Step
Enable DHCP snooping entry
6.
recording.
Configuring the network-side port
Step
Enter system view.
1.
Enter Layer 2 Ethernet
2.
interface view or Layer 2
aggregate interface view.
Set the link type of the port.
3.
Assign the port to the
4.
translated VLANs.
Configure the port as a
5.
DHCP snooping trusted port.
Configure the port as an ARP
6.
trusted port.
Configure the port to use the
7.
original VLAN tags of the
many-to-one mapping to
replace the VLAN tags of the
packets destined for the user
network.
Configuring one-to-two VLAN mapping
Configure one-to-two VLAN mapping on the customer-side ports of edge devices from which
customer traffic enters SP networks, for example, on PEs 1 and 4 in
mapping enables the edge devices to add an SVLAN tag to each incoming packet.
Before you configure one-to-two VLAN mapping, create the CVLAN and the SVLAN.
The MTU of an interface is 1500 bytes by default. After a VLAN tag is added to a packet, the packet
length is added by 4 bytes. As a best practice, set the MTU to a minimum of 1504 bytes for ports on
the forwarding path of the packet in the service provider network.
To configure one-to-two VLAN mapping:
Command
dhcp snooping binding record
Command
system-view
•
Enter Layer 2 Ethernet interface
view:
interface interface-type
interface-number
•
Enter Layer 2 aggregate
interface view:
interface bridge-aggregation
interface-number
•
Configure the port as a trunk
port:
port link-type trunk
•
Configure the port as a hybrid
port:
port link-type hybrid
•
port trunk permit vlan
vlan-id-list
•
port hybrid vlan vlan-id-list
tagged
dhcp snooping trust
arp detection trust
vlan mapping nni
207
Remarks
By default, DHCP snooping
entry recording is disabled on
an interface.
Remarks
N/A
N/A
By default, the link type of a
port is access.
N/A
By default, all ports that
support DHCP snooping are
untrusted ports when DHCP
snooping is enabled.
By default, all ports are ARP
untrusted ports.
By default, the port does not
replace the VLAN tags of the
packets destined for the user
network.
Figure
61. One-to-two VLAN