Unsolved
3 Posts
0
119
How to tunnel all traffic from one port to another except management VLAN
I'm trying to configure an N2048 with what is probably an unusual use case and am having trouble getting exactly what I need. What I'd like to do is take all traffic (tagged or untagged) received at port A and send it out port X, except for management traffic, which is configured for VLAN 100, which should go to port Y.
I've come up with a few configurations that have almost worked, but not quite.
Configuration 1:
I started out trying to use "switchport trunk native." This mostly works. But I found that frames tagged with a CVLAN are not received at port X.
Configuration 2:
I then tried "switchport mode dot1q-tunnel." This resolves the CVLAN limitation and correctly forwards all traffic to port X, but I can't figure out a way to get the management traffic to port Y.
Configuration 3:
I went back to experimenting with trunk mode and figured out that I can get the CVLAN traffic to pass if I change the dot1q ethertype to something nonstandard, but then that once again breaks the VLAN100 management traffic. Possibly because that traffic is now also using the configured nonstandard ethertype?
Is there any way to have one configuration that doesn't have either of these limitations?
DELL-Young E
Moderator
Moderator
•
3.9K Posts
0
October 26th, 2023 04:58
Hello thanks for choosing Dell.
https://dell.to/471BqVp
This can help configure with general port concepts to share traffic between two Vlans without management traffic.
example configuration:
Respectfully,
(edited)
BuyMeAPetMonkey
3 Posts
0
October 26th, 2023 21:36
Thank you for this suggestion, but it seems to have the same problem as my "configuration 1" attempt. It drops frames tagged with a CVLAN (in other words, ethertype 0x8100). I need both SVLANs and CVLANs to work (0x8100 and 0x88a8). Below is the relevant parts of my config based on your suggestion:
interface Gi1/0/35 (This is "Port A")
switchport mode general
switchport general pvid 635
switchport general ingress-filtering disable
switchport general allowed vlan add 635
switchport general allowed vlan add 100 tagged
no lldp transmit
no lldp receive
no lldp med
exit
!
interface Gi1/0/47 (This is "Port Y" where management goes)
spanning-tree disable
switchport mode general
switchport general pvid 100
switchport general allowed vlan add 100
no lldp transmit
no lldp receive
no lldp med
exit
!
interface Te1/0/1 (This is "Port X" where everything besides VLAN 100 should go (tagged or untagged)
switchport mode general
switchport general allowed vlan add 635
switchport general allowed vlan remove 1
no lldp transmit
no lldp receive
no lldp med
exit
!
BuyMeAPetMonkey
3 Posts
0
October 27th, 2023 23:24
I have read that, but it unfortunately doesn't have the answers I'm looking for, as far as I can tell. There's no mention of ethertypes in that document at all.
I did think of another potential solution, but then I realized it won't work either. It actually would have worked for the problem as I presented it above, but I had simplified the scenario a bit. To help further explain, here's an image:
DELL-Young E
Moderator
Moderator
•
3.9K Posts
0
October 29th, 2023 22:53
https://dell.to/3QCsq3O
Page# 897
Actually I think you’d like to configure QinQ or double VLAN in your environment.
I advise upgrading firmware 6.7.x.x on the switch.
if possible you can raise an official ticket so that the team can check out your switch logs from for analysis.
Respectfully,