cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2729
Views
10
Helpful
9
Replies

VLAN Tag removal on SG300.

shane.calnan
Level 1
Level 1

Hi all, tried searching but am unable to find an answer specific to my issue.

I'm testing some equipment at the moment, the basic setup is tester software on laptop connecting through the on-board ethernet NIC to our DUT. Some data needs to pass through our DUT and reach a second device. Tagged data flows from the laptop to the DUT. I have two SG300-10 switches available to me.

These tests require test data to be S-Tagged only; 802.1ad 0x88A8 Ethertype with my choice of VID (100). There is no C-Tag (0x8100), unusual I know! However my second device can't handle VLANs, so I need to remove the tag.

Previous test required C-Tagged data only, and I was able to remove the tags easily enough by connecting the DUT to the switch port 10, second device to port 9, and with port 10 set to bridge interface and a tagged member of VLAN 100, and port 10 an access interface on VLAN 100.

I've tried various combinations of setting port 10 to customer/general/trunk interfaces but have been unable to remove the tags coming out of port 9. I've been able to capture the desired frames on port 9 all right, but they are of course tagged. I am working on the presumption that the SG300 can remove S-Tags on egress.

The device at port 9 only needs to respond to ARP requests with a specific MAC address and reply on the same VLAN, which the switch would have to add to the ARP response. I don't know if this is possible but maybe I could replace this device with the second switch if it would respond to ARPs on a S-Tag only VLAN.

I'd appreciate any pointers that anybody has!

2 Accepted Solutions

Accepted Solutions

An access port on the SG300 facing the tagged port from the remote site should accomplish this. Usually tag manipulation always happens on ingress.

View solution in original post

Yes. Whatever the switch does on ingress it will also explicitly do the reverse on egress by default when it comes to tag manipulation.

View solution in original post

9 Replies 9

Aleksandra Dargiel
Cisco Employee
Cisco Employee

Hi Shane,

It is not clear if you have tried QinQ settings page 226:

http://www.cisco.com/c/dam/en/us/td/docs/switches/lan/csbms/sf30x_sg30x/administration_guide/Cisco_300Sx_v1_4_AG.pdf

Regards,

Aleksandra

Hi Aleksandra,

Thank you for your response. I've tried using QinQ settings by putting the device in QinQ mode by configuring port 10 as a customer interface. I then assigned port 9 as an access port (untagged by default) on the same VLAN (100), but the port doesn't remove the S-Tag that enters at port 10. As the page you suggested says, this tag is later removed by an egress device. I suppose I need this switch, or possibly my second one, to function as that egress device.

Best regards,

Shane

Hi Shane,

I have not tested myself but as far as I have seen similar setup:

Usually the user will have the same configuration on a switch at the other site, where the reverse will happen, and the outside tag will be taken off again.

which confirms you thinking.

Aleksandra

Yes that's exactly what I want. I suppose I effectively want to emulate a remote site with QinQ tagged data arriving and the service level tag removed before being switched to other devices.

An access port on the SG300 facing the tagged port from the remote site should accomplish this. Usually tag manipulation always happens on ingress.

In this case would the switch be smart enough to tag data going back out on that port, on egress? I presume either this happens or I would apply a tag to the second device port.

I'm unable to test this at the moment due to licencing issues with our tester software, but I'll come back when I've got it sorted. Thanks to everyone for their help!

Yes. Whatever the switch does on ingress it will also explicitly do the reverse on egress by default when it comes to tag manipulation.

What happens if you configure port 10 as an access port for vlan 100 and port 9 as an access port for VLAN 100? I'm assuming you are wanting to pop the customer tag being generated by the tester device, right?

I never thought about popping the tag off on ingress, that sounds very hopeful! I'll give that a go and report back.