802.1Q (Q-in-Q) BPDU Tunneling

BPDU tunneling over Q-in-Q enables a service provider to provide Layer 2 VPN connectivity between different customer sites. The service provider can give the customers an infrastructure to run various Layer 2 protocols and connect to all geographically-separated sites.

In Q-in-Q BPDU tunneling, a customer packet transferred through the service provider network is tagged twice (except for untagged customer traffic which has only one outer tag). Apart from the customer’s 802.1Q VLAN tags (C-VLAN), a service VLAN tag (S-VLAN) is also added on all the frames. By adding different VLAN tags for each customer, traffic (control/protocol/bpdu for which tunneling is enabled) from different customers can be segregated and transferred throughout the service provider network without any VLAN conflict. Also, the service provider network is transparent to the customer and can run STP (PVST, RSTP, MSTP), LACP, CDP, and LLDP seamlessly using the Layer 2 tunneling.

How Q-in-Q BPDU Tunneling Works

When Q-in-Q BPDU tunneling is enabled, the service provider (ingress) edge device receives the BPDU packets and delivers the packets to the CPU along with C-VLAN and S-VLAN information. Upon ingress to the service provider network, the protocol or BPDU MAC address is replaced with a tunnel MAC address and is sent across the service provider network. Intermediate devices on the service provider network forward the frame as an unknown multicast packet. Upon egress from the service provider network to the customer network, the tunnel MAC packets are decapsulated and delivered to the customer edge device. For Layer 2 protocols such as LACP and STP to converge properly, point-to-point connections must be emulated for each port using a unique customer-to-service VLAN.

In the following topology, Customer X site A and Customer X site B are connected in the service provider network through Q-in-Q BPDU tunneling. Both data and control packets coming from the customer site with customer VLAN (C-VLAN) are double-tagged with a Service VLAN (S-VLAN).

Q-in-Q Topology

Note: When Layer 2 protocol tunneling is enabled on a customer-connected interface of the service provider device, all the received tunnel protocol packets will be tunneled to the service network. To prevent any locally generated protocol packets (for example, STP or LLDP) on the service provider network from switching to the customer side, the corresponding protocols must be disabled on the device.

The Protocol or BPDU packet format at various stages is shown in the following topology.

Various Stages of Protocol or BPDU Packet Format

Q-in-Q BPDU tunneling does not affect any Class of Service (CoS) values that are configured on the C-VLAN. Ingress priority and CoS settings from the C-VLAN are copied to the S-VLAN. CoS values do not change in the reverse direction (S-VLAN to C-VLAN).

To add a specific check for VTP at tunnel egress, VTP is tunneled with CDP tunnel enabled using the cdp enable CLI. You must also run the cdp run CLI to enables the device to intercept and display CDP messages. For more information on CLIs, refer to the RUCKUS FastIron Command Reference.