Aggregated VLANs (Tag Profiles)

The IEEE 802.1ad (Q-in-Q) standard defines a tunneling mechanism that encapsulates an inner VLAN tag with TPID 0x8100 inside an outer tag with TPID 0x88a8 for transport across service provider networks. However, RUCKUS ICX devices offer an alternative implementation using tag profiles. This approach deviates from the typical standard but is designed to improve compatibility with third-party devices that only recognize TPID 0x8100.

Note: When a global tag profile is configured with a specific TPID and enabled on a customer-facing port (configured as untagged), the device treats incoming frames with a different TPID as untagged. These frames—potentially carrying multiple VLANs—are then encapsulated with an additional outer tag using TPID 0x8100 and the VLAN configured as untagged on that port. The result is a double-tagged frame, both tags using TPID 0x8100, where the original VLAN is nested under the tag profile VLAN.

VLAN aggregation allows multiple VLANs to be encapsulated within a single outer VLAN tag. This capability is particularly beneficial in Virtual Private Network (VPN) implementations, where it enables the provisioning of a private, dedicated Ethernet connection. Through VLAN aggregation, individual clients can transparently access their respective subnets across multiple interconnected networks.

Multiple customer VLANs can be encapsulated within a single service VLAN using VLAN aggregation. This approach enables the creation of isolated Layer 2 paths over a shared physical infrastructure. It is particularly effective in VPN deployments, where each client requires a private, dedicated Ethernet connection to transparently access its subnet across multiple network segments.

Consider the following about VLAN aggregation:

  • Service VLAN as a Container: A service VLAN encapsulates multiple customer VLANs, with each customer VLAN operating as a distinct Layer 2 circuit between two endpoints.
  • Transparent Connectivity: Devices connected at either end of a customer VLAN communicate as if they are directly linked, with the underlying network infrastructure remaining completely transparent.
  • Scalability: Up to 4,094 customer VLANs can be aggregated within a single service VLAN. On RUCKUS ICX devices, this enables a theoretical maximum of 16,760,836 isolated VLAN circuits (4094 × 4094).
  • Traffic Isolation: Devices within one customer VLAN are completely isolated from those in other VLANs, ensuring strict traffic separation and privacy for each client.
  • Flexible Topologies: VLAN aggregation supports both point-to-point and point-to-multipoint configurations, making it suitable for a wide range of deployment scenarios.

Conceptual Model of the Super Aggregated VLAN Application

Each client connected to an edge device is assigned to a unique port-based VLAN, functioning similarly to an Asynchronous Transfer Mode (ATM) channel. These individual client VLANs are aggregated by the edge device into a single service VLAN, which acts like an ATM path for transport across the core network.

The edge device forwards the aggregated VLAN traffic through the core, which may consist of multiple intermediate devices. At the opposite end of the core, another edge device de-aggregates the service VLAN, separating it back into the original client VLANs. These VLANs are then forwarded to their respective clients.

From the client's perspective, the connection behaves as a direct point-to-point link, with the underlying network infrastructure remaining completely transparent.