Supporting untagged traffic on OpenFlow hybrid ports on protected and unprotected VLANs

Untagged traffic is supported on protected VLANs or configured unprotected VLANs supporting IP traffic on an OpenFlow hybrid port. You can configure an untagged VLAN as a protected VLAN or an unprotected VLAN.
Note: To set the flow, the VLAN id is must if the port is untagged and have unprotected VLAN. Without the VLAN id, error is shown and the flow installation cannot be done.
Note: The openflow L2 or L3 lookup does not work on hybrid interfaces for default VLAN.
Note: On the RUCKUS ICX 7650, the following restrictions apply:
  • Ports with OpenFlow hybrid mode enabled cannot be added to an untagged VLAN group.
  • OpenFlow hybrid mode cannot be enabled on ports added to an untagged VLAN group.

OpenFlow port as an untagged member of only one VLAN

Assuming the port is configured as an OpenFlow hybrid port, the following cases are the configuration options to consider.

Case 1: When a port is added as untagged in an unprotected VLAN.

The configuration is accepted and untagged traffic on port 1/1/1, for example, is forwarded as per the OpenFlow rule if a matching rule is present. If a matching OpenFlow rule is not present, untagged traffic on port 1/1/1 is routed as per the routing table. If a route is not present, untagged traffic is processed according to the default OpenFlow rule (drop or send to the controller). DMAC should be the router MAC address to trigger Layer 3 routing as non-OpenFlow ports.

device(config-if-e10000-1/1/1)# openflow enable layer3 hybrid-mode
device(config-if-e10000-1/1/1)# vlan 300
device(config-vlan-300)# untagged ethernet 1/1/1

Case 2: When a port is added as untagged in a protected VLAN.

The configuration is accepted and untagged traffic on port 1/1/1, for example, is forwarded as per the route table.

device(config-if-e10000-1/1/1)# openflow enable layer3 hybrid-mode
device(config-if-e10000-1/1/1)# openflow protected-vlans 400
device(config-if-e10000-1/1/1)# vlan 400
device(config-vlan-400)# untagged ethernet 1/1/1

Case 3: When a port is removed as untagged from a configured unprotected VLAN.

The configuration is accepted and untagged traffic on port 2/1/1 is forwarded as per the OpenFlow rule if a matching rule is present. If a matching OpenFlow rule is not present, untagged traffic is processed according to the default OpenFlow rule (drop or send to the controller).

device(config-vlan-300)# no untagged ethernet 1/1/1

Case 4: When a port is removed as untagged from a protected VLAN.

The configuration is accepted and untagged traffic on port 1/1/1 is dropped.

device(config-vlan-400)# no untagged ethernet 1/1/1

Case 5: An untagged unprotected VLAN is configured as a protected VLAN on a port.

The configuration is accepted and untagged traffic on port 1/1/1 is forwarded as per the route table.

device(config-if-e10000-1/1/1)# openflow enable layer3 hybrid-mode
device(config-if-e10000-1/1/1)# vlan 300
device(config-vlan-300)# untagged ethernet 1/1/1
device(config-if-e10000-1/1/1)# openflow protected-vlans 300

Case 6: An untagged protected VLAN is removed from the port making it an untagged configured unprotected VLAN.

The configuration is accepted and untagged traffic on port 1/1/1, for example, is forwarded as per the OpenFlow rule if a matching rule is present. If a matching OpenFlow rule is not present, untagged traffic on port 1/1/1 is routed as per the routing table. If a route is not present, untagged traffic is processed according to the default OpenFlow rule (drop or send to the controller).

device(config-if-e10000-1/1/1)# openflow enable layer3 hybrid-mode
device(config-if-e10000-1/1/1)# openflow protected-vlans 400
device(config-if-e10000-1/1/1)# vlan 400
device(config-vlan-400)# untagged ethernet 1/1/1
device(config-if-e10000-1/1/1)# no openflow protected-vlans 400

Case 7: A configured untagged unprotected VLAN is deleted.

The configuration is accepted and untagged traffic on port 1/1/1 is forwarded as per the OpenFlow rule if a matching rule is present. If a matching OpenFlow rule is not present, untagged traffic is processed according to the default OpenFlow rule (drop or send to the controller).

device(config)# no vlan 300

Case 8: An untagged protected VLAN is deleted.

The configuration is accepted and untagged traffic on port 1/1/1 is dropped.

device(config)# no vlan 400