网络交换机的网络流量隔离行为
Stack Overflow 新手请点击此处。我很惊讶似乎没有人问过这个问题,我希望这是问这个问题的正确地方。我正在尝试确定是否应该期望常规网络交换机(只是简单的交换机,而不是路由器)能够隔离交换机内的本地网络流量(即定向到同一交换机中另一个本地端口的目标流量)?
例如,如果我有两台机器连接到同一交换机上的端口(例如端口 2 和 3)并使用定向非广播协议(例如 TCP)进行对话,我想确保这两台机器之间的流量不会将网络的其余部分转发到交换子网之外。
我正在构建一个家庭网络,我想使用交换机构建专用网络“子网”或“区域”,其中本地子网流量不会转发到“主干网”或网络的其余部分。请注意,我并不是试图阻止这些“区域”之间进出的任何入站或出站流量,但我只是想为这些区域实现“需要知道”的基础,以限制发往其中的本地化流量在网络范围内的暴露。相同的开关。具体来说,我希望主干网中不必要的流量尽可能少。
那么回到最初的问题:期望任何网络交换机足够智能而不将本地流量转发到网络的其余部分是否公平?我希望情况会如此,但我想确定一下。
PS:您可以假设我在网络上的某个位置有一个 DHCP/WINS 服务器,它将分配 IP 地址等。
我希望这个问题有意义,任何帮助将不胜感激! - K.
First-timer on Stack Overflow here. I'm surprised nobody seems to have asked this question, and I hope this is the right place to ask this. I'm trying to determine if I should expect regular network switches (just simple switches, not routers) to have the capability to isolate local network traffic (i.e. targeted traffic that is directed to another local port in the ame switch) within the switch?
For example, if I have 2 machines connected to ports on the same switch (say, ports 2 and 3) and conversing using a directed, non-broadcast protocol (e.g. TCP), I wanted to make sure the traffic between these 2 machines are not forwarded the the rest of the network outside of the switched subnet.
I'm building a home network and I wanted to build private network "subnets" or "zones" using switches where local subnet traffic does not get forwarded to the "backbone" or the rest of the network. Note that I am NOT trying to block any inbound or outbound traffic to/from/between these "zones", but I just wanted to implement a "need to know" basis for these zones to limit network-wide exposure for localized traffic destined within the same switch. Specifically, I wanted the backbone to have as little unnecessary traffic as possible.
So back to the original question: is it fair to expect any network switch out there to be smart enough not to forward local traffic to the rest of the network? I would expect this to be the case, but I wanted to make sure.
PS: You can assume I have a DHCP/WINS server somewhere on the network that will be assigning IP addresses and the such.
I hope the question makes sense, and any help will be appreciated!
- K.
如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。
绑定邮箱获取回复消息
由于您还没有绑定你的真实邮箱,如果其他用户或者作者回复了您的评论,将不能在第一时间通知您!
发布评论
评论(1)
简短的回答:是的,交换机足够智能(否则它就是一个集线器)。
如果您需要一些奇特的东西,您可以看看VLAN。
我相信这个问题属于 serverfault 或者可能是超级用户。这可能就是为什么没有人在这里问的原因:)
Short answer: yes, the switch is smart enough (otherwise it would be a hub).
And if you need fancy stuff you might have a look a VLANs.
And I believe this question belongs to serverfault or maybe superuser. That's probably why nobody asked it here :)