< Home

Configuring a Control VLAN

Context

In a SEP segment, a control VLAN is used to transmit SEP packets but not service packets, enhancing SEP security. Each SEP segment must be configured with a control VLAN. After being added to a SEP segment configured with a control VLAN, an interface is added to the control VLAN automatically.

On a SEP network that has no-neighbor edge interfaces, a device that is not in a SEP segment cannot be added to the control VLAN of the SEP segment. Otherwise, a loop will occur on the network.

Procedure

  1. Run system-view

    The system view is displayed.

  2. Run sep segment segment-id

    A SEP segment is created and the view of the SEP segment is displayed.

  3. Run control-vlan vlan-id

    A control VLAN is configured for the SEP segment to transmit SEP packets.

    The control VLAN must be not created, and is not used by RRPP, dynamic instances of VBST, VLAN mapping, and VLAN stacking. Additionally, no interface is added to the control VLAN in trunk, access, hybrid, or qinq mode.

    • Different SEP segments can use the same control VLAN.

    • If an interface has been added to the SEP segment, the control VLAN of the SEP segment cannot be deleted directly. To delete the control VLAN, run the undo sep segment segment-id command in the interface view to delete the interface from the SEP segment, and then run the undo control-vlan command in the SEP segment view to delete the control VLAN.

    • If no interface is added to the SEP segment, you can run the control-vlan vlan-id command multiple times. Only the latest configuration takes effect.

    • After the control VLAN is created successfully, the command used to create a common VLAN will be displayed in the configuration file.

      Each SEP segment must be configured with a control VLAN. After an interface is added to a SEP segment configured with a control VLAN, the interface will be automatically added to the control VLAN.

      • If the interface type is trunk, in the configuration file, the port trunk allow-pass vlan command is displayed in the view of the interface added to the SEP segment.
      • If the interface type is hybrid, in the configuration file, the port hybrid tagged vlan command is displayed in the view of the interface added to the SEP segment.

Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
< Previous topic Next topic >