VLAN Tagging
VLAN Tagging and 802.1q Configuration¶
VLAN (Virtual Local Area Network) tagging enables logical segmentation of a physical network using the IEEE 802.1q protocol. This standard adds a 4-byte VLAN tag to Ethernet frames, allowing multiple VLANs to coexist on a single physical link. VLAN tagging is critical for managing traffic isolation, trunking, and inter-VLAN routing in enterprise and cloud environments.
Linux systems use the ip command (via iproute2) and kernel modules to configure VLAN interfaces. Below, we detail the process of creating VLAN interfaces and managing VLAN tagging. Note that trunking configuration (e.g., allowing multiple VLANs on a physical port) is typically handled by network switches, not Linux kernel commands.
Creating VLAN Interfaces¶
To create a VLAN interface, use the ip command to define a virtual interface on top of a physical interface. The VLAN ID (1–4094) is specified in the type vlan clause.
# Create a VLAN interface (e.g., VLAN 10 on eth0)
sudo ip link add link eth0 name eth0.10 type vlan id 10
This creates a virtual interface eth0.10 associated with VLAN 10. To assign an IP address and bring the interface up:
Example: Full VLAN Setup¶
-
Create VLAN interfaces:
-
Assign IP addresses:
-
Bring interfaces up:
Verifying VLAN Configuration¶
Use the following commands to inspect VLAN interfaces and their status:
Check for entries like eth0.10 with the correct IP address and UP status.
Switch Trunking Configuration¶
Trunking enables multiple VLANs to traverse a single physical link between switches or between switches and end devices. VLAN trunking relies on the 802.1q protocol for tag insertion and negotiation. Below are examples for common switch vendors:
Cisco IOS¶
-switchport mode trunk enables trunking.-
switchport trunk allowed vlan specifies permitted VLANs.- 802.1q negotiation is handled via Dynamic Trunking Protocol (DTP).
Huawei Huawei Switches¶
-port link-type trunk configures the port as a trunk.-
port trunk allow-pass vlan defines allowed VLANs.- 802.1q tagging is enforced for VLAN traffic.
General Requirements¶
- Ensure switches are configured to accept VLAN tags (802.1q).
- Match VLAN IDs across interconnected devices.
- Verify trunk ports using commands like
show interfaces trunk(Cisco) ordisplay port trunk(Huawei).
Key Takeaways¶
- VLAN tagging (802.1q) enables logical network segmentation on physical links.
- Use
ip link addto create VLAN interfaces andip link setto configure them. - Trunking (allowing multiple VLANs on a physical port) is configured on network switches, not Linux. Ensure switches are set to accept VLAN tags for interoperability.
- Always verify VLAN configurations with
ipcommands to ensure proper tagging and routing.