Overview
Join Knox Hutchinson as he explores how service providers can extend layer 2 connectivity between customer sites.
Recommended Experience
- Completion of Juniper JNCIA-Junos is required
Related Certifications
- Juniper JNCIA-Junos
Related Job Functions
- Network engineers
- Network administrators
Knox Hutchinson has been a CBT Nuggets trainer since 2018 and has received a variety of Microsoft and Cisco certifications. His areas of expertise include data analysis, data visualization, and business intelligence solutions.
Introducing Service Provider Bridging (aka 802.1ad, aka Q-in-Q)
It's time to get familiar with our first service provider concept - service provider bridging!
The Problems with 802.1q
For all of the awesome things 802.1q does, it doesn't quite cut it when it comes to providing layer 2 services to customers.
Knowledge Check
How many bits are available for the 802.1q tag's VLAN ID?
How 802.1ad Solves SOME of Those Problems
Let's talk about how the IETF created 802.1ad in order to address the scaling issues of 802.1q.
Knowledge Check
Which tag is added to a frame by a service provider bridge device?
Frame Walk
Let's cover how a frame would move from one end of the network to the other, step by step.
Knowledge Check
What issue with 802.1q does Q-in-Q NOT solve?
Key Terms for Provider Bridging
Now let's get to know some key terms that are used in provider bridging networks.
Knowledge Check
What is the term (acronym) for a provider device that connects to customer devices.
The Challenge with Multiple Service Provider Bridging
Now let's talk about when a customer's network spans across multiple providers.
Knowledge Check
A provider cannot create a bidirectional translation of S-VLANs on a frame that is transiting the network. True or false?
VLAN Translation Key Terms
Let's cover some key terms in how a service provider network can alter the tagged VLANs on a frame as it moves through the network.
Knowledge Check
Which term is used to indicate the removal of a VLAN tag?
Virtual Private LAN Services (VPLS)
A VPLS is a type of layer 2 bridging network that is also common deployed as an EVC.
Knowledge Check
Which technologies are used to support a VPLS? (Choose three)
Summarizing Service Provider Bridging Concepts
Let's recap what we've learned about service provider bridging!
Conclusion
I hope this has been informative for you and I would like to thank you for consuming.
View Transcript
Introducing Service Provider Bridging (aka 802.1ad, aka Q-in-Q)
0:05Let's kick this playlist off with something big right out
0:08of the gate, something that's really relevant to service
0:10provider networks, and that is provider bridging.
0:13What really is provider bridging at the end of the day?
0:16Well, that's really what this entire skill is all about.
0:19We're going to be exploring how service providers can actually
0:22extend Layer 2 connectivity from one customer site all
0:26the way across their provider backbone
0:28into another customer site.
0:30We're even going to talk about what
0:31happens when more than one service provider comes
0:33into the mix.
0:34But here's the real kicker.
0:35I really wanted to start out with this topic right now,
0:37the service provider bridging, because lots of people
0:40feel like this is one of the hardest things
0:42to wrap their head around.
0:43So we need to tackle the big hard, thing first and get
0:46a major win under our belt as we progress through the service
0:49provider journey.
0:50So by the end of this skill, we'll
0:51fully understand what service provider bridging really
0:55does for us at the end of the day.
0:56What did the 802.1ad standard bring to the table?
1:00And how does a frame at a customer site
1:02make its way across a service provider's network all the way
1:06to the customer's other site?
1:07That's what this skill is going to uncover for us.
1:10So let's get going.
The Problems with 802.1q
0:05Now here's a little story.
0:06When I first made my way into the service provider world,
0:09I actually started exploring service provider technologies
0:12thanks to Juniper and Juniper Certification Track.
0:15But coming from the Enterprise world,
0:17the service provider world really caught me off guard.
0:20And there were some of the topics
0:22that I found really, really blown away about how deep
0:25and how much planning and how much design actually
0:27goes into manipulating all of these protocols.
0:29And the one thing that really caught
0:31me off guard the most that I found most challenging to wrap
0:33my head around was actually service provider bridging.
0:36You ready for the big spoiler at the end of the day, one
0:38of the things that you need to keep in mind as you journey
0:40through service provider bridging
0:41and that will really help you get through this?
0:43It's just dot 1Q trunking at the end of the day.
0:46So in this skill, what we're going to do
0:47is we're going to take a look at what the dot 1Q protocol really
0:50brought to the table and where some of the limitations where
0:53challenges came in for a service provider's network
0:56when they wanted to extend layer 2 services to their customers.
0:59So let's recap what dot 1Q really
1:01does, how it processes a frame and tags
1:03traffic as it goes over a trunk port,
1:05and then take a look at what a service provider may
1:07think about this type of traffic as it arrives on their devices.
1:10Let's get going.
1:11So I guess we need to launch right into this
1:13and settle the score right now.
1:15What is it that provider bridging really
1:17does at the end of the day?
1:18Take a look at this topology that I'm
1:20going to be using for the upcoming Nuggets,
1:22at least in this skill and the next skill.
1:24What we're really talking about in the blue section right
1:27here is going to be a customer network.
1:30And this pink section here is going
1:32to be their actual service provider network.
1:34Now in this blue section, we have their first site, which
1:37is obviously located in a city.
1:39Now over here, we also have the exact same customer.
1:42And they have a different site.
1:44Maybe that site is located in a different city,
1:47or different state, or maybe even in a different country.
1:49Whatever the case is, in order to get traffic moving
1:53from Site A to Site B, a service provider
1:56has to help them get there.
1:58So the point of a bridge is to actually extend a layer 2
2:03network from one end to the other.
2:06If you kind of look at it, what does this topology actually
2:09remind you of?
2:10It kind of reminds me of a bridge.
2:12We're going from one bit of land on one side of the water
2:15to another bit of land on a different side of the water.
2:18And the bridge is what actually gets us there.
2:21So yeah, do you see it?
2:22Does it make sense that at this point, what a bridge is really
2:24going to do is it's just going to give us across a service
2:27provider network.
2:28But really more specifically, what a service provider bridge
2:31is doing is it is providing layer 2 connectivity from one
2:35end to the other.
2:36And now is the part where you go think, how do they do that?
2:39Is it just a trunk port?
2:40And that really sets up the conversation about what it is
2:43that 802.1Q does and where it kind of falls short.
2:47You see, when we try to do 902.1Q trunking from one site
2:52to the next site, we found out pretty quickly that there are
2:55limitations, at least from the service provider's point
2:57of view, to actually providing just a simple layer 2 broadcast
3:02VLAN that they could send their tag traffic
3:04into, into the service provider network.
3:06Sure, we could absolutely create a trunk port,
3:09like a classic 802.1Q trunk port between this link right here.
3:14And that way traffic that originates from, say,
3:16this host here could be trunked up.
3:18And then we could just trunk it down here,
3:20then trunk it over here, then trunk it over here.
3:22And now it makes its way out.
3:24And this would behave as if our entire service provider network
3:26is nothing but switching.
3:28That is technically a solution that could fly.
3:31But we find out there are so many variables and so many
3:34problems with 802.1Q when we start talking about this.
3:37Let's talk about one of the first major issues with 802.1Q.
3:41And that's the actual tag itself.
3:43It's hard to beat Wikipedia for getting some good information
3:45about ethernet frames.
3:46And when I was in a pinch and needed,
3:48I need somebody to send me the header of a frame real quick,
3:50let's just use Wikipedia as our source to get that done.
3:53What I'm focused on right now is this piece of an Ethernet frame
3:57right here, the 802.1Q tag.
4:00Now we see that it is comprised of four octets,
4:03or it is 32 bits.
4:05And when you think about 32 bits, how many addresses
4:08is that total?
4:09That actually means there's something
4:11like 4 billion addresses that you could actually
4:13use at that point.
4:14But if we've ever worked with VLANs
4:15before, we know, wait a minute, I've
4:17never seen a VLAN 195,000 before.
4:21No, that's because the actual 802.1Q tag and the VLAN numbers
4:25that we're allowed to do-- if I give it a click here,
4:27we can scroll into it-- we can see that the actual 802.1Q
4:31header itself, right there, has these four octets defined by 1,
4:362, 3, 4.
4:37But the real kicker is the first octets
4:39are reserved by the tag protocol identifier.
4:43And then we see actually down here in the tag format,
4:46that the next four bits are also reserved,
4:49leaving only 12 bits that are usable for actually setting
4:53a VLAN ID.
4:54From the service provider's point of view,
4:56this means that we can only come up with 12 bits of VLAN
5:00information for all of our customers if we were to use
5:04802.1Q trunking.
5:06So jumping back to this diagram here,
5:08what we're saying is that this customer right here,
5:12if it wanted to use 802.1Q trunking,
5:15we could assign anything within those 12 bits and tell that
5:18customer, go ahead and trunk up to us with your data tagged
5:22with a specific VLAN.
5:23So let's pretend for a moment the customer said,
5:25that's great and all, but I actually
5:27want to send three or four VLANs across this trunk port for you.
5:31And you're like, OK, go ahead and send for VLANs.
5:34The real kicker is with these 12 bits,
5:36that means we only have 4,094 usable VLAN
5:41tags that we can use.
5:42And four of those just went to one customer.
5:45Do you already see where I'm going with this?
5:47One of the biggest issues with 801.1Q is that it
5:50isn't scalable.
5:51If we are a large service provider network-- maybe
5:54we're like a huge one like AT&T, or Vodafone, or Orange,
5:58or whatever.
5:58Maybe we're a massive service provider network.
6:01If we're only allowed 4,094 VLAN tags,
6:05obviously we're going to need some
6:06of those VLANs for our own internal network
6:09and our own trunking and VLANs that we're doing.
6:11But then all of a sudden, we are limited to the amount of VLANs
6:15that we can actually use for our customers.
6:17If we have thousands of customers,
6:19for instance, if we have more than 4,094 customers,
6:22we've just run out of VLANs, even
6:24if we gave them one VLAN each.
6:27So that's a major, major problem with 802.1Q trunking,
6:30is it even though the VLAN tag itself is a 32-bit field,
6:34only 12 of those bits make up the actual VLAN number itself.
6:38And therefore, there are only 4,094 VLANs
6:42within an actual VLAN environment.
6:44And as a service provider, if we have thousands
6:47upon thousands of customers, we simply run out of VLAN tags.
6:50And therefore, that's not going to cut it for us.
6:52But let's pretend for a moment that we
6:54didn't run out of VLAN tags.
6:55And we did sell this customer its four VLANs.
6:58What is the next issue that we're going to run into, is all
7:01of a sudden, this one VLAN-- let's pretend it's VLAN 110--
7:05this one VLAN 110 spans to here, then here, then here, then
7:09here.
7:10And what do you know about trunk ports, and routing loops,
7:13and switch loops, and frame loops?
7:15Spanning tree protocol.
7:18All of a sudden, now we have a spanning tree protocol issue,
7:22because our spanning tree protocol for this one VLAN
7:25has to span from the customer's network
7:28across our entire provider backbone, all the way
7:31into the other customer's network.
7:33Now you're thinking here, that's only five switches.
7:35What's the big deal, Knox?
7:37But in a real service provider network,
7:39how many jumps or hops or physical devices
7:42is this frame actually going to pass through?
7:44Potentially a lot.
7:45And now all of a sudden, this spanning tree environment
7:48has to span the entire duration, the entire length
7:51of this entire topology.
7:53And that becomes another major problem,
7:55because not only do we have to have
7:56spanning tree protocol able to converge
7:59and be deployed and scalable in that nature,
8:01we also have to just coordinate that many instances of spanning
8:05tree protocol against all of the different VLANs
8:08and then keep in mind like, who's going to be root bridge?
8:10And what was this customer doing again?
8:12What kind of hardware were they using?
8:14Because they might be using Cisco, and we're using Juniper,
8:16and we use different versions of spanning tree protocol.
8:19So that becomes an administrative nightmare too.
8:22Now one of the last problems with 802.1Q is think about
8:25the very processing of how a frame goes.
8:28If this device sends a ping destined to this device,
8:32and they believe they're on the same subnet,
8:34because our layer 2 topology spans that far,
8:38what does it really begin with?
8:40It begins with an ARP request, doesn't it?
8:42So that frame is going to enter right here on our provider
8:46equipment.
8:46And unless we've already learned about this Mac address
8:492, what is the default behavior on just VLAN switching
8:53or ethernet switching?
8:54If we don't know the outbound interface to send this on,
8:57it's going to broadcast the frame out all interfaces that
9:03are participating in the same VLAN,
9:04except, of course, the interface that the packet was received on
9:08or the frame was received on.
9:09So the frame will come in on this interface.
9:11And it'll get broadcast out all the other interfaces here.
9:14And then it'll come in on this interface.
9:16And it'll get broadcast out all the interfaces here.
9:19And then it'll come in on this interface.
9:20And it'll make its way out.
9:22Then return traffic has to make its way back in.
9:24And the broadcasts aren't necessarily the big deal.
9:27The big thing we're setting up here is our environment now has
9:31to learn about all of our customer's Mac addresses,
9:35because if we're going to be using an 802.1Q VLAN,
9:38all of the rules of ethernet switching apply here.
9:41So now in our entire provider environment,
9:45again, thinking about the fact that there
9:46could be 4,094 VLANs for all of our customers,
9:50now we have to learn all of our customer's Mac addresses.
9:54That's right.
9:55So these are some big limitations to actually using
9:58902.1Q, the fact that we only have 4,094 VLANs that we can
10:02play with and divvy up among our customers,
10:04the fact that spanning tree protocol is going to be in play
10:08here, and we're going to have to coordinate the deployment
10:10of spanning tree protocol for the entire VLAN,
10:13because that's going to span from one customer site all
10:16the way through a backbone into the other customer site.
10:18And then lastly, we're going to have
10:20to learn all of our customer's Mac addresses
10:23to send traffic from one site to the next site.
10:25So that sets up kind of the problems with 802.1Q.
10:28Let's talk about how service providers overcame this
10:31in such a fascinatingly simple way in the next Nugget.
10:34I hope this has been informative for you.
10:36And I'd like to thank you for viewing.
How 802.1ad Solves SOME of Those Problems
0:00[MUSIC PLAYING]
0:05For all of the awesome things that 802.1Q did
0:08for the enterprise world, allowing us to segment
0:10broadcast domains into multiple VLANs and then still be able
0:14to carry those VLANs across a trunk port by tagging it,
0:17we found out that there is a scale problem when it comes
0:20to service provider networks.
0:21They weren't able to extend layer 2 technologies all
0:24the way from one customer site to another customer site
0:27unless we had a very small number of customers actually
0:30demanding this.
0:31The issue is that that VLAN tag field is only a 12-bit field
0:35and therefore, only has 4,094 usable VLAN
0:38tags that we could actually use to help with our customers.
0:41Beyond that, we would have to coordinate things, like, MAC
0:44address table usage, as well as Spanning Tree Protocol
0:46usage across an entire infrastructure
0:49between both customers and with the service provider backbone
0:52itself.
0:53So enter 802.1ad, or what's also known as Q-in-Q technology.
0:58We're going to be talking about how 802.1ad addressed almost
1:02all of these issues, not quite all of them,
1:04but most of these issues, and is now one of the preferred ways
1:07that a service provider network can offer an EVC or an ethernet
1:11virtual connection from one customer site to another
1:14customer site.
1:15Let's get going, talking about 802.1ad.
1:18So are you ready to have your mind blown to see how service
1:22providers were able to overcome this limitation of 802.1Q?
1:25Think about this previous example that we set up here.
1:28We had our customer at this site sending in a frame.
1:31And we wanted it to make its way over to this site
1:33as if they were on the exact same layer 2 Ethernet segment.
1:36Let's pretend for a moment that this customer wanted
1:39to use the VLAN of 110.
1:43So it sends a tagged frame into our provider network,
1:47tagged with a VLAN of 110.
1:50What, then, do we do with this to make this so scalable and so
1:53simple that it actually works?
1:55We just add our own tag to it on the outside of that tag.
2:00We'll say we give this customer a tag ID of VLAN 200.
2:04That's right.
2:04That's exactly what's going to happen.
2:06And that's what the 802.1ad standard did is it created what
2:12is called Q-in-Q tunneling.
2:15That's right because it's 802.1Q tags inside of 802.1Q tags.
2:20Now, this concept may feel a little fuzzy right now.
2:23So don't worry.
2:24What we're going to do in this Nugget is now talk about how
2:27does 802.1ad really work.
2:30So in this scenario, what we as the service provider are saying
2:33is that our customer comes to us and they
2:35say they want layer 2 connectivity
2:38from this site here all the way to this site here.
2:42But they also don't want to be limited in the number of VLANs
2:46that they can actually use.
2:47So what they want to do is they really want
2:49to have the world open to them.
2:51They want to be able to use VLAN 1 through VLAN 4,094.
2:55So if we have an 802.1Q trunk right here between this link,
3:00between their customer equipment and our service provider
3:04equipment, we know that they're going to be tagging traffic
3:07as it goes up here.
3:08And it could be tagged with a VLAN
3:11of anywhere between one and 94.
3:13Let's go ahead and be really clever and call this tag
3:16the customer tag or C tag for short.
3:21And let's pretend for a moment that this device right here
3:24lives on VLAN 110.
3:26So it's going to be sending traffic in to this device
3:29and it gets tagged as it goes up to our equipment
3:31with a C tag of 110.
3:33We as a service provider do not want
3:36to have to worry about how many VLANs they want to use,
3:39nor do we want to worry about coordinating a Spanning Tree
3:42Protocol instance between them.
3:44So what we decide to do is we decide
3:46to assign this entire customer their own VLAN tag.
3:50Pretend for a moment that we say that this customer has
3:53a VLAN tag of 200.
3:55So in the Ethernet frame itself, they
3:58have sent us a frame that has a C tag of 110.
4:01And we're going to put a little tag on the outside of it.
4:05This is called the service tag or S tag for short
4:09And we're going to label it with an S tag of 200.
4:12So as the frame arrives on this device,
4:14we add the S tag of 200.
4:17And then forward it via a trunk port down to our next device.
4:22This device that sits dead center of it receives the frame
4:26and only looks at the S tag.
4:28It doesn't care about the C tag.
4:30It's only looking at the S tag.
4:31And it knows, oh, for S tag traffic, that's VLAN 200.
4:35And here are the ports that I can send VLAN 200 out of.
4:39So it sends VLAN 200 out some additional ports.
4:42And again, these devices receive the frame
4:46and see that it has an S tag of 200.
4:49But because it's also configured to know what customers it
4:52attaches to, these devices see that they are the end
4:56of the road for VLAN 200.
4:59And it removes the S tag, leaving only the customer tag.
5:03And it forwards the tagged traffic back down
5:06to this customer.
5:07So now think about it as if there were multiple hosts
5:10living off of this device.
5:12And maybe they were sending frames
5:13in on VLAN ID 113 or 493.
5:19They would all be tagged with a C tag.
5:21And then we would just drop our one S tag on the front of it.
5:25Traffic would then be forwarded via the S tag
5:27until it makes its way to the final destination, where the S
5:30tag is removed and then this device, the other customer
5:33device, inspects the C tag and sends the traffic on
5:36towards its next destination.
5:38We can see why this is called Q-in-Q tunneling, can't we?
5:43Because we have an 802.1Q tag inside of an 802.1Q tag.
5:47And pulling up trusty Wikipedia one more time,
5:50we could actually scroll down and take a closer look
5:52at the frame format here.
5:54This last frame format is the one
5:56we care about because here we've got a regular Ethernet frame.
6:00Here we've got one with an 802.1Q header.
6:02And here is an 802.1ad header.
6:05We simply have the two .1Q headers.
6:08Now, the first header that pops up here, this is the S tag.
6:12This is known as the outer tag.
6:15And this tag right here is the C tag.
6:18This is known as the inner tag.
6:21Yes, these are key terms that you should commit to memory.
6:24These are the terms that you would read in a textbook
6:26or maybe even see in an exam environment.
6:28You may see these pop up as the term S tag or C tag
6:32or you may also see them as an outer tag or an inner tag.
6:36So now, on one logical switch, what
6:39I'm saying here, that's a key term, is a logical switch,
6:42I could have 4,094 customers.
6:46And we could carry out of those customers
6:49their 4,094 VLANs because I can have 4,094 S tags.
6:56And we don't care about the inner tag or C tag that's
6:59being trafficked there.
7:00Now, to be fair, you can actually
7:02configure it to care about the C tag.
7:05We can restrict which VLANs are actually allowed
7:07to traverse through a network.
7:09And that's a bigger topic that we're
7:10going to talk about as we progress through this content.
7:13But to mark it even further, if you followed along
7:16in the JNCIA-Junos content, you learned
7:18about routing instances.
7:20And that was the ability to create separate logical routing
7:24instances or virtual instances on each one of our routers.
7:27This was like a VRF, where we could
7:29separate many different routing tables
7:31and logically separate them together.
7:33Here's the real truth.
7:34On these vMX devices or many other switching platforms,
7:38we can actually perform virtual switching.
7:41So we can have separate VLAN databases
7:43and separate MAC address tables.
7:45And therefore, there's really no limit to the amount of VLANs
7:49that we could actually configure and scale
7:51throughout our entire enterprise, except, of course,
7:54within the limitations of the physical hardware itself.
7:56We only have so much processing and RAM and disk space
7:59at the end of the day.
8:00So this introduces what 802.1ad, also known as Q-in-Q,
8:06also known as provider backbone bridging--
8:10it's going to take me forever to write backbone here-- bridging,
8:13there we go.
8:14That's right.
8:14This does kind of have three names at the end of the day.
8:17That introduces what this technology does and how we
8:20actually turned 802.1Q into a scalable protocol that helps us
8:25move layer 2 traffic from one customer site to the other.
8:28At the end of the day, before you go on any further and you
8:31get overwhelmed with this, just remember what we're really
8:34talking about is nothing more than .1Q trunking.
8:37That's really what we're doing.
8:38We've just added one more .1Q tag onto the actual frame
8:42itself.
8:43So that introduces how service provider bridging actually
8:45works.
8:46I hope this has been informative for you.
8:48And I'd like to thank you for viewing.
Frame Walk
0:00[MUSIC PLAYING]
0:05So it makes sense why it's called QinQ now, right?
0:08We've got an inner Q tag, and 802.1Q tag,
0:11followed by an outer 802.1Q tag.
0:14And we know that the provider network is only going to be
0:17focused on forwarding the outer 802.1Q tag.
0:20So what we're going to do now is actually
0:22perform a frame walk, where we follow how a frame would enter
0:26the provider network and how it would be processed
0:28and forwarded one hop at a time until it
0:30reaches its final destination.
0:32So let's take a look at the path a frame would walk as it enters
0:35a provider network using 802.1ad QinQ.
0:39So we talked about this a little bit in the previous Nugget.
0:41But it bears some dedicated time in its own right.
0:44It also bears repeating because this
0:46is going to really help you solidify
0:48your understanding of how provider
0:50bridging in QinQ really works.
0:52So let's talk about how a frame would
0:54move from one end of a topology to another when we've
0:57implemented QinQ tagging, especially when
1:00we have more than one customer.
1:01So I've changed the topology up just a little bit
1:04so that we can actually see what a frame
1:06walk would look like if we had multiple customers.
1:08Let's pretend for a moment that we had our blue customer.
1:11I'm going to call it customer A. And we've
1:14decided that we want customer A to have an S tag of 300.
1:19Now we've got our green customer who's also in the mix, too.
1:22Let's say that we've got customer B
1:25and we want them to have an S tag of 400.
1:30Again, keep in mind, it's important to remember
1:32what the difference between C tags and S tags really are.
1:34The C tag is going to be the customer's tag,
1:37meaning what VLAN 802.1Q tag have they applied
1:41to the Ethernet frame versus the S tag,
1:43which is what is the frame that we actually care about?
1:46We are applying it and forwarding it
1:48through our traffic, through our network.
1:49Starting with customer 1, a frame
1:52is originated in customer 1's network over here in this site.
1:56Let's call this site 1.
1:58And it gets tagged with a C tag of 110.
2:03And it arrives inbound on our network on this
2:05switch's ge-0/0/0 interface.
2:08The customers configure their outgoing interface as an 802.1Q
2:12trunk port so that it is tagged as it arrives on our interface.
2:16Now, do we really care about what
2:17it's tagged with at this point?
2:19Absolutely not.
2:20We don't look.
2:21Our device doesn't inspect that tag at all.
2:24It looks at this interface right here and says,
2:26oh, I see this is coming in on my customer A interface.
2:30And I know that customer A really belongs to VLAN 300.
2:35So after we've configured this device to associate ge-0/0/0
2:40here with customer A, customer A can trunk whatever they want
2:44to up to us at this point.
2:45But we know that this interface is really configured
2:48to operate in VLAN 300.
2:50So this device adds the S tag of 300 onto the frame,
2:56even though there is a C tag currently existing of 110.
2:59From there, we have trunk ports going out all of our interfaces
3:03into the provider core.
3:04Our device tags the traffic with the S tag
3:07and forwards it into the provider core.
3:09And the provider core only looks at the S tag.
3:12It only looks at the outermost tag.
3:15It may know that there is a C tag in operation
3:17because the actual tag field itself,
3:20the TPID indicates that it is an 802.1ad frame instead
3:24of an 802.1Q frame.
3:26But nonetheless, our device knows
3:28to inspect the S tag itself and says,
3:30oh, this is part of VLAN 300.
3:33Let me just forward it out all of the other interfaces that
3:35are speaking on VLAN 300, or out the destination
3:39interface if I know about the destination MAC address.
3:42So in this case, the device could send it out
3:45towards this provider device or this provider device
3:48because there are redundant uplinks
3:50into this network on the other customer's remote site.
3:52So the frame gets forwarded via the S tag information of 300
3:57that we have set on the frame as it entered our provider
4:00network.
4:00And as it begins to exit the provider network,
4:03this device knows when it has a leg in the customer's network
4:08as well.
4:08It knows to strip the S tag off of the frame and forward
4:11the original 802.1Q tagged frame towards the host device.
4:16Now, here's the real kicker.
4:17What happens when my other customer, my green customer
4:20down here where R33 is, wants to send
4:23in a frame with a C tag of 110?
4:27It configures and 802.1Q trunk on this interface.
4:31And it sends in the tagged frame with the C tag of 110.
4:35And it receives on ge-0/0/3.
4:38Again, I can't stress this enough.
4:40This device isn't going to inspect the C tag.
4:42But rather it's going to look at how this interface is
4:45configured. ge-0/0/3 would be configured to know, oh, OK,
4:49I belong to customer B's network.
4:52And we're going to apply the S tag of 400 on this frame.
4:56So it applies the S tag of 400 to the frame
4:59and then forwards it out the exact same trunk
5:02port towards the provider core.
5:03The provider core is going to inspect that S tag of 400.
5:07And it sees, ah, I need to send this out of my interfaces
5:10that are also participating in VLAN 400.
5:13Unless, of course, it knows, again, the exact destination
5:16MAC address and the interface it should forward
5:18traffic out of that way.
5:19The whole time this is going on, all of these devices
5:22are also learning about the source MAC addresses
5:25and logging them in their MAC address table.
5:27That's right.
5:28802.1Q solved a bunch of problems,
5:30but didn't solve every problem.
5:32The one problem that it didn't really solve
5:34is we still have to learn our customers MAC addresses.
5:37But we as service providers tend to overcome this problem by,
5:41well, billing them for that.
5:42We could charge them for a maximum number
5:45of MAC addresses.
5:46And if they go over it, we could charge them
5:47an additional amount.
5:49This is why you oftentimes see enterprises create
5:52their own dedicated VLAN specifically
5:54for traversing this backbone.
5:56And then they actually perform some form of NAT
5:59before the traffic goes outbound into this provider backbone.
6:02Nonetheless, this is a way that we can still
6:04maintain our resources at a reasonable level
6:07and not overwhelm our MAC address tables is we simply
6:10just bill for the number of MAC addresses
6:12that the customer sent in into our network.
6:14So as traffic is originated and sent into the network,
6:17our devices are going to learn about the source MAC addresses.
6:20And when it doesn't know about the destination MAC address,
6:23it performs the exact same flooding
6:25that you would expect before.
6:26It's just flooded based on the S tag's VLAN.
6:29Of course, as return traffic is sent back, all of our devices
6:33are learning about that destination MAC
6:34address or that source MAC address as well.
6:37And that way it keeps these MAC addresses in their MAC address
6:39tables.
6:40And then next time we have to forward traffic between sites,
6:43it will go much quicker because we're not
6:45having to wait for ARP replies and such like that.
6:47So this is covering the actual frame walk of an 802.1ad
6:51or QinQ environment.
6:52The big thing to keep in mind is that the interfaces themselves
6:56are what the provider network device knows
6:58to inspect and look at the configuration of in order
7:01to actually set the S tag.
7:02It doesn't care about the C tag unless we explicitly
7:06configure it to only allow specific certain C tags.
7:09And there are some use cases for that
7:10that we'll eventually get into.
7:12For now, that is 802.1ad end-to-end.
7:15I hope this has been informative for you.
7:16And I'd like to thank you for viewing.
Key Terms for Provider Bridging
0:05Now here's the next thing that really catches newcomers
0:08to the service provider world off guard.
0:10We already thought we've learned every networking acronym there
0:13is to know because we came from the enterprise world,
0:15and what you find out very quickly is you haven't.
0:18The service provider world is an entirely different world,
0:21and there is plenty of alphabet soup
0:23out there for you to learn.
0:24Provider bridging is not an exception to that.
0:27There are some key terms and some key acronyms
0:30that you will absolutely need to commit to memory because this
0:32is what you'll read in textbooks.
0:34This is what you'll see on exams,
0:35and this is what you'll hear me say
0:37throughout the upcoming Nuggets that we
0:38have within this skill and many other skills that
0:40are centered around service provider networking.
0:42So let's keep going talking about some
0:44of the key terms and acronyms that you
0:46will encounter when you talk about provider
0:48bridging in the real world.
0:49Let's get going.
0:50Yep.
0:51There's no escaping it.
0:52We have some key terms that we have
0:53to learn about some jargon, some service provider world
0:56usages that you'll see.
0:57Whenever you join a service provider
0:59network for the first time, you will
1:01be overwhelmed with the number of acronyms and crazy things
1:05that they actually do.
1:06So this is where we're going to get
1:07started learning about our first service provider key terms.
1:11What we're looking at here is an ethernet virtual connection,
1:15or EVC.
1:16This is the service that we're actually trying
1:19to provide to our customers.
1:20What they would try and say is we just
1:22want a layer two connection for one site to the next,
1:25and we would hand them a pamphlet that
1:27says what you're really talking about
1:29is an ethernet virtual connection.
1:31This is what would be on their bill.
1:32We're selling them an ethernet virtual connection,
1:35and the entire network or the entire domain
1:38that we manage here is called the provider bridge network.
1:42That's what this entire pink section is.
1:44Everything that is under our control as a service provider
1:47and participates in the service provider
1:49bridging, or the EVC, this is part of the provider bridge
1:53network.
1:54Now, the device that we're going to be connecting to,
1:56the customer's device, this is called the customer edge,
2:00and this is probably familiar to you
2:02if you've ever worked with MPLS or MPLS layer 3 VPN.
2:06The terminology doesn't change a whole lot here.
2:08All of the customer's equipment that we actually connect to
2:11is the customer's edge device because this
2:14is the edge of their network.
2:16They have a whole bunch of devices on the inside of that,
2:19but this is the actual edge, and this
2:20is as far as we go when it comes to caring about what goes on
2:23in their network.
2:24The network devices that we are providing for them to connect
2:28to, or the devices that they think they are connecting to,
2:31is oftentimes referred to as the provider edge.
2:33But specifically, when we're talking about bridging,
2:36we are talking about the provider edge bridge.
2:40So these four devices here that my customers are connecting to
2:44are provider edge bridges.
2:47And specifically, the ports that they're connecting in on-- we
2:50see we've got these ports all that I'm highlighting right
2:52here--
2:53these are called customer ports.
2:56So we've got ge-0/0/0, ge-0/0/3, ge-0/0/0, ge-0/0/3, ge-0/0/0,
3:02ge-0/0/3, ge-0/0/0, and ge-0/0/3.
3:07All of the ge-0/0/0s and ge-0/0/3s on my PEBs are
3:12customer ports, whereas all of the devices that are
3:15interconnecting my provider bridges--
3:19that's a connection like right here between a provider edge
3:22bridge or a connection right here between the provider edge
3:25bridge in the core--
3:26these are simply called network ports, very simple.
3:31Now, lastly, we have in the center of our provider bridge
3:34network, we have these core devices.
3:36And if you recall, based on the frame law,
3:39these devices only care about the S-VLAN tags themselves.
3:43These devices will almost never ever, ever inspect the C tag
3:48in forward based on the C tag.
3:50These devices that are only in the center of the network
3:53and are forwarding S tag frames are oftentimes
3:57called to S-VLAN bridges because they only
4:01participate in the S-VLAN.
4:03They only care about the S tag on the ethernet frame itself.
4:06So these are some of the key terms about all
4:09of the components and moving parts that actually make up
4:12a EVC, an ethernet virtual connection,
4:15and this is all of the stuff that goes on in a PBN.
4:18We've got the PEBs.
4:19We got the provider bridges.
4:21We've got the S-VLAN bridges.
4:22We have customer ports, and we have network ports.
4:24So that's been the terms that you
4:26need to know about when you're actually talking about how
4:28to deploy Q and Q environment.
4:30I hope this has been informative for you,
4:32and I'd like to thank you for viewing.
The Challenge with Multiple Service Provider Bridging
0:00[MUSIC PLAYING]
0:05There are some more key terms that we
0:07need to talk about but we're not going to talk
0:09about them in this Nugget.
0:09What we actually have to do in this Nugget
0:11is set up the reason that we have more key terms that I'm
0:15about to define for you.
0:17What I'm really talking about here
0:18is what happens when a service provider has
0:21to forward frames to a different service provider?
0:24Or maybe a service providers business unit
0:27has to forward frames to a different business unit
0:30in the same service provider.
0:31What we're really talking about here
0:33is what happens when we have VLAN mismatches when those
0:36S-tag as we transmit S-tag data from one service provider
0:39network to a different service provider network.
0:41Let's talk about the scenario about what
0:43to do when there are two service providers in play
0:45within a single customer's ethernet segment.
0:48Let's get going.
0:49So this example has been great up until this point
0:51because we've used it to talk about how
0:53a service provider could provide an EVC to its customers.
0:57That way, a customer who has a location here in this city
1:01and maybe has a location here in the exact same city,
1:04they could provide pretty simply layer two connectivity
1:07from one site to the next.
1:09But what happens when customers start
1:11to spread out a little more?
1:12Maybe they're not in the same city.
1:14Maybe they're not even in the same state.
1:16Maybe they're not even in the same country.
1:18What happens then when the enterprise wants to actually
1:21still provide a layer two connectivity from one side
1:23to the next but now we don't actually have
1:26autonomy in their remote site?
1:29We now have to partner with other service providers
1:32and this could come into some more coordination issues.
1:34Here's how we can actually go about making this work
1:37and setting up the next Nugget where we talk about some more
1:39key terms that actually goes with deploying Q-in-Q Now,
1:42what we're working with is that we have a scenario where
1:45we have one service provider, I'll
1:47call the service provider one.
1:49And now, in this new box, we have a service provider two.
1:53Our customer is still the same.
1:54Well, actually are both of our customers are still the same.
1:56They still have the blue customer
1:58and the green customer.
1:59And they still have one site here and one site here.
2:01And they still want layer two connectivity
2:03from this device over here to this device.
2:06But what happens now is we have this particular issue here.
2:10The good news is, is in both service provider environments.
2:13If they're willing to work together and make this happen,
2:15they're still just going to use Q-in-Q. That's right.
2:19We're still only talking about forwarding traffic
2:21based on S-tags.
2:23The coordination problem that we run into oftentimes
2:26is that service provider one may give this customer
2:30the S-tag of 300.
2:34Whereas service provider two may give that customer
2:37the S-tag of 396.
2:40Just to make something random up.
2:42So as they send in their traffic,
2:44it may come in with a C-tag one more time of 110.
2:48It'll be arriving right here on this interface where
2:51the S-tag tag of 300 is applied and forward it out
2:54of this interface.
2:55Now, what has to happen is right here
2:57on this device that sits on the edge.
2:59A translation will have to occur.
3:02And this is as simple as performing a VLAN translation.
3:06It's just like NAT for IP addresses.
3:08We would explicitly configure this device
3:12that sits in the core to inspect anything with the S-tag of 300
3:17and dust outbound towards this network.
3:20Swap the 300 tag for 396 and vise versa.
3:26Any traffic that arrives inbound from this network
3:29with an S-tag of 396, swap it for 300
3:32and then go about performing the forward lookup.
3:34So from here, this service provider
3:36would be receiving an S-tag of 396
3:39because the core device that sits
3:41in the center already swapped out our S-tag of 300
3:44for the S-tag of 396.
3:46So in this device receives the S-tag of 396,
3:49it knows to perform the VLAN forwarding based on the S-tag
3:52And in this case, it may actually strip off that S-tag
3:55and forward the 802.1Q frame on to the customer in blue.
3:58So this is actually another major talking point
4:00about Q-in-Q. Q-in-Q actually set up
4:03the functionality to allow for changing the VLAN tags
4:08themselves.
4:08That's right.
4:09We're actually pulling off VLAN tags.
4:11We're stripping them off and then replacing them
4:14as they go on the fly.
4:15And the big thing that now we want to talk about, it makes
4:17sense when we explore this as a service provider
4:20to service provider communication.
4:22I mean, we've seen it already up until this point,
4:24where we had a service provider one, maybe this
4:26was something like AT&T. And then service provider two,
4:29maybe this is something like Verizon.
4:30It makes sense that they would never or rarely
4:33assign the exact same customer the exact same S-tag.
4:36And therefore, some translation would
4:38have to happen along the way to actually make
4:40this connectivity work.
4:42But what could actually happen is that these are actually
4:45the same service provider.
4:46That could actually happen and this is one business unit.
4:50And this is a completely separate business unit.
4:52It's unlikely that a large nationwide service provider
4:56has the exact same VLAN or the exact same numbering scheme
5:00or naming scheme from one state to the next.
5:02As traffic transits across the country
5:06even within the same service provider,
5:08there's a chance that it will leave the autonomous
5:10system or an autonomous boundary and transition
5:13into a different networking team's infrastructure
5:16and a translation would still need to occur in this case.
5:19So keep in mind that when you join the service provider
5:21world, yeah, absolutely, when you have a coordination
5:25attempt between two different service providers,
5:27there's probably going to be a translation that takes place.
5:30But if you're joining a large service provider that
5:33spans multiple geographies, there's
5:35still a pretty high chance that translation
5:37needs to take place in your provider bridging solution.
5:40So a cool thing about EVCs is that customers
5:44who span from one corner of the country to the other
5:47could still possibly receive an EVC solution
5:50through the coordination of multiple service providers
5:52working together and creating VLAN translations of the S-tag
5:56as they go on the fly.
5:57I hope this has been informative for you.
5:59And I'd like to thank you for viewing.
VLAN Translation Key Terms
0:00[MUSIC PLAYING]
0:05In the previous Nugget, we introduced the concept
0:07of VLAN translation.
0:09And it makes a lot of sense-- that
0:10is one provider needs to send traffic
0:12to a different provider, but they're
0:14using two different S-VLAN tags, or S-tags.
0:17We need to coordinate the translation from one network
0:20to the next network and vise versa.
0:22So now what we're going to talk about
0:24is how does that translation actually occur,
0:26and what are the key terms that are centered around changing
0:29the actual VLAN tags themselves on these ethernet frames?
0:33Let's get going talking about the key terms centered
0:35around VLAN translation and, ultimately,
0:38how we can manipulate the actual tags themselves.
0:41Let's go.
0:42So in the previous Nugget, I made sure--
0:44or tried really hard, at least-- not to spoil or give away
0:47any of the key terms.
0:48But it's really important that when
0:50we talk about removing or changing VLAN tags,
0:53we really need to have these key terms drilled into our memory
0:57because these are actual words that service provider network
1:01engineers speak.
1:02These are the actual words that you
1:03will see on exam environments or read in textbooks.
1:06So make sure that you learn these words
1:09and commit them to memory when you're
1:10talking about things like service provider bridging
1:13as well as MPLS.
1:15You're going to see these words pop up one more time.
1:18The three words that are really coming into play
1:20here are pop, push, and swap.
1:24Let's start off with pop.
1:25What we're really talking about here
1:26is when this host, Docker30 here,
1:29sends a frame into the network, it gets tagged,
1:33and it comes all the way up to the edge.
1:35And now it's time to remove that S-tag
1:38so that only the C-tag remains.
1:40That is a pop operation.
1:42We're popping the top off.
1:43We're popping that outer tag, the S-tag,
1:46out of the ethernet frame itself,
1:48leaving only the C-tag behind.
1:50And then, we forward it on.
1:52That is a pop operation.
1:54Commit that to memory, because it's an important one to know.
1:57But what about when we added the S-tag frame on?
2:00The frame was sent via an 802.1Q trunk port up to our device
2:05and, at the time, it only contained the C-tag.
2:08Before it left our PEB, or provider edge bridge,
2:12we had to push a tag onto the device.
2:15This is the add operation.
2:17So under pop, I'll just go ahead and put this now
2:20for cleanliness sake.
2:20We've got the remove tag operation.
2:22Under push, we've got the add tag operation.
2:25And this is where we push the S-tag.
2:28Then, lastly, we have the swap operation,
2:31and that's what occurred right here.
2:33This is where we actually did kind of a pop-push.
2:36We popped the S-tag off, and then pushed a new S-tag on.
2:42They simplify that by calling it a swap.
2:44So in this case-- we set it up in the previous example--
2:46we had an S-tag of 300 that was pushed onto the frame
2:51as it arrived in our provider bridge network.
2:54We forwarded the frame based on VLAN 300 information.
2:58The S-VLAN bridge received it, and it
3:00knows, based on the configuration, that it's time
3:03to swap the frame.
3:05So it performs the swap operation,
3:07which under the hood, is popping 300 and pushing-- we pushed 396
3:12in the previous example.
3:14And then, the 396 frame moves forward
3:16into the new provider network.
3:18The provider edge bridge, or PEB, device in the new provider
3:21edge network performs the penultimate pop operation,
3:25leaving only the C-tag, and then forwards it
3:28into the customer's network.
3:29And that sets up the three different types
3:32of operations that you will encounter in the service
3:34provider bridging technologies.
3:36But here's the real kicker, now it's time
3:38to talk about it even a little bit more.
3:40We can take these three technologies
3:42and perform combo moves, so to speak.
3:45And you will also encounter these in the real world.
3:48So there is such a thing as pop-pop.
3:51This is where we remove the outer tag
3:53and also remove the inner tag.
3:56There is also pop-swap.
3:59This is where we remove the outer tag
4:02and swap the inner tag.
4:04There is a swap-swap.
4:06This is where we swap the outer tag
4:09as well as swap the inner tag.
4:12Now, I'll let you figure out what is a push-push.
4:15Go ahead and pause the video and take a moment
4:17to think about it.
4:18[MIMICKING "JEOPARDY" THEME]
4:21This is where we add both an inner tag and an outer tag
4:25to an Ethernet frame.
4:27So this is covering the key terms
4:28that you need to know about when it actually comes time
4:30to translate a VLAN S-tag or C-tag.
4:34We have the ability to control all of the information
4:37as it traverses through our entire network.
4:39So we can not only pop the S-tag and swap the S-tag
4:42or push as S-tag, we can also manipulate the C-tag
4:45if we actually have a use case for doing that.
4:47And these are the three key terms that you really
4:49need to commit to memory when it comes time
4:51to talk about VLAN translation.
4:52I hope this has been informative for you,
4:54and I'd like to thank you for viewing.
Virtual Private LAN Services (VPLS)
0:05Now, this last Nugget is a little bit
0:07of lagniappe for you.
0:08It's nothing much more than good-to-know information
0:11there's not a whole lot that you really
0:13need to dig too deep into this.
0:14But the big thing that I wanted to set you up for
0:17is really what happens when you go out there in the real world
0:19and start working in service provider networks,
0:21or you go beyond the JNCIS and you go
0:24towards the JNCIP or the JNCIE.
0:26One of the things that you'll find out really quick is that
0:29802.1ad and QinQ is not the most widely deployed service
0:34provider-bridging technology that's out there.
0:36What you actually may run into is something called VPLS.
0:38Let's talk a little bit more about what
0:40VPLS does for us at the end of the day in a service provider
0:43network.
0:43Let's go.
0:44Now, the last thing I wanted to talk about here
0:46was VPLS, because it is true that in the actual service
0:50provider world, this is becoming the more prominent way
0:53to provide Layer 2 private VPN technologies to our customers.
0:57We're talking about a different way
0:59to perform EVCs, or Ethernet Virtual Connections.
1:02What really goes on here is that we
1:04have a logical infrastructure here
1:07that provides a backbone that looks something like this.
1:10To our customers, they only see this as a Layer 2 broadcast
1:14segment, not really any differently
1:17than QinQ technologies.
1:19But what really goes on here, is we're not eating up
1:21all of our VLAN space.
1:22We're not actually performing QinQ tunneling.
1:26What we're really doing here is leveraging
1:28functionalities of MPLS, as well as the IGPs themselves,
1:33like OSPF and ISIS.
1:36In order to actually deploy VPLS,
1:38well, you're really starting to break
1:39into not only JNCIP technologies and topics, we're actually
1:43talking more into JNCIE technologies and topics,
1:47because it is heavy, heavy, heavy, on MPLS and traffic
1:51engineering the correct label switched paths.
1:54We haven't talked about all those yet.
1:56We will talk a lot about the MPLS, label switch paths,
1:59and traffic engineering using the RSVP protocol, as well
2:03as variations of these IGPs, ultimately resulting in CSPF.
2:08Don't worry about this too much.
2:09We're going to talk all about it.
2:11And it will set you up for success
2:13when you start to get into VPLS, should your studies actually
2:16take you that far.
2:17Just know that VPLS is an alternative to 802.1ad
2:21and QinQ, and it relies heavily on MPLS.
2:24But from the customer's point of view,
2:26it still looks the exact same.
2:28It's like one gigantic ethernet broadcast network,
2:31where they can see all of their different sites and VLANs
2:34and connect to each other through Layer 2 technologies
2:37as a flat network.
2:38That's just a brief primer on what VPLS does.
2:41It really just leverages MPLS in order
2:44to provide the exact same EVC as QinQ.
2:47I hope this has been informative,
2:48for you and I'd like to thank you for viewing.
Summarizing Service Provider Bridging Concepts
0:05I know you're dying to see configurations
0:07right now, because you're like, oh, oh, let's see it in action.
0:09Let's make some packets flow.
0:10And I am too.
0:12Deploying these configurations on a Juniper device
0:15is kind of a big thing.
0:16There's a lot of stuff that's going on here.
0:18And that's why we've got an entire skill dedicated
0:20to the deployment of service provider
0:22bridging coming up next in this playlist.
0:24For now, we needed to introduce all of these core concepts
0:28and really lay the foundation for the fact
0:31that the service provider world is totally different.
0:33We're now looking at networking from an entirely different lens
0:37than we may have been when we were in the enterprise world.
0:39So we've introduced the core concepts
0:41of what provider bridging does.
0:43What problems did it really solve with 802.1Q?
0:46And then we talked about, how is the 802.1ad system really
0:51deployed throughout this enterprise,
0:52how does a frame flow from one hop to the next,
0:56and then even talked about some things like,
0:57what do we do when there's multiple service providers
1:00in the mix here.
1:00And we talked about then we could do things
1:02like VLAN translation.
1:04So this sets up the foundations for service provider networking
1:07and service provider bridging.
1:08I hope this has been informative for you,
1:10and I'd like to thank you for viewing.
Team training path
Turn this skill into assignable team training
This free skill is a preview of the courses your team can assign, track, and report on with CBT Nuggets.
$708
seat / year