You can configure interface-based bridge protocol data unit (BPDU) tunneling based on the different roles of provider edges (PEs) and customer edges (CEs) or on the same role of PEs and CEs. After the configuration is complete, when an interface of a PE receives a BPDU from a user network, the PE adds a VLAN tag to the BPDU based on the PVID of the interface, selects a BPDU tunnel based on the VLAN ID in the tag, and transmits the BPDU through the BPDU tunnel. In this manner, BPDUs from different user networks are isolated.
You can configure interface-based BPDU tunneling based on the different roles of PEs and CEs or on the same role of PEs and CEs.
Different roles of PEs and CEs: CEs are customers, and PEs are providers.
Same role of PEs and CEs: CEs and PEs are both customers.
If PEs and CEs are configured with different roles, the PEs can transparently transmit BPDUs sent by the CEs. In this case, you do not need to enable BPDU tunneling on the interfaces of the PEs.
If PEs and CEs have the same role, the PEs cannot transparently transmit BPDUs sent by the CEs. In this case, you need to enable BPDU tunneling on the PE interfaces.