Escolar Documentos
Profissional Documentos
Cultura Documentos
Course outline
to 7302-7360 ISAM
1. Welcome
Technologies
1.
L2 High
Technology
R4.6
Cap. NT/5520 AMS - L2 & PPPoX forwarding
2. Layers Intro
2. 1.
NETechnologies
Operation
1. ISAM 1.asL2aTechnology
L2/iBridge
2. Layers Intro
2. IHUB L2 Forwarding
2. NE Operation
3. Intelligent
Brigding IACM
1. ISAM as a L2/iBridge
4. Enhanced
2. IHUBIntelligent
L2 ForwardingBridging
5. VMAC3. Intelligent Brigding IACM
4. Enhanced
Intelligent
Bridging
6. PPPoX
Handling
in ISAM
7. ISAM 5.asVMAC
a L2-CC
6. PPPoX Handling in ISAM
8. Cross Connect IACM
7. ISAM as a L2-CC
3. Maintenace
8. Cross Connect IACM
1.
IHUB
Mirroring
3. Maintenace
1. IHUB Mirroring
3
@@PRODUCT
@@COURSENAME
Course objectives
Upon
completion
of this course, you should be able to:
7302-7360
ISAM
R4.6 High
Cap.
- L2 & PPPoX
forwarding
Explain
Ethernet
as NT/5520
a technologyAMS
and elements
of ethernet
frames
Understand VLANs (virtual local area network) and how they are supported by the
Ethernet.
Upon completion of this course, you should be able to:
Explain different ways to establish IP connectivity to access the Internet,
Give an overview of the different forwarding modes that are available,
Describe
Explain Ethernet
and Configure
as a technology
a L2 service
and elements
onto theofISAM
ethernet
& interconnect
frames
of end users to the
respective
L2
service
for
Residential
Bridge
and
the
different,Cross
Connect
modes
Understand VLANs (virtual local area network) and how they are supported
by the Ethernet.
Associate an RB or XC VLAN to a bridge port,
Explain and
different
ways
to establish
IP connectivity
to access the Internet,
Explain
enable
virtual
MAC addresses
implementation,
Describe
Give an overview
Enhanced
of the
Intelligent
differentBridging
forwarding
and
modes
explain
thathow
are available,
it differs from plain Layer 2
forwarding,
Describe and Configure a L2 service onto the ISAM & interconnect of end users to the respective L2
Retrieve
Enhanced
Intelligent
data from Connect
the ISAM,
service for
Residential
Bridge andBridging
the different,Cross
modes
Configure Enhanced Intelligent Bridging on the ISAM with AMS and CLI,
Associatethe
an RB
or XC VLAN
to afor
bridge
Describe
different
models
PPPport,
handling in the ISAM,
Describe
and
configure
mirroring
Explain and enable virtual MAC addresses implementation,
Describe Enhanced Intelligent Bridging and explain how it differs from plain Layer 2 forwarding,
Retrieve Enhanced Intelligent Bridging data from the ISAM,
Configure Enhanced Intelligent Bridging on the ISAM with AMS and CLI,
Describe the different models for PPP handling in the ISAM,
4
@@PRODUCT
@@COURSENAME
Section 2
NE Operation
Module 1
ISAM as a L2/iBridge
TAC42050-HO03 Edition I2.0
7302-7360 ISAM
R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
TAC42051_V1.1-SG Edition 2.0
211
NE Operation ISAM as a L2/iBridge
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
Module objectives
After attending this session, you will be able to:
Describe the forwarding mode intelligent Bridging (Residential
Bridge VLAN)
213
NE Operation ISAM as a L2/iBridge
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
Table of Contents
1 Introduction
2 Intro
Standard Bridging
1 Introduction
1.1 General Overview
3 Intelligent
Bridging
1.2 Intelligent Bridging overview
4 Intelligent
Bridging
2 Intro Standard
Bridging types
2.1 Standard bridging concept
5 Intelligent
Bridging
2.2 Security/scalability
issue(MPLS)
with standard bridging
2.3 Standard bridging: Issues
3 Intelligent Bridging
3.1 The intelligent bridging model
3.2 Intelligent Bridging: shared VLAN per protocol
3.3 Intelligent Bridging: Shared VLAN service
3.4 Intelligent Bridging: VLAN association
3.5 Intelligent bridging: network issues
3.6 Broadcast messages & flooding US
3.7 Broadcast messages & flooding DS
3.8 Secure MAC address learning
3.9 Duplicate MAC-address learning
3.10 Intelligent Bridging, things to consider
3.11 Intelligent Bridge: Summary
4 Intelligent Bridging types
4.1 I-Brigde Modes
4.2 Summary: Intelligent Bridge mode
5 Intelligent Bridging (MPLS)
5.1 Unified forwarding model for Access + Aggregation
215
ALL RIGHTS RESERVED.
5.2 MPLS
Applications - Virtual PrivateCOPYRIGHT
LAN ALCATEL-LUCENT
Service2013.
(VPLS)
NE Operation
ISAM as a L2/iBridge
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
Page
7
8
9
10
11
12
13
14
15
18
19
20
21
22
23
24
25
26
28
29
30
31
32
33
34
7
10
14
29
32
1 Introduction
217
NE Operation ISAM as a L2/iBridge
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
1 Introduction
Anything
Eth - VLAN
L2
Anything
Eth (VLAN)
ATM/AAL
Phys layer
Anything
Eth (VLAN)
Phys layer
User
side
Eth-VLAN
Anything
Eth (VLAN)
GEM
Phys layer
layer 2 forwarding
CPE
Decision
Forwarding mode
Forwarding models
capable of handling
PPP traffic
L2
Forwarding models
capable of handling
DHCP traffic
218
NE Operation ISAM as a L2/iBridge
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
In case the 7302 ISAM performs L2 forwarding, it means that the internal forwarding is
basically done on layer 2 information. The layer 2 is Ethernet, including the concept of
VLANs.
In both layer 2 forwarding models (intelligent bridge as well as cross-connect), the ISAM
can accept tagged frames coming from a user. The operator can configure exactly which
tag is to be expected on the bridge port and frames carrying another tag will be discarded
(filter).
In case of VLAN translation, the user sends tags that are recognized, but only have a local
meaning and will immediately be translated into a network vlan.
In case of cross-connect, it is possible to have C-VLAN transparency (where only the SVLAN is configured in the ISAM). In that case, the user can send any C-VLAN. The ISAM
will not filter based on C-VLAN. See section on cross-connect.
1 Introduction
Aggregation Network
Internet
Access
Network
Video
VLAN
IP backbone
Network
Call
server
HSI
VLAN
73xx
Home Network
Switch
BTV
VLAN
Video
server
New
services
VoIP VLAN
IP Router
Ethernet switch
219
NE Operation ISAM as a L2/iBridge
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
Most customers require a VLAN per service between ISAM and EMAN, which is
Intelligent Bridging per service in ISAM.
2 1 10
NE Operation ISAM as a L2/iBridge
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
2 1 11
NE Operation ISAM as a L2/iBridge
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
BC or unknown MAC DA
Ethernet
BR
BRAS
BC or unknown MAC DA
CPE
DSLAM
CPE
CPE
DSLAM
2 1 12
NE Operation ISAM as a L2/iBridge
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
The issue on the slide occurs with standard Ethernet bridges. Operators using VPLS in the EMAN will not have this issue!
2 1 13
NE Operation ISAM as a L2/iBridge
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
Scalability:
Broadcast
storms
Broadcast frames are flooded over the entire aggregation network . This
generates an important amount of traffic, that can result in service degradation or
denial of service.
Security
Broadcast
Customer segregation
Customers
Undesirable & unstable behavior: user B gets traffic destined to user A and vice
versa.
PADI = PPPoE Active Discovery Initiation packet (which is broadcasted). This is the first
message in the initialization phase to establish a PPPoE session.
3 Intelligent Bridging
2 1 14
NE Operation ISAM as a L2/iBridge
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
3 Intelligent Bridging
protocol filtering
may lead to a frame being forwarded, sent to a host processor, discarded or
forwarded & sent to a host processor
2 1 15
NE Operation ISAM as a L2/iBridge
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
In a standard bridge all ports are treated equally. The special thing about Intelligent Bridging is that it makes
a distinction between network ports and user ports.
With Intelligent Bridging, frames received from a user will always be sent towards the network and never to
another user. All traffic received from a user interface is forwarded only on the uplink, and never to other
users. This protects a user's MAC-address from being exposed to other users; and also ensures that user's
traffic is passing through the IP edge point where it can be charged for.
Unicast
Broadcast
and multicast frames from a user are only forwarded to the interface towards the network and
3 Intelligent Bridging
2 1 16
NE Operation ISAM as a L2/iBridge
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
3 Intelligent Bridging
ISP1
IP
Login to ISP
or corporate
BRAS
E-MAN
Network
ISP2
E-MAN
Network
Corporate
Routing to the
correct ISP is done
based on user-id
and password in
the BRAS
Routing to the
correct ISP is
based on the
VLAN-id
2 1 17
NE Operation ISAM as a L2/iBridge
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
In case of Intelligent bridging multiple users are connected to the same VLAN, or in other
words we have aggregation at the DSLAM level within a VLAN.
In the figure at the left, we see multiple VLAN bridges supported in 1 DSLAM, which connect
to different Service Providers (SP) (wholesale). Each SP is connected to the DSLAM with a
specific VLAN-ID. The user ports are connected to the VLAN of their corresponding SP.
Multiple user ports can be associated to a single VLAN-ID.
The MAC address lookup is performed in the forwarding table of the respective VLAN. With
the principle that we have 1 VLAN ID per {IP-edge-DSLAM} pair means that in each Ethernet
switch the SP has its own forwarding table.
In the figure at the right we see that the routing to the correct SP is based on user-id and
password and that all the users are connected with the same VLAN-ID to the BRAS.
3 Intelligent Bridging
DHCP
Server
PVC per
user/EFM
IPoE
PPPoE
xxx 73xx ISAM
IPoE
IPoE
HSI PPPoE
HSI PPPoE
BTV
Switch
BTV
L2 service
Router
BRAS
IPoE
PPPoE
xxx
= PVID
2 1 18
NE Operation ISAM as a L2/iBridge
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
3 Intelligent Bridging
DHCP
Server
VoIP
VoIP
Video
Video
HSI
HSI
BTV
Router
Switch
BTV
73xx ISAM
2 1 19
NE Operation ISAM as a L2/iBridge
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
L2 service
BRAS
3 Intelligent Bridging
ISAM
Bridge Port
Network VLAN
Subscriber VLAN
VLAN 1 (HSIA)
Bridge 10
VLAN 5 (HSIA)
Bridge 11
VLAN 2 (Video)
Bridge 20
CPE
MCast
VLAN 6 (Video)
Bridge 21
VLAN 3 (Voice)
Bridge 40
2 1 20
There are many operators who base their network architecture on one PVC per service
when connecting ADSL subscribers. Once those operators start deploying VDSL, they
need to use the VLAN as a "PVC emulation".
The ISAM support the ability to emulate a multi-PVC configuration on an EFM interface
using the VLAN as a "PVC emulation", i.e. it is possible to associate a set of VLAN Ids at
the subscriber interface with a set of forwarding engines being chosen from the
following list:
VLAN-CC (Transparent or Protocol aware): In this case, the C-VLAN received at the
user side is either forwarded as a C-VLAN CC or encapsulated into an S-VLAN (VLAN
stacking).
i-Bridge: In this case, the VLAN received at the user side will be bridged into an ibridge identified by the same VLAN Id.
IP Routing
Additionally, in case of VLAN-CC or i-Bridge, we support VLAN translation to make
wholesaling possible without impacting the CPE configuration. Starting from a set of
pre-defined C-VLAN tags at the CPE side (i.e. the same for all CPEs), it is possible to
retag the received packet with a new C-VLAN (VLAN-CC or i-bridge) or a stacked VLAN
(VLAN-CC), so that the traffic can be passed to the VLAN associated with the
combination of service provider and service.
Copyright 2013 Alcatel-Lucent. All Rights Reserved.
TAC42050-HO03 Edition I2.0
3 Intelligent Bridging
BR
VLAN1
CPE
ISAM
IP edge
Ethernet
Problem:
If user A can obtain the MAC@ of
User C, since the Ethernet switch
learns all Mac @ , user to user
communication is possible
2 1 21
NE Operation ISAM as a L2/iBridge
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
ISAM
CPE
On the previous slides, we learned how user-to-user communication is avoided inside the
ISAM. But, it is also important to mention that a VLAN must be unique between an [IP-edgeISAM] pair in the Ethernet network to support the Intelligent Bridging feature. For example,
take the network configuration shown above, where 2 ISAMs with the same VLAN ID are
connected to the IP edge via the EMAN network through a single VLAN. Or in other words a
single VLAN exists between ISAM1, ISAM2, and the IP-edge).
In this case, the Ethernet switch learns all user MAC addresses and if user A can obtain the
MAC address of user C, then user A can send traffic directly to user C without going to the
IP-edge. This is not acceptable: in Intelligent Bridging mode no direct user to user
communication is allowed in the network.
Another issue is that in such a configuration, an ISAM would receive all broadcast / flooded
frames from any ISAM in the VLAN, with potential performance issues as a consequence.
3 Intelligent Bridging
Ethernet
BRAS
BR
CPE
PC A
VLAN 2
ISAM
CPE
PC B
ISAM
2 1 22
NE Operation ISAM as a L2/iBridge
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
CPE
PC
for traffic:
If we would allow for user-to-user communication directly in the ISAM, we would also
have to introduce mechanisms to measure and account for the traffic. Not just for
billing purposes (most services will likely not use volume-based billing), but also for
features such as legal intercept. So in other words, this kind of peer-to-peer traffic
would be hidden to the operator. Peer-to-peer traffic operators will probably not like
that.
Copyright 2013 Alcatel-Lucent. All Rights Reserved.
TAC42050-HO03 Edition I2.0
3 Intelligent Bridging
Ethernet
BR
CPE
ISAM
BRAS
BC or unknown
MAC DA
CPE
CPE
ISAM
2 1 23
NE Operation ISAM as a L2/iBridge
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
In a normal bridge, when a message is received with a destination MAC-address not yet in
the self-learning table, the message is broadcast to all the other interfaces. Also broadcast
messages are flooded to all interfaces. In an Intelligent bridge you want to avoid
broadcasting downstream, where messages are unintentionally distributed to all users.
Therefore, you need to put mechanisms in place that together with the systems set up in
the upstream, will inhibit BC messages to be sent to all users and avoid the flooding of
messages with unknown MAC DA to all users.
For some applications, it is useful that flooding BC is possible. A solution for these
applications is to make flooding BC/discarding BC a configurable option per VLAN.
3 Intelligent Bridging
MacC
ISP
MacB
IP
Port x
BRAS
MacA
bridged
ETH
ISAM
port
VLAN
ID
Max
port
Mac@
Mac@
MacA
MacB
Connected
via PPPoE
Discard Mac@
00-08-02-E9-F2-9D
x
2 1 24
NE Operation ISAM as a L2/iBridge
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
There are two motivations to block the number of MAC-addresses per port:
Security: avoid that a malicious user can fill up all the complete bridging table of devices in
the network (DSLAM and others), by sending traffic with different MAC addresses.
Service differentiation: by limiting the number of MAC addresses per port, the operator can
offer different types of service subscriptions to the user, limiting or allowing a certain
number of devices to connect simultaneously to the network. For this application, it is clear
that the limitation should be configurable per port.
Note: In this example the users PCs are connected to the internet via PPPoE. In that case, the BRAS
also has the possibility to limit the number of PPPoE sessions per user-id. Within PPPoE, the unique
PPPoE session-id can be used to provide this additional security. The BRAS can use the PPPoE
session-id for user-identification during the session itself, which is linked to an earlier
username/password given during the PPPoE session set-up. The BRAS knows that a user has been
given so many sessions. If you have maximum sessions on a VP/VC basis, you can also limit the
number of PPPoE sessions per VP/VC. However, in the case of Ethernet Backhaul, the BRAS has no
info on the VP/VC sessions.
Within DHCP, there is no information that identifies the user. In that case, limiting the number of
MAC-addresses learned per port on the DSLAM is a possible solution. But what about a multi-edge
environment? .
If we want the DHCP server itself to limit the number of sessions per user, the DHCP request needs
to provide the information that defines the user ( VP/VC , port ). This is possible by implementing
DHCP-option 82 (shown later).
During the creation of a RB-VLAN, in the Residential Bridge VLAN service template, a list of MAC2013 Alcatel-Lucent. All Rights Reserved.
addresses for discarding trafficCopyright
can be added.
TAC42050-HO03 Edition I2.0
3 Intelligent Bridging
Mac@
Mac A
Mac A
Mac A
Port x
ETH
Port y
Mac A
Problem:
2 users with same MAC-address,
forwarding engine cant distinguish
If a user on line x is using a certain MAC-address and a second user on a different line y is
trying to connect with the same MAC-address, a mechanism should be there so that that
MAC-addresses will only appear once in the (filtering db) learning table of that VLAN.
If this would not be done, then the MAC-address would be overwritten in the bridge's
learning table, such that traffic is forwarded either to user A or B in a rather unpredictable
way. So this feature allows to guarantee uniqueness of MAC-addresses in the aggregation
network.
In the 7302 ISAM, specific rules are implemented making sure that the MAC-address will be
learned once. This is called secure MAC-address learning
We are not only resolving the customer segregation issue bu,t we also avoid that a
malicious user (user 1) cannot take over the MAC-address of user 2 (MAC-address antispoofing, blocking duplicate MAC-address).
Note: MAC-addresses are supposed to be unique per VLAN. They are not necessarily unique
for the complete system.
3 Intelligent Bridging
User can access network with a different IP address than the assigned IP
address
Pure layer 2 device
Scalability
Switches learn all MAC addresses of all end-users
IP edge learns all MAC addresses & IP addresses of all end-users
2 1 26
NE Operation ISAM as a L2/iBridge
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
3 Intelligent Bridging
2 1 27
NE Operation ISAM as a L2/iBridge
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
3 Intelligent Bridging
User 1
VoIP
HSI
VoD+BTV
VLAN
VDSL line
(PTM)
IB
@
VLAN
VLAN
User 2
IB
VoIP- VLAN
VoIP
HSI VLAN
HSI
IB
VoIP
HSI
Video - VLAN
VoD+BTV
VLAN
VDSL line
(PTM)
mind that frames can only be bridged inside the same VLAN.
4) Hence, several subscriber ports can be assigned to the same VLAN, leading to the
concept of VLAN per service. In this structure, all traffic belonging to one service is
grouped in one VLAN so subscriber identification cannot be done based on VLAN. To
help with this, 7302/7330 is able to insert the line ID in some frames, helping BRAS
(for PPP traffic) or edge routers (for IP traffic) to do subscriber management.
5) So, what is different compared to standard bridging? Mainly, security aspects since
spoofing and other security features have been enabled. IP address anti-spoofing is a
mechanism that keeps track of the IP addresses allocated for each port and discards
any traffic for that port that is not destined to any of those IP addresses.
7)
ISAM R4.5 provides support for VLAN Stacking (S+C VLAN) on iBridge forwarder. Better Scalability due
to VLAN stacking.
Support for Open Access business model by dedicating a S VLAN per service provider and C VLAN per
user.
2 1 29
NE Operation ISAM as a L2/iBridge
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
C-VLAN Ibridge
Unlike traditional I-Bridge, the S+C Bridge allows for the addition / removal of a
VLAN tag. Two stacked iBridge modes are currently supported:
S+C iBridge
S-Tunnel iBridge
I-Bridge
SC-IBridge
S30,
C10,x
S-IBridge tunnel
C10,x
SC
IBRIDGE
C10,x
MAC@ FWD DB
2 1 30
NE Operation ISAM as a L2/iBridge
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
S20,
Any C,x
Any C,x
S
IBRIDGE
MAC@ FWD DB
Any C, x
The traditional I-Bridge in ISAM is called a C-VLAN I-Bridge and this forwarding model does not support adding
/ removing VLAN tag information on customer traffic (it has been explained previously).
In an attempt to keep with growing customer requirements and standard alignment, the ISAM platform also
support stacked VLAN Bridges. With a stacked VLAN bridge, in addition to bridging operations, the operatior
can configure ISAM to add/remove VLAN header to customer upstream / downstream traffic.
The Access Node supporting S+C bridges is considered to be a VLAN aware bridge, where each N:1 VLAN (SBridge) is a separate Virtual Bridge (VB) instance. Each VB performs independent source MAC address learning
and frame forwarding processing. Unlike traditional I-Bridge, the S+C Bridge allows for the addition / removal
of a VLAN tag on upstream egress / downstream egress traffic flows.
Two stacked iBridge modes are currently supported:
S+C iBridge (called mapped mode)
S-Tunnel iBridge (called tunnel mode)
The S+C iBridge mode allows C-VLAN tag operations, such as C-VLAN translation, in addition to
adding/removing an S-VLAN header. This forwarding mode requires the operator to configure a VLAN Port for
each C-VLAN.
The S-Tunnel iBridge mode allows the operator to minimize provisioning by creating a tunnel VLAN port on a
specific bridge port. On this bridge port all tagged/untagged customer frames which match the tunnel VLAN
port are encapsulated by an S-VLAN header.
The S+C iBridge mode supports both protocol-unaware and protocol-aware modes of operations. For example,
DHCP option 82 insertion, PPPoE Intermediate Agent and secure forwarding (ARP Relay, DHCP Snooping, IP
anti-spoofing) is supported for protocol-aware S+C iBridge operations.
Protocol awareness is supported for customer untagged and single-tagged frames. Protocol unaware is
supported for customer untagged, single/dual/multi -tagged frames. In context of GPON and EPON access
solutions, some restrictions may apply on the ONT for the ability to support dual and multi-tagged frames.
IB
11
11
FDB 11
NetVlan 11
21
C-IB
IB
14
FDB 21
NetVlan 21
Ethernet
31 12
NetVlan 31,12
31 23
NetVlan 31, 23
51
NetVlan 51
2 1 31
NE Operation ISAM as a L2/iBridge
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
IB
12
FDB 31,12
IB
17
FDB 31, 23
IB
3
S+C- IB
(Mapped)
FDB 51
S-IB
(Tunnel)
All the upstream frames can be untagged, single tag or with several tags (for example, business services). If
the frame has several tag, the ISAM only analyzes the outer tag to forward it (in the case of C-IB does not
add any VLAN and in the case of S+C IB adds a Vlan). In the case of S-IB (tunnel mode), all the vlans are
forwared transparently and the system addes a S-Vlan.
there are 5 different combinations in the Intelligent Bridge forwarding mode:
1. Not Adding Vlan Tag in upstream. User Vlan Specific and not translated
2. Not Adding Vlan Tag in upstream. User Vlan Specific and translated
3. Adding Vlan Tag in upstream. User Vlan Specific and not translated
4. Adding Vlan Tag in upstream. User Vlan Specific and translated
5. Adding Vlan Tag in upstream. Any User Vlan and not translated
End of module
ISAM as a L2/iBridge
2 1 36
NE Operation ISAM as a L2/iBridge
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
Section 2
NE Operation
Module 2
IHUB L2 Forwarding
TAC42051-HO01 Edition I2.0
7302-7360 ISAM
R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
TAC42051_V1.1-SG Edition 2.0
221
NE Operation IHUB L2 Forwarding
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
Module objectives
Upon completion of this module, you will be able to:
223
NE Operation IHUB L2 Forwarding
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
Table of Contents
1 IHUB basic operation
2 IHUB
L2 forwarding in the overall picture
1 IHUB basic operation
1.1 The ISAM as a two
3 Configuration
of stage
IHUBbox
VLAN via AMS
1.2 Self learning in the IHUB
4 Configuration
IHUB VLAN
via CLI
1.3 MAC movementof
& user-to-user
communication
2 IHUB L2 forwarding in the overall picture
2.1 Supported forwarding models
2.2 VLANs on the IHUB (1/2)
2.3 L2 Services
3 Configuration of IHUB VLAN via AMS
3.1 AMS: Layer 2
3.2 AMS: Create VPLS service
3.3 AMS: VPLS service details
3.4 AMS: Create a single SAP at a time
3.5 AMS: SAP details (1/2)
3.6 AMS: Create a number of SAPs in one go (1/3)
4 Configuration of IHUB VLAN via CLI
4.1 CLI: VLANs do not show IHUB VLANs
4.2 CLI: Configured services info
4.3 CLI: Show v-VPLS service overview
4.4 CLI: Show in which service a SAP is used
4.5 CLI: Show overall FDB
4.6 CLI: Show per service FDB
225
NE Operation IHUB L2 Forwarding
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
Page
7
8
9
10
11
12
13
15
16
17
18
19
20
21
23
26
27
28
29
30
31
32
7
11
16
26
227
NE Operation IHUB L2 Forwarding
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
gem
ethernet (encapsulated)
ethernet
ethernet
xDSL
NT
FW Engine
IWF
FW Engine
IHUB
LT
GPON
P2P-eth
228
NE Operation IHUB L2 Forwarding
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
MacA
LT
X
E-MAN
U
Y
E-MAN
MacB
LT
B A
B C
Z
LT
MacC
229
NE Operation IHUB L2 Forwarding
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
residential =
ports)
user facing ports (local and remote LT, subtending, and direct user
The following rules for MAC movement & port-to-port communication apply:
From
To
MAC movement
User-to-user communication
Residential
Residential
Disabled
Disabled
Residential
Regular
Enabled
Regular
Regular
Enabled
Regular
Residential
Disabled
2 2 10
NE Operation IHUB L2 Forwarding
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
2 2 11
NE Operation IHUB L2 Forwarding
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
2 2 13
NE Operation IHUB L2 Forwarding
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
2 2 14
NE Operation IHUB L2 Forwarding
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
2.3 L2 Services
VLAN
v-VPLS
: SAP
IHUB
LT
VLAN value used at the LT level is forwarded on IHUB by configuring a SAP (Service Access
Point) on a v-VPLS. A SAP is a combination of a physical port (in this case one of the IHUB
ports) and a VLAN ID.
Note: A SAP in the ISAM can be of only one type, q-tagged. Unlike the SAP in IPD
equipment, that can be either untagged, q-tagged or q-in-q tagged.
2 2 16
NE Operation IHUB L2 Forwarding
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
equipment
Select NE
Infrastructure
Layer 2
equipment
See Next
Slide
Select NE
Infrastructure
Layer 2
L2 Services
Create - L2 Service
2 2 18
NE Operation IHUB L2 Forwarding
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
2 2 19
NE Operation IHUB L2 Forwarding
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
The service ID can be different from the VLAN ID, though it may be good practice to
make them equal. However. service IDs live in a shared namespace between all types
of services (e.g. L2 and L3). So conflict must be avoided and since the service ID has a
huge range [1, 2147483647], it can be useful to derive the service ID from the VLAN in
a logical way (e.g. adding a digit).
See Next
Slide
Select NE
Infrastructure
Layer 2
VPLS Services
VPLS Service
Create VPLS SAP
2 2 20
NE Operation IHUB L2 Forwarding
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
2 2 21
NE Operation IHUB L2 Forwarding
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
2 2 22
NE Operation IHUB L2 Forwarding
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
See Next
Slide
Select NE
Infrastructure
Layer 2
L2 Services
L2 Service x
Actions:
Create Port SAPs
2 2 23
NE Operation IHUB L2 Forwarding
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
2 2 24
NE Operation IHUB L2 Forwarding
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
2 2 25
NE Operation IHUB L2 Forwarding
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
2 2 26
NE Operation IHUB L2 Forwarding
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
2 2 27
NE Operation IHUB L2 Forwarding
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
user-user-com
exit
customer 1 create
stp
exit
exit
exit
customer 10 create
sap nt-a:xfp:1:151 create
exit
description "ALUniv-A"
exit
exit
exit
sap lt:1/1/3:151 create
ies 10 customer 10 create
exit
stp
shutdown
address 172.31.79.190/25
exit
exit
exit
shutdown
exit
exit
description "VLAN3000"
no shutdown
no shutdown
stp
exit
exit
shutdown
exit
2 2 28
NE Operation IHUB L2 Forwarding
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
=========================================================
Services
=========================================================
ServiceId
Type
Adm
------------------------------------------------------------------------------151
v-VPLS
Up
Up
300
v-VPLS
Down
4080
v-VPLS
Up
Down
11
Up
10
------------------------------------------------------------------------------Matching Services : 3
-------------------------------------------------------------------------------
2 2 29
NE Operation IHUB L2 Forwarding
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
Template Used
==================================================
Service Access Points Using Port lt:1/1/1:3000
==================================================
PortId
SvcId
Ing.
Fltr
Fltr
-------------------------------------------------------------------lt:1/1/1:3000
300
none
none Up Down
-------------------------------------------------------------------Number of SAPs : 1
--------------------------------------------------------------------
2 2 30
NE Operation IHUB L2 Forwarding
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
MAC
Source-Identifier
------------------------------------------------------------------------------151
00:12:72:00:27:66
sap:lt:1/1/3:151
L/0
06/28/2012 23:21:06
4080
00:03:ba:73:47:b1
sap:nt-a:xfp:1:4080
L/0
06/13/2012 15:29:39
4080
00:03:ba:86:dd:39
sap:nt-a:xfp:1:4080
L/0
07/09/2012 16:14:55
4080
00:03:ba:cf:90:d3
sap:nt-a:xfp:1:4080
L/0
06/13/2012 15:29:32
4080
00:0d:9d:d3:37:64
sap:nt-a:xfp:1:4080
L/0
07/09/2012 15:43:05
4080
00:13:21:f2:b4:ab
sap:nt-a:xfp:1:4080
L/0
07/09/2012 16:18:32
4080
00:14:4f:5f:20:ca
sap:nt-a:xfp:1:4080
L/0
06/13/2012 15:29:33
4080
00:14:4f:cb:17:ac
sap:nt-a:xfp:1:4080
L/0
06/13/2012 15:29:32
-------------------------------------------------------------------------------------------------No. of Entries: 20
-------------------------------------------------------------------------------------------------Legend: L=Learned; P=MAC is protected
2 2 31
NE Operation IHUB L2 Forwarding
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
=======================================================
Forwarding Database, Service 151
=======================================================
ServId
MAC
Source-Identifier
------------------------------------------------------------------------------151
00:12:72:00:27:66 sap:lt:1/1/3:151
L/0
06/28/2012 23:21:06
2 2 32
NE Operation IHUB L2 Forwarding
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
Module summary
Upon completion of this module, you are able to:
2 2 33
NE Operation IHUB L2 Forwarding
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
End of module
IHUB L2 Forwarding
2 2 34
NE Operation IHUB L2 Forwarding
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
Section 2
NE Operation
Module 3
Intelligent Bridging IACM
TAC42050-HO05 Edition I2.0
7302-7360 ISAM
R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
TAC42051_V1.1-SG Edition 2.0
231
NE Operation Intelligent Brigding IACM
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
Module objectives
After attending this session, you should be able to:
233
NE Operation Intelligent Brigding IACM
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
Table of Contents
1 Intro Intelligent Bridging
2 Configuration:
Create the IB VLAN
1 Intro Intelligent Bridging
1.1 The ISAM as a two
boxassociation on bridge port
3 Configuration:
IBstage
VLAN
1.2 Intelligent Bridge mode in 7302 ISAM
4 Exercises
1.3 Intelligent Bridge
1.4 LT self-learning
5 Annex
A: Basic GPON QoS configs
1.5 Upstream
1.6 Downstream
1.7 Secure MAC address learning
2 Configuration: Create the IB VLAN
2.1 IB VLAN set-up
2.2 Creation of IB VLAN on NE
2.3 Creation of IB VLAN on IACM
2.4 Modifying IB VLAN on IACM
2.5 IB Configuration of SYSTEM and/or per VLAN aging timer
2.6 Residential bridge parameters
2.7 Creation of IB VLAN via CLI
2.8 Residential bridge parameters
3 Configuration: IB VLAN association on bridge port
3.1 Logical user port xDSL/ATM
3.2 Logical user port VDSL/EFM or P2PEth
3.3 Logical user port - GPON
3.4 IB VLAN association of port on IACM
3.5 IB VLAN association
3.6 IB VLAN association of port on IACM
235
COPYRIGHT ALCATEL-LUCENT 2013. ALL RIGHTS RESERVED.
3.7 IB
VLAN
association
of port on IACM
NE Operation
Intelligent
Brigding
IACM
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
3.8 Configuration of the port on VLAN in IB
3.9 Create VLAN association on bridge port
3.10 Define PVID on bridge port
3.11 RB VLAN association with VLAN translation
3.12 IB VLAN association of port on IACM (CLI)
3.13 Deletion of VLAN
3.15 VLAN related show commands
3.16 Stacked-IB (S+C-Ibridge)
3.17 S+C IBridge association with VLAN translation
3.18 Stacked-IB (S-Ibridge)
3.19 Stacked-IB (CLIs)
4 Exercises
5 Annex A: Basic GPON QoS configs
5.1 Ingress QoS profile
5.2 Bandwidth profile
Page
7
8
9
10
11
12
13
14
15
16
17
18
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
38
39
40
41
43
44
48
50
52
53
63
64
65
7
15
27
53
63
237
NE Operation Intelligent Brigding IACM
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
gem
ethernet
xDSL
NT
LT
IWF
FW Engine
FW Engine
xHUB
GPON
P2P-eth
238
NE Operation Intelligent Brigding IACM
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
CPE
Ph port
VLAN
VP/VC
VLAN
8/35
100
8/37
100
EFM
x
External
Ethernet
links
xHUB
ASAM
link
LT
FW Engine
100
100
1-16
FW Engine
100
239
100
Ph. Port
8/35
8/37
Only
once over all 7302 ISAMs in the complete Ethernet network to which the 7302 ISAM
is connected.
2 3 10
NE Operation Intelligent Brigding IACM
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
The xHUB and the LTs autonomously learn MAC addresses. They also autonomously age these MAC addresses.
Aging timers are configurable. The idea is that the xHUB is configured with the same aging timer as the one
of the IWF of the LT. This is needed to avoid conflicts, e.g. when the MAC address is aged on the xHUB, then
the xHUB could learn the MAC address on another interface with unpredictable behavior as a consequence.
Once a MAC address is aged, then no downstream communication is possible until the address is learned again
in the upstream direction.
So its important that the MAC ageing time is properly configured, otherwise data-plane connectivity may be
lost between the network and the ISAM end-users (nightly SW download on STB, incoming VoIP calls, )
In case of PPPoE traffic the MAC aging time can be kept small, because PPP has a built-in keepalive mechanism
In case of DHCP-based service scenario's, the MAC ageing time must be taken in the same order of
magnitude as the DHCP lease time
1.4 LT self-learning
only in the upstream - when initiated from user logical port
Self-learning can be disabled per user logical port.
In case of self-learning, limiting number of MAC addresses is possible.
LT
x
To Service
xHUB
y
z
2 3 11
NE Operation Intelligent Brigding IACM
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
MacB
MacC
We call the LT IWF half a bridge as it only learns MAC addresses in the upstream direction.
This has as a consequence that no connection can be initiated from the network side if the
MAC address on the user side is not known or has not been learned yet.
1.5 Upstream
only user to network allowed
<-Network
<-SHUB
LT
<-- BC
-->
User A - LT1
User B - LT1
User C - LT4
User D
S-ASAM
LT
User A - LT1
User B - LT1
User C - LT4
User D
S-ASAM
LT
User A - LT1
User B - LT4
User C - LT4
User D
S-ASAM
-->
-->
-->
<-Network
<-SHUB
-->
-->
-->
<-Network
<-SHUB
-->
-->
-->
2 3 12
NE Operation Intelligent Brigding IACM
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
Blocked
This is valid for all cases, i.e. Broadcast (BC), Unknown MAC Destination Address and Known
MAC Destination address.
Unicast frames with unknown destination MAC addresses are flooded to the network side.
no
no
broadcast
Frames with known destination MAC addresses arent forwarded to user ports, but to the
network side
No
1.6 Downstream
broadcast control configurable per VLAN in IB mode
BC -->
Network
SHUB
SHUB
SHUB
2 3 13
NE Operation Intelligent Brigding IACM
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
-->
-->
-->
-->
-->
-->
-->
-->
-->
-->
-->
-->
-->
-->
-->
LT
-->
-->if BC allowed
-->
User A - LT1
User B - LT1
User C - LT4
User D
S-ASAM
LT
-->
-->
-->
User A - LT1
User B - LT1
User C - LT4
User D
S-ASAM
LT
-->
-->
-->
User A - LT1
User B - LT1
User C - LT4
User D
S-ASAM
Broadcast from Network to User is only allowed if enabled by the operator, per VLAN in IB
mode.
For the unknown MAC DA case, the LT will not forward the frames to the users.
In case of a known MAC DA, all frames are forwarded.
unicast frames with known MAC DA are forwarded to the appropriate logical user port
unicast
No
No
xHUB
, always MAC
, MAC movement
NT
VLAN
E-MAN
network links,
outband MGT link
Control link
LT
ASAM links
IWF
2
3
CPE
ASAM links
CPE
LT
IWF
CPE
subtending links
3
user links
2 3 14
NE Operation Intelligent Brigding IACM
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
On the IWF
If the MAC-address was already configured or learned on another user logical port, the MACaddress wont be learned on the second port and the frame is dropped (Conflict alarm).
2 3 15
NE Operation Intelligent Brigding IACM
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
create VLAN
on LTs
Via AMS
Different versions of one VLAN
possible
ports to a VLAN.
Network
Select NE
Infrastructure
Layer 2
VLAN
Create VLAN
See Next
Slide
2 3 17
NE Operation Intelligent Brigding IACM
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
5520AMS doesnt use templates for VLANs. The only way to configure VLANs is on the NE
itself.
For a residential bridge VLAN, the S-TAG = 0. No stacked VLANs for intelligent bridging!
(The reason why you see the S-VLAN id is that the same screens are used for cross-connect,
where you can have stacked VLANs.)
mode: RB
2 3 18
NE Operation Intelligent Brigding IACM
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
Not all parameters can be configured here already. You can configure e.g. static MAC
addresses afterwards. See further.
broadcast
control
Protocol
Control
(NTP,RIP)
Protocol filter
(PPPoE,IPoE,IP
v6oE)
2 3 19
NE Operation Intelligent Brigding IACM
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
Not all parameters can be configured here already. You can configure e.g. static MAC
addresses afterwards. See further.
PPPoE relay
tag
DHCP option
82
2 3 20
NE Operation Intelligent Brigding IACM
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
Not all parameters can be configured here already. You can configure e.g. static MAC
addresses afterwards. See further.
Virtual MAC
translation
MC control
2 3 21
NE Operation Intelligent Brigding IACM
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
From R3.5 VLAN specific aging time can be set. If set, this value will override the IACM
Layer2 - Ethernet System Parameters Forwarding Database Aging Time. If the default value
1 is left, the IACM system parameter is used.
To avoid problems the LT aging timer must be the same as the SHUB aging timer.
Network
Select NE
Infrastructure
Layer 2
VLAN
Select VLAN
MAC Addresses
Static
Create
Unicast Static MAC Address
2 3 22
NE Operation Intelligent Brigding IACM
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
2 3 23
NE Operation Intelligent Brigding IACM
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
From R3.5 VLAN specific aging time can be set. If set, this value will override the IACM
Layer2 - Ethernet System Parameters Forwarding Database Aging Time. If the default value
1 is left, the IACM system parameter is used.
In this case 300s is the value
To avoid problems, the LT aging timer must be the same as the SHUB aging timer.
CLI Commands: System aging timers IACM
Configure bridge ageing-time [10...1000000]
CLI Command: MAC aging PER VLAN (IACM)
Broadcast control on LT
BC off by
Default
From
Service
Hub
MAC-DA
Broadcast
BC in IWF on LT blocked in DS
On:
-
Allow BC in DS
2 3 24
NE Operation Intelligent Brigding IACM
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
Off: BC blocked
On: BC allowed
LT
2 3 25
NE Operation Intelligent Brigding IACM
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
Enabled:
option 82/PPPoE information added by LT
All :
allow all protocols on VLAN
IPoE:
allow only IPoE on VLAN
PPPoE :
allow only PPPoE on VLAN
IPv6oE:
allow only IPv6oE on VLAN
PPPoE + IPoE + IPv6: allow only PPPoE, IPoE & IPV6oE on VLAN
Or other combinations between the three
2 3 27
NE Operation Intelligent Brigding IACM
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
LT x
FW Engine
IWF
This enables the capability to learn Mac addresses in the LT. But currently there is no means yet
to transport data upstream, out of the ONT on to the LT. This means it is the T-CONT which still
needs to be set up (see later)!
If you try to make the bridge port member of a VLAN without the qos interface youll get an
error message:
Attach
Ingress QoS Profile to Vlan Port refused due to missing bandwidth profile on Queue
2 3 31
NE Operation Intelligent Brigding IACM
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
VLAN Translation
VID based on port of arrival and translated to a network VID
2 3 32
NE Operation Intelligent Brigding IACM
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
A VLAN bridge supports port-based VLAN classification and may support port-and-protocolbased VLAN classification.
In port-based VLAN classification within a bridge, the VLAN-ID associated with an untagged
or priority tagged frame is determined based on the port of arrival of the frame into the
bridge. This classification mechanism requires the association of a specific Port VLAN
Identifier, or PVID, with each of the bridges ports. In this case, the PVID for a given port
provides the VLAN-ID for untagged and priority tagged frames received through that port.
For bridges that implement port-and-protocol-based VLAN classification, the VLAN-ID
associated with an untagged or priority-tagged frame is determined based on the port of
arrival of the frame into the bridge and on the protocol identifier of the frame.
For port-and-protocol based tagging, the VLAN bridge will have to look at the Ethertype, the
SSAP, or the SNAP-type of the incoming frames. When the protocol is identified, the VID
associated with the protocol group to which the protocol belongs will be assigned to the
frame. This classification mechanism requires the association of multiple VLAN-IDs with
each of the ports of the bridge; this is known as the VID Set for that port.
port default VLAN must be chosen equal to the VLAN used for BTV traffic
no
protocol based VLAN must be defined for IP, otherwise we end up generating a wrong
tag when issuing IGMP messages to the end user
E-MAN
Network
IPoE
PPPoE
xxx
LT
IPoE
PPPoE
xxx
E-MAN
Network
LT
CPE
= PVID
2 3 33
NE Operation Intelligent Brigding IACM
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
CPE
Network VLAN
VLAN 10 (HSIA, SP1)
VLAN 11 (HSIA, SP2)
VLAN 20 (VoD, SP1)
Subscriber VLAN
Bridge 10
VLAN 1 (HSIA)
Bridge 11
VLAN 5 (HSIA)
Bridge 20
VLAN 2 (Video)
CPE
MCast
Bridge 21
VLAN 6 (Video)
Bridge 40
VLAN 3 (Voice)
VLAN per service
& per provider
2 3 34
NE Operation Intelligent Brigding IACM
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
There are many operators who base their network architecture on one PVC per service when
connecting ADSL subscribers. Once those operators start deploying VDSL, they need to use
the VLAN as a "PVC emulation".
ISAM supports the ability to emulate a multi-PVC configuration on an EFM interface using the
VLAN as a "PVC emulation", i.e. it is possible to associate a set of VLAN Id's at the subscriber
interface with a set of forwarding engines being chosen from the following list :
VLAN-CC
(Transparent or Protocol aware): the C-VLAN received at the user side is either
forwarded as a C-VLAN CC or encapsulated into an S-VLAN (VLAN stacking).
i-Bridge:
IP
Aware Bridge
IP
Routing
i-bridge
on IACM
Bridge port VID mapping
External
ethernet
links
Control
link
Aggregation
function
on xHUB
Define egress ports within
the VLAN
Control/mgt
functions
FE
GE/FE 1
GE/FE 2
..
ASAM
links
GE/FE 7
LIM
IWF
GE1
..
LIM
IWF
GE16
PVC
PVC
2 3 35
NE Operation Intelligent Brigding IACM
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
In
In
the xHUB
the ASAM
2 3 36
NE Operation Intelligent Brigding IACM
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
2 3 37
NE Operation Intelligent Brigding IACM
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
select Default
VLAN and click OK
2 3 38
NE Operation Intelligent Brigding IACM
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
VLAN Translation
Network
Subscriber
VLAN
2 3 39
NE Operation Intelligent Brigding IACM
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
For example, you configure a RB VLAN association with VLAN translation on a VDSL EFM
bridge port. The modem is configured in such a way that it generates tagged traffic, e.g.
local subscriber VLAN 10. This subscriber VLAN is translated into the network VLAN 150.
All
frames returned to the subscriber should again have VLAN tag 10.
Configure that the frames returned to the subscriber should be single-tagged.
VLAN translation
configure bridge port 1/1/<slot>/<port>:<VP>:<VC>#
vlan-id <VLAN ID> vlan-scope <local> network-vlan <VLAN ID>
2 3 40
NE Operation Intelligent Brigding IACM
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
No VLAN Translation:
leg:isadmin>configure>bridge>port>1/1/2/1:8:36#
vlan-id 200
leg:isadmin>configure>bridge>port>1/1/2/1:8:35#
info
#-------------------------------------------------------------------------------------------------- port
1/1/2/1:8:35
max-unicast-mac 4
vlan-id 200
exit
exit
leg:isadmin>configure>bridge>port>1/1/2/2:8:35#
info
port
1/1/2/2:8:35
max-unicast-mac 4
vlan-id 10
network-vlan 150
vlan-scope local
exit
vlan-id 200
exit
exit
2 3 41
NE Operation Intelligent Brigding IACM
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
2 3 42
NE Operation Intelligent Brigding IACM
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
Select NE
Infrastructure
Layer 2
VLAN
Create VLAN
2 3 44
NE Operation Intelligent Brigding IACM
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
2 3 45
NE Operation Intelligent Brigding IACM
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
2 3 46
NE Operation Intelligent Brigding IACM
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
2 3 47
NE Operation Intelligent Brigding IACM
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
2 3 48
NE Operation Intelligent Brigding IACM
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
2 3 49
NE Operation Intelligent Brigding IACM
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
2 3 50
NE Operation Intelligent Brigding IACM
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
2 3 51
NE Operation Intelligent Brigding IACM
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
2 3 52
NE Operation Intelligent Brigding IACM
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
4 Exercises
2 3 53
NE Operation Intelligent Brigding IACM
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding
Perform these exercises with CLI and AMS unless specified differently
Exercises
1.
2.
3.
What are the ports belonging to VLAN 200 on the xHUB? Explain what you see.
2 3 54
4.
5.
Explain the total configuration of the user logical port PVC 8/35 on port TRAINING-a .
Note : For the downstream forwarding , we assume that the xHUB knows the MAC-addresses of the end
user within the respective VLANs .
6.
What happens when the end-user sends a frame with VLAN tag 200?
7.
What happens when the end-user sends a frame with VLAN tag 300?
8.
9.
What happens with a frame with VLAN tag 200 coming from the network?
10. What happens with a frame with VLAN tag 300 coming from the network?
11. How many MAC-addresses can be learned in VLAN 200 on the logical user port VP/VC 8/35 of port
TRAINING-a?
12. Explain the total configuration of the user logical port PVC 8/35 on port TRAINING-b.
Note : For the downstream forwarding , we assume that the xHUB knows the MAC-addresses of the
end user within the respective VLANs .
Egress
Ingress
DSL port
DSL port
150
150
8/35
160
160
210
210
50
50
13. What happens when the end-user sends a frame with VLAN tag 150?
14. What happens when the end-user sends a frame with VLAN tag 50?
16. What happens when a frame with VLAN tag 150 is sent towards the end user?
17. What happens when a frame with VLAN tag 160 is sent towards the end user?
18. What happens when a frame with VLAN tag 210 is sent towards the end user?
19. What happens when a frame with VLAN tag 50 is sent towards the end user?
20. What happens when an untagged frame is sent towards the end user?
21. How many MAC-addresses can be learnt on the user logical port PVC 8/35 on port TRAINING-b
For these exercises go back to the board and ports assigned to you to do the
configuration exercises.
1. Go to the port that you configured before and where the modem is connected. Use
CLI to apply the service with VLAN id as default VLAN 150 to PVC 8/36. Frames coming
from the end user are untagged. You should be able to connect with 2 PCs. DHCP server
is available on the other side .
setup
2. Check if you are able to get an IP address. from the DHCP server.
Note: in function of the modem setup you need to either use VMware on the trainee PC
or disconnect your PC from the AUA LAN and connect the PC to the modem (or
connect your own PC to the modem ). Ask the teacher what to do!
Force your PC to ask for a new IP-address (DHCP release/renew) ipconfig /release
and ipconfig /renew.
What is the IP-address you received ? What is the IP-address of the DHCP server?
3. Check the MAC-address learnt on your bridge port using AMS and CLI.
4. Are you able to ping the PC of one of your colleagues connected to the same
ISAM? Explain.
5. Use the AMS to associate logical port 8/35 with VLAN 200 as the default VLAN.
Frames coming from the end user are untagged. You should be able to connect with 3
PCs to this connection.
VLAN 200 terminates on a BRAS so use PPPoE to set up a connection. Check if you can
surf the web.
Note: in function of the modem setup PPPoE session needs to be initiated from modem
or PC . Ask the trainer what to do !
Setup
6. Check the MAC-address learnt on the VP/VC 8/35 and VP/VC 8/36 with the AMS.
What do you notice ? Explain what you see.
7. Use the AMS to remove the RB vlan with id 200 from the 8/35 ATM termination
point on your port.
8. Use the CLI to remove the RB vlan with id 150 from the 8/36 ATM termination
point on your port.
9.
Create RB VLAN with VLAN ID=20x ( x = adsl-x) via CLI. All traffic type is possible within
the VLAN. The VLAN is default VLAN on logical port 8/35. 4 user sessions possible on the logical
port. No user line id is required for DHCP or BRAS. No MC service is deployed within the VLAN.
Try to initiate a PPPoE session towards the network. Verify if your configuration works.
Note: BRAS will not provide you with an IP@ ( Setup of the network currently not ready )
Setup
10. Create a Service for RB VLAN on the AMS. All traffic type is possible within the VLAN. 4
user sessions possible on the logical port. No user line id is required for DHCP or BRAS. No MC
service is deployed within the VLAN.
Leave status under construction.
Note : unique VLAN-ID per [IP-edge ISAM] pair to prohibit user-to-user communication.
11. You want to have line identification information on the DHCP server. Try to apply the
change and explain
12. Use the AMS to associate the service you just created on VP/VC 8/36 of the port
assigned to you. VLAN id to be used is VLAN 16x (x=adslx). Frames coming from
the end user are untagged. VLAN 16x is the default VLAN. Check if your
configuration works by setting up a DHCP session and see if you are able to receive
an IP@ .
Setup
15. In normal operation would you normally apply such change with CLI?
16. Your management changed mind again, and now only wants IPoE traffic in
VLAN 16x and disable option 82. Apply the change with AMS. Check if you are still
able to retrieve an IP@ via DHCP. Does it work ? Why? Why not??
17. Can you ping the client PC from the server side on VLAN 16x?
Ask the trainer to assist you since access to DHCP server is secured.
First check the ARP table of DHCP server and make sure the MAC@ of your PC is no longer in the
self-learning table of VLAN 16x, then issue the ping command.
What do you notice? Explain.
18. Force the system to allow broadcast frames to pass through in the downstream direction.
Use a CLI command to achieve this goal. Verify, and explain what you notice.
19. Delete the association with VLAN 20x from VP/VC 8/35 on your port and associate VP/VC
8/35 with VLAN 21x.
VLAN 21x is a RB service and parameters are such that only PPPoE traffic is allowed on this VLAN.
Perform this exercise with the AMS.
Check if your setup works .
What is the IP@ you get from the BRAS ?
What is the IP@ you got from the DHCP server?
Note: BRAS will not provide you with an IP@ ( Setup of the network currently not ready )
Setup
20.
Try to delete VLAN 16x from the ISAM via the AMS. What happens? Explain.
Note: If not possible just proceed to the next exercise after explanation
21.
Version 2 of service with VLAN-ID 16x has been deployed in the entire network. Delete
version 1 from the AMS.
22.
Configura two stacked Ibridge. One of them must work in a mapped mode (S+C Ibridge)
and the other one must be work in a tunnel mode (S Ibridge).
23.
MC Teaser .
Set-up a MC control-channel on VP/VC 8/36 and allow your user to see package 1 . Ask the
teacher for assistance and see if you can watch some video.
End of module
Intelligent Brigding IACM
2 3 67
NE Operation Intelligent Brigding IACM
7302-7360 ISAM R4.6 High Cap. NT/5520 AMS - L2 & PPPoX forwarding