127
complete separation between traffic from different user groups. Moreover, the addition of
double-tagged space increases the number of available VLAN tags which allow service
providers to use a single SP-VLAN (Service Provider VLAN) tag per customer over the
Metro Ethernet network.
Preamble
SFD
D
A
S
A
Type/LEN
PAYLOAD FCS
Original frame
Preamble
SFD
D
A
S
A
TAG
TCI/P/C/VID
Type/LEN
PAYLOAD FCS
802.1q
Frame
Preamble
SFD
D
A
S
A
Outer Tag
or SP-Tag
Inner Tag
or C-Tag
TCI/P/C/VID
Type/LEN
PAYLOAD FCS
Double-
tagged
Frame
Double-Tagged Frame
As shown below in
“Q-in-Q Example” illustration, Headquarter A wants to communicate with
Branch 1 that is 1000 miles away. One common thing about these two locations is that they
have the same VLAN ID of 20, called C-VLAN (Customer VLAN). Since customer traffic will
be routed to service provider
‟s backbone, there is a possibility that traffic might be forwarded
insecurely, for example due to the same VLAN ID used. Therefore, in order to get the
information from Headquarter to Branch 1, the easiest way for the carrier to ensure security
to customers is to encapsulate the original VLAN with a second VLAN ID of 100. This
second VLAN ID is known as SP-VLAN (Service Provider VLAN) that is added as data
enters the service provider
‟s network and then removed as data exits. Eventually, with the
help of SP-Tag, the information sent from Headquarter to Branch 1 can be delivered with
customers
‟ VLANs intactly and securely.
Q-in-Q Example
Summary of Contents for FOS-3124 SERIES
Page 202: ...202 Restart DHCP service ...