Cisco Systems understanding native VLAN

Bookmark this page:  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
understanding native VLAN spork.sporkman 09-23-05
Posted by on September 23, 2005, 10:10 pm
Please log in for more thread options
Hi all,

Before I approach our carrier with this, I want to make sure I've got
everything straight here...

The scenario is as follows. We have a 100Mb FE link to ConEdison
Communications in NYC. This is what they call a "hubbed" connection
(carryover from telco ds3 "hubbing" I guess). In this case it means
that on that connection we can order multiple metro ethernet circuits
to other locations and have them all appear as distinct VLANs. Pretty
straightforward, right? Our "hub" connection should send/receive
tagged ethernet frames. ConEd specifies what VLAN ID each remote
ethernet circuit will have.

So we brought up our first circuit (to our office). This circuit is
untagged. They told me it would appear on the other end as VLAN 3264.
So I put something similar to this in the router at the "hub" end:

in fa5/0
no ip address
duplex full

in fa5/0.3264
encapsulation dot1Q 3264
ip address 10.0.0.1 255.255.255.252

Then put my laptop at 10.0.0.2/30 and tried pinging 10.0.0.1. Link on
both sides was up. No ping response, no arp entries on the router.

After some head-scratching I added "native" to the subinterface above
and everything worked.

After reading a bit in the archives here, it sounds like I do need a
native vlan, no matter whether I want one or not. But the fact that it
works with the "native" tag really isn't making sense to me. If ConEd
is expecting tagged packets (with ID 3264) on their side of the 100Mb
connection and is adding tags on the other end (with ID 3264) why would
this work?

Of course now we're up and running on the link, so I'm a little
hesitant to add a "dummy" subinterface/vlan at the 100Mb end, make it
native and then remove the "native" directive from subif 3264.

Any ideas? I'm thinking that perhaps our order got screwed up and our
100Mb end is not really vlan-enabled. But I'm also a bit stumped on
what exactly happens with a config such as I've posted above. Am I
actually sending ANY tagged frames? If tagged frames come in, would I
see them?

Thanks,

Charles


Posted by Erik Tamminga on September 24, 2005, 4:21 am
Please log in for more thread options
Hi Charles,

Using only a native vlan is like using no trunking/tagging at all. You can
put the ip address on the physical interface and things would work as well.
What I think they did is configure a trunk on their side of the remote end
and issue vlan 3264 as their first and native vlan. Adding a second
"circuit" to the already existing hub connection now only means adding a
second sub-interface. This is when they actually start tagging frames.
If tagged frames do come in (with unknown tags, for unknown subinterfaces),
I guess you'll see them as input errors on your interface.
If they promised a 802.1q trunk I would leave the config as you have it
right now. It's a correct configuration and allows for easy additions of new
vlans.

Erik

> Hi all,
>
> Before I approach our carrier with this, I want to make sure I've got
> everything straight here...
>
> The scenario is as follows. We have a 100Mb FE link to ConEdison
> Communications in NYC. This is what they call a "hubbed" connection
> (carryover from telco ds3 "hubbing" I guess). In this case it means
> that on that connection we can order multiple metro ethernet circuits
> to other locations and have them all appear as distinct VLANs. Pretty
> straightforward, right? Our "hub" connection should send/receive
> tagged ethernet frames. ConEd specifies what VLAN ID each remote
> ethernet circuit will have.
>
> So we brought up our first circuit (to our office). This circuit is
> untagged. They told me it would appear on the other end as VLAN 3264.
> So I put something similar to this in the router at the "hub" end:
>
> in fa5/0
> no ip address
> duplex full
>
> in fa5/0.3264
> encapsulation dot1Q 3264
> ip address 10.0.0.1 255.255.255.252
>
> Then put my laptop at 10.0.0.2/30 and tried pinging 10.0.0.1. Link on
> both sides was up. No ping response, no arp entries on the router.
>
> After some head-scratching I added "native" to the subinterface above
> and everything worked.
>
> After reading a bit in the archives here, it sounds like I do need a
> native vlan, no matter whether I want one or not. But the fact that it
> works with the "native" tag really isn't making sense to me. If ConEd
> is expecting tagged packets (with ID 3264) on their side of the 100Mb
> connection and is adding tags on the other end (with ID 3264) why would
> this work?
>
> Of course now we're up and running on the link, so I'm a little
> hesitant to add a "dummy" subinterface/vlan at the 100Mb end, make it
> native and then remove the "native" directive from subif 3264.
>
> Any ideas? I'm thinking that perhaps our order got screwed up and our
> 100Mb end is not really vlan-enabled. But I'm also a bit stumped on
> what exactly happens with a config such as I've posted above. Am I
> actually sending ANY tagged frames? If tagged frames come in, would I
> see them?
>
> Thanks,
>
> Charles
>



Posted by on September 25, 2005, 12:30 am
Please log in for more thread options
Excellent, thanks. I wish I had a better idea of how things work on
their side. It seems fairly simple - they have about 6 buildings per
ring with a tiny little Cisco 35xx in each building. They pull the
fiber to the switch in each building and the GigE (or 10GigE?) loop
actually goes into then out of each switch. But I'm not sure what gear
they use to aggregate everything. They do allow me to get a vlan out
to any port in any building, so I guess we'll just see what happens
when the next vlan gets turned up.


Similar ThreadsPosted
understanding native VLAN September 23, 2005, 10:10 pm
Native, and management vlan "Vlan 1" September 21, 2005, 2:50 pm
VLAN Project and Native VLAN July 13, 2007, 5:06 am
Native VLAN February 8, 2007, 9:40 pm
native vlan December 18, 2008, 6:45 am
Native VLAN Warning August 23, 2005, 8:24 am
Native VLAN question November 22, 2005, 5:58 am
native vlan question April 15, 2008, 3:51 am
native vlan for mgmt July 18, 2009, 9:20 pm
Change native VLAN on ASA 5520 July 5, 2007, 6:17 am
Native Vlan Mismatch error January 20, 2008, 2:09 am
change native vlan globaly on 3560 January 5, 2007, 2:08 pm
Native VLAN mismatch on Cisco 2950 August 9, 2007, 6:30 pm
Changing native vlan on access port August 12, 2009, 6:53 pm
Native Vlan Cisco 1200 Access Point March 11, 2006, 7:50 pm
Residential Cabling Guide

Home Cabling Guide

Finally, an instantly downloadable book that saves you thousands in home improvement dollars! Enjoy living in 21st century technology-advanced home while increasing its selling value and competitive advantage on the real estate market. Whether your cabling is for home office or high-tech leisure, you can wire your home yourself or learn "wirish" to speak with your cabling contractors in their language!

Learn More