Understanding Ieee 802.1Q Tunneling - Cisco ONS 15454 Software Feature And Configuration Manual

Sonet / sdh ml-series multilayer ethernet card
Hide thumbs Also See for ONS 15454:
Table of Contents

Advertisement

Configuring IEEE 802.1Q and Layer 2 Protocol
Tunneling
Virtual private networks (VPNs) provide enterprise-scale connectivity on a shared infrastructure, often
Ethernet-based, with the same security, prioritization, reliability, and manageability requirements of
private networks. Tunneling is a feature designed for service providers who carry traffic of multiple
customers across their networks and are required to maintain the VLAN and Layer 2 protocol
configurations of each customer without impacting the traffic of other customers. The ML-Series cards
support IEEE 802.1Q tunneling and Layer 2 protocol tunneling.
This chapter contains these sections:

Understanding IEEE 802.1Q Tunneling

Business customers of service providers often have specific requirements for VLAN IDs and the number
of VLANs to be supported. The VLAN ranges required by different customers in the same
service-provider network might overlap, and traffic of customers through the infrastructure might be
mixed. Assigning a unique range of VLAN IDs to each customer would restrict customer configurations
and could easily exceed the VLAN limit of 4096 of the IEEE 802.1Q specification.
Using the IEEE 802.1Q tunneling feature, service providers can use a single VLAN to support customers
who have multiple VLANs. Customer VLAN IDs are preserved and traffic from different customers is
segregated within the service-provider infrastructure even when they appear to be on the same VLAN.
The IEEE 802.1Q tunneling expands VLAN space by using a VLAN-in-VLAN hierarchy and tagging
the tagged packets. A port configured to support IEEE 802.1Q tunneling is called a tunnel port. When
you configure tunneling, you assign a tunnel port to a VLAN that is dedicated to tunneling. Each
customer requires a separate VLAN, but that VLAN supports all of the customer's VLANs.
Customer traffic tagged in the normal way with appropriate VLAN IDs comes from an IEEE 802.1Q
trunk port on the customer device and into a tunnel port on the ML-Series card. The link between the
customer device and the ML-Series card is an asymmetric link because one end is configured as an
IEEE 802.1Q trunk port and the other end is configured as a tunnel port. You assign the tunnel port
interface to an access VLAN ID unique to each customer. See
Cisco ONS 15454 SONET/SDH ML-Series Multilayer Ethernet Card Software Feature and Configuration Guide, R4.0
78-15224-02
Understanding IEEE 802.1Q Tunneling, page 8-1
Configuring IEEE 802.1Q Tunneling, page 8-4
Understanding Layer 2 Protocol Tunneling, page 8-6
Configuring Layer 2 Protocol Tunneling, page 8-7
Monitoring and Verifying Tunneling Status, page 8-9
C H A P T E R
Figure
8-1.
8
8-1

Advertisement

Table of Contents
loading

Table of Contents