VLAN (Virtual LAN)

1. VLAN์ด๋ž€?

๐Ÿ“Œ ์ •์˜

VLAN(Virtual LAN)์€ ํ•˜๋‚˜์˜ ๋ฌผ๋ฆฌ์ ์ธ ๋„คํŠธ์›Œํฌ ์Šค์œ„์น˜๋ฅผ ๋…ผ๋ฆฌ์ ์œผ๋กœ ์—ฌ๋Ÿฌ ๊ฐœ์˜ ๋„คํŠธ์›Œํฌ(LAN)๋กœ ๋‚˜๋ˆˆ ๊ฒƒ์ž…๋‹ˆ๋‹ค.

๐Ÿ’ก VLAN = ๊ฐ€์ƒ์˜ ๋„คํŠธ์›Œํฌ ๋ถ„๋ฆฌ
๋™์ผํ•œ ์Šค์œ„์น˜ ๋‚ด์—์„œ๋„ ํฌํŠธ ๊ทธ๋ฃน์„ ๋‚˜๋ˆ„์–ด ์„œ๋กœ ๋‹ค๋ฅธ ๋„คํŠธ์›Œํฌ์ฒ˜๋Ÿผ ๋™์ž‘ํ•˜๊ฒŒ ํ•จ

2. VLAN์ด ํ•„์š”ํ•œ ์ด์œ 

๊ธฐ์กด LAN ๋ฌธ์ œ์ 

  • ์Šค์œ„์น˜๋Š” ๋ชจ๋“  ํฌํŠธ๋ฅผ ํ•˜๋‚˜์˜ ๋ธŒ๋กœ๋“œ์บ์ŠคํŠธ ๋„๋ฉ”์ธ์œผ๋กœ ๋ฌถ์Œ
  • ํŠธ๋ž˜ํ”ฝ์ด ๋งŽ์•„์ง€๋ฉด ๋„คํŠธ์›Œํฌ ํ˜ผ์žก ๋ฐœ์ƒ
  • ๋ณด์•ˆ ๋ฌธ์ œ: ๋‹ค๋ฅธ ํŒ€์ด ์„œ๋กœ์˜ ํŠธ๋ž˜ํ”ฝ์„ ๋ณผ ์ˆ˜ ์žˆ์Œ

VLAN ๋„์ž… ํšจ๊ณผ

๋ฌธ์ œ์ VLAN ๋„์ž… ํ›„
๋ธŒ๋กœ๋“œ์บ์ŠคํŠธ ๋„๋ฉ”์ธ ๊ณผ๋Œ€VLAN๋ณ„ ๋„๋ฉ”์ธ ๋ถ„๋ฆฌ
๋ถ€์„œ ๊ฐ„ ๋ฐ์ดํ„ฐ ๊ฒฉ๋ฆฌ ์–ด๋ ค์›€๋…ผ๋ฆฌ์ ์œผ๋กœ ๋ถ„๋ฆฌ ๊ฐ€๋Šฅ
๋„คํŠธ์›Œํฌ ๊ตฌ์กฐ ๋ณ€๊ฒฝ ์–ด๋ ค์›€์œ ์—ฐํ•œ ํฌํŠธ ํ• ๋‹น ๊ฐ€๋Šฅ

3. VLAN ๊ตฌ์„ฑ ๋ฐฉ์‹

๐Ÿ“Œ ํฌํŠธ ๊ธฐ๋ฐ˜ VLAN

  • ๊ฐ€์žฅ ์ผ๋ฐ˜์ 
  • ์Šค์œ„์น˜ ํฌํŠธ๋ฅผ ๊ธฐ์ค€์œผ๋กœ VLAN ID ๋ถ€์—ฌ
plaintext๋ณต์‚ฌํŽธ์ง‘ํฌํŠธ 1~4: VLAN 10 (๊ด€๋ฆฌ๋ถ€์„œ)  
ํฌํŠธ 5~8: VLAN 20 (์˜์—…๋ถ€์„œ)

๐Ÿ“Œ MAC ์ฃผ์†Œ ๊ธฐ๋ฐ˜ VLAN (๋“œ๋ญ„)

  • ์ ‘์†ํ•œ ์žฅ๋น„์˜ MAC ์ฃผ์†Œ๋ฅผ ๊ธฐ๋ฐ˜์œผ๋กœ VLAN ๊ฒฐ์ •
  • ์œ ๋™์ ์œผ๋กœ ์žฅ๋น„๋ฅผ ์—ฐ๊ฒฐํ•  ์ˆ˜ ์žˆ์Œ (์ด๋™์„ฑโ†‘)

๐Ÿ“Œ ํ”„๋กœํ† ์ฝœ ๊ธฐ๋ฐ˜ VLAN

  • ํŠน์ • ํ”„๋กœํ† ์ฝœ(IP, IPX ๋“ฑ)์— ๋”ฐ๋ผ VLAN์„ ๋ถ„๋ฆฌ
  • ์ผ๋ฐ˜์ ์ธ ํ™˜๊ฒฝ์—์„œ๋Š” ์ž˜ ์‚ฌ์šฉ๋˜์ง€ ์•Š์Œ

4. VLAN Tagging (802.1Q)

๐Ÿ“Œ VLAN ํƒœ๊น…์ด๋ž€?

VLAN ์ •๋ณด๋Š” Ethernet ํ”„๋ ˆ์ž„ ์•ˆ์— VLAN ID๋ฅผ ์‚ฝ์ž…ํ•ด์„œ ๊ตฌ๋ถ„ํ•ฉ๋‹ˆ๋‹ค.
์ด ๋ฐฉ์‹์„ IEEE 802.1Q ํ‘œ์ค€์ด๋ผ๊ณ  ํ•ฉ๋‹ˆ๋‹ค.

๐Ÿ“Œ Tag ๊ตฌ์กฐ (802.1Q ํ—ค๋” ๊ตฌ์กฐ)

ํ”„๋ ˆ์ž„ ํ—ค๋”์— ๋‹ค์Œ๊ณผ ๊ฐ™์€ ํ•„๋“œ๊ฐ€ ์‚ฝ์ž…๋จ:

ํ•„๋“œ์„ค๋ช…
TPID (Tag Protocol ID)0x8100: VLAN Tag๊ฐ€ ์žˆ์Œ์„ ๋‚˜ํƒ€๋ƒ„
Priority (3bit)QoS ์šฐ์„ ์ˆœ์œ„ ์ง€์ •
CFI (1bit)Canonical Format Indicator (์‚ฌ์šฉ ๋นˆ๋„ ๋‚ฎ์Œ)
VLAN ID (12bit)VLAN ๋ฒˆํ˜ธ (0~4095) โ€“ 4096๊ฐœ VLAN ๊ฐ€๋Šฅ

5. VLAN ํฌํŠธ ์ข…๋ฅ˜ (Access vs Trunk)

ํฌํŠธ ํƒ€์ž…์—ญํ• ํƒœ๊น…
Access Port๋‹จ์ผ VLAN์—๋งŒ ์†ํ•จ (PC, ํ”„๋ฆฐํ„ฐ ๋“ฑ ์—ฐ๊ฒฐ)ํƒœ๊น… ์—†์Œ
Trunk Port์—ฌ๋Ÿฌ VLAN ํ†ต๊ณผ ๊ฐ€๋Šฅ (์Šค์œ„์น˜ โ†” ์Šค์œ„์น˜)802.1Q ํƒœ๊น… ์‚ฌ์šฉ
Hybrid PortAccess + Trunk ๊ธฐ๋Šฅ ํ˜ผํ•ฉ (ํŠน์ • ์žฅ๋น„์— ์‚ฌ์šฉ)ํ•„์š”์— ๋”ฐ๋ผ ํƒœ๊น…

์˜ˆ์‹œ ๊ตฌ์„ฑ

[PC] โ”€ Access Port (VLAN 10)
โ”‚
[์Šค์œ„์น˜1] โ”€โ”€โ”€โ”€ Trunk Port โ”€โ”€โ”€โ”€ [์Šค์œ„์น˜2]
โ”‚
Access Port (VLAN 10)

๐Ÿ”น 6. VLAN ๊ฐ„ ํ†ต์‹  (Inter-VLAN Routing)

  • ์„œ๋กœ ๋‹ค๋ฅธ VLAN์€ ๊ธฐ๋ณธ์ ์œผ๋กœ ํ†ต์‹  ๋ถˆ๊ฐ€
  • VLAN ๊ฐ„ ํ†ต์‹ ์„ ์œ„ํ•ด์„œ๋Š” IP์ฃผ์†Œ๊ธฐ๋ฐ˜์˜ ๋ผ์šฐํŒ…์ด ํ•„์š”ํ•˜๋ฏ€๋กœ ๋ผ์šฐํŒ… ์žฅ๋น„(L3 Switch or Router) ํ•„์š”
  • VLAN ์ž์ฒด๋Š” 2๊ณ„์ธต์—์„œ ๋™์ž‘ํ•˜์ง€๋งŒ, VLAN ๊ฐ„ ๋ผ์šฐํŒ…(Inter-VLAN Routing)์€ 3๊ณ„์ธต์—์„œ ๋™์ž‘

๐Ÿ“Œ ๋ฐฉ์‹ 1: ๋ผ์šฐํ„ฐ ๋ฐฉ์‹ (Router-on-a-stick)

  • ํ•˜๋‚˜์˜ ๋ผ์šฐํ„ฐ ํฌํŠธ์— ์—ฌ๋Ÿฌ ๊ฐœ์˜ ์„œ๋ธŒ ์ธํ„ฐํŽ˜์ด์Šค ํ• ๋‹น
[์Šค์œ„์น˜] โ†โ†’ [Router (VLAN 10/20 ์ธํ„ฐํŽ˜์ด์Šค)]

๐Ÿ“Œ ๋ฐฉ์‹ 2: 3๊ณ„์ธต ์Šค์œ„์น˜ ๋ฐฉ์‹

  • ์Šค์œ„์น˜ ๋‚ด๋ถ€์—์„œ IP ๋ผ์šฐํŒ… ์ฒ˜๋ฆฌ โ†’ ์†๋„ ๋น ๋ฆ„

๐Ÿ”น 7. VLAN์˜ ์žฅ์ ๊ณผ ๋‹จ์ 

โœ… ์žฅ์ 

ํ•ญ๋ชฉ์„ค๋ช…
๋ณด์•ˆ๋ถ€์„œ๋ณ„๋กœ ๋…ผ๋ฆฌ์  ๋„คํŠธ์›Œํฌ ๋ถ„๋ฆฌ ๊ฐ€๋Šฅ
ํŠธ๋ž˜ํ”ฝ ๊ด€๋ฆฌ๋ธŒ๋กœ๋“œ์บ์ŠคํŠธ ํŠธ๋ž˜ํ”ฝ ๋ถ„์‚ฐ
์œ ์—ฐ์„ฑ๋ฌผ๋ฆฌ์  ์œ„์น˜์™€ ๋ฌด๊ด€ํ•˜๊ฒŒ ํฌํŠธ ์„ค์ •๋งŒ์œผ๋กœ ๊ตฌ์„ฑ
๊ด€๋ฆฌ ํŽธ์˜๋ถ€์„œ ์ด๋™ ์‹œ ์ผ€์ด๋ธ” ์žฌ๋ฐฐ์„  ์—†์ด VLAN ๋ณ€๊ฒฝ ๊ฐ€๋Šฅ

โŒ ๋‹จ์ 

ํ•ญ๋ชฉ์„ค๋ช…
๊ตฌ์„ฑ ๋ณต์žก์„ฑ์ž˜๋ชป๋œ ์„ค์ • ์‹œ ๋„คํŠธ์›Œํฌ ์žฅ์•  ๋ฐœ์ƒ ๊ฐ€๋Šฅ
๋ผ์šฐํŒ… ํ•„์š”VLAN ๊ฐ„ ํ†ต์‹  ์‹œ ์ถ”๊ฐ€ ์žฅ๋น„ ํ•„์š”
ํƒœ๊น… ๊ด€๋ฆฌTrunk ํฌํŠธ ์„ค์ • ์‹ค์ˆ˜ ์‹œ ๋„คํŠธ์›Œํฌ ์ถฉ๋Œ ๊ฐ€๋Šฅ

8. VLAN ์„ค์ • ์˜ˆ์‹œ (Cisco IOS ๊ธฐ์ค€)

Access ํฌํŠธ VLAN ์„ค์ •

Switch(config)# interface fastEthernet 0/1
Switch(config-if)# switchport mode access
Switch(config-if)# switchport access vlan 10

Trunk ํฌํŠธ ์„ค์ •

Switch(config)# interface fastEthernet 0/24
Switch(config-if)# switchport mode trunk
Switch(config-if)# switchport trunk allowed vlan 10,20

๐Ÿ”น 9. VLAN ๋ณด์•ˆ ํŒ

๋ณด์•ˆ ๊ธฐ๋Šฅ์„ค๋ช…
VLAN Hopping ๋ฐฉ์ง€๊ธฐ๋ณธ VLAN 1์„ ์‚ฌ์šฉํ•˜์ง€ ์•Š์Œ
Unused ํฌํŠธ ๋น„ํ™œ์„ฑํ™”์‚ฌ์šฉํ•˜์ง€ ์•Š๋Š” ํฌํŠธ shutdown ์ฒ˜๋ฆฌ
Port SecurityํฌํŠธ๋ณ„ ํ—ˆ์šฉ MAC ์ฃผ์†Œ ์ œํ•œ
Dynamic ARP InspectionARP ์Šคํ‘ธํ•‘ ๋ฐฉ์ง€
Private VLAN๊ฐ™์€ VLAN ๋‚ด ์žฅ๋น„๋ผ๋ฆฌ ํ†ต์‹  ์ฐจ๋‹จ ๊ฐ€๋Šฅ (ISP ํ™˜๊ฒฝ์—์„œ ์‚ฌ์šฉ)

10. ์š”์•ฝ ์ •๋ฆฌ

ํ•ญ๋ชฉ๋‚ด์šฉ
์ •์˜์Šค์œ„์น˜ ๋‚ด์—์„œ ๋…ผ๋ฆฌ์ ์œผ๋กœ ๋„คํŠธ์›Œํฌ๋ฅผ ๋ถ„๋ฆฌํ•˜๋Š” ๊ธฐ์ˆ 
๋™์ž‘ ์›๋ฆฌํฌํŠธ์— VLAN ID๋ฅผ ํ• ๋‹นํ•˜์—ฌ ๋ถ„๋ฆฌ, Trunk ํฌํŠธ๋กœ ์ „๋‹ฌ ์‹œ VLAN Tag ์ถ”๊ฐ€
ํ‘œ์ค€IEEE 802.1Q
๊ตฌ์„ฑ ์š”์†ŒAccess Port, Trunk Port, VLAN ID
ํ†ต์‹  ๋ฐฉ์‹VLAN ๊ฐ„ ํ†ต์‹ ์€ L3 ์žฅ๋น„ ํ•„์š”
์žฅ์ ๋ณด์•ˆ์„ฑ, ์œ ์—ฐ์„ฑ, ํŠธ๋ž˜ํ”ฝ ๋ถ„์‚ฐ
๋‹จ์ ์„ค์ • ๋ณต์žก, ๋ผ์šฐํŒ… ํ•„์š”, ํƒœ๊น… ์˜ค๋ฅ˜ ๊ฐ€๋Šฅ์„ฑ

Leave a Comment