شرح تفصيلي لل VLAN بطريقة مبسطة وجرافيك احترافي — Transcript
Full transcript
- 0:00Welcome to a new video in the
- 0:02Networking Basics and Concepts series
- 0:04from IT Dose. Today, we'll discuss a
- 0:07very important networking concept: the
- 0:09VLAN, which stands for Virtual Local
- 0:11Area Network. Before we talk about
- 0:14VLANs, you must first know what a LAN
- 0:16is. We've already discussed it in
- 0:19detail in a previous video, where we
- 0:20defined it as a group. Of devices like
- 0:23computers, servers, routers, and
- 0:25switches, all connected in the same
- 0:27place such as a home, office, or small
- 0:30company. Technically speaking, a LAN is
- 0:33a single broadcast domain. What does
- 0:36broadcast domain mean? If Samir, for
- 0:38example, is in an apartment and starts
- 0:41speaking loudly, everyone in the
- 0:43apartment will hear him, but those
- 0:46outside won't hear a thing. So, Samir
- 0:48and the people with him in the
- 0:49apartment are considered to be in a
- 0:51single broadcast domain because they
- 0:53can all hear each other. If I were to
- 0:55send a broadcast frame, for instance,
- 0:57with a destination MAC address
- 0:58consisting entirely of Fs. Then that
- 1:01frame would reach every device located
- 1:03within that broadcast domain. Back to
- 1:06VLANs. A VLAN is simply the act of
- 1:09splitting a single LAN into multiple
- 1:11LANs. This is done to reduce broadcast
- 1:14traffic or to separate broadcast
- 1:16domains. The simple network in front of
- 1:18us is a LAN. In this case, we have one
- 1:22broadcast domain because of the switch.
- 1:25So, if device A sends a broadcast
- 1:27message, it means all devices will
- 1:30receive the same message. This is
- 1:32perfectly fine if we are talking about
- 1:34a small network like this one. A
- 1:36network consisting of four devices. But
- 1:38let's imagine if each of these devices
- 1:40represented an entire department in a
- 1:43large company, and naturally, each
- 1:45department would contain a large number
- 1:47of devices. If any device sent a
- 1:49broadcast, we would have massive
- 1:51congestion and very high traffic. This
- 1:54would, of course, degrade the network's
- 1:56performance and speed. Now, we have a
- 1:58company with four departments. Sales,
- 2:01Finance, HR, and IT. We need a way to
- 2:05divide the broadcast domains. To reduce
- 2:08the traffic on the network. Let's think
- 2:11about the solutions we have. The first
- 2:14solution that will come to mind is to
- 2:16use a router. Since a router separates
- 2:18networks. Each interface on the router
- 2:20would be a network with a separate
- 2:22broadcast domain. For example, we could
- 2:24divide every two departments into one
- 2:26network. In this case, we would have
- 2:28two broadcast domains. But this would
- 2:31obviously come with a cost. Because we
- 2:33would need to buy a router and add more
- 2:35cables. There is also another solution
- 2:38better than this one. Which is to split
- 2:40the network so each department is
- 2:42separate. Here, we would need to get a
- 2:44switch for every department. And then,
- 2:46we would have a separate broadcast
- 2:48domain for each department. Here, we
- 2:51have significantly reduced the
- 2:52broadcast overhead. We've also improved
- 2:54traffic, and network performance will
- 2:56certainly improve. But for this to
- 2:59happen, it requires a lot of cost and
- 3:01complex implementation. Meaning both
- 3:03solutions we mentioned would require us
- 3:06to buy additional hardware. What if we
- 3:08don't want to buy anything? That is
- 3:10when we turn to VLANs. VLANs allow us
- 3:13to separate networks and broadcast
- 3:15domains. Just like the second solution
- 3:18that used four switches. But not
- 3:20physically, rather virtually. In short,
- 3:23I can divide the broadcast domains.
- 3:26Here, the traffic for each department
- 3:28will be separate from the other. It is
- 3:30as if I have four switches inside one
- 3:32single switch. This is done by
- 3:35assigning specific interfaces or ports
- 3:38to a specific VLAN. Only interfaces
- 3:41within the same VLAN can communicate
- 3:43with each other. In this example, for
- 3:45instance, each department gets a VLAN
- 3:47ID. For example, Finance gets VLAN ID
- 3:5110, Sales gets VLAN 20, IT gets VLAN 30
- 3:55, and finally, HR gets VLAN 40. If we
- 3:59want to add another department, say
- 4:02Support, all we need to do is assign
- 4:05its interface to VLAN 50. The same
- 4:09applies if I want to add a new server
- 4:12for HR. In that case, all I would do is
- 4:16assign the server's interface to VLAN
- 4:1940 for HR. Then the HR department will
- 4:21be able to communicate with the server
- 4:23easily. By using the VLAN concept, we
- 4:28can separate broadcast domains. And
- 4:30improve network performance without
- 4:33having to spend money, buy new
- 4:35equipment, or redesign from scratch.
- 4:37Not to mention that it is highly
- 4:39scalable. Meaning I can add or remove
- 4:41VLANs from the network easily. And of
- 4:43course, it provides better security
- 4:45because. I can separate networks from
- 4:47each other and control who has access
- 4:49and who does not. And I can also apply
- 4:52specific rules for each VLAN network.
- 4:55Let's understand together how traffic
- 4:57flows with VLANs in place. In this
- 5:00example, we have four departments. So
- 5:02we divided our switch into four VLANs.
- 5:04So that the network for each department
- 5:07is isolated. If we have, for example, a
- 5:09device from IT that wants to talk to a
- 5:11device from HR. Of course, both are on
- 5:15the same switch, but each is in a
- 5:17different VLAN. In this case, the frame
- 5:20must go to Layer 3, meaning it must go
- 5:22to the router. Because this is
- 5:24considered a completely different
- 5:26network. So here, the frame will leave
- 5:28the device in IT and go to the switch.
- 5:31The switch will send it to the gateway,
- 5:33which is the router. After that, the
- 5:36router will forward the frame back to
- 5:38the switch. And the switch will finally
- 5:41send the frame to the destination
- 5:43device. All switches have a default
- 5:46VLAN. Meaning a default VLAN that
- 5:49already exists, usually called VLAN 1,
- 5:52and all interfaces are on this default
- 5:55VLAN. This allows any interface to talk
- 5:58to any other interface on the same
- 6:01switch. And of course, we can create
- 6:03other VLANs to segment the switch. We
- 6:05can create up to 4094 VLANs. This is
- 6:09because the VLAN ID ranges from 0 to
- 6:144096, and since we don't use 0 or 4096,
- 6:18we have from 1 to 4095 available to use
- 6:22. Now, suppose we have two, VLAN 10 and
- 6:26VLAN 20; naturally, interfaces on VLAN
- 6:3010 can communicate with each other. And
- 6:33the same for VLAN 20. We can also have
- 6:36the same VLANs across multiple switches
- 6:39and have them communicate. Meaning a
- 6:42VLAN can span across more than one
- 6:44switch. And it can have interfaces on
- 6:46this switch and on the other switch.
- 6:48But here we will have a problem.
- 6:50Because interfaces only communicate
- 6:53with those on the same VLAN. So for the
- 6:56link between these two switches, which
- 6:58VLAN would it belong to? Of course, if
- 7:01we set it to VLAN 10 or 20, they won't
- 7:04be able to communicate. So the solution
- 7:07here is a specific type of interface
- 7:09called a trunk. Any switch has two
- 7:13types of ports: access ports and trunk
- 7:16ports. All the ports we talked about,
- 7:19which belong to a specific VLAN, are
- 7:22called access ports. We use these to
- 7:24connect devices to the switch. But the
- 7:27trunk port connects switches together.
- 7:29It can send traffic from different
- 7:32VLANs. So how does the receiving switch
- 7:35know which VLAN the traffic is coming
- 7:38from? This is where the tag comes into
- 7:40play. To understand tags, we need to go
- 7:42back a little bit. When a device sends
- 7:45data to another device via a switch, it
- 7:47starts. Creating a frame. The switch
- 7:49forwards this frame to reach the
- 7:52destination. Here, the sending and
- 7:54receiving devices don't know which VLAN
- 7:56they are on. But if we have multiple
- 7:59switches connected via a trunk port.
- 8:02Here, the device sending the frame will
- 8:05send it normally. But when the frame
- 8:07reaches the first switch, before
- 8:10sending it to the second switch via the
- 8:13trunk port, it adds something new to
- 8:15the frame called an 802.1 Q tag. It's
- 8:18also called a dot1q tag. This tag is
- 8:22four bytes long. And it contains
- 8:24important information. Like the TPID,
- 8:26which is the Tag Protocol Identifier.
- 8:29This indicates that the frame contains
- 8:32a dot1q tag and distinguishes it from
- 8:34regular Ethernet frames. It also
- 8:37includes something called TCI, which is
- 8:39the Tag Control Information. And the
- 8:42most important thing in the TCI is that
- 8:44it contains the VLAN ID. So naturally,
- 8:47when the second switch receives the
- 8:48frame, it reads the tag and understands
- 8:50which VLAN it belongs to. In short, the
- 8:53frame leaves the device without any
- 8:56tags. But the trunk port is what adds
- 8:58the tag to it. That is why the trunk
- 9:01port is called a tagged port. Whereas
- 9:03the access port is called an untagged
- 9:05port. There is a very important feature
- 9:07. In the dot1q tag, which is the Native
- 9:11VLAN. It is configured for every trunk
- 9:13port. The switch does not add a dot1q
- 9:17tag to frames that are on the Native
- 9:19VLAN. Meaning, when a frame reaches the
- 9:21trunk port without a tag, the second
- 9:23switch assumes that the frame belongs
- 9:25to the Native VLAN. And by default, the
- 9:28Native VLAN is always VLAN 1. Let's
- 9:32assume we have two devices on VLAN 1.
- 9:35As we said, the frame leaves the sender
- 9:37device to the switch without a tag. Now
- 9:39, the switch will send the frame via
- 9:42the trunk port to the other switch,
- 9:44also without a tag. And this is because
- 9:46it comes from the Native VLAN. When the
- 9:48second switch receives the frame from
- 9:50the trunk port and finds that it has no
- 9:52tag, it will assume that this frame
- 9:54belongs to its native VLAN, which is
- 9:56VLAN 1. Then it will forward this frame
- 9:58to the destination, and it will still
- 10:00be without a tag. That is why it is
- 10:03very important that the native VLANs on
- 10:05all switches are the same. Let's see
- 10:07what might happen if the native VLANs
- 10:09are not the same. Let's assume, for
- 10:12example, that we change the native VLAN
- 10:14of one of these two switches. Instead
- 10:17of VLAN 1, we will set it to VLAN 10;
- 10:19naturally, the device will send the
- 10:22frame to the first switch. The switch
- 10:24will see that it belongs to the native
- 10:27VLAN, so as we said, it will send the
- 10:29frame without any tags to the next
- 10:31switch via the trunk port. The second
- 10:34switch will see that a frame has
- 10:36arrived from the trunk with no tags, so
- 10:39it will immediately assume it belongs
- 10:41to its own native VLAN, which is VLAN
- 10:4310, and here the frame will not reach
- 10:46the destination. That is why when we
- 10:48configure a switch and change the
- 10:51native VLAN, you will always find it
- 10:53gives you a warning message that the
- 10:55native VLANs do not match. You are
- 10:59surely asking yourself now, what is the
- 11:01point of the native VLAN? Let me tell
- 11:03you. We agreed before that hubs are
- 11:06considered Layer 1 devices. Meaning all
- 11:08they do is forward frames, as they
- 11:11cannot understand tags. Let's assume we
- 11:14have a hub here in the middle with a
- 11:16computer connected to it. If I do not
- 11:18send the frame from the native VLAN,
- 11:20then the frame will go with the 802.1 Q
- 11:23tag. In that case, the hub will
- 11:24obviously reject the frame because, as
- 11:26we said, it does not understand tags.
- 11:28So in this case, I must send it from
- 11:30the native VLAN so it reaches the hub
- 11:33without a tag. Then, when it is
- 11:34forwarded to the switch, it will assume
- 11:36it belongs to the native VLAN. And with
- 11:39that, we have reached the end of our
- 11:41episode, where we talked in detail
- 11:42about VLANs. If you liked the video,
- 11:44please hit like, leave your opinion in
- 11:46the comments, and don't forget to
- 11:48subscribe to the channel so you can
- 11:49receive everything we post.
About this transcript
This page contains the full transcript of شرح تفصيلي لل VLAN بطريقة مبسطة وجرافيك احترافي by IT Dose, generated from the public captions YouTube serves with the video. The transcript has 1,972 words across 287 segments, with the original timestamps preserved so you can click any line to jump to that moment in the embedded player.
What you can do with it
Use the transcript to take notes, quote the speaker, build a study guide, generate a summary with ChatGPT or Claude via the YouTube Summary tool, or export it as a timed subtitle file with YouTube to SRT. You can also re-open it in the transcriber to translate the transcript into 100+ languages.
Free YouTube transcript tool
YouTube2Text is a free YouTube transcript generator — no signup, no daily limit. Paste any YouTube link and get the full transcript instantly, with timestamps, click-to-jump, translation to 100+ languages, AI prompts for ChatGPT, Claude, and Gemini, and exports to TXT, SRT, VTT, or Markdown.