Got it

Vlan settings

Created: Feb 27, 2020 09:06:28Latest reply: Feb 28, 2020 07:58:43 192 5 0 0
  Rewarded HiCoins: 0 (problem resolved)

Hi everyone,

I would like to know if there is a way to setup a switch port to allow more than one vlans but deny all the untagged frames.

If I understood well.

The access port allows just one vlan which is different from the default vlan (pvid), if the frame is untagged should tagged as pvid and allow it.

The trunk port allows more than one vlans which is different from the default vlan (pvid), if the frame is untagged should tagged as pvid control if it is allowed to pass.

But there are no mode where an untagged packet it is not deny directly. For instance if I allow on one port the vlan 30-33 and an untagged frame arrives and the default vlan is 1, it will be denied.

I had a look at the this link https://support.huawei.com/enterprise/it/doc/EDOC1000178168/f9b8a34a/adding-and-removing-vlan-tags

but if the default vlan is 1, frame seems allowed.

Thank you for your support



  • x
  • convention:

Featured Answers

Recommended answer

Admin Created Feb 27, 2020 09:33:33 Helpful(1) Helpful(1)

Hi @Huadmin,
You can configure the port as trunk port, and deny the vlan 1 pass through, then it only allows the tagged packets passing through. Just as the configuration below:
#
interface GigabitEthernet0/0/1
port link-type trunk
undo port trunk allow-pass vlan 1
port trunk allow-pass vlan 30 to 33
#
View more
  • x
  • convention:

All Answers
chenhui Admin Created Feb 27, 2020 09:33:33 Helpful(1) Helpful(1)

Hi @Huadmin,
You can configure the port as trunk port, and deny the vlan 1 pass through, then it only allows the tagged packets passing through. Just as the configuration below:
#
interface GigabitEthernet0/0/1
port link-type trunk
undo port trunk allow-pass vlan 1
port trunk allow-pass vlan 30 to 33
#
View more
  • x
  • convention:

Huadmin Created Feb 27, 2020 12:41:24 Helpful(0) Helpful(0)

Hi @Chenhui, thank you for your reply.
Another question if I can.
I have an hp switch with default vlan 1 plus another vlan 2.
My HP port 20 is configured with vlan 1 and 2 ( both tagged)
Also have a huawei switch with default vlan 1 plus vlan 2.
I tried to configure my Huawei port 20 with vlan 1 and 2 but if i set allow 1 2 shows only 2 as you can see below

interface GigabitEthernet0/0/20
port link-type trunk
port trunk allow-pass vlan 2
port description switch

Traffic from hp vlan 1 doesn't go through, instead if I untag the HP vlan 1 the traffic is allowed in Huawei switch.
Is there a way to accept tagged traffic on the Huawei switch even though the tagged frame vlan match the default vlan id?
View more
  • x
  • convention:

lubna Created Feb 27, 2020 14:50:11 Helpful(0) Helpful(0)

Enable 802.1Q VLANs
  1. Navigate to the System menu on the left side of the page.

  2. Click VLAN Group Setting, as indicated in Figure VLAN Group SettingVLAN Group Setting.

  3. Select IEEE 802.1Q VLAN (Figure Enable 802.1Q VLANs). ...

  4. Click OK to confirm the switch to 802.1Q trunking, as shown in Figure Confirm change to 802.1Q VLAN.


nn


View more
  • x
  • convention:

chenhui Admin Created Feb 28, 2020 07:39:22 Helpful(0) Helpful(0)

Posted by Huadmin at 2020-02-27 12:41 Hi @Chenhui, thank you for your reply.Another question if I can.I have an hp switch with default vla ...
Hi @Huadmin
Yes, it's easy to do that.
By default, the PVID for Huawei trunk port is vlan 1, which means, when the packets received from the trunk port with tagged vlan 1, it will drop the packets. You just need to change the PVID to another vlan. Please refer the configuration below:
interface GigabitEthernet0/0/20
port trunk pvid vlan xxx
View more
  • x
  • convention:

tesfama MVE Created Feb 28, 2020 07:58:43 Helpful(0) Helpful(0)

interface g0/0/1
port link-type trunk
port trunk allow-pass vlan 10 to 30
undo port hybrid tagged vlan 1
View more
  • x
  • convention:

Hi%20my%20name%20is%20Tesfamariam.%20I%20am%20an%20IP%20and%20wireless%20engineer%20at%20Huawei%20partner%20company.

Comment

Comment
You need to log in to comment to the post Login | Register

Notice Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " Privacy."
If the attachment button is not available, update the Adobe Flash Player to the latest version!

My Followers

Login and enjoy all the member benefits

Login

Huawei Enterprise Support Community
Huawei Enterprise Support Community
Block
Are you sure to block this user?
Users on your blacklist cannot comment on your post,cannot mention you, cannot send you private messages.