SNR S2989G-8TX — настройка функций безопасности для малых сетей [395/553]

Превью страниц Страница 395 / 553
SNR S2989G-48TX-DC [395/553] Flexible qinq configuration task list
S2989G-24TX Operation Manual
Chapter 6 Security Function Configuration
6-122
especially adaptive to small office network or small metropolitan area network using
layer-3 switch as backbone equipment.
There are two kinds of QinQ: basic QinQ and flexible QinQ, the priority of flexible
QinQ is higher than basic QinQ.
6.15.1.2 Basic QinQ
Basic QinQ based the port. After a port configures QinQ, whether the received packet
with tag or not, the device still packs the default VLAN tag for the packet. Using basic
QinQ is simple, but the setting method of VLAN tag is inflexible.
6.15.1.3 Flexible QinQ
Flexible QinQ based data flow. It selects whether pack the external tag and packs
what kind of the external tag by matching the material flow. For example: implement the
property of flexible QinQ according to the user’s VLAN tag, MAC address, IPv4/IPv6
address, IPv4/IPv6 protocol and the port ID of the application, etc. So, it can encapsulate
the external tag for the packet and implements different scheme by different users or
methods.
6.15.2
Flexible QinQ Configuration Task List
The match of flexible QinQ data flow uses policy-map rule of QoS to be sent, the
configuration task list is as follows:
1. Create class-map to classify different data flows
2. Create flexible QinQ policy-map to relate with the class-map and set the corresponding
operation
3. Bind flexible QinQ policy-map to port
1. Configure class map
Command
Explanation
Global mode
class-map <class-map-name>
no class-map <class-map-name>
Create a class-map and enter class-
map mode, the no command deletes
the specified class-map.
match {access-group <acl-index-or-name>
| ip dscp <dscp-list>| ip precedence
<ip-precedence-list>| ipv6 access-group
<acl-index-or-name>| ipv6 dscp
Set the match standard of class-map,
(classify data flow by ACL, CoS, VLAN
ID, IPv4 Precedent or DSCP, etc for
the class map); the no command

Содержание

666

Изучите основные и гибкие методы QinQ для настройки безопасности в малых офисных и метрополитенских сетях. Узнайте, как эффективно управлять VLAN и данными.