[c-nsp] Possible Stupid Questions Alert - Combining VLAN's

Adrian Chadd adrian at creative.net.au
Mon Jun 25 21:07:44 EDT 2007


On Tue, Jun 26, 2007, Skeeve Stevens wrote:
> Damn and Awesome ;-)
> 
> Now I know what the concept is called. but needing a router sucks.

You don't -need- a router, you just need clearly defined boundaries between
your internal network and your borders.

There's no magic rule which states you -must- have the same vlan numbering
scheme on all devices. You just need something consistent for the same
dot1q ethernet domain.

What you could do (What I've done in this situation) is:

* Run border switch/router/switch-router(s) with whatever VLAN setup your
  IXP requires;
* Run an L3 port to interconnect to your internal network;
* Run your own private vlan mapping inside your network.

This works great for small IP ISPs who aren't trying to trunk those VLANs
all over their internal network - ie, they're only for "non-VRF"
traditional IP interconnect. It does require you to have two seperate
devices but you should be doing that anyway.

It all depends on what you're trying to achieve. If you have a bunch of
VLANs at your border that you need to drag out elsewhere (say private VLAN
interconnect for a customer somewhere else in your network) then you need
to pull different tricks. But then, it depends on your budget and what
you're actually trying to achieve. :)




Adrian



More information about the cisco-nsp mailing list