User Guide
Configuring IEEE 802.1Q Tunneling
3-133
3
Web – Click VLAN, 802.1Q VLAN, Port Configuration or Trunk Configuration. Fill in 
the required settings for each interface, click Apply.
Figure 3-77 Configuring VLANs per Port
CLI – This example sets port 3 to accept only tagged frames, assigns PVID 3 as the 
native VLAN ID, and then sets the switchport mode to hybrid.
Configuring IEEE 802.1Q Tunneling
IEEE 802.1Q Tunneling (QinQ) is designed for service providers carrying traffic for 
multiple customers across their networks. QinQ tunneling is used to maintain 
customer-specific VLAN and Layer 2 protocol configurations even when different 
customers use the same internal VLAN IDs. This is accomplished by inserting 
Service Provider VLAN (SPVLAN) tags into the customer’s frames when they enter 
the service provider’s network, and then stripping the tags when the frames leave 
the network. 
A service provider’s customers may have specific requirements for their internal 
VLAN IDs and number of VLANs supported. VLAN ranges required by different 
customers in the same service-provider network might easily overlap, and traffic 
passing through the infrastructure might be mixed. Assigning a unique range of 
VLAN IDs to each customer would restrict customer configurations, require intensive 
processing of VLAN mapping tables, and could easily exceed the maximum VLAN 
limit of 4096. 
QinQ tunneling uses a single Service Provider VLAN (SPVLAN) for customers who 
have multiple VLANs. Customer VLAN IDs are preserved and traffic from different 
customers is segregated within the service provider’s network even when they use 
the same customer-specific VLAN IDs. QinQ tunneling expands VLAN space by 
Console(config)#interface ethernet 1/3 4-116
Console(config-if)#switchport acceptable-frame-types tagged 4-171
Console(config-if)#switchport ingress-filtering 4-171
Console(config-if)#switchport native vlan 3 4-172
Console(config-if)#switchport mode hybrid 4-170
Console(config-if)#










