802.1Q (Q-in-Q) BPDU Tunneling
In Q-in-Q BPDU tunneling, a customer packet transferred through the service provider network is tagged twice (except for untagged customer traffic which has only one outer tag). Apart from the customer’s 802.1Q VLAN tags (C-VLAN), a service VLAN tag (S-VLAN) is also added on all the frames. By adding different VLAN tags for each customer, traffic (control/protocol/bpdu for which tunneling is enabled) from different customers can be segregated and transferred throughout the service provider network without any VLAN conflict. Also, the service provider network is transparent to the customer and can run STP (PVST, RSTP, MSTP), LACP, CDP, and LLDP seamlessly using the Layer 2 tunneling.
How Q-in-Q BPDU Tunneling Works
When Q-in-Q BPDU tunneling is enabled, the service provider (ingress) edge device receives the BPDU packets and delivers the packets to the CPU along with C-VLAN and S-VLAN information. Upon ingress to the service provider network, the protocol or BPDU MAC address is replaced with a tunnel MAC address and is sent across the service provider network. Intermediate devices on the service provider network forward the frame as an unknown multicast packet. Upon egress from the service provider network to the customer network, the tunnel MAC packets are decapsulated and delivered to the customer edge device. For Layer 2 protocols such as LACP and STP to converge properly, point-to-point connections must be emulated for each port using a unique customer-to-service VLAN.
In the following topology, Customer X site A and Customer X site B are connected in the service provider network through Q-in-Q BPDU tunneling. Both data and control packets coming from the customer site with customer VLAN (C-VLAN) are double-tagged with a Service VLAN (S-VLAN).
The Protocol or BPDU packet format at various stages is shown in the following topology.
Q-in-Q BPDU tunneling does not affect any Class of Service (CoS) values that are configured on the C-VLAN. Ingress priority and CoS settings from the C-VLAN are copied to the S-VLAN. CoS values do not change in the reverse direction (S-VLAN to C-VLAN).
To add a specific check for VTP at tunnel egress, VTP is tunneled with CDP tunnel
enabled using the
cdp enable CLI. You must also run the
cdp run CLI to enables the device to intercept and display CDP messages. For more information
on CLIs, refer to the
RUCKUS FastIron Command Reference.

