Selective QinQ

Selective QinQ allows specific VLANs to be double-tagged with an outer VLAN, enabling precise traffic segregation, efficient VLAN management, and secure multi-tenant isolation across shared network infrastructure.

Feature Overview

Selective QinQ is an enhancement over standard QinQ, which applies a second VLAN tag (SVLAN) to all incoming frames, regardless of their inner VLAN ID (CVLAN). While standard QinQ is useful for extending VLAN space and encapsulating customer traffic across provider networks, it lacks flexibility in handling specific VLANs. Selective QinQ addresses this by tagging only the frames that match defined criteria—typically based on specific CVLANs or other attributes. This selective encapsulation allows for granular traffic control, improved VLAN scalability, and secured isolation of targeted VLANs.

Key Terms for Understanding Selective QinQ

  • CVLAN (Customer VLAN): Inner VLAN tag used to identify traffic within a customer's network.
  • SVLAN (Service VLAN): Outer VLAN tag added by the service provider to segregate and transport customer traffic across the provider’s network.
  • New CVLAN: Refers to a configurable customer VLAN (CVLAN) that can be added or used to replace an existing one during Selective QinQ tunneling.

How Selective QinQ Works

When traffic enters a configured switch interface, the system checks whether the frame's CVLAN matches a predefined list or range. If it matches, the switch encapsulates the frame with an additional outer VLAN tag, creating a double-tagged (QinQ) packet. This selective tagging ensures that only targeted VLANs are transported across the network using the outer service VLAN. Frames that do not match the configured CVLANs remain untagged or are handled according to other rules. This feature is particularly useful in service provider or multi-tenant environments where overlapping VLANs must be isolated and efficiently managed across shared infrastructure.

Requirements

The following requirements must be met to enable this functionality on the controller.

  • RUCKUS ICX devices must be running FastIron firmware version 10.0.20b_cd2 or later
  • SmartZone must be running version 7.1.1 or later
  • RUCKUS ICX models supported: ICX 7550, ICX 7650, ICX 7850, and ICX 8200
  • New CVLAN only supports the model ICX 8200

Considerations

Consider the following when configuring and using this feature:

  • CVLAN-to-SVLAN mapping must be unique per interface.
  • Only one new CVLAN is supported per port.
  • Only one untagged QinQ configuration is supported per port.
  • A maximum of 250 CVLAN entries can be created in a QinQ tunnel at once.

Limitations

Note the following limitations regarding this feature:

  • When configuring Selective QinQ with both an untagged CVLAN and enabling a new CVLAN, the port cannot have tagged VLANs or an untagged SVLAN configuration.
  • Selective QinQ without a new CVLAN and Selective QinQ with new cvlan cannot co-exist on the same switch.
  • Ports with a QinQ tunnel configuration cannot be part of a Link Aggregation Group (LAG).
  • Only port-level QinQ tunnel configuration is supported (no global or VLAN-based configuration).
  • The default VLAN cannot be an SVLAN.
  • Reserved VLANs cannot be used as an SVLAN.

Best Practices

Follow these best practices when using the Selective QinQ feature:

  • Always validate that your ICX firmware supports the features you are configuring.
  • Create topology diagrams with VLANs and port numbers for documentation to provide a clear visual representation of the network layout, making it easier to understand and troubleshoot.
  • Take configuration backups before and after making any changes to the network configuration to ensure that you can restore the network to its previous state in case of any issues or errors during the configuration changes.

Prerequisites

Follow these prerequisites when using the Selective QinQ feature.

  • The service VLAN must already exist throughout the network path towards it destination.