Advanced Traffic Management Guide K/KA/KB.15.15
Table 33 Impacts of QinQ configurations on other switch features
Impacts of QinQ configurations and allowed operationsSwitch feature
In QinQ mixed VLAN or S-VLAN modes:
• On double-tagged frames , the VID applicable when applying ACLs will be the S-VLAN tag
and not the C-VLAN tag.
ACLs
In QinQ mixed VLAN mode:aaa
• auth-vid/unauth-vid configuration is not supported on S-VLAN ports; the auth-vid/unauth-vid
cannot be an S-VLAN id.
• If a port that is a member of C-VLANs is configured with auth-vid or unauth-vid and it needs to
be added to the S-VLAN domain, the auth/unauth configuration must first be undone.
In QinQ mixed VLAN mode:
• ARP-protect is not supported on S-VLANs, nor on S-VLAN ports.
arp-protect
In QinQ VLAN or S-VLAN modes:
• CDP frames are consumed at customer network ports, if CDP is enabled on the device port,
and the customer device shows up as a CDP neighbor on the customer-network port. If not, the
frames are dropped.
CDP
In QinQ mixed VLAN or S-VLAN modes:DHCP
• DHCP relay applies only to C-VLANs.
• DHCP snooping is not supported on S-VLANs.
In QinQ S-VLAN mode:
• directed-broadcast is not supported on provider core devices.
directed-broadcast
In QinQ mixed VLAN mode:GVRP
• S-VLAN ports cannot be GVRP enabled.
• Regular VLANs will participate in C-VLAN GVRP if enabled to do so. S-VLANs will tunnel all
C-VLAN GVRP frames through.
• An explicit GVRP disable on a port is a prerequisite for moving the port to an S-VLAN domain.
• Port-based interfaces do not have support for provider-GVRP protocols. Provider GVRP frames
received at S-VLAN interfaces will be dropped.
• If a VLAN being configured as an S-VLAN is already a GVRP VLAN on the switch, this S-VLAN
creation would be blocked.
338 QinQ (Provider bridging)










