VLAN介紹和工業SIP電話配置

VLAN總覽

何謂VLAN

乙太網路是基於CSMA/CD(載波感測多重存取/碰撞偵測)的共用媒介網路技術。大量主機會造成嚴重資料碰撞、廣播風暴、效能下降與網路中斷。交換器可減少碰撞,但無法隔離廣播流量。

VLAN(虛擬區域網路)技術可將實體LAN分割為多個邏輯廣播網域,藉此解決上述問題。同一VLAN內的設備可如同在同一LAN內互相通訊;不同VLAN無法直接通訊,藉此限制廣播範圍。

VLAN互連邏輯圖

VLAN不受實體位置限制。設備可位於同一台交換器、跨越多台交換器,或穿越路由器,仍隸屬於同一VLAN。

VLAN的優點:

  1. 限制廣播網域、降低路由負載、減少延遲、節省頻寬並提升整體效能。

  2. 強化資安:VLAN間進行第二層隔離,跨VLAN通訊需依賴第三層路由。

  3. 彈性虛擬工作群組:無需變更實體佈線,即可對使用者進行邏輯分組。

VLAN運作原理

為辨識VLAN訊框,會在資料鏈結層(第二層)的乙太網表頭加入VLAN標籤。

IEEE於1999年制定802.1Q協定做為VLAN標籤的標準規範,定義了在乙太網封包中加入VLAN資訊的標準方式。

802.1Q會在來源MAC位址與EtherType欄位之間插入一個4位元組標籤:

  • 2位元組:TPID(標籤協定識別元)

  • 2位元組:TCI(標籤控制資訊)

TCI包含PCP(優先權編碼點)、CFI(標準格式指示器)與VID(VLAN識別元)。

傳統乙太網訊框格式

圖 1-2 傳統乙太網訊框格式

VLAN標籤結構

圖 1-3 VLAN標籤欄位

VLAN標籤欄位說明:

  1. TPID:16位元,辨識802.1Q標籤;預設值 0x8100。

  2. Priority(優先權):3位元,對應802.1p服務等級(CoS)。

  3. CFI:1位元,MAC位址格式;0 = 標準格式,預設值 0。

  4. VLAN ID:12位元,用來識別VLAN;有效範圍1–4094(0 與 4095 為保留編號)。

備註:雙標籤(QinQ)訊框僅由交換器處理外層標籤,內層標籤會視為負載資料。

VLAN應用場景

2.3.1 LLDP簡介

LLDP(鏈結層探索協定)可讓網路設備在區域網路內公告並接收鄰居設備資訊。資訊會儲存於MIB,可透過SNMP(RFC 2922)查詢。

LLDP採用TLV(型別/長度/數值)結構承載設備資訊,多個TLV組成一筆LLDPDU(LLDP資料單元)。

型別長度數值
7 位元9 位元0-511 位元組

圖 1-4 TLV結構

LLDP-MED(媒體端點探索)為VoIP設備專用擴充規格,提供以下功能:

  • 設備能力探索

  • 語音VLAN組態

  • PoE電源管理

  • 資產盤點管理

  • 緊急來電位置辨識

備註:LLDP 與 LLDP-MED 無法在同一連接埠同時執行。

IP話機的LLDP功能:

啟用LLDP後,話機會週期性發送自身資訊並監聽交換器封包。若應用類型 = 語音,話機會自動從交換器學習語音VLAN ID、更新組態並重新開機套用VLAN。

LLDP組態步驟(網頁介面):

  1. 使用admin/admin登入網頁管理介面。

  2. 前往 網路 → 進階設定

  3. 啟用 LLDP。

  4. 設定傳送間隔(1–3600秒)。

  5. 點擊套用並重新啟動話機。

LLDP組態網頁介面

圖 1-5 LLDP組態介面

啟用LLDP後,話機具備以下行為:

  • 週期性發送群播LLDP封包。

  • 於WAN/LAN連接埠接收LLDP封包。

  • 支援MAC/PHY組態設定。

  • 透過網路政策TLV取得VLAN(覆蓋手動設定)。

話機發送LLDP封包話機接收LLDP封包學習VLAN後發送LLDP封包

2.3.2 CDP簡介

CDP(Cisco探索協定)是Cisco專屬的第二層設備探索協定。

IP話機的CDP功能:
話機會公告自身資訊並監聽交換器的CDP封包,自動學習語音VLAN ID、更新組態後重新開機。

CDP組態步驟(網頁介面):

  1. 使用admin/admin登入。

  2. 前往 網路 → 進階設定

  3. 啟用 CDP。

  4. 設定訊息傳送間隔(1–3600秒)。

  5. 點擊套用

CDP組態介面

圖 1-6 CDP組態介面

話機發送CDP封包話機接收CDP封包學習VLAN後發送CDP封包

2.3.3 DHCP VLAN

話機支援透過DHCP自動探索VLAN。預設使用Option 132取得VLAN ID,最多支援5組自訂DHCP選項。

DHCP VLAN組態步驟(網頁介面):

  1. 使用admin/admin登入。

  2. 前往 網路 → 進階設定

  3. 啟用 DHCP VLAN。

  4. 輸入DHCP選項編號(例如 132)。

  5. 點擊套用

DHCP VLAN組態介面

圖 1-7 DHCP VLAN組態介面

運作流程:

  1. 話機廣播送出DHCP Discover封包。

  2. 伺服器回覆包含Option 132(VLAN ID)的封包。

  3. 話機釋放現有IP、將所有流量標上學習到的VLAN ID,並重新發起DHCP請求。

話機發送DHCP Discover話機接收DHCP Offer

2.3.4 手動設定VLAN

VLAN預設為停用。可分別針對WAN(網際網路)連接埠與LAN(電腦)連接埠獨立設定VLAN ID 與 802.1p 優先權(0–7,7為最高優先權)。

WAN VLAN設定(網頁介面):

  1. 使用admin/admin登入。

  2. 前往網路 → 進階設定

  3. 啟用 VLAN。

  4. 設定 WAN VLAN ID(1–4094)。

  5. 設定優先權(0–7)。

  6. 點擊套用

WAN VLAN組態介面

圖 1-8 WAN VLAN設定

LAN VLAN設定(網頁介面):

  1. 使用admin/admin登入。

  2. 前往 網路 → 進階設定

  3. 設定 LAN VLAN 模式與 ID。

  4. 設定優先權。

  5. 點擊套用

LAN VLAN組態介面

圖 1-9 LAN VLAN設定

話機LCD畫面VLAN設定:

選單 → 進階設定(密碼:123) → 網路 → QoS&Vlan → WAN VLAN / LAN VLAN

WAN VLAN LCD介面LAN VLAN LCD介面

組態驗證:
擷取網路封包,確認SIP與RTP訊框內的802.1Q標籤、VLAN ID及802.1p優先權是否正確。

封包擷取畫面封包擷取畫面

交換器VLAN設定

認識Trunk、Access、Hybrid、Tagged、Untagged

乙太網交換器連接埠支援三種模式:

  • Access(存取模式):隸屬單一VLAN;用於終端裝置(電腦)連接。

  • Trunk(中繼模式):承載多個VLAN;用於交換器之間互連。

  • Hybrid(混合模式):承載多個VLAN;支援自訂無標籤輸出。

核心規則:

  • Tagged(含標籤):訊框送出時保留802.1Q VLAN標籤。

  • Untagged(無標籤):交換器於送出前移除VLAN標籤。

  • PVID(連接埠預設VLAN):指派給無標籤入埠訊框的預設VLAN。

連接埠類型入埠處理出埠處理
接收無標籤訊框接收含標籤訊框
Access加入PVID標籤非所屬VLAN則丟棄移除標籤並轉送
Trunk允許則加入PVID標籤允許的VLAN才接收僅VLAN等於PVID時移除標籤
Hybrid允許則加入PVID標籤允許的VLAN才接收依連接埠組態決定保留或移除標籤

Cisco 2960 交換器 VLAN組態

乙太網VLAN預設參數

參數預設值範圍
VLAN ID11–4094
VLAN 名稱VLANxxxx
MTU15001500–18190
狀態啟用啟用/暫停

建立或修改VLAN

步驟指令用途
1configure terminal進入全域組態模式
2vlan 建立或編輯VLAN
3name 設定VLAN名稱
4end退出至特權模式
5show vlan檢查組態
6copy running-config startup-config儲存組態

刪除VLAN

步驟指令用途
1configure terminal進入全域組態模式
2no vlan 刪除指定VLAN
3end退出組態模式
4show vlan brief驗證刪除結果

指定連接埠隸屬VLAN(存取連接埠)

步驟指令用途
1configure terminal進入全域組態
2interface 選擇欲設定的連接埠
3switchport mode access設為存取模式連接埠
4switchport access vlan 指派隸屬VLAN
5end退出組態模式

設定中繼連接埠

步驟指令用途
1configure terminal進入全域組態
2interface 選擇欲設定的連接埠
3switchport mode trunk設為中繼模式連接埠
4switchport trunk native vlan 設定原生VLAN
5end退出組態模式

設定中繼埠允許通行VLAN

switchport trunk allowed vlan { add | all | except | remove }

設定原生VLAN

switchport trunk native vlan

適用設備

Cisco 2960 系列交換器

目錄
客服 電話
We use cookie to improve your online experience. By continuing to browse this website, you agree to our use of cookie.

Cookies

This Cookie Policy explains how we use cookies and similar technologies when you access or use our website and related services. Please read this Policy together with our Terms and Conditions and Privacy Policy so that you understand how we collect, use, and protect information.

By continuing to access or use our Services, you acknowledge that cookies and similar technologies may be used as described in this Policy, subject to applicable law and your available choices.

Updates to This Cookie Policy

We may revise this Cookie Policy from time to time to reflect changes in legal requirements, technology, or our business practices. When we make updates, the revised version will be posted on this page and will become effective from the date of publication unless otherwise required by law.

Where required, we will provide additional notice or request your consent before applying material changes that affect your rights or choices.

What Are Cookies?

Cookies are small text files placed on your device when you visit a website or interact with certain online content. They help websites recognize your browser or device, remember your preferences, support essential functionality, and improve the overall user experience.

In this Cookie Policy, the term “cookies” also includes similar technologies such as pixels, tags, web beacons, and other tracking tools that perform comparable functions.

Why We Use Cookies

We use cookies to help our website function properly, remember user preferences, enhance website performance, understand how visitors interact with our pages, and support security, analytics, and marketing activities where permitted by law.

We use cookies to keep our website functional, secure, efficient, and more relevant to your browsing experience.

Categories of Cookies We Use

Strictly Necessary Cookies

These cookies are essential for the operation of the website and cannot be disabled in our systems where they are required to provide the service you request. They are typically set in response to actions such as setting privacy preferences, signing in, or submitting forms.

Without these cookies, certain parts of the website may not function correctly.

Functional Cookies

Functional cookies enable enhanced features and personalization, such as remembering your preferences, language settings, or previously selected options. These cookies may be set by us or by third-party providers whose services are integrated into our website.

If you disable these cookies, some services or features may not work as intended.

Performance and Analytics Cookies

These cookies help us understand how visitors use our website by collecting information such as traffic sources, page visits, navigation behavior, and general interaction patterns. In many cases, this information is aggregated and does not directly identify individual users.

We use this information to improve website performance, usability, and content relevance.

Targeting and Advertising Cookies

These cookies may be placed by our advertising or marketing partners to help deliver more relevant ads and measure the effectiveness of campaigns. They may use information about your browsing activity across different websites and services to build a profile of your interests.

These cookies generally do not store directly identifying personal information, but they may identify your browser or device.

First-Party and Third-Party Cookies

Some cookies are set directly by our website and are referred to as first-party cookies. Other cookies are set by third-party services, such as analytics providers, embedded content providers, or advertising partners, and are referred to as third-party cookies.

Third-party providers may use their own cookies in accordance with their own privacy and cookie policies.

Information Collected Through Cookies

Depending on the type of cookie used, the information collected may include browser type, device type, IP address, referring website, pages viewed, time spent on pages, clickstream behavior, and general usage patterns.

This information helps us maintain the website, improve performance, enhance security, and provide a better user experience.

Your Cookie Choices

You can control or disable cookies through your browser settings and, where available, through our cookie consent or preference management tools. Depending on your location, you may also have the right to accept or reject certain categories of cookies, especially those used for analytics, personalization, or advertising purposes.

Please note that blocking or deleting certain cookies may affect the availability, functionality, or performance of some parts of the website.

Restricting cookies may limit certain features and reduce the quality of your experience on the website.

Cookies in Mobile Applications

Where our mobile applications use cookie-like technologies, they are generally limited to those required for core functionality, security, and service delivery. Disabling these essential technologies may affect the normal operation of the application.

We do not use essential mobile application cookies to store unnecessary personal information.

How to Manage Cookies

Most web browsers allow you to manage cookies through browser settings. You can usually choose to block, delete, or receive alerts before cookies are stored. Because browser controls vary, please refer to your browser provider’s support documentation for details on how to manage cookie settings.

Contact Us

If you have any questions about this Cookie Policy or our use of cookies and similar technologies, please contact us at support@becke.cc .