Managing VLANS
This section provides the following procedures related to VLAN management used in the Switching view.
Network VLAN Configuration Overview
The Tellabs 1100 system VLAN implementation is based on industry standards specified in IEEE 802.1Q (VLAN Tagging), 802.1p (Priority Tagging), and 802.1ad (Q-in-Q/VLAN Stacking). These protocols allow User and User Group segmentation (for network segmentation and security) and service level priority indication for quality of service. An example of a VLAN Group is a pool of users (or devices, e.g. printers) with the same service level agreement (SLA).
IEEE802.1ad (Q-in-Q/Stacked VLANs) Support
The Tellabs 1100 system allows each VLAN (or group) to be provisioned with independent security features including strong authentication (compliant with IEEE 802.1x), Access Control Lists (ACLs), and ingress datagram rate limiting. The Tellabs 1100 Series system also offers communication efficiency by providing optionally configured distributed Ethernet Bridging capability (compliant with IEEE 802.1Q) throughout the platform.
For some applications, Layer 2 bridging is desired to ensure that end users can share information through the shortest path, thus reducing bandwidth use throughout the network.
Provisioning VLAN and VLAN Groups
In the Panorama PON management system, VLANs and VLAN Groups are defined in the provisioning process as part of Service and Connection Profiles. These are global profiles that ultimately define an SLA for a specific user (VLAN) or group of users (VLAN Group). As part of the service Connection Profile, Ethernet Bridging can be either ENABLED or DISABLED, depending upon the service delivery mechanism desired. If Ethernet Bridging is enabled, all users within this group are able to communicate using standard bridging functions. If Ethernet Bridging is disabled, all user traffic is forwarded to the network uplink, providing complete datagram isolation between end-user traffic.
Up to 4,081 end-user VLANs (and VLAN Groups) can be provisioned on the platform. Each VLAN Group can support a near-unlimited number of end-user ports (and services) only limited to the Ethernet bridge capacity of the system (16,384 entries). The combination of cross-connections and the Connection Profiles is used to define these constructs. Use of the Connection Profile allows ease in the definition of allowed services. The subscriber side of the connection defines the port and VLAN. A VLAN value of -1 indicates untagged, 0 indicates priority tagged, and any other value is taken as the subscriber-side VLAN. With untagged traffic, the priority is preserved when the Network VLAN is applied. Untagged traffic gets the specified Network VLAN. For tagged traffic, the VLAN is translated into the proper Network VLAN.
At the end user port, VLANs are delivered into the client environment using a combination of VLAN Tagged, VLAN Priority Tagged, or Untagged. A maximum of five independent VLANs can be provisioned on each end-user Ethernet port, allowing a combination of tagged/untagged scenarios. The function of extending VLAN Tags to the client device is referred to as VLAN Trunking. If VLAN Trunking is used in any Service profile, then all subsequent Service profiles must have VLAN Trunking as their Service Type. In this configuration, each provisioned VLAN is based on a particular service (e.g. data, VoIP). The figure below depicts an end-user environment with multiple VLANs for one subscriber interface.

Managing Network VLANs with VLAN Property and VLAN Assignment
The Tellabs 1100 Series, via Panorama PON EMS, uses two tables to configure and manage network VLANs. They are (1) VLAN Property and (2) VLAN Assignment located in the Switching view.
The attributes of VLAN(s) in the VLAN Property table are covered in this section.
- Defining Attributes in the VLAN Property Table
- Configuring VLANs
- Provisioning Private VLANs
Defining Attributes in the VLAN Property Table
The VLAN Property Table defines the VLANs that are used by the system. This table allows the user to define and set up the attributes associated with each VLAN, which include Start, End, Count, ACL Mode, Bridge Type, MST ID, Registration Type, Enable Dynamic ARP and Description.
The Dynamic Address Resolution Protocol Inspection (DAI) feature, available in the VLAN Properties tab, prevents DHCP snooping or unauthorized attacks from occurring on ports and devices. When the Dynamic ARP Inspection protocol is used, the IP address on a port can be verified. However, whenever DAI is not used, then the IP address is not available and then the data is essentially a Layer 2 MAC table. The relationship between the DAI protocol that prevents snooping; the DHCP snooping table where Acknowledgment messages are sent from the DHCP server to the learned IP address binding; and the Forwarding Database table that records the IP / MAC bindings all contribute to maintaining a secure network environment.
For more information about using the Dynamic ARP Inspection feature, refer to Dynamic ARP Inspection for more details. When configuring VLANs, the user can enable DAI in the VLAN Property table for a specific VLAN to enable DHCP snooping.
| Note: Please note that the VLAN Properties Table must have an entry for that VLAN prior to it being assigned to an Interface. |
| Note: Not all fields appear unless the Bridge Type set for the OLT as found in the OLT > Bridge tab dialog is Provider-802.1ad. |

Refer to the figure above to view an example VLAN Property Table and table below for the field descriptions.
VLAN Property Table Fields
| VLAN Attribute- | Field Description- |
| Start |
Starting VLAN ID in the range assigned to an interface. Either single or VLAN ranges are supported. |
|
End |
Ending VLAN ID in the range assigned to an interface. Either single or VLAN ranges are supported. |
| Count |
Number of VLANs in the entry. |
| ACL Mode |
Defines the default behavior of the VLAN. The rule defined here is found at the end of every set of ACL filters and defines what happens to packets that do not match any ACL rule. The following choices are available:
Note: For further information on the ACL feature and detailed descriptions of each ACL Filter Mode setting, refer to the Access Control List (ACL) for Data Connections and Configure ACL Mode.
|
| Bridging Type |
The Bridge Type defines the basic bridging behavior configured for each VLAN. The following Bridge Types are available: Full Bridging - This setting is used when a typical enterprise networking type of bridge behavior is desired. The Full Bridging option bridges any type of traffic and is a standard L2 bridge. This bridge type supports IPv4, IPv6 and any other protocol that runs over Ethernet, such as Notables. This bridge type is not protocol-aware and therefore many protocol-aware functions are not available, such as Option 82 insertion, DHCP relay agent, etc. Full Bridging enables flooding of unknown unicast, broadcast, or multicast. Multicast flooding is both L2+L3 for N:N connections and L2 for N:N+IPTV connections. |
| Private VLANs - Allows private VLAN service that prevents port to port bridging for untrusted ports. This is typically used to force traffic from ONTs to be sent only to the uplink ports on the network. It prevents user-to-user bridging. | |
| MSTID | MSTID - Id is defaulted to CIST. |
| Enable DAI | Check the checkbox to enable Dynamic ARP Inspection (DAI) for the VLAN. |
| Description |
Freeform a user-defined field to name or describe this uplink interface. Since a VLAN can appear on more than one interface, it can be useful for defining where each path terminates (i.e. NET1 (Uplink)). |
Based on the VLAN Property table Bridge Type, see table below, the system enforces the following service types on cross-connects:
Table: Cross Connects - Allowed Bridging Types
| Cross Connect Service Type- | VLAN Property Table - Bridge Type Allowed- |
| VoIP | Full Bridging |
| Bridging N:N | Full Bridging |
| IPTV | Full Bridging |
Configuring VLANs
| Note: Before beginning, become familiar with Managing Internal Reserved VLANs. |
- In the Application View Bar, select the Switching (
) icon. - In the Common Tree, select the OLT.
- Click the VLAN Properties tab. The VLAN Property table appears, displaying existing VLANs that can be defined.
- Click Add a Row or use the (
) icon. - For the row entry (refer to VLAN Property Table Fields and enter values for the starting and ending VLAN values, ACL Mode, Bridge Type, MST ID, Registration, Enable DAI (for VLAN), and Description fields.
- To define more VLANs for the system, click Add a Row again, to repeat the process.
- To copy one or more populated rows, right-click on the VLAN Property table, and select Copy row(s).
- Click the Paste row(s). The Input pop-up displays that prompt how many rows of VLANs to paste. Enter the number of rows and click the Ok button.
- To delete one or more populated rows, select the row and click the Delete (
) icon. - When finished, click the Apply button. If an error occurs, read the message, and click the Ok button to close.
- Use the Refresh button to update VLAN entries.
Provisioning Private VLANs
A Private VLAN is used to configure a VLAN so that the ONT UNI port can only communicate with the uplink port. A private VLAN prevents any direct device-to-device communication on a specific VLAN. Consequently, these devices can only communicate with each other through a router, which is in the network attached to the uplink. This feature prevents many Layer 2 exploits by preventing user-to-user communication at the Layer 2 level.
Private VLANs are enabled by marking the Bridge Type as Private VLAN. This setting is located in the Switching View > VLAN Properties tab.
To provision a private VLAN, do the following:
- In the Application View Bar, click Switching (
). - In the Common Tree, select the OLT.
- Click the VLAN Properties tab. The VLAN Property Table displays existing VLANs that can be defined.

- In the VLAN Property Table, click Add a Row (
) icon. - Enter the Start and End VLAN values for the interface.
- Select Private VLAN from the drop-down list in the Bridge Type column.
- To enable Dynamic ARP Inspection (DAI) for the VLAN, check the Enable DAI checkbox.
- To define more Private VLANs, click Add a Row (
) icon again, and then repeat the process. - Click the Apply button after defining the VLAN entries. A message confirms that the VLAN Property was saved successfully.
- Click the OK button, and then click the close button on the VLAN Property Table.