunk Port)

  • Tag ๊ธฐ๋Šฅ์€ ํ•˜๋‚˜์˜ port์— ์—ฌ๋Ÿฌ ๊ฐœ์˜ VLAN์„ ํ•จ๊ป˜ ์ „์†กํ•  ์ˆ˜ ์žˆ๊ฒŒ ํ•ด์ค€๋‹ค

    • ์ด port๋ฅผ Tagged port ๋˜๋Š” Trunk port๋ผ๊ณ  ํ•œ๋‹ค

  • ์—ฌ๋Ÿฌ ๊ฐœ์˜ VLAN์„ ๋™์‹œ์— ์ „์†กํ•ด์•ผ ํ•˜๋Š” Tagged port๋Š” ํ†ต์‹ ํ•  ๋•Œ Ethernet Frame ์ค‘๊ฐ„์— VLAN Field๋ฅผ ๋ผ์›Œ ๋„ฃ์–ด ์ด ์ •๋ณด๋ฅผ ์ด์šฉํ•œ๋‹ค

    • Tagged Port ๋กœ packet์„ ๋ณด๋‚ผ ๋•Œ๋Š” VLAN ID๋ฅผ ๋ถ™์ด๊ณ , ์ˆ˜์‹ ์ธก์—์„œ๋Š” ์ด VLAN ID๋ฅผ ์ œ๊ฑฐํ•˜๋ฉด์„œ ํ•ด๋‹น VLAN ID์˜ VLAN์œผ๋กœ packet์„ ๋ณด๋‚ผ ์ˆ˜ ์žˆ๊ฒŒ ๋œ๋‹ค

  • Tagged Port๋ฅผ ์‚ฌ์šฉํ•˜๋ฉด VLAN๋งˆ๋‹ค ํ†ต์‹ ํ•˜๊ธฐ ์œ„ํ•ด ํ•„์š”ํ–ˆ๋˜ ์—ฌ๋Ÿฌ ๊ฐœ์˜ port๋ฅผ ํ•˜๋‚˜๋กœ ๋ฌถ์–ด ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ์œผ๋ฏ€๋กœ port ๋‚ญ๋น„ ์—†์ด network๋ฅผ ์œ ์—ฐํ•˜๊ฒŒ design ํ•  ์ˆ˜ ์žˆ๋‹ค

  • Tagged Port ๊ธฐ๋Šฅ์ด switch์— ์ƒ๊ธฐ๋ฉด์„œ switch์˜ packet ์ „์†ก์— ์‚ฌ์šฉํ•˜๋Š” MAC Address Table์—๋„ ๋ณ€ํ™”๊ฐ€ ์ƒ๊ฒผ๋‹ค

    • ๋‹ค๋ฅธ VLAN๋ผ๋ฆฌ ํ†ต์‹ ํ•˜์ง€ ๋ชปํ•˜๋„๋ก Mac Address Table์— VLAN์„ ์ง€์ •ํ•˜๋Š” field๊ฐ€ ์ถ”๊ฐ€๋œ ๊ฒƒ์ด๋‹ค!

      • ์ฆ‰, ํ•˜๋‚˜์˜ switch์—์„œ VLAN์„ ์ด์šฉํ•ด network๋ฅผ ๋ถ„๋ฆฌํ•˜๋ฉด VLAN ๋ณ„๋กœ Mac Address Table์ด ์กด์žฌํ•˜๋Š” ๊ฒƒ ์ฒ˜๋Ÿผ ๋™์ž‘ํ•œ๋‹ค

  • Tagged Port๋Š” ์—ฌ๋Ÿฌ ๊ฐœ์˜ VLAN, ์ฆ‰ ์—ฌ๋Ÿฌ network๋ฅผ ํ•˜๋‚˜์˜ ๋ฌผ๋ฆฌ์  port๋กœ ์ „๋‹ฌํ•˜๋Š” ๋ฐ ์‚ฌ์šฉ๋œ๋‹ค

  • Tagged Port๋Š” ์ผ๋ฐ˜์ ์œผ๋กœ ์—ฌ๋Ÿฌ network๊ฐ€ ๋™์‹œ์— ์„ค์ •๋œ switch ๊ฐ„์˜ ์—ฐ๊ฒฐ์—์„œ ์‚ฌ์šฉ๋œ๋‹ค

  • Tagged Port๋กœ packet์ด ๋“ค์–ด์˜ฌ ๊ฒฝ์šฐ Tag๋ฅผ ๋ฒ—๊ฒจ๋‚ด๋ฉด์„œ Tag๋œ VLAN ์ชฝ์œผ๋กœ packet์„ ์ „์†กํ•œ๋‹ค

Untagged Port (Access Port)

  • ์ผ๋ฐ˜์ ์ธ port๋ฅผ Untagged Port ๋˜๋Š” Access Port ๋ผ๊ณ  ํ•œ๋‹ค

  • Untagged Port ํ•˜๋‚˜์˜ VLAN์— ์†ํ•œ ๊ฒฝ์šฐ์—๋งŒ ์‚ฌ์šฉ๋œ๋‹ค

    • ๊ทธ๋ž˜์„œ ์ผ๋ฐ˜์ ์œผ๋กœ ํ•˜๋‚˜์˜ network์— ์†ํ•œ server์˜ ๊ฒฝ์šฐ Untagged๋กœ ์„ค์ •ํ•œ๋‹ค

  • Untagged Port๋กœ packet์ด ๋“ค์–ด์˜ฌ ๊ฒฝ์šฐ, ๊ฐ™์€ VLAN์œผ๋กœ๋งŒ packet์„ ์ „์†กํ•œ๋‹ค

๊ฐ€์ƒํ™” Server

  • Switch ๊ฐ„์˜ ์—ฐ๊ฒฐ์ด ์•„๋‹Œ sever์™€ ์—ฐ๊ฒฐ๋œ port๋„ ๊ฐ€์ƒํ™” server๊ฐ€ ์—ฐ๊ฒฐ๋  ๋•Œ๋Š” ์—ฌ๋Ÿฌ VLAN๊ณผ ํ†ต์‹ ํ•ด์•ผ ํ•  ์ˆ˜๋„ ์žˆ๋‹ค

    • ์ด ๊ฒฝ์šฐ server์™€ ์—ฐ๊ฒฐ๋œ port๋”๋ผ๋„ Untagged๊ฐ€ ์•„๋‹Œ Tagged๋กœ ์„ค์ •ํ•œ๋‹ค

      • Tagged ์ƒํƒœ์ด๋ฏ€๋กœ ๊ฐ€์ƒํ™” server์ชฝ interface์—์„œ๋„ tagged ์ƒํƒœ๋กœ ์„ค์ •ํ•ด์•ผ ํ•œ๋‹ค

    • ๊ฐ€์ƒํ™” server ๋‚ด๋ถ€์— ๊ฐ€์ƒ switch๊ฐ€ ์กด์žฌํ•˜๋ฏ€๋กœ switch๊ฐ„ ์—ฐ๊ฒฐ๋กœ ๋ณด๋ฉด ๋” ์ดํ•ดํ•˜๊ธฐ ์‰ฝ๋‹ค

VLAN ๊ฐ„ ํ†ต์‹ 

  • VLAN์€ switch ํ†ต์‹ ์„ ๋ถ„ํ• ํ•˜๋Š” ๊ธฐ๋Šฅ ๋•Œ๋ฌธ์— unicast, multicast, broadcast๋ชจ๋‘ VLAN์„ ๋„˜์–ด๊ฐ€์ง€ ๋ชปํ•œ๋‹ค

  • ์ผ๋ฐ˜์ ์œผ๋กœ VLAN์ด ๋‹ค๋ฅด๋‹ค๋Š” ๊ฒƒ์€ ๋ณ„๋„์˜ network๋กœ ๋ถ„ํ• ํ•œ ๊ฒƒ์ด๊ธฐ ๋•Œ๋ฌธ์— network๊ฐ€ ๋‹ค๋ฅด๊ณ , IP ์ฃผ์†Œ ํ• ๋‹น๋„ ๋‹ค๋ฅธ network๋กœ ํ• ๋‹น๋˜๋Š” ๊ฒƒ์ด ์ผ๋ฐ˜์ ์ด๋‹ค

    • ๋‹ค๋ฅธ network ๊ฐ„์˜ ํ†ต์‹ ์ด ํ•„์š”ํ•˜๋‹ค๋ฉด router์™€ ๊ฐ™์€ 3๊ณ„์ธต ์žฅ๋น„์˜ ๋„์›€์ด ํ•„์š”ํ•˜๋‹ค

Last updated