This topic explains how VLAN mapping translates customer VLAN IDs into service-provider VLAN IDs on Cisco Catalyst IE9300 Rugged Series Switches. VLAN mapping enables VLAN ID reuse across a shared backbone while maintaining secure traffic isolation for dispersed customer sites.
A VLAN mapping is a Layer 2 feature that translates customer VLAN IDs (VLAN ID assigned by the customer) into service VLAN IDs (VLAN ID assigned by the service provider) on trunk ports connected to your network. The VLAN mapping:
-
enables service providers to reuse of VLAN IDs across shared backbones by maintaining traffic isolation, and
-
requires that all features on mapped ports reference the S-VLAN instead of the original C-VLAN.
Typical deployment scenario
In a typical deployment, service providers want to provide a transparent switching infrastructure where customers' remote switches function as part of the local site. Customers can use the same VLAN ID space and seamlessly run Layer 2 control protocols across the provider network. Service providers should not impose their VLAN IDs on customers.
Service providers internal VLAN assignments might conflict with a customer VLANs. VLAN mapping solves this issue by translating customer VLANs into different service provider VLANs as traffic travels through the provider's network.
VLAN mapping operations and behaviors
VLAN mapping is supported on all models of Cisco Catalyst IE9300 Rugged Series Switches with Network Essentials or Network Advantage licenses. You must reference the S-VLAN instead of the original C-VLAN when configuring any feature on a VLAN-mapped port. A service provider’s internal assignments might conflict with a customer’s VLAN. To isolate customer traffic, a service provider can map a specific VLAN to another while the traffic is in its cloud.
When packets enter a port configured for VLAN mapping, the switch maps the specified C-VLAN to the specified S-VLAN based on the port number and the packet's original C-VLAN. All forwarding operations on the switch use S-VLAN information, not C-VLAN information, because the VLAN ID is mapped to the S-VLAN at ingress. When packets exit the port, symmetrical mapping back to the customer C-VLAN occurs automatically.
Always configure features on a VLAN-mapped port with the S-VLAN instead of the customer VLAN ID (C-VLAN). One-to-one VLAN mapping is not supported.
VLAN mapping deployment
For example, if customer A and customer B use the same VLANs (such as VLAN 10) at multiple sites on different sides of a service provider network, you can map the customer VLAN IDs to unique service provider VLAN IDs (such as VLAN 100 for customer A, VLAN 200 for customer B) for packet travel across the backbone. The original customer VLAN IDs are restored at the other side of the service provider backbone for use in the other customer site. Configure the same set of VLAN mappings at customer-connected ports on each side of the service provider network.