VLAN 1 does not show up when allow-pass

Created: Feb 20, 2020 12:16:32Latest reply: Feb 20, 2020 14:43:28 129 10 0 0
  Rewarded HiCoins: 0 (problem resolved)

Hello everyone


I'm trying to get my head around this. Currently our whole network is built with HPE switches and we're currently swichting to Huawei switches.

The scenario:


FW (sets VLANs per Network) -> Core Switch -> Access Switch -> Huawei Switch


VLAN:

1 to 20 (VLAN 1 is for our Client Network)


What i'm trying to do:

I want to configure the Huawei switch like the current access switch which will be replaced by the Huawei Switch.

HPE Switch:

Trunk2:

    tagged 1-20

    lacp


Huawei Switch:

interface Eth-Trunk2

    port link-type trunk

    port trunk allow-pass vlan 2 to 9

    mode lacp


interface 0/0/13 to 0/0/24

    port link-type access

    undo poe enable


If i connect a client to those ports i cant get an IP from our DHCP. I can't get VLAN 1 working on the Huawei switch and i dont know why?

What happens when a trunk prot with pvid 1 gets a tagged packed with vlan 1?


What have i tried?

[sw-Eth-Trunk2]port trunk allow-pass vlan 1

[sw-Eth-Trunk2]port trunk pvid vlan 50


Thanks for your help!


bearclub

  • x
  • convention:

Featured Answers

Best answer

Recommended answer

chenhui
Admin Created Feb 20, 2020 13:34:25 Helpful(1) Helpful(1)

@bearclub, please assign the PVID to another VLAN through command below:
[Huawei-Eth-Trunk1]port trunk pvid vlan VLAN-ID
  • x
  • convention:

bearclub
bearclub Created Feb 20, 2020 14:01:12
@bearclub - okey it work, thank you very much. But how do i know now that VLAN 1 is tagged on this interface? This is what i did but the config does not show me that VLAN 1 is tagged on this interface

[sw-Eth-Trunk2]port tr pv vl 50
[sw-Eth-Trunk2]port tr al vl 1
[sw-Eth-Trunk2]dis this
#
interface Eth-Trunk2
port link-type trunk
port trunk pvid vlan 50
port trunk allow-pass vlan 2 to 20
mode lacp
#
return  
All Answers
chenhui
chenhui Admin Created Feb 20, 2020 12:21:40 Helpful(0) Helpful(0)

Hi @bearclub,
When a trunk prot with pvid 1 gets a tagged packed with vlan 1, the packet will be dropped.
By the way, trunk port allows the VLAN1 passing through by default, and the default PVID for the trunk port is VLAN 1.
  • x
  • convention:

bearclub
bearclub Created Feb 20, 2020 12:31:13
Hi @chenhui

So according to your answer this should work right? All the other VLANs work (VoIP, Managment, ...) except VLAN 1.  
chenhui
chenhui Admin Created Feb 20, 2020 12:41:50 Helpful(0) Helpful(0)

@bearclub, from your HPE configuration, it seems that the VLAN 1 traffic will be transferred with VLAN tag attached, but the Huawei configuration you listed will untag the VLAN 1.
Please confirm if you need the VLAN 1 traffic being transferred with tagged or untagged.
  • x
  • convention:

bearclub
bearclub Created Feb 20, 2020 12:54:48
@chenhui - yes the HPE switch does and should transfer everything with tags including VLAN 1 - how can i get the huawei switch to accept vlan 1 to 20 with tags?  
chenhui
chenhui Admin Created Feb 20, 2020 13:34:25 Helpful(1) Helpful(1)

@bearclub, please assign the PVID to another VLAN through command below:
[Huawei-Eth-Trunk1]port trunk pvid vlan VLAN-ID
  • x
  • convention:

bearclub
bearclub Created Feb 20, 2020 14:01:12
@bearclub - okey it work, thank you very much. But how do i know now that VLAN 1 is tagged on this interface? This is what i did but the config does not show me that VLAN 1 is tagged on this interface

[sw-Eth-Trunk2]port tr pv vl 50
[sw-Eth-Trunk2]port tr al vl 1
[sw-Eth-Trunk2]dis this
#
interface Eth-Trunk2
port link-type trunk
port trunk pvid vlan 50
port trunk allow-pass vlan 2 to 20
mode lacp
#
return  
bearclub
bearclub Created Feb 20, 2020 14:03:10 Helpful(0) Helpful(0)

@chenhui - Repost with proper formatted text

okey it works, thank you very much!

But how do i know now that VLAN 1 is tagged on this interface? This is what i did but the config does not show me that VLAN 1 is tagged on this interface

[sw-Eth-Trunk2]port tr pv vl 50
[sw-Eth-Trunk2]port tr al vl 1  
[sw-Eth-Trunk2]dis this
#
interface Eth-Trunk2
 port link-type trunk
 port trunk pvid vlan 50
 port trunk allow-pass vlan 2 to 20
 mode lacp
#
return


  • x
  • convention:

chenhui
chenhui Admin Created Feb 20, 2020 14:17:52 Helpful(0) Helpful(0)

Posted by bearclub at 2020-02-20 14:03 @chenhui - Repost with proper formatted textokey it works, thank you very much!But how do i know now ...
Well, VLAN 1 are allowed passing through by default, and it wouldn't be displayed in the conifguration though the administrator manually assign the command port trunk allow vlan 1. But if you ban the VLAN 1 from the trunk port, the corresponding configuration will be displayed explicitly.
Actually, I'm not sure why designed like this. Maybe, the R&D guys consider the administators know this point.
  • x
  • convention:

bearclub
bearclub Created Feb 20, 2020 14:34:22 Helpful(0) Helpful(0)

@chenhui - thank you for clearing this up. Looks like we have to migrate vlan 1 to another vlan so its properly manageable/readable. To be honest, even if the administrators know this point i think it should be shown in the config anyways - i think it's easier to check your config, specially when displaying the whole config file. 


But lets have a look maybe i will get used to it ;)


Thanks for your help!


  • x
  • convention:

chenhui
chenhui Admin Created Feb 20, 2020 14:43:28 Helpful(0) Helpful(0)

Posted by bearclub at 2020-02-20 14:34 @chenhui - thank you for clearing this up. Looks like we have to migrate vlan 1 to another vlan so i ...
My pleasure. :D
  • x
  • convention:

Comment

Reply
You need to log in to reply to the post Login | Register

Notice Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " Privacy."
If the attachment button is not available, update the Adobe Flash Player to the latest version!

My Followers

Login and enjoy all the member benefits

Login and enjoy all the member benefits

Login