Anda di halaman 1dari 133
ZTEDH ZXR10 5900/5200 Series All Gigabit-Port Intelligent Routing Switch User Manual (Ethernet Switching Volume) Version 2.8.23.A 518057 Tel: (86) 755 26771900, Fax: (86) 755 25770801 LEGAL INFORMATION Copyright © 2006 ZTE CORPOR ATION. ‘The contents of this document are protected by copyright laws and intemational treaties. Any reproduction or dtribution of this document or any partion ofthis document, in any frm by any means, thou the prior written consent of ZTE CORPO- RATION s prohibited, Addtionally, the contents of this document are protected by contractual confidential obligations. ‘All company, brand and product names are trade or service matks, or registered trade or service marks, of ZTE CORPOR ATION or of their respective owners, This document is provided "a i", and all express, implied, or statutory warranties, representations or condtions are ds- claimed, inducing without limitation any implied warranty of merchartabty,fness for pattcular purpose, title er norin- Fringement, ZTE CORPORATION anditslcensers shall nat be lable For damages resulting from the use oF or reliance on the information contained herein. ZZTE CORPCRATION or its licensors may have current or pencing intellectual property ights or applications covering the subject, tmalter ofthis document. Except as expressly provided in any wien license between ZTE CORPORATION ands licensee, the user of ths documert shallnct acquire any license to the subject matter herein {ZTE CORPORATION reserves the right to upgrade or make technical change to this product without further notice Users may ist ZTE technical sunpert website hitp:/Jensuppatzte.com cn to inquire related information. ‘The imate right to interpret this product resides in ZTE CORPORATION. Revision History Revision No. _| Revision Date | Revision Reason R12 20091015, Edition update Serial Number: sj2I20095127 Contents About This Manual... VLAN Configuration .. VLAN Overview VLAN Type VLAN Tag... VLAN Link Type Default VLAN PVLAN.. Qing Subnet VLAN Protocol VLAN VLAN Translation ...... SuperVLAN ... Configuring VLAN Creating VLAN ees Creating a VLAN in VLAN Database .. Setting VLAN Name .. - Setting VLAN Link Type on Ethernet Interface. ‘Adding VLAN Member Port ‘Adding Ports to @ VLAN in Batches Setting the Native VLAN for a Trunk or Hybrid Port Setting VLAN Filtering on a Port....... Setting Frame Filtering Type of a Port Creating VLAN Layer 3 Interface VLAN Configuration Example Configuring PVLAN Configuring Qing Configuring Subnet VLAN Configuring Protocol VLAN ...... Configuring VLAN Translation Configuring SuperVLAN VLAN Maintenance and Diagnosis......... © CCMRMRBVWVAAFFAHHHERHOKDEEE 10 212 213 old old 16 SVLAN Configuration . SVLAN OVErVIEW. osscee SVLAN Configuration - SVLAN Configuration Example .. Basic SVLAN Configuration... Transparent Transmission SVLAN Configuration... 802.1P Priority Configuration SVLAN Maintenance and Diagnosis... SVLAN COS Configuration. SVLAN COS Overview... Configuring SVLAN Cos. - SVLAN COS Configuration Example .. SVLAN COS Maintenance and Diagnosis....... ZESR and SVLAN Linkage Networking Configuration ZESR and SVLAN Linkage Networking Overview....... Configuring ZESR and SVLAN Linkage Networking Configuring SVLAN... cee Configuring Port MAC Duplication. Configuring Port LOOPBACK Configuring One-Way PVLAN Configuring ZESR Configuration Example MAC Address Table Configuration " Introduction to MAC Address - Composition and Meaning of MAC Address Table ... MAC Address Classification... - MAC Address Table Establishment and Deletion.. Configuring MAC Address Table. Setting MAC Address Aging Time. Burning MAC Addresses ee Configuring MAC Address Permanent....... Binding MAC Address to a Port .... Enabling MAC Address Learning Limiting MAC Address Count - Setting MAC Address Learning Protection. Setting Port Unkown Source MAC Address Filtering Setting MAC Address Filtering...... Viewing MAC Address Table. MAC Address Table Configuration Example ....seccsseeesseseee39 STP Configuration. STP OVEPVIEW vossssosessesssseeectsssssesseteninsenseestsvasscesesnns SSTP MOde sessssessssssstseesssnseensevssseeseessinnesseecnsveneee 4d RSTP Mode vosssssssssssseseesssnseenssvssnsnseessnssnseeenessensee 42 MSTP Mode .csssssssssssssssessssnsteniesssssesetsnsnnesseecnesveseee 42 BPDU Protection s.ssssssssesssssseeeessssseesinsnseeseessensesees Configuring STP sssscssssssseeectssssseetenussesseeaesasseesnn 4S Enabling/Disabling STP ....ssssesssessssseseteensesseeeesvessee 49 Configuring STP Mode sj sssssseessessssseseessnsesseeenesseseee 49 Configuring STP Parameters soccer 49 Creating Instances... cestisnneneanneee 50 Configuring MSTP Name and Version ....esssssesseeenesveseee SD Configuring Switch and Port Priority .....cscsssesseeeesseseee SL Excluding a Port from Spanning Tree Calculation .........052 BPDU Protection Configuration........sesssesseseeeeesseseeeennn 52 Configuring BPDU Protection on Edge Port....s.sseceesseseee52 Configuring Port Loopback FUNCHION.....scsssssesseeenesseseee 53 Configuring Port Root Protection Function ....s.sseeessssee53 STP Configuration Examples....cjssessessessesseeessssseeenenn 53 BPDU Protection Configuration Example ...s.ssesesesseseeeere 56 Edge Port BPDU Protection Configuration Examples .........56 Port Loopback Protection Configuration Example .........0057 Port Root Protection Configuration Example.....secccesses0058 STP Maintenance and Diagnosis. Link Aggregation Configuration Link Aggregation Overview Configuring Link Aggregation ......sssscssessesseeeesssseeeenen62 Link Aggregation Configuration Example ..sesscseesseseeeen63 Link Aggregation Maintenance and Diagnosis.......ssssee 64 IGMP Snooping Configuration IGMP Snooping OVErVieW..ecscssssssessetenessesseeeessssscssien 67 Multicast Group JOIN ....scsesssseeecessssseseesennesseeseessesees68 Multicast Group Leave sacessosssecssssssesetsnensesseeenssesees68 Fast LEAVE secsssssssssssnteesssnstennesssnensetsninnesseeenessesees69 Configuring IGMP Smooping.....csssssseseessesseeeessssseeeeie 68 Enabling IGMP snooping ....sssesscsesssssesetenessesseeeees senses 69 Configuring ssm-mapping ....socccsessssseseessesseeenessesees69 Configuring Topology Discovery Convergence ..s..ccessesee070 Configuring an Agent Quetier .sccseossesseesseeesnseeeee 70 Configuring IGMP Agent ....c.ssessssesesnssetsseeeesseesnneee7O Restricting a Multicast GrOUp .ss.scsssseessesssseeeetenensesseee TL Configuring Static IGMP SNOOPING «..ssssssssssessuessesseee TL Modifying Default Time....ssssssssssssseeeessssseeeetenessesseee TL IGMP Snooping Configuration Example ...scsesssseesetsneeseseene72 IGMP Snooping Maintenance and Diagnosis....s..csessessereeee72 Sflow Configuration. OVEVIEW sssccsstsssssessetsussesssenesssssseennisssnsesensessssseeeens 7S SFlow Sam pling Unit .sscccssssssssesssseesessssssessetensveseeee 76 SFIOW Agent Unit .scsssssssssssseseesssscesetsssssssesenssvessees 76 SFIOW Collector ssssscssssussssssesemesssseesetsssseseetenessenseesTO Configuring SFIOW ...sssesssssssssesssussssseesssssssesensnessssseeenns 77 SFlow Configuration Example ..sccssssssesessssssesensneesssseeeens 77 SFlow Maintenance and Diagnosis....s.cssssssssesesneesssseeeens 78 ZESS Configuration ZESS Overview eo Configuring ZESS ....sscssssssssssssessssesseessesessssvssesereetseseeeesB2 Creating ZESS Domain ..ssssssssesssseeeenesssseeserenessensers82 Configuring Preup Time ...sscssssssesssseesensssessetenss senses 83 Configuring ZESS Mode v..ssssssscesssseesetsessessetenessesseee 83 Configuring ZESS Control VLAN ...ssssccscsssssseeeetenensesseee 84 Configuring ZESS Port. sssssssssesssseeeessssseeeetenessessees 8A Clearing ZESS receive-vian POrts ..ssccsessessesseteeesseseees BS ZESS Configuration Example ..esccessssseeesssssseseesn essences 85 ZESS Maintenance ...sscsesesssseessessssseesissnseseesnsenssseeee 88 Ethernet OAM Configuration. 802.3ah OVEFVIEW vecssesesesssssetesesssnseecntsssnseserseeesssseeeens 89 OVERVIEW ssscsesssssssssnnussssnsteeiesssssesetnessessetenesseseees89 Remote DiSCOVErY..csssssssssssseenesssssesetsensessetenessessees9O Remote Loopback ...sssssssssssesesssseesesensessetenesseseees90 Link Monitor. sccssssscessssssssssseeesssssceeeisssssssetsnensessees SD Configuring 802.3ah s.esccessssssssnessssseeeenesssscesnsnenseesens DD Function Configuration ....ssssssssesssseesenesssseesetenessessene SL Enhanced Function Configuration ....s.cccsssssseesetenesseseeee 92 Instance Configuration .....ssssescsesssseesenessssessetenes senses 93 CFM Configuration ..ssscscsessssscsstiussssseeeenunssscesetsnennensens SF CFM OVErViEW vssssscsssssssssssetsiessssceeessssnseentscensensens D4 Configuring CFM ....cssssssssssssesnesssssesetesssssetsnsssesseee97 Basic Configuration s.oscssssssseesssssseseesnessssseeeens97 CFM Function Configuration ....cscssssseeeesssen 99 Enhanced Function Configuration ....sccesssseeeee 102 Instance Configuration ....ecsocseesseesseeeeeseee OL UDLD Configuration... UDLD OVErVIOW seccssesssseseessetsseeeenssetssetensnseesssesens 105 Configuring UDLD ..ssescssssssssetsseeeenssttnstennnseeessesees 106 UDLD Global Configuration ...sseccsoseesessesseeeessseess 106 UDLD Interface Configuration ..essscsesssseesseeeeeseeees 107 UDLD Configuration Notification Items ....essseeecsessene 107 LLDP. LLDP OVErVIOW oecccssesssseeeessetsseeenesssetsnetesnseesssesees 109 Configuring LLDP ...sssscssessssssetssereesssstsssetensseeessesees LLO LLOP Configuration Example .oecsescssesseeesseseenseeevsesees 110 L2PT Configuration. LOPT OVErVIEW cesccsseessseeenssetsseeeeinssetnetetsnseesssesens LLB Command Configuration .....ssesssssssesssesssesennseeesesee LLB L2PT Configuration Example...sesssocccsessessseeecsseesnseeee 114 Figures Tables . Glossary... About This Manual Purpose Intended Audience Prerequisite Skill and Knowledge What Is in This Manual ZXR10 5900/5200(V2.8.23.A) Series All Gigabit-Port Intelligent Routing Switch User Manual (Ethernet Switching Volume) provides procedures and guidelines that support the operation on ZXR10 5900/5200 Series All Gigabit-Port Intelligent Routing Switch, in= dluding = ZXR10 5924 Gigabit Routing Switch = ZXR10 5928 Gigabit Routing Switch = ZXR10 5928-Fi Gigabit Routing Switch = ZXR10 5952 Gigabit Routing Switch = ZXR10 5224 Gigabit Convergence Switch = ZXR10 5228 Gigabit Convergence Switch = ZXR10 5228-Fl Gigabit Convergence Switch = ZXR10 5252 Gigabit Convergence Switch = ZXR10 5928-PS Gigabit Convergence Switch This manual is intended for engineers and technicians who per- form operation activities on ZXR10 5900/5200 alll Gigabit-Port In- telligent Routing Switches. To use the Ethernet Switching Volume effectively, users should have a general understanding of OSI Model. Familiarity with the following is helpful, = Protocols = Routing concepts and Data Communication Terminologies ‘The Ethernet Switching Volume contains the following chapters: ‘TaBLe 1 CHAPTER SUMMARY Chapter Summary Chapter 1. VLAN This chapter describes the content and Configuration related knowledge of VLAN and related configuration Chapter 2. SVLAN This chapter describes the content and Configuration related knowledge of SVLAN and related configuration Chapter 3 SVLAN COS | This chapter describes the content and Configuration related knowledge of SVLAN COS and related configuration. Chapter 4 ZESR and | This chapter describes the content SVLAN Linkage Network- | and related knowledge of ZESR and ing Configuration SVLAN Linkage Networking and related configuration Confidential and Proprietary Information of ZTE CORPORATION 2XR40 5900/5200 Series User Manual (Ethernet Switching Volume) TIE Related Documentation Chapter Summary Chapter 5 MAC Table | This chapter describes the content, and Operation related knowledge of MAC Table and related configuration. Chapter 6 STP This chapter describes the content and Configuration related knowledge of STP and related configuration. Chapter 7 Link Aggrega- | This chapter describes the content and tion Configuration related knowledge of Link Aggregation and related configuration. Chapter 8 IGMP Snooping | This chapter describes the content and Configuration related knowledge of IGMP Snooping and related configuration. Chapter 9 SFLOW This chapter describes the content and Configuration related knowledge of SFLOW and related configuration. Chapter 10 ZESS This chapter describes the content and Configuration related knowledge of ZESS and related configuration. Chapter 11 Ethernet | This chapter describes the content and ‘OAM Configuration related knowledge of Ethernet OAM and related configuration. Chapter 12 UDLD ‘This chapter describes the content and Configuration related knowledge of UDLD and related configuration. Chapter 13 LLDP This chapter describes the content and Configuration related knowledge of LLDP and related configuration. Chapter 14 L2PT This chapter describes the content and Configuration related knowledge of L2PT and related configuration. The following documentation is related to this manual: ZXR10 5900/5200(V2.8.23.) Series All Gigabit-Port Intelli- gent Routing Switch Hardware Manual = ZXR10 5900/5200(v2.8.23.A) Series All Gigabit-Port Intelli- gent Routing Switch User Manual (Ethernet Switching Volume) = ZXR10 5900/5200(V2.8.23.A) Series All Gigabit-Port Intelli- gent Routing Switch User Manual (Basic Configuration Volume) = ZXR10 5900/5200(v2.8.23.A) Series All Gigabit-Port Intelli- gent Routing Switch User Manual (IPv4 Routing Volume) = ZXR10 5900/5200(v2.8.23.A) Series All Gigabit-Port Intelli- gent Routing Switch User Manual (IPv6 Routing Volume) = ZXR10 Router-Ethernet Switch Command Manual - Command Index = ZXR10 Router-Ethernet Switch Command Manual - System Management Confidential and Proprietary Information of ZTE CORPORATION TIER About This Manual ZXR10 Router-Ethernet Switch Command Manual - Functional System I ZXR10 Router-Ethernet Switch Command Manual - Functional System Volume II ZXR10 Router-Ethernet Switch Command Manual - Functional System Volume III ZXR10 Router/Ethernet Switch Command Manual — Functional System IV ZXR10 Router/Ethernet Switch Command Manual — Protocol Stack I ZXR10 Router/Ethernet Switch Command Manual — Protocol Stack IT ZXR10 Router/Ethernet Switch Command Manual — Protocol Stack III ZXR10 Router/Ethernet Switch Inform ation Manual Confidential and Proprietary Information of ZTE CORPORATION il 2XR40 5900/5200 Series User Manual (Ethernet Switching Volume) TIE This page is intentionally blank, iv Confidential and Proprietary Information of =TE CORPORATION Chapter 1 VLAN Configuration Table of Contents VLAN OVErVieW vssssocssessssssseeeesssssscesetsnunssssetenesvasseeansee D Configuring VLAN s..ssssscssssseesnssssucesnissnnensensieevsnseesvsees 8 Configuring PVLAN..ssscsssssseesnssssacesnnuennenseesiesvenseesnisss 20 Configuring Qin... siossessnaneeninsninneeesesvoneeesenene LD Configuring Subnet VLAN.....c.ss.tonssnstenssiessusetensseeesieeee AB Configuring Protocol VLAN vivsecssscssssceeensssseseesiesvoneeesnn 3 Configuring VLAN Translation .....cssssccsssssssessetsunssesseeeevsns LE Configuring SuperVLAN «.......- seociessnaeeentsinninnseeseenns 14 VLAN Maintenance and Diagnosis........c:su...cesuseeensseeesieeee 16 VLAN Overview Virtual Local Area Network (VLAN) is a technology that divides a physical network into several logical (virtual) Local Area Networks (LANs). Each VLAN is identified by a VLAN ID (VID) VLAN technology divides users within a physical LAN into different broadcast domains (VLANs) according to requirements. Users with the same demands are grouped to the same broadcast domain, while those with different demands are separated. Each VLAN, like 2 logically independent LAN, shares the same at- tributes as those physical LANs. All broadcast and unicast traffics within a VLAN are limited to the VLAN but are not forwarded to any other VLAN. Devices in different VLANs must rely on L3 rout- ing switching for communication between them VLAN provides the following advantages: 1. Lower broadcast traffic on the network 2. Enhanced network security 3. Streamlined network management VLAN Type LAN type of a device depends on how it will divide a received frame toa VLAN. ZXR10 5900/5200 supports port-based VLAN, the sim- plest and most effective method of VLAN division. It divides its various ports into different VLANs, so that any traffic received on a port belongs to its corresponding VLAN. ‘Confidential and Proprietary Information of STE CORPORATION 1 2XR40 5900/5200 Series User Manual (Ethernet Switching Volume) TIED Assume ports 1, 2 and 3 belong to the same VLAN, while the other ports belong to other VLANs, then frames received on port 1 are broadcast to ports 2 and 3 only while they are not passed to any other port. When a user in a VLAN moves to a new location, it no longer belongs to the original VLAN unless the user is assigned to that VLAN again. VLAN Tag It is possible to transmit services of several VLANs over a single link ifa frame carries information about its native VLAN while being passed through a network. IEEE 802.19 implements this function through attaching a VLAN tag to the Ethernet frame. ‘A VLAN tag is a four-byte long number, and it comes after the source MAC address and before the length/type field in an Ethernet frame. Figure 1 shows the VLAN tag format. FIGURE 1 VLAN TAG FORMAT. TPID(2 bytes) | TCI(2 bytes) 7 54 07 o VLAN tag is applied to cross-switch VLANs, when the link between switches is usually called a trunk. VLAN tag allows VLANs cross several switches to be created through one or more trunks. When the ports connecting these switches receive a tagged frame, the ports can judge which VLAN the frame belongs to based on the VLAN tag. Each 802.19 port is allocated a default VLAN ID, called PVID. Un= tagged frames recaived on a port is considered belonging to the default VLAN, and then broadcasted in that VLAN ZXR10 5900/5200 supports IEEE 802.1Q tag. VLAN Link Type ZXR10 5900/5200 ports support the following links: 1. Access link It connects devices (such as workstation) that cannot iden- tify VLAN tags to the VLAN switch port, It transmits untagged frames only to a single VLAN 2. Trunk link 2 Confidential and Proprietary Information of STE CORPORATION TIER Chapter 1 VLAN Configuration It connects two devices that can identify VLAN tags and car- ries several VLAN'S services. It transmits tagged frames only to several VLANs. The most common trunk link is the one be~ tween two VLAN switches. 3. Hybrid Link It transmits both tagged and untagged frames. For a given VLAN, however, it only transmits frames of the same type. Default VLAN ZXR10 5900/5200 has a default VLAN initially, which has the fol- lowing features: = VLAN ID as 1 = VLAN name as VLANOOO1 = All ports included = Untagged by default on all ports PVLAN ‘To improve network security, messages among different users shall be separated. The traditional method is to assign a VLAN to each user. The method has obvious limitation, which can be seen from the following aspects: 1. At present, IEEE 802.1Q standard supports utmost 4094 VLANs, which limits the number of users and network expan- sion. 2. Each VLAN corresponds to one IP subnet, so vast di nets will cause the waste of IP addresses, 3. Planning and management to a mass of VLANs and IP subnets is extremely complicated PVLAN (Private VLAN) technology is developed to solve these prab- lems. PVLAN divides the ports in VLAN into three types: the port con- necting to the user is called Isolate Port, the port connecting to a group of users that need interconnection and intercommunication is called Community Port and the port connecting to the upstream router is called Promiscuous Port. The isolated port communicates with the promiscuous port only, but not with any other isolated port or community port. Community port can communicate with promiscuous port and any other community port, but not with iso- lated port. Thus ports in the same VLAN are separated. The user who connects with isolated port can only communicate with its default gateway, the user who connects community port can in= terconnect and intercommunicate, Network security is ensured. ZXR10 5900/5200 supports 20 PVLAN groups, each group having customized isolated ports and at most 256 isolated ports, 16 com munity ports and 8 promiscuous ports. ded sub- ‘Confidential and Proprietary Information of STE CORPORATION 3 2XR40 5900/5200 Series User Manual (Ethernet Switching Volume) TIED QinQ Qing, also known as VLAN stack, is a graphic name for the IEEE 802.19 based tunnel protocol. QinQ technology encapsulates the original VLAN tag (inner tag) with another VLAN tag (outer tag) so that the inner tag is masked. QinQ implements simple Layer 2 VPN (L2VPN) without protocol support, applicable to small-sized LANs with L3 switches as their core. Qing typical networking is shown in Figure 2. Port to the cus- tomer network is called the customer part: The port to the Service Provider network is called the uplink port, and the SP edge access device is called Povider Edge (PE). FIcuE 2 QINQ TYPICAL NETWORKING SPVLAN 10 Customer gem Spv SPVLAN 10 User network 1 Soil CYLAN 1-100 TP switchs User network 2 CVLAN 1-100 SP Netwrok The customer network is usually connected to the PE through trunk VLAN. Uplinks ports in the SP network are connected symmetri~ cally in the trunk VLAN mode. When a packet (tagged/untagged) from customer network 1 reaches the customer port of switch A. Switch A attaches an outer tag (VLAN ID as 10) to its forcibly. Within the SP network, packet is forwarded to all ports in VLAN 10. This packet finally arrives at switch B. Switch 8 recognizes that the port to customer network 2 is a customer port, then dispatches the outer tag complying with the traditional 802.19 to restore the original packet. Switch B sends the packet to customer network 2. Thus data is transparently transmitted between customer net- works 1 and 2 through the SP network. This allows the customer considerable flexibility for Private VLAN ID planning, without any conflict with those of the SP network. Subnet VLAN Subnet-based VLAN applies to L2 VLAN networks for flexible con- figuration of data frame forwarding. Subnet-based VLAN forward a data frame to a VLAN based on the source IP address. This source IP address based VLAN can forward user data from differ- ent subnets cross several VLANs, while remain the original VLAN membership unchanged 4 Confidential and Proprietary Information of TE CORPORATION TIER Chapter 1 VLAN Configuration Subnet VLAN isolates data frames from different source IP ad- dresses so that a user has access to data from its own subnet only. The subnet VLAN priority in untagged frame forwarding is higher than that of protocol VLAN or PVID; the priority of tagged frame forwarding in the tagged mode is higher than that of subnet VLAN Portis enabled on Subnet VLAN by default and also can be disabled according to actual demands. ZXR 10 5900/5200 supports up to 256 subnet VLANs, that is, sup- ports processing data frames from 256 source IP subnets Protocol VLAN Protocol-based VLAN applies to L3 networks or those running many protocols, Protocol-based VLAN divides packets based on their network layer encapsulation protocol. Packets with the same tag belong to the same protocol VLAN. This network layer protocol based VLAN can broadcast packets cross several VLAN switches. It allows users to move freely in the network while remain their VLAN membership unchanged This solution eliminates the need to reconfigure the VLAN when a user moves to another physical location in the network. In addi- tion, as VLANs are identified based on the protocol type instead of attached frame tag, traffic through the network reduces. Protocol VLAN is not only enabled on all physical ports by default but also disabled on ports according to demands, which identifies that VLANs are based on the packet tag only. It separates packets with different tags so that users have access to data from other users in the same VLAN only. ZXR10 5900/5200 supports up to 16 protocol VLANs. This means that protocol VLANs support processing packets with 16 kinds of tags. VLAN Translation VLAN translation permits the switches of different users to have same VLAN ID. With VLAN translation, core switch modifies the same VLAN ID of edge switches into the different VLAN ID. This function isolate user in core switch and simply the configuration of edge switch ZXR10 5900/5200 support 768 VLAN translation. SuperVLAN On a traditional ISP network, one IP subnet is allocated to each user, which means that the occupation of three IP addresses by a single user as its subnet address, broadcast address and default ‘Confidential and Proprietary Information of STE CORPORATION 5 2xR20 5900/5200 Series User Manual (Ethernet Switching Volume) TIE gateway address. Even if there are a number of idle IP addresses in a user's subnet, they cannot be allocated to other users. This causes waste of IP addresses. SuperVLAN effectively resolves this problem. It merges several VLANs (called sub-VLAN) to a SuperVLAN so that they can use the same IP subnet and default gateway. With the SuperVLAN technology, the ISP needs only one IP sub- net for its SuperVLAN. It creates a sub-VLAN for each ofits users ‘These sub-VLANs can use flexibly the IP addresses in the Super- VLAN subnet and share the default gateway of the SuperVLAN Each sub-VLAN is an independent broadcast dom ain, ensuring user isolation, and communicates with other sub-VLANs through Super- VLAN routing Configuring VLAN Creating VLAN Command Function axmao(centig)# vlan {|} This creates specific VLAN and enters into VLAN configuration mode Creating a VLAN in VLAN Database ‘To create a VLAN in VLAN database, use the following command. Command Function 2xn10(conéig)¢vlan list [name ] | This creates a VLAN in VLAN database, Setting VLAN Name To set VLAN name, use the following command. Command Function 2xR10 (cone ig-vi nx) ghame This sets VLAN name. VLAN name uniquely identifies a VLAN. This can be a group, de~ partment and region name. By default, 2 VLAN name is “VLAN” é Confidential and Proprietary Information of ZTE CORPORATION TIER Chapter 1 VLAN Configuration + VLAN ID, VLAN ID includes four digits (0s are pretended when there are less than four digits). Name of VLAN 4 is VLANOOO4. Setting VLAN Link Type on Ethernet Interface To set VLAN link type on Ethernet port, use the following command. Command Function 23810 conf ig-ses_i/)#Switchport mode {access|trunk | This sets VLAN link type on [hybrid} Ethernet port, ‘There are three VLAN link types for Ethernet interface of ZXR10 5900/5200: Access mode, Trunk mode and Hybrid mode. Access mode is used by default, = Ports of access mode belong to only one VLAN, support un= tagged frames and are usually connected to computers. = Ports of trunk mode can belong to several VLANs (re~ ceives/sends packets from/to several VLANs), support tagged frames, and are usually used as trunk ports between switches. = Ports of hybrid mode can belong to several VLANs (re~ ceives/sends packets from/to several VLANs), support both tagged and untagged frames (customized), and can be used to connect both switches and computers. Ports of hybrid mode are different from trunk ports. They send both tagged and untagged frames (trunk ports send untagged frames only when they are from the default VLAN). Adding VLAN Member Port To add an access, trunk or hybrid port to a specified VLAN, use following commands. ‘Access port only can be added to one VLAN, Trunk port and Hybrid port can be added into multiple VLANs. = To add an access port into a specific VLAN, use the following commands Command Function 2xR10(config-gei_1/x)#switchport access vlan This command adds an access {[} port to a specified VLAN. = To add a trunk port to a specific VLAN, use the following com- mand. ‘Confidential and Proprietary Information of STE CORPORATION 7 £XR:10 $900/5200 Series User Manual (Ethernet Switching Volume) TIER Command Function z4R10 (conéig-ges_1/x)#switchport trunk vlan This command adds a trunk port to a specified VLAN, = To add a hybrid port into a specific VLAN, use the following commands Command Function z1R10(conéig-ges_1/x)#switchport hybrid vlan [tagiantag] This command adds a hybrid port to a specified VLAN Adding Ports to a V’ To add ports to a VLAN in batches, AN in Batches Use the following command. Command Function zxpio(conéig-vi nt) ¢switchport {pvid|tag|untag} This adds ports to a VLAN in batches, Setting the Native VLAN for a Trunk or Hybrid Port ‘An access port belongs to only one VLAN, its native VLAN is the VLAN to which it belongs. This requires no additional configuration Trunk port and hybrid port belong to multiple vians and they need to set native vian. If native vian is set on port, when one frame with no vian tag is received on port, it will be forwarded to the port belonging to this native vian. Native vian of trunk port and hybrid port is vian 1 by default, Step | Command Function 1 | zxpto(coneig-ges_1/x)#switchport trunk native vlan {|} This command sets native VLAN for a trunk port. 2 | zxp1o(contig-ges_1/x)#switchport hybrid native vlan {T} This command sets native VLAN for a hybrid port Setting VLAN Filtering on a Port To set VLAN filtering on a port, use the following command. 8 Confidential and Proprietary Information of ZTE CORPORATION TIER Chapter 1 VLAN Configuration Command Function 2xR10(contig-sei_a/=)# ingress filtering {enable|disab le} This sets VLAN filtering on a port. When ingress filtering is enabled on a port, the port drops a re~ ceived frame if the VLAN to which the frame belongs does not include the ingress. By default, VLAN ingress filtering is enable. Setting Frame Filtering Type of a Port To set frame filtering type of a port, use the following command Command Function 23810 conf ig-sei_a/)#acceptable frame types {allltag} This sets frame filtering type of a port, This sets the frame type of the port which can receive all types of frames including untagged and tagged frames. By default, all frames are received. Creating VLAN Layer 3 Interface Command Function zxR10(contigyginterface {vlan |} This creates VLAN layer 3 interface. It is necessary to create this VLAN before creating VLAN layer 3 interface. VLAN Configuration Example ‘The ports gei_1/1 and gei_1/2 on Switch A, and the ports gei_1/1 and gei_1/2 on switch 8, belong to VLAN 10; the ports gei_1/4 and gei_1/S on switch A, and the ports gei_i/4 and gei_1/5 on switch B, belong to VLAN 20. The four ports are all access ports, as shown in Figure 3. Switches A and B are connected through ports gei_1/24 (two trunk ports) over a trunk link. ‘Confidential and Proprietary Information of STE CORPORATION 5 2XR40 5900/5200 Series User Manual (Ethernet Switching Volume) TIED FIGURE 3 VLAN NETWORKING vian20 Configuration of Switch A: ZxRI0_A(contigifvian 10 (contigrvlanl0)fswivchpore pvid gei_1/i-2 (contigrvl ani) Bete TA(conesgi vlan ZXRLO_A(contigrvl anz0)Bawivchport pyid gei_1/ 4-5 ZXRLO_A(contigrvl an20)Bexie ZIRLO_A(contig)Bineeztace gei_3 ZXRLO_A(contig-=gei_i/24)fawitchpoxt mode trunk ZARLO_A(contig-gei_1/74)fswscenpore trunk vian 10 ZARLO_A(con€ig-gei_l/74)fswseenport teunte vlan 20 ZARLO_A(contig-geiil/24)Bexse Configuration of Switch B: ZxRL0_B(contighfvian 10 ZxRLO_B(contigrvl anlO)Bswivchport pyid gei_1/1-2 ZXRLO_B(contigrvl anlO)Bexie BXRLO-B (contig)¥vian ZXRLO_B(contig-vl anz0)Bawivchport pyid gei_1/ 4-5 ZXRLO_B (contigrv an20)Bexie ZXRLO_B(contig)Bineextace ges )fswicchpore mode trunie )fswicekpore crunk vian 10 )fawicekpore crunk vlan 20 bese Configuring PVLAN Step | Command Function 1 | zxn10;coneigngvlan private-map session-id [i | This configures isolated solate I[promis ][community | ports, promiscuous ports and ] community port of Private VLAN, 2 | zxp10(coneignshow vlan private-map This displays the configuration information of PVLAN Example The configuration of two isolated groups is shown below. Isolated group 1: gei_1/1,gei_1/2,xgei_2/1 and xgei_3/1 are iso- lated ports, port gei_1/10 is a promiscuous port. 10. Confidential and Proprietary Information of ZTE CORPORATION TIER Chapter 1 VLAN Configuration Isolated group 2: gei_1/3,gei_1/4 and gei_4/1 are isolated ports, gei_1/S,gei_1/6 and gei_S/1 are community ports, gei_1/11 and gei_1/12 aré promiscuous ports: The detailed configuration is as follows: 2xR10(con€ighfvian private-map seszion-id 1 isolate gei_1/ 1-2, gei 2/1, gei_3/1 promis gei_1/ 10 2ERL0(conéigh#vian private-map seasion-id 2 isolate gei_1/2-8,gei_ 8/1 promis ges i/i-12 community gei_l/S-6,gei_ 5/1 BxRI0(conéig)Fokow vian peivace-map ge4_4/5-6, 5055/2 zeRL0 (contig) Configuring QinQ Step| Command Function 1 | zxnao(coneig~se)¢switchport qing When configuring Qing, it {normalluplink|customer|tpid } needs to set customer port of SPVLAN to untagged port and Uplink port to tagged port. 2 | xnso(coneign# show ging This views configuration information of Qing Example In, assume switch A's customer port is gei_1/1, its uplink port is gei_1/24, switch B’s customer port is gei_i/1 and its uplink port Is gei_1/24, Configuration of Switch A A(contig)fvian 10 Alcontignvlan)Bexie Alcontighbinverface gei 1/2 Alcontignif)fswivehpose ging custome Alconfignif)fawivehpoze access vian 10 DERLO_A(contignis)Bexie DRLO_AlcontighBincertace gei_1/74 DIRLO_Alcontig-ie)gowieekpere ging wpl ine DERLO_Alcontigris)fowivehpose mode crue DIRLO_Alcontignis)fowivehpose erenk vlan 10 ZERLO_A(contigrie)bexie Configuration of Switch B ZeR10_B(contighfvian 10 ZERO (contigrvian)Bexie ZeRL0_B(contighBincerface gei_1/2 ZIRLO_B (config-is)fowivchpese ging custome DiRL0_B (config-is)fowivehpose access vian 10 ZERO (contignie)bexie DERLO_B (contighBincertace gei_1/74 ZERL0_B (contignie)fowiechpere ging wpl ink ZERL0_B (config-is)fowivehpose mode crue DERLO_B (configris)fowivchpose erink vlan 10 ZERLO_B (configrie)bexie ‘Confidential and Proprietary Information of ZTE CORPORATION 42 £XR:10 $900/5200 Series User Manual (Ethernet Switching Volume) TIER Configuring Subnet VLAN Step Command Function zxn10(conéig)fvlan subnet-map session-no vlan {} This creates a subnet VLAN zeR10(conéigi#show vlan subnet-map This displays configuration of subnet VLAN. Example As shown in Figure 4, configure VLAN data on the switch. Config tire VLAN2O and VLANSO, Port gei_1/1 belongs to VLAN20, port gei_1/2 belongs to VLAN30, port gei_ 1/10 belongs to both VLAN20 and VLAN30. Configure different PVIDs for gei_1/1, gei_1/2 and gei_1/10. PCs in 20.20.20.0/24 have access to server 1, and the PC whose IP address is 30.30.30.1 has access to server 2 FIGURE 4 SUBNET VLAN CONFIGURATION EXAMPLE Server I Server? Hub (2. - Ws: 20.2020.024 Configuration of switch: Gei_vi0 (Vlan 20,30) 3 ies 30.3030.1/24 [sexeate 2 VLA and assign ports to it*/ ZxRLO (confighfineezface ges i/L ZARLO | contig-gei_i/ 1)fawiceh fe mode Bybrid ZxRL0 (config-geiii/ 1)fawicenpore hybrid navive vian 2 ZARLO (config-geiil/ L)fawivenpere Rybria vian 20 uncag 12 Confidential and Proprietary Information of ZTE CORPORATION TIER Chapter 1 VLAN Configuration ZeR10 (conéig-ges_1/ a) fexie ZER10 (contig iBintexace get_W/ ZERLO(conéignge! 1/2 )fowieckpoxt mode hybrid ZERL0 (cont ig-gei_i/ 2)fowieenpose hybrid native vian 20 2xR10(con€ig-gei_l/ 2)$swivehpost hybeid vian 20 wntag ZeR10 (cone ig-ges_a/ =) exe DRL (conéighBinextace get_1/10 ZERL0(conéignge! 1/ 10)fswsccnpore mode hybrid ZuR10 (cone ig-geii/ 10)fawscehpore Aybrid van 70,90 uneag 2ER10 (conéig-gest/ 10)fexse [streave subnee VEA asc*/ ZERLO(coneiglivian zubnec-map seasion—ne ZeRLO (contighfvi me vubnec—map seasion—ne [sdisabie subnee VLA in some ports which don’ © need subnet VLAIY/ ZERLO(coneigifincertace get _l/S ZERL0(conéignges i) S)fvian ubnet-map disable ZERLO (cone ig-ges al S)Hexie Configuring Protocol VLAN Step| Command Function 1 | 2xx10(conigy#vlan protocol-map session-no This configures protocol {ethernet2| Ilc| snap}<0xHHHH> vlan | VLAN. {| } 2 | zxe10(contign#show vlan protocol-map This views the configuration of protocol VLAN, Example Customer port gei_1/1 of a switch receives 0X1000 packets and 0X1001 packets. These packets with different tags can be ob- served on the other two ports, gei_1/2 and gei_1/3 respectively. The detailed configuration is as follows: Configuration of switch: [sereave protocol vian daca*/ BxRLO(confighfvian protecel-map sezzion-no 1 ethernet: ZERLO (cont ig)ifvi an protace! [ope pore inte corzesponding VLAE*/ ZuR10 (coneighfincestace get_l/ 1 ZERL0 (conéig-isiowivehpare mode trunk DERL0 (coneig-ishgowieehpose ezunk Vian 10,20 ZERLO (coneig-is}éexie ZeRL0 (contig if incertace get_V/2 ZERL0 (conéig-isiowieehpare mode trunk ZERL0 (coneig-is)fowieehpore crunk vian 10 ZERO (coneig-is)gexie BxRLO(conéigh#ine gei_l/2 DARL (conéig-isifowieehpore mode crunk DARL (conéig-is)gowieehpore ceunke vian 20 ZERO (contig-is}fexie [sdisshie protocol vian in some ports which don’ © need protocol vian/ ZERLO(conéig if incerface get_W/S ZER10 (cone ig~ge! i) S)fvian protocel-map aisable ZERLO (cone ig-ges al S)Hexie ‘Confidential and Proprietary Information of ZTE CORPORATION 13 2xR20 5900/5200 Series User Manual (Ethernet Switching Volume) TIE Configuring VLAN Translation Step | Command Function 1 | zxnaoicontigygvlan translate session-no This configures VLAN ingress-port Translation ingress-vian egress-vlan 2 | zxp10(coneignshow vlan translate This views the configuration of VLAN Translation. 3 | zxp10(coneigngvlan egr-translate session-no This configures VLAN egress-port egr-translation: egress-vian ingress-vlan Example Port gei_1/1 receives a packet which belongs to vian100. This packet is to be sent to xgei_2/1. Port xgei_2/1 belongs to VLAN 200. As for the downlink data, users hope that VLAN 200 for- warded from xgei_2/1 is converted to VLAN 100. The detailed configuration is as follows: Configuration of switch: ZxRL0 (confighfvian exanslate session-ne 1 ingress-post gei_H/1 ingress~vian 100 egress-visn 200 ZERLO(confighfvian ege-teanslave sension=ne 1 egress-port gei_i/1 egeess-vian 200 ingress-vian 100 ZERLO(contighfineeztace ge M/t ZARLO(config-gei_1/1)#ingress filtering aisable ZxRLO (contig-geiil/ L)fawivenpore mode Bybrid ZXRL0 (config-geiil/ L)gawivenpere Aybria vian 100,200 ZxR10 (contig-geii/ L)Fexse ZARLO(confighfinteztace ges 2/1 2xR10 (contis-ge: ZxR10 (contig-ge: 2ARLO (contis-ge: L)swivckpoze mode hybrid L)gswivenpese hybrid vian 200 Ligerie Configuring SuperVLAN Step | Command Function 1 | zxnaoicontisyginterface {supervian | } 2 | zxpto(contig-vi ax yssupervian This adds sub-VLANs onto ‘SuperVLAN. 3 | zxnio(con¢isy¢supervian inter-subvlan-routing This enables/disables routing {enable|disable} function among sub-VLANs. 4 | exmuosshow supervian This views SuperVLAN configuration information Example As shown in Figure 5, configure a SuperVLAN on switch A, with its subnet as 10.1.1.0/24 and gateway as 10.1.1.1. Configure two 14 Confidential and Proprietary Information of ZTE CORPORATION TIER Chapter 1 VLAN Configuration sub-VLANs on switch 8, VLAN 2 and VLAN 3, and configure them to belong to the SuperVLAN. Switch A and switch B are connected through trunk ports. FIGURE 5 SUPERVLAN CONFIGURATION EXAMPLE Switeh A KF Saper Vian .L-L024 gei_1/10 gei_t/0 gei_/6 Vian2 Vian 3 Configuration of Switch A [screave 2 SupezVLAM, and assign subnet and gateway for it*/ ZeRi0_Alconfig)#ineerface supezvianl0 ZeRLO_A(contigrsupesvl ani0)#ip address 101.11 755.255. ZERLO_A(configesupezvl anl0)#ex ie [nda che SubULAT vo che SupesVLAN*/ geno d(centightvisn ZERLO_A(configrvian= )oupezvi an 10 Alcontig~vi ans )Bexie ‘A(contighfvian 2 ‘A(configrviand Baupervian 10 ITA cont igrvi an? )Bexie [sSee vian trunk poze) ZARLO_AlcontighBintertace gei_1/10 DERLO_Alcontigrges 1/ 10)fawiechpore mode czunk DERLO_A(configrges_l/ 10 }fawseekpore exunke Vian, ZERLO_A(configrges_i/ 1D}exse Configuration of Switch B ZeRL0_B(contighBincertace gei V2 ZERL0_B (configrges_i/ L)Bswiechpoze access vlan ZERO (contigeges_W/ 1)Bexie ZERLO_B (contighB interface gei_1/7 ZERL0_B (contigrges_i/2)Bawiechpost access vlan ‘eR10_B (contignges 2) Beste ZERLO_B (confighB interface gei_1/S DERLO_B (configrges_1/ S)Bswiechpoze access vian 2 DERLO_B (contigeges_W/ 5)Bexie ZERLO_B (confighB interface gei_W/E ZeR10_B(contigrges_1/ €)Bawiech access vian 2 ‘Confidential and Proprietary Information of ZTE CORPORATION 15 2XR40 5900/5200 Series User Manual (Ethernet Switching Volume) TIED ZARLO_B(contigrges_1/10)f.exse VLAN Maintenance and Diagnosis For convenient VLAN maintenance and diagnosis, ZxR10 5900/5200 provides the following commands: show vlan [brieflaccess|trunk|hybridlid [ifindex JIname [ifindex]] This command can be used to view information about all VLANs, VLAN with specified ID/name, and VLANs with their ports made as Access/Trunk/Hybrid. The two examples are as follows 1. This example shows how to view the configuration inform ation of VLANs. ZXRLO|confighfshow vin TagPores ‘| Viao001 active 100002 1S00 0 gei_a/’ 49 Vimto0i0 ceive 100010 1500 9 geia/i-a gei_a/3-8 Soovaanoi20 aceive 100120 1500 0 ges a get aa seid geo " BiRIO (contig This example shows information of all the VLANs with their port mode as Trunk. TIRLD( config show vian tzunk TagPores 49 VLa0030 active 10000 1500 9 gei_a/2 ses 3 was = Biadtecins 16 Confidential and Proprietary Information of ZTE CORPORATION Chapter 2 SVLAN Configuration Table of Contents SVLAN OVELVIOW wssossssssssssseecesussssceentsnensssseestesvasseestssse 7 SVLAN Configuration ..s.cccsssscesssssssoseeessunssseseesnsvenseesesnne DT SVLAN Configuration Example vs.cs.sscssessssssesseesnesvonseesnsnee 8 SVLAN Maintenance and Diagn0Sis..c.ccscsucssssseessssvessceenin 21 SVLAN Overview The full name of SVLAN is selective VLAN. SVLAN is a kind of VLAN tunnel technology. It provides multi-point to multi-point VLAN transparent transportation service and simple Layer 2 VPN tunnel by means of adding a VLAN tag outside original 802.19 tag and getting rid of outside VLAN tag when the packet is transported to edge switch SVLAN has the function of providing SPVLAN tag according to traf fic, which is different from that ordinary QinQ adds SPVLAN tag based on ports. That is, in the same Customer port, according to difference between traffic carried CVLAN tags, provide corre= sponding SPVLAN tag based on user demands. VLAN can modify outer tag value according to inner tag, outer tag, or the combination of the former tages. Also it can control if downlink stream need to be redirected from uplink port to cus- tomer port, With SVLAN function, User can implement map from QOS to SPVLAN of CVLAN tag. SVLAN Configuration 1. To configure SVLAN, use the following command ‘Confidential and Proprietary Information of ETE CORPORATION 17 2xR20 5900/5200 Series User Manual (Ethernet Switching Volume) TIE Step | Command Function x 1 | zxnaoicontigygvlan ging session-no | This command configures customer-port uplink-port SVLAN. in-vlan {ovlan {|}{ priority < priority-id>]| untag 2 | zxp1o(coneigygvlan ging extend-session-no This command configures customer-port < interface-name VLAN. > uplink-port < interface-name >{in-vian |outer-vian | untag }Louter-vian }{ovlan { Priority < priority-id >| map JI helpvian }Lunredirect] Param ters Description: Parameter Description <1 -768> customer-port CUSTOMER port, which connects user uplink-port UPLINK port, which connects service provider in-vlan VID of CVLAN ovlan VID of SPVLAN Priority designate SPVLAN 802.1p priority <0~7> untag transparent transportation CVLAN TAG extend-session-no <1- 1000> untag Not carrying CVLAN or VID of CVLAN is 0. outer-vian ‘The packet has two layer tages before entering into customer port, it designates outer VID. map designate 802.1p priority in SPVLAN as 802.1 priority in CVLAN helpvian When transporting CVLAN TAG transparently, the needed auxiliary VLAN VID. When single tag transporting transparently, packet only carries CVLAN TAG when sended from UPLINK port. When double tags transporting transparently, auxiliary VLAN VID should be the same as outer one. The packet still has two layer tags sended from UPLINK port. unredirect ‘The downlink packet received from uplink port needn't redirect to customer port forcibly. To delete SVLAN configuration, use the following command. 418 Confidential and Proprietary Information of ‘CORPORATION TIER ‘chapter 2 SVLAN Configuration Step| Command Function 1 | axr1o(contigy#no vlan ging session-no | This deletes SVLAN configuration 2 | zxp10(coneigy#no vlan ging extend-session-no This deletes SVLAN {lall} configuration Param ters Description: Parameter Description session-no <1 - 768> extend-session-no <1- 1000> SVLAN Configuration Example Basic SVLAN Configuration Example 1: Port 1 is a customer port, and port 2 is an uplink port. When CVLAN is 10, 12 and untag, the packet from porti SPVLAN is 997,998 and 999 respectively. 2xR10(con€ighfewitchport gei_l/1 qing customer ZER10 (contig hf ince tace get DERL0 (contig-isiowivehpore mode hybrid ZERL0 (conéig-islfowivenpore Rybrid vlan $87 tag DARL (conéig-is}fowieehpore hybrid vlan $68 tag 2XRL0 (conf ig-if)fawivehpore hybrid vian S85 Cag ZERO (coneig-is}gex ie ZERLO (conéighfvian ging extend-sersion-no 1 customer-port gei_i/2 pl ink-pozt gei_i/? invvian 10 ovian 997 BERLO(contig)fvian ging extend-session-no 2 customer-port gei_i/2 pl ine-port gei_i/? invvian 1? ovian 990 BERLO(contig)fvian ging extend-session-no 2 customer-port gei_i/2 upline-pore gei_i/? wneag ovlan 65S ‘The SVLAN example of viewing configuration: DARIO (con€ighfshow vian ging exvend-seasion Session customer Uplink in Vian Curez-vian vlan Helpvlan 2 sei sei a/2 10 $87 seit 3 2 s88 a seit geil? eneag sss zeR10 (contig Example 2: Port 1 is a customer port, and port? is an uplink port. For the packet from portl: CVLAN is 10, outer tag is 100, new SPVLAN(modified outer tag) is 200; outer tag VID is 101, new SPVLAN(modified outer tag) is 201, downlink stream needn't redi- rection. 2xR10(con€ig)f vian qing extend-session-ne 1 custoner-port ‘Confidential and Proprietary Information of ZTE CORPORATION 13 2XR40 5900/5200 Series User Manual (Ethernet Switching Volume) TIED gei_A/d wplink-pore gei_i/? incvian 10 outer-vian 100 ovian 700 axElo(contighf vian ging extend-veasien-ne 2 cusvomer-port gei_l/2 The SVLAN example of viewing configuration: ZxRL0 (confighfshow vian ging extend-seasion Transparent Transmission SVLAN Configuration Example 1: single tag transparent transmission, port 1 is customer port. Port 2 is uplink port, for the message from port 1: when CVLAN is 10 transmitted transparently, helper vian is 100. 2XRL0 (confighfawitehport gei_i/1 qing customer ZARLO (confighfineestace ges i: ZARLO (config-ie}Bawicenpore mode hybrid ZXRLO (config-is}fawivehpore Aybrid vian 100 untag ZxRLO (contig—ie}Bexie 2 DERLO(contig)Bvian ging extend-session-no 1 customes-port gei_l/2 wplink-pose gei_i/? sn~wlan 10 helpvian 100 The SVLAN example of viewing configuration is as follows ZxRL0 (confighfshow vian ging extend-session 1 z geia/2 geia/e 10 00 Example 2: double tags transparent transmission, port 1 is cus- tomer port, port 2 is uplink port, for the message from port 1: when CVLAN is 10 and outer tag is 100, transmitted transparently, helper vian is 100. ZxR10 (confighfincestace gei_1/2 ZARLO (config-if}Bowicenpore mode hybrid ZxRLO(config-if)f swiechpost hybrid vian 100 cag. ZARLO(contig-ie}fexie 2 DERLO(contighBvian ging extend-sersion-no 1 customer-port gei_l/2 ‘wpl ink-pore gei_/2 invvlan 10 ouees~vian 100 helpvlan 100 The SVLAN example of viewing configuration is as follows ZxRL0 (confighfshow vian ging extend-session 1 2 gett geia/? 10 100 00 20. Confidential and Proprietary Information of ZTE CORPORATION TIER ‘chapter 2 SVLAN Configuration 802.1P Priority Configuration Example: port 1 is customer port, port 2 is uplink port. For the message from port 1: when CVLAN is 10 and SPVLAN is 100, SPVLAN priority is 5; when CVLAN is 12 and SPVLAN is 200, SPVLAN priority is CVLAN priority. 2xR10(con€ighfewitchport gei_l/1 qing customer ZER10 (contig hBincertace get_W/= DERL0 (contig-isiowivehpore mode hybrid ZxRL0 (conéig-it)fswicehpore hybrid vian 100 vag ZERLO (conéig-is}fowicehpore Rybria vlan 70 tag ZERO (coneig-is}gex ie ZERLO (conéighfvian ging extend-sersion-no 1 customer-port gei_1/2 ZERLO(conéighfvian ging extend-sersion-no 2 customer-port gei_1/2 ‘The SVLAN example of viewing configuration is as follows. ZARLO(conéighfshow vian ging extend-session 1 Session Castone: Upline In Vlan Outer-vian Ovlan Nelpvlan seta geia/? 20 seit seit at 200 ZERLO contig SVLAN Maintenance and Diagnosis For convenient SVLAN maintenance and diagnosis, ZXR10 5900/5200 provides the following commands: Step| Command Function 1 | sxe10(contigntshow vlan ging session-no This views one or all sessions ‘session id> configuration of SVLAN 2 | zxp0(contigntshow vlan ging extend-session-no | This views one or all extend-session configuration of SVLAN ‘Confidential and Proprietary Information of ETE CORPORATION 21 2XR40 5900/5200 Series User Manual (Ethernet Switching Volume) TIE This page is intentionally blank, 22 Confidential and Proprietary Information of ZTE CORPORATION Chapter 3 SVLAN COS Configuration Table of Contents SVLAN COS OVErVieWosscsesssseesssessssceeessnenssssetenesvasseeaninn 23 Configuring SVLAN COS.....sssccsssssssseesnisenseeseenissveneeesninn 23 SVLAN COS Configuration Example svscssssscsscssessecsscsseeenennns 24 SVLAN COS Maintenance and DiagnOsis.....c.csscssscsscsseeennnnn 24 SVLAN COS Overview In SVLAN QinQ mode, when receiving tagged data packet from user trunk port, uplink port reserves the original data packet tag and attaches service provider tag. This tag includes 2 bytes Eth- ernet type (0x8100) and 2 bytes priority and VID, in which priority field is 3bits and this field is COS, we call this as service type, ser- vice level. Or service priority. The function is to configure’ COS priority value Configuring SVLAN COS Step] Command Function 1] sxnsoccontigi#eos-session < session id >[eos0 | This configures SVLAN COS £0-7>\jleost <0-7>}cos2 <0-7>)[eos3 destionidel -e> <0-7>)j[cosd <0-7>}[e0s5 <0-7>}[cos6 £0-7>i[e087 <0-7>] This configures a cos one time or many coses, 2 | sxntocconeisisinterface This enters interface configuration mode. 3] sxnaoicontig-sei_a/=y#cos-mode cos-map-session | This applies session session id corresponding cos to physical interface 4 | sxmoccontigiano cos-session This deletes SVLAN COS configuration 5 | sxnsoccontig-sei_a/=)8no cos-mode cos-map-ses _| This deletes the binding of sion session on physical port. ‘Confidential and Proprietary Information of ETE CORPORATION 23 2XR40 5900/5200 Series User Manual (Ethernet Switching Volume) TIED O note: Each physical port can only apply one session. The new configura- tion will replaces the old one. For example, configure the following two commands on gei_1/1 interface configuration mode: 1, cos-mode cos-map-session 1 2. cos-mode cos-map-session 2 Here only 2 takes effect. SVLAN COS Configuration Example For example, assume that on port gei_1/1, configure cos0 prior- ity map is 7, cosi priority map is 6, cos2 priority map is 5, cos3 priority map is 4, cos4 priority map is 3, CosS priority map is 2, c0s6 priority map is 1, cos7 priority map is 7; on port gei_1/2, configure cosi priority map is Usconsiguee cos seasion*/ ZARLO(confighf cos-sension 1 cox0 7 cost € ce: ZERLO(confighficos-seszion 2 cos 5 [sapply cos session on physical pore*/ ZARLO (contighfineestace ged L/L ZXRLO(config-get_1/ 1)fcos-nade cosmmap~seszion 1 2xR10 (config-geii/ 1)Fexse ZXRL0 (confighfintexface gei_1/: ZXRLO (contig-get_1/7)#e05" ZxRL0 (contig-ge: SVLAN COS Maintenance and Diagnosis To perform SVLAN maintenance and diagnosis, ZXR10 5900/5200 provides the following commands to view all SVLAN session con= figuration information. 1. This views SVLAN COS one or all session configuration. show qos cos-session 2. This views if a physical port applies ACL. show ru iterface 24 Confidential and Proprietary Information of ZTE CORPORATION Chapter 4 ZESR and SVLAN Linkage Networking Configuration Table of Contents ZESR and SVLAN Linkage Networking OvervieW .....ssssseee25 Configuring ZESR and SVLAN Linkage Networking v.38 Configuration Example ..cssssee seicsesasneeens 2B ZESR and SVLAN Linkage Networking Overview ZESR and SVLAN linkage networking is applicable for multi-ring multi-domain network. SVLAN can switch ports quickly according to ring’s connectivity status when fault occurs on the node of ring. When configuring SVLAN, each configuration data only can des- ignate a customer port as an uplink port. Meanwhile, a group of in-vian and customer port only can configure a SVLAN data. Therefore itis necessary to configure vian attribute of another port same as that of uplink port for designating multiple uplink ports for SVLAN. Configure SVLAN and VLAN two different uplink ports, one is active and another is standby. But only one port can be active at one time, maintain only one logically connective route between any two nodes controlled by ZESR configuration. ‘Confidential and Proprietary Information of ETE CORPORATION 25 2XR40 5900/5200 Series User Manual (Ethernet Switching Volume) TIED Configuring ZESR and SVLAN Linkage Networking Configuring SVLAN 1. To configure SVLAN, refer to SVLAN configuration. To configure other uplink ports, refer to VLAN configuration. O vote: 1, When configuring SVLAN based on ACL, configure downlink data flow is not redirection. 2, The designated uplink port when configuring SVLAN is totally equivalent to the ordinary port that has the same VLAN at- tribute. The packet with double-layer tag will be broadcast in VLAN that outer tag designates. Example The example shows how to configure SVLAN. 2xRL0 (confighfvian ging extend-zexsion-ne 1 customer-pert ge+_1/1 uplink-pore ges_l/2 invvian 10 ovlan 100 unsedizece ZuRi0 (contighfineestace gei_l/t ZARLO(config-gei_1/ 1)fowiceRpore ging customer ZERLO | config-geiil/ L)gawivenpore mode Rybria BxRL0 (config-gei_d/ L)fawitehpere hybrid vian 10,100 weg ZxR10 (contig-geini/ L)Fexse ZXRL0 (config)fintextace ges 1/2 ZXRL0 (contig-ged 2xR10 (conéigged ZxR10 (contig-ged ZxR10 (contig-geiii/2)#exse ZxRL0 (confighfineextace ge 1/9 ZERLO(config-gei_1/2)fowiceRpore mode exunk ZXRLO | config-geiil/2)gawivenpore crunk native vian 100 ZXRL0 (contig-geiil/2)gowivenpore trune vlan 100 ZxRL0 (contig-geii/2)#exse ZARLO(confighfingeztace gei 1/4 ZXRLO (config-gei_1/ 4)gowiceRpore mode exunk ZXRLO (config-geiil/ 4)gawivenpore crunk native vian 100 ZXRL0 (contig-geiil/ 4)Sawivenpore txunie vlan 100 ZxRLO (contig-geiii/ 4)fexie 26 Confidential and Proprietary Information of ZTE CORPORATION TIE Chapter 4 ZESR and SVLAII Linkage Networking Configuration Configuring Port MAC Duplication Step| Command Function 1 | sxnso(contig-ges_a/x }¢mac-duplicate <0-4> This configures port MAC src-vlan dest-vian duplication. 2 | sxmso(contig-ges_i/x )#no mac-duplicate <0-4> This cancels port MAC duplication. O vote: Port is configured as customer port of SVLAN based on ACL. The learning L2 entry on port is vian id of inner tag , need to enable MAC duplication for customer port. CPU duplicates a L2 entry of outer tag vian id, downlink packet can get customer port informa- tion according to outer vian id L2 entry. Configuring Port LOOPBACK Configure uplink port of SVLAN based on ACL to implement loop- back. At this time ,the port doesn’t send packet. All packets are loopback on this port and forwarded to other ports in the same vian. In one vian, at least two ports should exist to send packets as SVLAN uplink port. Command Function 24R10(conéig-gei_1/x)#loopback {enable|disable} This configures port to implement loopback on the interface mode. O vote: When loopback enable is configured, port learning function will be closed automatically, whereas port learning function is opened au- tomatically when loopback disable is configured. Loopback port as uplink port of SVLAN only receives packet that SVLAN cus- tomer port redirects after adding tags and loopbacks to uplink port, which doesn’t receive packet forwarded by uplink port. Therefore it needn’t port learning function. If port learning function is not disabled, port learns L2 entry when loopbacking message, which causes L2 entry, set by MAC duplication function on customer port, to be coverd. ‘Confidential and Proprietary Information of ETE CORPORATION 27 2XR40 5900/5200 Series User Manual (Ethernet Switching Volume) TIED Configuring One-Way PVLAN To configure to forbid uplink port of SVLAN based on ACL to forward data to loopback port, use the following comm ands. Step | Command Function 1 | zxnio(con¢igygvlan private-map-unidirectional This configures one-way session-id source destination PVLAN source port and destination port, 2 | zxp10(coneigygno vlan private-map-unidirectional | This cancels one-way PVLAN session-id configuration 3 | zxp10(coneigyshow vlan private-map-unic irectio _| This displays the configuration information of one-way PVLAN, Example O vote: 1. Uplink data packet is forwarded by customer port and broad- cast in SPVLAN after looped by loopback port, To prevent cus- tomer port from receiving data message looped by loopback port, generally, configure a one-way PVLAN data whose source port is loopback port and destination port is customer port. Downlink data packet is forwarded directly to customer port information by uplink port, needn't be forwarded to loopback port. To avoid that the data packet that uplink port forwards to loopback port loops and is forwarded to uplink port again, must configure a one-way PVLAN data whose source port is uplink port and destination port is loopback port This example shows how to configure one-way PVLAN ZxRL0 (confighfivian privave-map-wiidizectional sessionnid 1 source gei i/2-4 dest inacion gei_l/= ZERLO(consighfvian privavermap-tnidizectional session-id 2 source geii/= destination gei_/L Configuring ZESR Refer to ZESR related chapter. Configuration Example 1. Configure gei_1/1 as customer port on the switch, the CVID which receives data packet is VLAN 10, configure gei_1/3/ and gei_1/4 as uplink port, the SPVID which forwards data packet is VLAN 100, configure SVLAN based on ACL and configure 28. Confidential and Proprietary Information of ZTE CORPORATION TIER Chapter 4 ZESR and SVLAN Linkage Netw orking Configuration gei_1/2 as auxiliary loopback port. The detailed configuration is as follows BREAD (conEighfvian ging exvend-session“no 1 custones“port Sei_U/i wpline-pore gei_l/z in-vian 10 ovian 100 unsedizect Exaio(contight ineertace ge i BRIO contig-gei a bawiveRpoze ging customer DARIO contig-gei_W/ Lifawivenport mode hybsia BRAD coneig-gei_ Lifswivehpose hybrid native vlan 10 2xR10(contig-geina/ 1)Sswivehpeze hybrid vian 10/100 uneag BARA (contig-gesd/ 1)Bexse DARIO contigh#ingextace ge V/2 DIR contig-gei_a/ 2)fawicchport mode sunk BRAD coneig-gei_/ 2)gswivenpose vewk navive vlan 100 BARD coneig-gei_i/ 2)fawivehpost crunk vlan 100 BARAO contig-ges i 2)Bexse DARIO contigh#ingextace ge_V/2 DRL (contig-gei_/ 2)fawicchpost mode txtnk BRAD coneig-gei_/ a)gavivehpose vewk navive vlan 100 BARD (coneig-gei_i/ 2)fawivehpost crunk vlan 100 BERD contig-ges i! 2)Bexse DARIO contigh#indectace gei_V/4 DIR contig-gei_/ 4)fawicchport mode sunk BRAD coneig-gei_/ a)gawivehpose vewk navive vlan 100 BARD coneig-geili/ a)fawivehpost crunk vlan 100 BARAO contig~gesd/ Borie DARIO (contigh# interface gei_/1 DERLO(con€ig-gei_A/ L)fmac-aupl icave 0 szc-vian 10 dest-vian 100 BARA (contig~ges i 1)Bexse BERD (contigh#indectace ges_W/ ZRRID(con€ig-gei al 2)#loaphick enable ZARAO contig-ges i 2)Bexte 2xR10(conéig)fvian privace-map-unidizectional sessionmid 2 source gei_i/2-4 destination geil? 2xR10(conéTg)fvi an privace-map-wnidizectional session-id 2 source gei_i/? desvinavion geil Configure gei_1/1 as customer port on the switch, the CVID which receives data packet is VLAN 10, configure gei_1/3and gei_1/4 as uplink port, the SPVID which forwards data packet is VLAN 100, configure SVLAN based on VLAN translation. The detailed configuration is as follows BIRD (conEighfvian ging sezsion-no 1 custones“port Gei_U/i wpline-pore gei_i/? in-vian 10 evian 100, Exaio(contight invertace ge BRIO contig-gei a bawiveRpoze ging customer DARIO contig-gei_W/ Lifawivenport mode hybsia BRAD coneig-gei_ Lifswivehpose hybrid native vlan 10 2xR10(contig-geina/ 1)Sswivehpeze hybrid vian 10/100 uneag ZARA contig-gei i 1)Bexse DARD (contigh# indextace gei_/2 BRAD coneig-gei a 2)dawicchport mode tsunk BRAD coneig-gei_/ a)gavivehpose vewk navive vian 100 BARD (coneig-gei_i/ 2)fawivehpost crunk vlan 100 ZARA contig-gei i 2)Bexse DARIO (contigh# interface gei_/4 BRAD coneig-gei a 4)dawicchpore mode txunk BRAD coneig-gei_/ a)gawivehpose vewk navive vlan 100 BARD coneig-geili/ a)fawivehpost crunk vlan 100 BARD contig-gei ld Berio ‘Confidential and Proprietary Information of ZTE CORPORATION 23 2XR40 5900/5200 Series User Manual (Ethernet Switching Volume) TIE This page is intentionally blank, 30 Confidential and Proprietary Information of ZTE CORPORATION Chapter 5 MAC Address Table Configuration Table of Contents Introduction to MAC Address ....cssssesscssuesssssetenesvesseeein SL Configuring MAC Address Table.......... Seocinsenneeennsoneee 33 MAC Addréss Table Configuration Example ....c.sccsens.cese ieee. 38 Introduction to MAC Address MAC Media Access Control address is the hardware identification of a network device. The switch forwards packets based on MAC address. MAC address is unique, ensuring accurate packet for- warding. Each switch maintains a MAC address table called forwarding database (FDB). FDB records one-to-one mapping relationship between MAC addresses and switch ports. When receiving a data frame, the switch decides whether to drop it or forward it to the proper port based on this table. The FDB is the basis and prerequisite for fast forwarding Composition and Meaning of MAC Address Table A MAC address and a VLAN ID pair uniquely identify a MAC address table entry. ZXR10 5900/5200 MAC address table entry includes the following items 1, MAC address: such as 00D0.D056.95CA 2. Port No.: MAC address corresponding port such as gei_1/1, smartgroup1 3. VLAN ID: MAC address corresponding VLAN ID such as 10 4. Other marks: Indicate MAC address state and operation. ZXR10 5900/5200 MAC address table entry has the following marks: = stc: Whether the MAC address is a static one. = per: Whether the MAC address is permanent. ‘Confidential and Proprietary Information of ZTE CORPORATION 32 2XR40 5900/5200 Series User Manual (Ethernet Switching Volume) TIED = toS: Whether the MAC address is solid. = stF: Whether to drop frames from the source MAC address. = dsF: Whether to drop frames from the destination MAC ad= dress. = Time: the time of MAC address on the switch. Desiganated by day:hour:minute: second, During L2 forwarding, the switch checks its MAC address table for the destination MAC address of the received frame, and then for- ward data to the corresponding port. MAC Address Classification ZXR10 5900/5200 MAC address is divided into the following types: 1, Dynamic MAC address Dynamic MAC addresses are learned by the switch from data frames it receives, and are deleted when the aging time is due. When the device connects to another port on the switch, the corresponding mapping relationship between the MAC addtess and port number also changes in the MAC address table, Dy- namic MAC addresses are lost when the switch is powered off and must be learned again when the switch is rebooted. Static MAC address Static MAC addresses are configured manually and will never age. The mapping relationship between MAC address and port number in the MAC address table remains unchanged despite of changes of the connecting port between switch and device Static MAC addresses are also lost when the switch is powered off and must be configured again when the switch is rebooted, 3. Permanent MAC address Permanent MAC addresses are also configured manually, The mapping relationship between MAC address and port number in the MAC address table remains unchanged despite of changes of the connecting port between switch and device. Permanent MAC addresses will not disappear when the switch is powered off. MAC Address Table Establishment and Deletion ‘The MAC address table of a switch is null initially. Itis created for fast forwarding. As the size of the MAC address table is limited and network device changes are frequent, invalid MAC address table entries should be deleted from the switch in time. 1, Dynamic Learning 2 ‘Confidential and Proprietary Information of ZTE CORPORATION TIER Chapter 5 MAC Address Table Configuration Dynamic MAC addresses in the MAC address table are learned by the switch. The procedure of switch learning MAC address is as follows ‘Switch analyzes the source MAC address and VLANID (for ex- ample, MAC1#VID 1) once it receives a data frame on a port. Ifjudging the MAC address to be valid and learnable, the switch checks MAC1+VID1 in its MAC address table. If the entry is not found, the address is added to the MAC address table, other- wise the entry is updated O nore: i, MAC address learning is to learn the source MAC address of received data frames, not the destination MAC address. ji, MAC address learning applies to unicast addresses only, not to broadcast or multicast addresses: MAC Address Aging The size of the MAC address table is limited, so a MAC address aging mechanism is provided for effective resource utility of the MAC address table. ‘A switch considers a device that has got offline or is not in communication when it fails to receive any data frame from that device for a certain time period (set aging time), that is, it does not receive any data frame from its source MAC address as that of device's MAC address. Then the switch deletes that MAC address of the device from its MAC address table and updates the MAC address table, MAC address aging applies to dynamic MAC addresses only. Manual Addition and Deletion An entry can be added to the MAC address table of a switch with a configuration comm and when the network is relatively stable and device is connected to a fixed switch port. Configuration can take place for dynamic, static or permanent MAC address. Configuring static or permanent MAC addresses can prevent MAC spoofing attacks. MAC address can be deleted with the MAC address deletion command. Deleting command of ZxR10 5900/5200 can forcibly delete a dynamically learned MAC address Configuring MAC Address Table MAC address table of switch can run normally with the default con- figuration. But some appropriate configuration on MAC address table can improve the network stability. ‘Confidential and Proprietary Information of ZTE CORPORATION 3 2XR40 5900/5200 Series User Manual (Ethernet Switching Volume) TIED ‘The configuration of MAC address table includes the following con- tents. Setting MAC Address Aging Time MAC address aging time influences the switch’s performance, A shorter aging time may make the switch delete useful MAC ad= dress table entries, As a result, it broadcasts many packets it loses track to their destination MAC addresses, which consumes the bandwidth, ‘A longer aging time may lead to too many useless entries in the MAC address table, which use up the MAC address table resources New MAC addresses cannot be added to the MAC address table, so forwarding performance also reduces To set MAC Address Aging Time, use the following command. Command Function 2xn10(conéig)# mac aging-time

Anda mungkin juga menyukai