[previous] Clear Spacer [next]

Administering Virtual LANs (VLANs)

A virtual LAN (VLAN) is a logical definition of a network work group. It is roughly equivalent to a broadcast domain. A VLAN interface is your system's point of attachment to a given VLAN. A VLAN and a VLAN interface are analogous to an IP subnetwork and an IP interface.

For more information about VLANs, see the Implementation Guide for your system.


Menu Structure

The commands that you can use depend on the system that you have, your level of access, and the types of modules and other hardware options that are configured for your system. The following diagram shows the complete list of commands for all systems. See the checklist at the beginning of each command description in this chapter for whether your system supports the command.

The bridge vlan stpMode command is available only when you enable allClosed mode on the CoreBuilder 3500 system or the CoreBuilder 9000 Layer 3 switching module. The command does not appear when you are using the default VLAN mode (allOpen) or when you use allClosed mode on a Layer 2 system or module.

bridge vlan summary

Displays a summary of VLAN information. In a summary report, the system displays the ports and protocols that are assigned to each VLAN.

Valid Minimum Abbreviations

b v s (in allOpen mode)

b v su (in allClosed mode)

Important Considerations

Options (3500, 9400, 3900, 9300)

Prompt

Description

Possible Values

[Default]

VLAN interface index

Index numbers of the VLAN interfaces for which you want summary information

1 (if you have only one VLAN)

Fields in the Bridge VLAN Summary Display

Field

Description

Index

System-assigned index number that identifies a VLAN. Statistics appear in the display for the VLAN that you specify.

Name

Character string of from 0 to 32 bytes that identifies the VLAN

Origin

For all platforms except the CoreBuilder 3500, the VLAN origin is always static, which indicates that the VLAN was created by the user. For the CoreBuilder 3500, the origin indicates whether the VLAN was created statically (static) or created dynamically from a GVRP update (GVRP). The GVRP state must be enabled both as a bridge-wide parameter and for the participating bridge ports as a bridge-port parameter.

Ports

Numbers (indexes) of the bridge ports that belong to the VLAN.

On the CoreBuilder 9000, the list of ports includes the front-panel ports and the appropriate backplane ports. Example: On a 12-port Layer 3 module, the list of ports includes ports 1 - 12 and port 13, which is the module's backplane port).

Type (VLAN mode)

Either allOpen or allClosed. VLANs in allOpen mode share a single address table for all configured VLANs; in allClosed mode, each VLAN has its own unique address table. Standard bridging rules apply based on the table addresses that are assigned to the specific VLAN.

VID

VLAN ID; the unique, user-defined integer that identifies this VLAN. It is used by management operations.

bridge vlan detail

Displays per-port information such as tagging in addition to the VLAN summary information. For the CoreBuilder 3500 and the CoreBuilder 9000 Layer 3 switching modules, this command also displays VLAN statistics.

Valid Minimum Abbreviation

b v det

Important Considerations

Options (3500, 9400, 3900, 9300)

Prompt

Description

Possible Values

[Default]

VLAN interface index

Index numbers of the VLAN interfaces for which you want detailed information

1 (if you have only one VLAN)

Fields in the Bridge VLAN Detail Display

Field

Description

Ignore STP mode (3500 and 9000 Layer 3)

Whether a VLAN can ignore STP blocked ports and let routing traffic pass through. Possible values: enabled and disabled.

Index

Assigned index number that identifies a VLAN. Statistics appear for the VLAN that you specify.

Layer 3 addresses (3500 and 9000 Layer 3)

Fields used to set up flood domains for overlapping IP VLAN subnetworks (network-based VLANs)

Name

Character string 0 to 32 bytes that identifies the VLAN

Origin

For all platforms except the CoreBuilder 3500, the VLAN origin is always static, which indicates that the VLAN was created by the user. For the CoreBuilder 3500, the origin indicates whether the VLAN was created statically (static) or created from a GVRP update (GVRP).

Ports/Port

Index numbers of the bridge ports that belong to each VLAN. In the second part of the detail display, the Port column lists the ports for the VLAN individually and indicates ports that are trunked or have tagging.

On the CoreBuilder 9000, the list of ports includes the front-panel ports and the appropriate backplane ports. Example: On a 12-port Layer 3 module, the list of ports includes ports 1 - 12 and port 13, which is the module's backplane port.

Protocol (3500 and 9000 Layer 3)

Protocol suites for the VLAN

rxBcastBytes (3500 and 9000 Layer 3)

Number of received broadcast bytes

rxBcastFrames (3500 and 9000 Layer 3)

Number of received broadcast frames

rxMcastBytes (3500 and 9000 Layer 3)

Number of received multicast bytes

rxMcastFrames (3500 and 9000 Layer 3)

Number of received multicast frames

rxUcastBytes (3500 and 9000 Layer 3)

Number of received unicast bytes

rxUcastFrames (3500 and 9000 Layer 3)

Number of received unicast frames

Tag type (3500 and 9000 Layer 3)

Whether tagging is set to none or 802.1Q (IEEE 802.1Q tagging)

txBcastBytes (3500 and 9000 Layer 3)

Number of transmitted broadcast bytes

txBcastFrames (3500 and 9000 Layer 3)

Number of transmitted broadcast frames

txMcastBytes (3500 and 9000 Layer 3)

Number of transmitted multicast bytes

txMcastFrames (3500 and 9000 Layer 3)

Number of transmitted multicast frames

Type (VLAN Mode)

Either allOpen or allClosed. VLANs in allOpen mode share a single address table for all configured VLANs. In allClosed mode, each VLAN has its own unique address table. Standard bridging rules apply based on the table addresses that are assigned to the specific VLAN.

VID

VLAN ID; the unique, user-defined integer that identifies this VLAN. It is used by management operations.

bridge vlan define (3500/9000 Layer 3)

For CoreBuilder 9000: Applies to Layer 3 switching modules only.

Creates a port-based, protocol-based, or network-based VLAN on the CoreBuilder 3500 system or a CoreBuilder 9000 Layer 3 module. When you statically configure a VLAN on the system, you assign it a VLAN ID (VID), a set of bridge ports, and, optionally, a protocol type and IEEE 802.1Q tagging. If you specify IP as the protocol, you can also specify a Layer 3 address.

For details about this command on the SuperStack II Switch 3900, the Switch 9300, the CoreBuilder 9400, and CoreBuilder 9000 Layer 2 modules, see "bridge vlan define (3900/9300/9400/ 9000 Layer 2)" next.

Valid Minimum Abbreviation

b v def

Important Considerations

Options

Prompt

Description

Possible Values

[Default]

VID

Unique, user-defined integer used by management operations

1 - 4094

Next available VID

Bridge ports

Index numbers of the bridge ports that belong to the VLAN. If you include trunked ports, specify the anchor port of the trunk. On the CoreBuilder 9000, the list of ports includes the front-panel ports and the module's backplane port.

-

Protocol suite

One or more protocol suites that you want to specify for the VLAN

unspecified (factory default)

Layer 3 address configuration (IP VLAN)

Whether you want to define Layer 3 information for the IP VLAN

y

Layer 3 address and mask (IP VLAN)

Fields (IP network address and subnet mask) you can use to set up flood domains for overlapping IP VLAN subnetworks

Any valid IP network address and subnet mask

-

Per-port tagging

Whether you want to configure IEEE 802.1Q VLAN tagging. You are prompted to answer for each port that you selected.

y

Tag type

Whether you want to configure no tagging or IEEE 802.1Q tagging (the VID) for each port.

none

VLAN name

Unique, user-defined name that identifies members of the VLAN. If you use spaces, put quotation marks around the VLAN name.

Up to 32 ASCII characters or spaces

-

Procedure

1 .   Enter the VLAN identification (VID) number for this interface.

2 .   Select the bridge ports.

3 .   Select one or more protocol suites.

If you select an IP protocol suite, proceed with step 4. If you did not choose an IP protocol suite for this interface, proceed to step 5.

4 .   To specify Layer 3 address information for an IP VLAN:

a .   Enter y for Layer 3 addressing.

b .   Enter the Layer 3 network address.

c .   Enter the Layer 3 subnet mask. To accept the default or current value in brackets [ ], press Return or Enter.

If you do not want Layer 3 addressing, enter n at step a.

5 .   Specify whether you want per-port tagging (n or y). The default is y.

6 .   If you specified per-port tagging, enter the tag type for the indicated port (none or 802.1Q).

7 .   If you have defined more than one port, you are prompted again for a tag type for each port.

8 .   Enter the VLAN name.

Bridge VLAN Define Example (9000 Layer 3)

This example shows the steps necessary to define a protocol-based VLAN for IPX 802.3 on a Layer 3 switching module. In this example, only the backplane port (port 13) of the module has IEEE 802.1Q tagging; the front-panel ports in this VLAN are not tagged. Because you have tagged the module's backplane port, you must also tag the corresponding switch fabric module port of the switch fabric module for that VLAN. (Use the EME to connect to the switch fabric module and configure the VLAN.)

CB9000@slot2.1 [12-E/FEN-TX-L3] (bridge/vlan): define
Enter VID (1-4094) [5]: 5
Select bridge ports (1-13|all|?): 1-5,13
Enter protocol suite
(IP,IPX,Apple,XNS,DECnet,SNA,Vines,X25,NetBIOS,unspecified, IPX-II,IPX-802.2,IPX-802.3): IPX-802.3
Enter protocol suite ('q' to quit) (IP,Apple,XNS,DECnet,SNA,Vines,X25,NetBIOS,IPX-II,IPX-802.2,IPX-802.3): q
Configure per-port tagging? (n,y) [y]: y
Enter port 1 tag type (none,802.1Q): none
Enter port 2 tag type (none,802.1Q): none
Enter port 3 tag type (none,802.1Q): none
Enter port 4 tag type (none,802.1Q): none
Enter port 5 tag type (none,802.1Q): none
Enter port 13 tag type (none,802.1Q): 802.1Q
Enter VLAN Name {?} [ ]: IPX1

Bridge VLAN Define Example (3500)

This example shows the steps necessary to define a network-based IP VLAN with a Layer 3 address and subnet mask, as well as IEEE 802.1Q tagging on some ports. This VLAN has trunk ports.

bridge vlan define (3900/9300/9400/ 9000 Layer 2)

Creates a port-based VLAN on standalone systems or the CoreBuilder 9000 Layer 2 modules. When you configure a port-based VLAN, you assign a VLAN ID (VID), a set of bridge ports, and, optionally, IEEE 802.1Q tagging.

For details about this command on the CoreBuilder 3500 and CoreBuilder 9000 Layer 3 modules, see "bridge vlan define (3500/9000 Layer 3)" earlier in this chapter.

Valid Minimum Abbreviation

b v def

Important Considerations

Options

Prompt

Description

Possible Values

[Default]

VID

Unique, user-defined integer used by global management operations

1 - 4094

Next available VID

Bridge ports

Index numbers of the bridge ports that belong to the VLAN. If you include trunked ports, specify the anchor port of the trunk. See "Important Considerations" for information about the list of ports.

-

Per-port tagging

Whether you want to configure 802.1Q VLAN tagging. You are prompted to answer for each port that you selected.

y

Tag type

Whether you want no tagging or IEEE 802.1Q tagging (the VID). For a port shared by another VLAN, verify that the specified tag type is not in conflict with the port's tag type in another VLAN.

none

VLAN name

Unique, user-defined name that identifies members of the VLAN. If you use spaces, put quotation marks around the VLAN name.

Up to 32 ASCII characters or spaces

-

Procedure

Press Return or Enter to accept the default or existing values that appear in brackets [ ].

1 .   Enter the VLAN identification (VID) number.

2 .   Enter one or more port numbers. To assign all ports to the VLAN, enter all.

3 .   Configure the per-port tagging.

4 .   Enter the tag type for each port in the VLAN.

5 .   Enter the VLAN name.

Bridge VLAN Define Example (9000 Layer 2)

This example shows a port-based VLAN that includes tagged front-panel ports and a tagged backplane port (port 21). These ports are tagged because they overlap with ports that belong to other VLANs:

CB9000@slot 10.1 [20-E/FEN-TX-L2] (bridge/vlan): define
Enter VID (1-4094) [3]: 3
Select bridge ports (1-22|all|?): 1-5,21
Configure per-port tagging? (n,y) [y]: y
Enter port 1 tag type (none,802.1Q): 802.1Q
Enter port 2 tag type (none,802.1Q): 802.1Q
Enter port 3 tag type (none,802.1Q): 802.1Q
Enter port 4 tag type (none,802.1Q): 802.1Q
Enter port 5 tag type (none,802.1Q): 802.1Q
Enter port 21 tag type (none,802.1Q): 802.1Q
Enter VLAN Name {?} [ ]: vlantag3

Bridge VLAN Define Example (3900)

This example shows a port-based VLAN that includes two untagged ports and a tagged port.

Select menu option (bridge/vlan): define
Enter VID (1-4094) [3]: 3
Select bridge ports (1-27|all|?): 3-5
Configure per-port tagging? (n,y) [y]: y
Enter port 3 tag type (none, 802.1Q) [none]: none
Enter port 4 tag type (none, 802.1Q) [none]: none
Enter port 5 tag type (none, 802.1Q) [none]: 802.1Q
Enter VLAN name {?} [ ]: Sales

bridge vlan modify (3500/9000 Layer 3)

For CoreBuilder 9000: Applies to Layer 3 switching modules only.

Changes an existing port-based, protocol-based, or network-based VLAN definition on the CoreBuilder 3500 system or CoreBuilder 9000 Layer 3 module.

To use this command on the SuperStack II Switch 3900 or Switch 9300, the CoreBuilder 9400, and CoreBuilder 9000 Layer 2 modules, see "bridge vlan modify (3900/9300/9400/ 9000 Layer 2)" next.

Valid Minimum Abbreviation

b v modi

Important Considerations

Options

Prompt

Description

Possible Values

[Default]

VLAN interface index

System-assigned index number that identifies a VLAN

1 (if you have only the default VLAN)

VID

Unique, user-defined integer used by global management operations

1 - 4094

Current VID

Bridge ports

Index numbers of the bridge ports that belong to the VLAN. To add trunked ports, specify the anchor port of the trunk.

Current ports in the VLAN

Protocol suite

One or more protocol suites that you want to specify for the VLAN

Current protocol type

Modify Layer 3 address? (IP VLAN)

Whether you want to modify the Layer 3 information for the VLAN

y

Layer 3 address and mask (IP VLAN)

Optional fields (IP network and mask) used to set up flood domains for overlapping IP VLAN subnetworks

Any valid IP network address and mask

Current address and mask

Per-port tagging

Whether you want to modify the per-port 802.1Q VLAN tagging. You are prompted to answer for each port that you specified.

y

Tag type

Either no tagging or IEEE 802.1Q tagging (the VID)

Current tag type for each port

VLAN name

Unique, user-defined name that identifies members of the VLAN. If you use spaces, put quotation marks around the VLAN name.

Up to 32 ASCII characters or spaces

Current name

Procedure

To modify information for a VLAN, follow these steps:

1 .   Select the VLAN interface index.

2 .   Enter the VLAN identification (VID) number.

3 .   Specify the index numbers of the bridge ports.

4 .   Specify one or more protocol suites.

If you have selected the IP protocol suite, proceed with step 5. If you did not define an IP protocol suite for this VLAN, proceed to step 7.

5 .   To modify the Layer 3 address information:

a .   Enter y to modify the Layer 3 addressing.

b .   Enter the Layer 3 network address.

c .   Enter the Layer 3 subnet mask. To accept the default or existing value in brackets [ ], press Return or Enter.

If you do not want to modify the Layer 3 addressing, enter n

6 .   Specify whether you want to modify per-port tagging.

7 .   If you want to modify per-port tagging, enter the new tag type for the port (none or 802.1Q).

8 .   If you have specified that you want to modify more than one port, enter a tag type for each port.

9 .   Enter a new VLAN name or keep the current name.

The VLAN name can include up to 32 ASCII characters, including spaces. If you include spaces, put quotation marks around the VLAN name.

Bridge VLAN Modify Example (9000 Layer 3)

This example shows the steps to modify the per-port tagging for a protocol-based VLAN on a Layer 3 module. In this example, front-panel port 5 is changed to have IEEE 802.1Q tagging, and its associated device is IEEE 802.1Q enabled.

CB9000@slot2.1 [12-E/FEN-TX-L3] (bridge/vlan): modify
Select VLAN interface index {1-5|?}: 5
Enter VID (1-4094) [5]: 5
Select bridge ports (1-13|all|?) [1-5,13]: 1-5,13
Enter protocol suite
(IP,IPX,Apple,XNS,DECnet,SNA,Vines,X25,NetBIOS,unspecified, IPX-II,IPX-802.2,IPX-802.3) [IPX-802.3]: IPX-802.3
Enter protocol suite ('q' to quit) (IP,IPX, Apple, XNS, DECnet,SNA,Vines,X25,NetBIOS,IPX-II,IPX-802.2): q
Modify per-port tagging? (n,y) [y]: y
Enter port 1 tag type (none,802.1Q) [none]: none
Enter port 2 tag type (none,802.1Q) [none]: none
Enter port 3 tag type (none,802.1Q) [none]: none
Enter port 4 tag type (none,802.1Q) [none]: none
Enter port 5 tag type (none,802.1Q) [none]: 802.1Q
Enter port 13 tag type (none,802.1Q) [802.1Q]: 802.1Q
Enter VLAN Name {?} [IPX]: IPX1

Bridge VLAN Modify Example (3500)

This example shows the steps to modify the member ports and per-port tagging for an IP VLAN.

Select menu option: bridge vlan modify
Select VLAN interface index {1-2|?}: 2
Enter VID (1-4094) [2]: 2
Select bridge ports (1-4, 6, 9-13|all|?) [3,6,9]: 9,11
Enter protocol suite
(IP,IPX,Apple,XNS,DECnet,SNA,Vines,X25,NetBIOS,unspecified, IPX-II,IPX-802.2,IPX-802.3, IPX-802.2-SNAP) [IP]: IP
Enter protocol suite ('q' to quit) (IPX,Apple,XNS,DECnet,SNA,Vines,X25,NetBIOS,IPX-II, IPX-802.2, IPX-802.3, IPX-802.2-SNAP): q
Modify layer 3 address? (n,y) [y]:
Enter layer 3 address [158.101.152.0]:
Enter layer 3 mask [255.255.255.0]:
Modify per-port tagging? (n,y) [y]: y
Enter port 9 tag type (none,802.1Q) [none]: 802.1Q
Enter port 11 tag type (none,802.1Q) [none]: 802.1Q
Enter VLAN Name {?} [IP1]: IP1

bridge vlan modify (3900/9300/9400/ 9000 Layer 2)

Changes a port-based VLAN definition on the indicated system Layer 2 module. See "Important Considerations" for information on when changes take effect.

To use this command on the CoreBuilder 3500 or CoreBuilder 9000 Layer 3 modules, see the "bridge vlan modify (3500/9000 Layer 3)" earlier in this chapter.

Valid Minimum Abbreviation

b v modi

Important Considerations

Options

Prompt

Description

Possible Values

[Default]

VLAN interface index

System-assigned index number that identifies a VLAN

1 (if you have only the default VLAN)

VID

Unique, user-defined integer used by management operations

1 - 4094

Current VID

Bridge ports

Index numbers of the bridge ports that belong to the VLAN. To add trunked ports, specify the anchor port of the trunk.

Current ports in VLAN

Per-port tagging

Whether you want to configure 802.1Q VLAN tagging. You are prompted to answer for each port that you selected.

y

Tag type

Either no tagging or IEEE 802.1Q tagging (the VID)

Current tag type for each port

VLAN name

Unique, user-defined name that identifies members of the VLAN. If you use spaces, put quotation marks around the VLAN name.

Up to 32 ASCII characters or spaces

Current name

Procedure

1 .   Enter the VLAN interface index.

2 .   Enter a VLAN identification (VID) number or keep the default in brackets.

3 .   Specify the index numbers of the bridge ports.

4 .   Specify whether you want to modify per-port tagging.

5 .   If you modify per-port tagging, enter the new tag type for the port (none or 802.1Q).

6 .   If you have defined more than one port, enter a tag type for each port.

7 .   Enter a new VLAN name or keep the current name.

The VLAN name can include up to 32 ASCII characters, including spaces. If you include spaces, put quotation marks around the VLAN name.

Bridge VLAN Modify Example (9000 Layer 2)

This example shows the removal of two ports from a port-based VLAN that includes tagged front-panel ports and a tagged backplane port (port 21).

CB9000@slot 10.1 [20-E/FEN-TX-L2] (bridge/vlan): modify
Select VLAN interface index {1-3|?}: 3
Enter VID (1-4095) [3]: 3
Select bridge ports (1-22|all|?) [1-5,21]: 1-3,21
Configure per-port tagging? (n,y) [y]: y
Enter port 1 tag type (none,802.1Q) [802.1Q]: 802.1Q
Enter port 2 tag type (none,802.1Q) [802.1Q]: 802.1Q
Enter port 3 tag type (none,802.1Q) [802.1Q]: 802.1Q
Enter port 21 tag type (none,802.1Q) [802.1Q]: 802.1Q
Enter VLAN Name {?} [vlan3]: vlantag3

Bridge VLAN Modify Example (3900)

This example shows changes in the per-port tagging type.

Select menu option (bridge/vlan): modify
Select VLAN interface index {1-2|?}: 2
Enter VID (1-4094) [2]:
Select bridge ports (1-27|all|?) [2-6]:
Modify per-port tagging? (n,y) [y]:
Enter port 2 tag type (none,802.1Q) [none]: 802.1Q
Enter port 3 tag type (none,802.1Q) [none]: 802.1Q
Enter port 4 tag type (none,802.1Q) [none]: 802.1Q
Enter port 5 tag type (none,802.1Q) [none]: 802.1Q
Enter port 6 tag type (none,802.1Q) [none]: 802.1Q
Enter VLAN name [v2]: v2mktg

bridge vlan remove

Deletes a VLAN definition.

Valid Minimum Abbreviation

b v r

Important Consideration

Options

Prompt

Description

Possible Values

[Default]

VLAN interface index

System-assigned index number that is associated with the VLAN

-

Continue verification (9000 Layer 2 and Layer 3

Whether you want to continue with the VLAN removal, even though the removal may take a few minutes to complete.

y

Bridge VLAN Remove Example (3500)

bridge vlan mode

Determines whether data with a unicast MAC address can be forwarded between VLANs.

Valid Minimum Abbreviation

b v mode

Important Considerations

Options

Prompt

Description

Possible Values

[Default]

VLAN mode

Selected VLAN mode for the entire system

allOpen (factory default), or current value

bridge vlan stpMode

For CoreBuilder 9000: Applies to Layer 3 switching modules only.

If allClosed mode is enabled, allows the system to ignore the Spanning Tree Protocol (STP) state for a specified VLAN interface or all interfaces.

Valid Minimum Abbreviation

b v st

Important Considerations

Options

Prompt

Description

Possible Values

[Default]

VLAN interface index

System-assigned index number that is associated with the VLAN

-

STP state

Whether you want to ignore the STP state for the VLAN index

disabled

Bridge VLAN STP Mode Example (3500)

[previous] Clear Spacer [next]