DGS-6604
m
vlan-tunnel ingress checking
CLI Reference Guide
927
vlan-tunnel ingress checking
Use this command to specify to drop the C-tagged packets that do not match any
VLAN encapsulation pair or remarking pair. Use the no form of this command to
allow the unmatched packet to be forwarded.
vlan-tunnel ingress-checking
no vlan-tunnel ingress-checking
Syntax
None
Default
Disabled
Command Mode
Interface configuration (only available for a UNI port)
Usage Guideline
If the receiving packet is tagged, the VLAN tunnel table (including VLAN
encapsulation and VLAN remarking) is searched using the packet VLAN ID and
the ingress port. If there is an entry missing, then the packet can optionally be
dropped or have a SP VLAN (service provider VLAN) tag added based on the
VLAN lookup tables (MAC, Subnet, Protocol, Port VLAN ID). When VLAN tunnel
ingress filtering is enabled, the translation missed packets are dropped. If it has
an SP VLAN tag added to the translation missed packet and forward to the SP
VLAN, it is referred to as VLAN tunnel ingress-checking disabled.
Examples
This example shows how to enable the VLAN tunnel ingress-checking Ethernet
eth3.1
Verify the settings by entering
show vlan-tunnel
command.
Switch(config)#interface eth3.1
Switch(config-if)#vlan-tunnel ingress-checking