4.1 Example: Configuring the QinQ VLAN
The QinQ-VLAN-based private line service can achieve the interconnection and secure
communication among branches in different areas within the enterprise private network.
Prerequisites
l
Network devices and lines must be in the normal state.
l
The authentication data of the access user must be configured on the BRAS.
l
The system is working properly.
Service Requirements
l
An enterprise requires to achieve the interconnection and secure communication between
its headquarters and the branches located in different areas through Layer 2 switching
network, and to isolate the data of different departments.
l
The access device uses xDSL or LAN access.
Networking
shows an example network for configuring the private line service.
The two branches of the enterprise are connected to the (metropolitan area network) MAN
through the MA5600T/MA5603T/MA5608T. The upper-layer network must work in the Layer
2 mode, and must forward packets according to the VLAN and the MAC address.
On the MA5600T/MA5603T/MA5608T, the attribute of the upstream VLAN of user packets is
configured as QinQ private line service. A VLAN tunnel is created in Layer 2/Layer 3 MAN
for transmitting data carrying the VLAN tag. Different VLAN IDs are used for different
departments to achieve user isolation and data security. In this way, the service packets of the
enterprise private network can be transparently transmitted through the public network, and the
two branches can communicate with each other securely.
SmartAX MA5600T/MA5603T/MA5608T Multi-service
Access Module
Commissioning and Configuration Guide
4 Configuration Example of the Private Line Service
Issue 01 (2014-04-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
390