Operation Manual – VLAN-VPN
H3C S5600 Series Ethernet Switches
Chapter 1 VLAN-VPN Configuration
1-4
To do...
Use the command...
Remarks
Enter system view
system-view
—
Enter Ethernet port view
interface interface-type
interface-number
—
Enable the inner-to-outer
tag priority replicating
feature
vlan-vpn inner-cos-trust
enable
Enable the inner-to-outer
tag priority mapping
feature and create a
priority mapping
vlan-vpn priority
old-priority remark
new-priority
Either of the two
configurations is required.
By default, neither the
inner-to-outer tag priority
replicating feature nor the
inner-to-outer tag priority
mapping feature is
enabled.
Caution:
z
If you have configured the port priority (refer to
QoS-QoS Profile
Configuration
part
in this manual), you will be prompted that the port priority configured for the current
port gets invalid after you enable the inner-to-outer tag priority replicating feature.
z
The inner-to-outer tag priority replicating feature is mutually exclusive with the
inner-to-outer tag priority mapping feature.
1.3 Displaying and Maintaining VLAN-VPN Configuration
To do...
Use the command...
Remarks
Display the VLAN-VPN
configurations of all the ports
display port vlan-vpn
Available in any view
1.4 VLAN-VPN Configuration Example
1.4.1 Transmitting User Packets through a Tunnel in the Public Network by
Using VLAN-VPN
I. Network requirements
As shown in
Figure 1-4
, Switch A and Switch B are both S5600 series switches. They
connect the users to the servers through the public network.
z
PC users and PC servers are in VLAN 100 created in the private network, while
terminal users and terminal servers are in VLAN 200, which is also created in the
private network. The VLAN VPN connection is established in VLAN 1040 of the
public network.