Low-voltage path · Division 11: Networks for low-voltage technicians · Lesson 210

Plan VLAN membership with the network administrator

Free for apprenticesRead it or play it. No card, no account, nothing to cancel.
Plan VLAN membership with the network administrator

What you should be able to do

Build a reviewable port-membership worksheet with the network administrator before a camera or controller is connected or moved. Separate the VLAN assignment, IP addressing plan, uplink transport and permitted application traffic. This lesson is planning instruction, not authorization to reconfigure a production switch.

Technical Basis

A VLAN is a logical Layer 2 segment. A basic untagged endpoint can use an access port assigned to its VLAN. An 802.1Q trunk can carry several VLANs; the administrator specifies which are allowed and how native or untagged traffic is handled. Confirm both ends and the actual platform documentation. Voice, hybrid and other specialized port arrangements require their own design.

Separate VLANs do not by themselves describe every security rule. In a conventional routed design, communication between IP subnets needs routing and the applicable access policy. VLAN numbers and IP subnet numbers are different identifiers. Neither a port label nor an illuminated link indicator establishes that an application is reachable.

Original Worked Plan

The following values are fictional training allocations, not defaults or suggested assignments for a customer's site.

SW1 port 3 connects camera C1: access VLAN 110. SW1 port 4 connects controller D1: access VLAN 120. SW1 port 24 connects SW2 port 24: trunk, carrying tagged data VLANs 110 and 120. VLAN 110 has the supplied IPv4 subnet 192.168.40.0/24. VLAN 120 has the supplied IPv4 subnet 192.168.60.0/24.

The worksheet intentionally leaves the trunk's native/untagged treatment unresolved. It cannot be released for implementation until the administrator supplies and approves that field at both ends. The illustrated tagged data list is not a complete switch configuration. It does not specify management connectivity, spanning tree, authentication, multicast behavior or device-specific control traffic.

Notice that VLAN 110 maps to an address prefix containing 40, not 110. This is valid in the fictional plan. Do not infer an IP address from the VLAN number. The administrator must separately allocate each endpoint's address, mask or prefix, gateway and required services. A camera moved from port 3 to port 4 could receive physical link while joining the wrong segment.

Gather The Requirements

Start with a device inventory: asset name, purpose, location, switch identity, physical port and endpoint tagging capability. Confirm the endpoint's identity using the approved inventory rather than assuming a handwritten patch-panel label is current. Record the planned VLAN ID and name, supplied address allocation and the person responsible for the network.

Ask which applications must communicate with this endpoint. For C1, the worksheet might request communication with one named recorder. For D1, it might request communication with a named access-control server. These are requirements to evaluate, not a blanket instruction to open traffic between the two VLANs. List source, destination, service, direction and operational reason; obtain exact protocol and port requirements from the equipment documentation and administrator. Document approved DNS and time dependencies as separate entries.

A network membership worksheet does not establish fire-alarm, emergency communication or other life-safety compliance. Equipment listings, manufacturer instructions, the approved system design and applicable jurisdictional requirements still control those systems.

Review Before Implementation

Trace the proposed endpoint connection through each relevant switch link. Have the administrator verify that the required VLAN exists and that its intended path is available. Compare both ends of the SW1-to-SW2 connection. A correct endpoint access port is insufficient if the needed VLAN is missing from an intervening uplink.

Keep the management path visible in the change review. Record who will make the authorized change, the scheduled window, expected interruption and a recovery method. Never select a convenient unused-looking port or broaden an allowed list simply to make a test succeed. This course exercise does not instruct the apprentice to change live equipment.

Worked through

Use these columns: Asset; location; switch/port; endpoint tagging; VLAN ID/name; address-plan reference; uplink path; required services; approver; test evidence; result.

For the C1 exercise, write SW1/3, untagged endpoint, access VLAN 110 and the supplied 192.168.40.0/24 plan. Mark the final address and service permissions as pending until assigned. For the uplink, write SW1/24 to SW2/24, tagged 110 and 120, and native/untagged policy pending. A pending item is not a pass.

After an authorized implementation, the responsible technician should verify the effective port membership, correct endpoint address and the intended application function. Test an approved prohibited communication case only within the administrator's test scope. Record actual observations, time, device identity and configuration reference. Application success alone does not prove that unwanted access is blocked.

Practice

  1. C1 is plugged into SW1/4 and shows link. Is the approved membership proven?
  2. VLAN 110 uses 192.168.40.0/24. Must the address be changed to contain 110?
  3. SW1/24 carries VLAN 110, but SW2/24 does not allow it. Is the path ready?
  4. The native/untagged field is blank. Can this worksheet be called implementation-ready?
  5. C1 and D1 have different VLANs. Does that alone prove all traffic between them is blocked?

Answers

  1. No. Port 4 is assigned to VLAN 120 in this plan; identify the connection and resolve the discrepancy with the administrator.
  2. No. Use the supplied allocation; VLAN ID and IP prefix are different fields.
  3. No. The administrator must reconcile the intended path at both ends.
  4. No. Obtain the platform-specific approved handling first.
  5. No. Routing and effective access controls must be evaluated and tested within scope.

Where beginners go wrong

Mistake: Changing the supplied 192.168.40.0/24 prefix to contain 110 so it matches VLAN110. Correction: Keep VLAN identity and the administrator's IP allocation in separate worksheet fields.

Mistake: Approving the uplink because VLAN110 appears in one switch's allowed list. Correction: Review both trunk ends, the full path and the unresolved native/untagged treatment before releasing the plan.

Mistake: Marking all cross-VLAN access blocked simply because C1 and D1 use different VLANs. Correction: Ask the administrator to document routing and effective service restrictions and verify the approved communication cases.

Sources

Cisco, VLAN Configuration Guide, Configure VLAN Trunking: https://www.cisco.com/c/en/us/td/docs/switches/lan/c9000/lyr2-fwd/vlan/vlan-configuration-guide/configure-vlan-trunks.html Read for trunk modes, allowed VLAN lists and matching native VLAN settings. Defaults and feature restrictions are platform-specific; they are not universal commissioning instructions.

Cisco, Inter-VLAN Routing on an RV34x Router with Targeted ACL Restrictions: https://www.cisco.com/c/en/us/support/docs/smb/routers/cisco-rv-series-small-business-routers/1393-Inter-VLAN-Routing-with-Targeted-ACL-Restrictions.html Product-specific overview of routing and traffic restrictions; this lesson does not reuse its configuration procedure.

Also working toward the electrician journeyman licence? Take the free 15-question readiness check

Texas journeyman, 15 questions, scored by topic against the 70% mark. No card, and no account needed to start.

Free study material for low-voltage apprentices. This is a national foundation course: requirements differ by state and by local jurisdiction, and a practice that is common in one place is not a rule everywhere. Nothing here is a licence, a certification, or authority to work unsupervised, and completing it does not count as apprenticeship hours or continuing-education credit. Check the codes adopted where you are working, the licensing authority for that work, and your employer's safety programme. VoltMark is not affiliated with, endorsed by, or sponsored by NFPA, OSHA, NICET, BICSI, FOA, or any state or local licensing authority.

—