Layer 2 Support for OpenFlow Hybrid Mode

The following Layer 2 features are supported in the OpenFlow hybrid mode on protected VLANs and unprotected VLANs:

  • Layer 2 switching and MAC learning
  • STP
  • LLDP, FDP, and CDP
  • LACP

The following diagram shows the flow for an ingress packet.

Packet Flow Diagram for Layer 2 Support

Layer 2 Switching and MAC Learning

Source address MAC learning happens on the protected VLANs and on configured unprotected VLANs. The unconfigured VLAN traffic is dropped or sent to the controller based on the default rule.

On untagged VLANs, untagged traffic is flooded and the source is learned. The tagged traffic that matches the untagged VLAN is dropped. If the untagged VLAN becomes a protected VLAN, flow rules do not apply to untagged traffic. When the VLAN is configured as unprotected, the untagged traffic follows the matching flow rule in the presence of a flow.

When the tagged VLAN is a protected VLAN, flow rules do not apply on matching tagged traffic. If the VLAN is configured as an unprotected VLAN, the flow matching tagged traffic follows the flow rule in the presence of flow. In the absence of flow, the default rule applies.

STP

The Spanning Tree Protocol (STP) can be enabled in the following ways:

  • When enabled globally, STP runs on all configured VLANs. STP runs on the OpenFlow hybrid ports with both tagged or untagged configured VLANs. The OpenFlow non-hybrid ports are not part of the STP instances.
  • On per-VLAN basis: When STP is enabled on a VLAN, all ports (OpenFlow hybrid ports) become part of the STP instance.
  • On a per-port basis: STP can be enabled on OpenFlow hybrid ports. STP is blocked on normal OpenFlow ports, so these ports are not part of any VLAN or STP instance.

In the absence of flows, STP works normally on OpenFlow hybrid ports. If the VLAN that is running STP becomes a protected VLAN, then OpenFlow flows are bypassed, but STP runs effectively. When the STP VLAN is configured as an unprotected VLAN and a matching OpenFlow rule is present, the OpenFlow rule overrides STP on both ingress and egress.

The STP Bridge Protocol Data Units (BPDUs) are tagged packets, which contain the VLAN ID on which the STP instance is running.

When you add a flow to match control packets, it may affect the convergence of Layer 2 protocols. For proper protocol convergence, the VLANs that are running STP on OpenFlow hybrid ports should be protected VLANs.

LLDP, FDP, and CDP

The Link Layer Discovery Protocol (LLDP), Foundry Discovery Protocol (FDP), and Cisco Discovery Protocol (CDP) are supported on OpenFlow hybrid ports. The LLDP BPDUs are untagged packets. When untagged VLANs are protected, protocol convergence happens. When untagged VLANs are not protected and a matching OpenFlow rule is present, the PDUs are not processed. They take the OpenFlow path, and protocol convergence is affected.

LACP

The Link Aggregation Control Protocol (LACP) is supported on a keep-alive LAG (singleton link) on the OpenFlow hybrid port. The LACP PDUs are untagged packets. When untagged VLANs become protected, protocol convergence happens. When untagged VLANs are not protected and a matching OpenFlow rule is present, the PDUs are not processed. They take the OpenFlow path, and protocol convergence is affected.

Layer 2 Support Limitations

  • Layer 2 hybrid mode is supported in Layer 2 and Layer 23 modes only.
  • LACP support on a keep-alive LAG is limited to OpenFlow hybrid ports only.
  • Traffic is not forwarded on STP blocked ports, even when a matching OpenFlow flow is present.
  • Source MAC learning happens for an unprotected VLAN in the presence of a matching OpenFlow flow as well.