Loader

Managing VLANS

This section provides the following procedures related to VLAN management used in the Switching view.

Network VLAN Configuration Overview

The Tellabs 1100 system VLAN implementation is based on industry standards specified in IEEE 802.1Q (VLAN Tagging), 802.1p (Priority Tagging), and 802.1ad (Q-in-Q/VLAN Stacking). These protocols allow User and User Group segmentation (for network segmentation and security) and service level priority indication for quality of service. An example of a VLAN Group is a pool of users (or devices, e.g. printers) with the same service level agreement (SLA).

IEEE802.1ad (Q-in-Q/Stacked VLANs) Support

The Tellabs 1100 system allows each VLAN (or group) to be provisioned with independent security features including strong authentication (compliant with IEEE 802.1x), Access Control Lists (ACLs), and ingress datagram rate limiting. The Tellabs 1100 Series system also offers communication efficiency by providing optionally configured distributed Ethernet Bridging capability (compliant with IEEE 802.1Q) throughout the platform.

For some applications, Layer 2 bridging is desired to ensure that end users can share information through the shortest path, thus reducing bandwidth use throughout the network.

Provisioning VLAN and VLAN Groups

In the Panorama PON management system, VLANs and VLAN Groups are defined in the provisioning process as part of Service and Connection Profiles. These are global profiles that ultimately define an SLA for a specific user (VLAN) or group of users (VLAN Group). As part of the service Connection Profile, Ethernet Bridging can be either ENABLED or DISABLED, depending upon the service delivery mechanism desired. If Ethernet Bridging is enabled, all users within this group are able to communicate using standard bridging functions. If Ethernet Bridging is disabled, all user traffic is forwarded to the network uplink, providing complete datagram isolation between end-user traffic.

Up to 4,081 end-user VLANs (and VLAN Groups) can be provisioned on the platform. Each VLAN Group can support a near-unlimited number of end-user ports (and services) only limited to the Ethernet bridge capacity of the system (16,384 entries). The combination of cross-connections and the Connection Profiles is used to define these constructs. Use of the Connection Profile allows ease in the definition of allowed services. The subscriber side of the connection defines the port and VLAN. A VLAN value of -1 indicates untagged, 0 indicates priority tagged, and any other value is taken as the subscriber-side VLAN. With untagged traffic, the priority is preserved when the Network VLAN is applied. Untagged traffic gets the specified Network VLAN. For tagged traffic, the VLAN is translated into the proper Network VLAN.

At the end user port, VLANs are delivered into the client environment using a combination of VLAN Tagged, VLAN Priority Tagged, or Untagged. A maximum of five independent VLANs can be provisioned on each end-user Ethernet port, allowing a combination of tagged/untagged scenarios. The function of extending VLAN Tags to the client device is referred to as VLAN Trunking. If VLAN Trunking is used in any Service profile, then all subsequent Service profiles must have VLAN Trunking as their Service Type. In this configuration, each provisioned VLAN is based on a particular service (e.g. data, VoIP). The figure below depicts an end-user environment with multiple VLANs for one subscriber interface.


 

Managing Network VLANs with VLAN Property and VLAN Assignment

The Tellabs 1100 Series, via Panorama PON EMS, uses two tables to configure and manage network VLANs. They are (1) VLAN Property and (2) VLAN Assignment located in the Switching view.

The attributes of VLAN(s) in the VLAN Property table are covered in this section.

  • Defining Attributes in the VLAN Property Table
  • Configuring VLANs
  • Provisioning Private VLANs

Defining Attributes in the VLAN Property Table

The VLAN Property Table defines the VLANs that are used by the system. This table allows the user to define and set up the attributes associated with each VLAN, which include Start, End, Count, ACL Mode, Bridge Type, MST ID, Registration Type, Enable Dynamic ARP and Description.

The Dynamic Address Resolution Protocol Inspection (DAI) feature, available in the VLAN Properties tab, prevents DHCP snooping or unauthorized attacks from occurring on ports and devices. When the Dynamic ARP Inspection protocol is used, the IP address on a port can be verified. However, whenever DAI is not used, then the IP address is not available and then the data is essentially a Layer 2 MAC table. The relationship between the DAI protocol that prevents snooping; the DHCP snooping table where Acknowledgment messages are sent from the DHCP server to the learned IP address binding; and the Forwarding Database table that records the IP / MAC bindings all contribute to maintaining a secure network environment.

For more information about using the Dynamic ARP Inspection feature, refer to Dynamic ARP Inspection for more details. When configuring VLANs, the user can enable DAI in the VLAN Property table for a specific VLAN to enable DHCP snooping.

Information Note: Please note that the VLAN Properties Table must have an entry for that VLAN prior to it being assigned to an Interface.
Information Note: Not all fields appear unless the Bridge Type set for the OLT as found in the OLT > Bridge tab dialog is Provider-802.1ad.

 

Refer to the figure above to view an example VLAN Property Table and table below for the field descriptions.

 

VLAN Property Table Fields

VLAN Attribute- Field Description-
Start

Starting VLAN ID in the range assigned to an interface. Either single or VLAN ranges are supported.

End

Ending VLAN ID in the range assigned to an interface. Either single or VLAN ranges are supported.
Count

Number of VLANs in the entry.

ACL Mode

Defines the default behavior of the VLAN. The rule defined here is found at the end of every set of ACL filters and defines what happens to packets that do not match any ACL rule. The following choices are available:

  • Disable All ACLs - This is the default behavior which disables ACLs on the VLAN and results in all traffic being permitted unless an ACL exists on a specific port that denies it.
  • Basic ACL Default Deny - Only Basic ACLs are allowed on the VLAN, up to 2048 per PON port, up to a total of 8192 per PON card. A permit ACL with a match is required to pass traffic on the port.
  • Extended Default Deny - Basic and Extended ACLs are allowed up to a total of 512 per PON card. System behavior is to deny all traffic unless explicitly permitted by the filter. A permit ACL with a match is required to pass traffic on the port. Deny ACLs are used to discard traffic that is not wanted from the port.

Note: For further information on the ACL feature and detailed descriptions of each ACL Filter Mode setting, refer to the Access Control List (ACL) for Data Connections and Configure ACL Mode.

  • Extended Default Permit - Basic and Extended ACLs are allowed up to a total of 512 per PON card. System behavior is to permit all traffic unless explicitly denied by the filter.
Bridging Type

The Bridge Type defines the basic bridging behavior configured for each VLAN. The following Bridge Types are available:

Full Bridging - This setting is used when a typical enterprise networking type of bridge behavior is desired. The Full Bridging option bridges any type of traffic and is a standard L2 bridge. This bridge type supports IPv4, IPv6 and any other protocol that runs over Ethernet, such as Notables. This bridge type is not protocol-aware and therefore many protocol-aware functions are not available, such as Option 82 insertion, DHCP relay agent, etc. Full Bridging enables flooding of unknown unicast, broadcast, or multicast.

Multicast flooding is both L2+L3 for N:N connections and L2 for N:N+IPTV connections.

Private VLANs - Allows private VLAN service that prevents port to port bridging for untrusted ports. This is typically used to force traffic from ONTs to be sent only to the uplink ports on the network. It prevents user-to-user bridging.
MSTID MSTID - Id is defaulted to CIST.
Enable DAI Check the checkbox to enable Dynamic ARP Inspection (DAI) for the VLAN.
Description
 
Freeform a user-defined field to name or describe this uplink interface. Since a VLAN can appear on more than one interface, it can be useful for defining where each path terminates (i.e. NET1 (Uplink)).

 

Based on the VLAN Property table Bridge Type, see table below, the system enforces the following service types on cross-connects:
 

Table: Cross Connects - Allowed Bridging Types 

Cross Connect Service Type- VLAN Property Table - Bridge Type Allowed-
VoIP Full Bridging
Bridging N:N Full Bridging
IPTV Full Bridging

 Configuring VLANs

Information Note: Before beginning, become familiar with Managing Internal Reserved VLANs.
  1. In the Application View Bar, select the Switching () icon.
  2. In the Common Tree, select the OLT.
  3. Click the VLAN Properties tab. The VLAN Property table appears, displaying existing VLANs that can be defined.
  4. Click Add a Row or use the ( ) icon.
  5. For the row entry (refer to VLAN Property Table Fields and enter values for the starting and ending VLAN values, ACL Mode, Bridge Type, MST ID, Registration, Enable DAI (for VLAN), and Description fields.
  6. To define more VLANs for the system, click Add a Row again, to repeat the process.
  7. To copy one or more populated rows, right-click on the VLAN Property table, and select Copy row(s).
  8. Click the Paste row(s). The Input pop-up displays that prompt how many rows of VLANs to paste. Enter the number of rows and click the Ok button.
  9. To delete one or more populated rows, select the row and click the Delete () icon.
  10. When finished, click the Apply button. If an error occurs, read the message, and click the Ok button to close.
  11. Use the Refresh button to update VLAN entries.

Provisioning Private VLANs

A Private VLAN is used to configure a VLAN so that the ONT UNI port can only communicate with the uplink port. A private VLAN prevents any direct device-to-device communication on a specific VLAN. Consequently, these devices can only communicate with each other through a router, which is in the network attached to the uplink. This feature prevents many Layer 2 exploits by preventing user-to-user communication at the Layer 2 level.

Private VLANs are enabled by marking the Bridge Type as Private VLAN. This setting is located in the Switching View > VLAN Properties tab.

To provision a private VLAN, do the following:

  1. In the Application View Bar, click Switching ().
  2. In the Common Tree, select the OLT.
  3. Click the VLAN Properties tab. The VLAN Property Table displays existing VLANs that can be defined.


     
  4. In the VLAN Property Table, click Add a Row () icon.
  5. Enter the Start and End VLAN values for the interface.
  6. Select Private VLAN from the drop-down list in the Bridge Type column.
  7. To enable Dynamic ARP Inspection (DAI) for the VLAN, check the Enable DAI checkbox.
  8. To define more Private VLANs, click Add a Row () icon again, and then repeat the process.
  9. Click the Apply button after defining the VLAN entries. A message confirms that the VLAN Property was saved successfully.
  10. Click the OK button, and then click the close button on the VLAN Property Table.

 

 

 

 

FEEDBACK: Are you happy with this material?