Supporting Untagged Traffic on OpenFlow Hybrid Ports on Protected and Unprotected VLANs

Untagged traffic is supported on protected VLANs or configured unprotected VLANs supporting IP traffic on an OpenFlow hybrid port. You can configure an untagged VLAN as a protected VLAN or an unprotected VLAN.
Note: The VLAN ID must be used to set the flow if the port is untagged and supports an unprotected VLAN. Without the VLAN ID, an error message is displayed and the flow installation cannot be completed. For example, openflow hybrid-interface cannot be configured on an untag-port as shown below.
device(config-if-e1000-1/1/1)#openflow enable layer2 hybrid-mode
Error: openflow hybrid-mode not enabled on port 1/1/1 as it is untag port in a
vlan.
Note: On the RUCKUS ICX 7650, the following restrictions apply:
  • Ports with OpenFlow hybrid mode enabled cannot be added to an untagged VLAN group.
  • OpenFlow hybrid mode cannot be enabled on ports added to an untagged VLAN group.

OpenFlow Port as an Untagged Member of Only One VLAN

Assuming the port is configured as an OpenFlow hybrid port, the following cases are the configuration options to consider.

Case 1: When a port is added as untagged in an unprotected VLAN.

The configuration is accepted and untagged traffic on port 1/1/1, for example, is forwarded according to the OpenFlow rule if a matching rule is present. If a matching OpenFlow rule is not present, untagged traffic on port 1/1/1 is routed according to the routing table. If a route is not present, untagged traffic is processed according to the default OpenFlow rule (drop or send to the controller). DMAC should be the router MAC address to trigger Layer 3 routing as non-OpenFlow ports.

device(config-if-e10000-1/1/1)# openflow enable layer3 hybrid-mode
device(config-if-e10000-1/1/1)# vlan 300
device(config-vlan-300)# untagged ethernet 1/1/1

Case 2: When a port is added as untagged in a protected VLAN.

For RUCKUS ICX 7150, ICX 7650, and , the configuration is accepted and untagged traffic on port 1/1/1, for example, is forwarded according to the route table.

device(config-if-e10000-1/1/1)# openflow enable layer3 hybrid-mode
device(config-if-e10000-1/1/1)# openflow protected-vlans 400
device(config-if-e10000-1/1/1)# vlan 400
device(config-vlan-400)# untagged ethernet 1/1/1

For , when there is a protected VLAN configured on an openflow interface without associating the interface to the said VLAN. It is possible for the device to start flooding across all the openflow interfaces rather than dropping the same by the L2 engine. Hence it is recommended not to configure the protected VLAN without associating the interface to the VLAN.

Case 3: When a port is removed as untagged from a configured unprotected VLAN.

The configuration is accepted and untagged traffic on port 1/1/1 is forwarded according to the OpenFlow rule if a matching rule is present. If a matching OpenFlow rule is not present, untagged traffic is processed according to the default OpenFlow rule (drop or send to the controller).

device(config-vlan-300)# no untagged ethernet 1/1/1

Case 4: When a port is removed as untagged from a protected VLAN.

The configuration is accepted and untagged traffic on port 1/1/1 is dropped.

device(config-vlan-400)# no untagged ethernet 1/1/1

Case 5: An untagged unprotected VLAN is configured as a protected VLAN on a port.

For RUCKUS ICX 7150, ICX 7650, and , the configuration is accepted and untagged traffic on port 1/1/1 is forwarded according to the route table.

device(config-if-e10000-1/1/1)# openflow enable layer3 hybrid-mode
device(config-if-e10000-1/1/1)# vlan 300
device(config-vlan-300)# untagged ethernet 1/1/1
device(config-if-e10000-1/1/1)# openflow protected-vlans 300

For , when there is a protected VLAN configured on an openflow interface without associating the interface to the said VLAN. It is possible for the device to start flooding across all the openflow interfaces rather than dropping the same by the L2 engine. Hence it is recommended not to configure the protected VLAN without associating the interface to the VLAN.

Case 6: An untagged protected VLAN is removed from the port making it an untagged configured unprotected VLAN.

The configuration is accepted and untagged traffic on port 1/1/1, for example, is forwarded according to the OpenFlow rule if a matching rule is present. If a matching OpenFlow rule is not present, untagged traffic on port 1/1/1 is routed according to the routing table. If a route is not present, untagged traffic is processed according to the default OpenFlow rule (drop or send to the controller).

device(config-if-e10000-1/1/1)# openflow enable layer3 hybrid-mode
device(config-if-e10000-1/1/1)# openflow protected-vlans 400
device(config-if-e10000-1/1/1)# vlan 400
device(config-vlan-400)# untagged ethernet 1/1/1
device(config-if-e10000-1/1/1)# no openflow protected-vlans 400

Case 7: A configured untagged unprotected VLAN is deleted.

The configuration is accepted and untagged traffic on port 1/1/1 is forwarded according to the OpenFlow rule if a matching rule is present. If a matching OpenFlow rule is not present, untagged traffic is processed according to the default OpenFlow rule (drop or send to the controller).

device(config)# no vlan 300

Case 8: An untagged protected VLAN is deleted.

The configuration is accepted and untagged traffic on port 1/1/1 is dropped.

device(config)# no vlan 400