[go: nahoru, domu]

Jump to content

IEEE 802.1Q: Difference between revisions

From Wikipedia, the free encyclopedia
Content deleted Content added
TelecomNut (talk | contribs)
m →‎Frame format: Clarification of TPID in same bit position as EtherType
 
(322 intermediate revisions by more than 100 users not shown)
Line 1: Line 1:
{{short description|IEEE networking standard supporting VLANs}}
'''IEEE 802.1Q''', or '''VLAN Tagging''', is a [[computer network|networking]] standard written by the [[IEEE 802.1]] workgroup allowing multiple [[network bridge|bridge]]d networks to transparently share the same physical network link without leakage of information between networks. IEEE 802.1Q — along with its shortened form ''dot1q'' — is commonly used to refer to the [[Encapsulation (networking)|encapsulation]] protocol used to implement this mechanism over [[Ethernet]] networks.


'''IEEE 802.1Q''', often referred to as '''Dot1q''', is the [[computer network|networking]] standard that supports [[virtual local area network]]ing (VLANs) on an [[IEEE 802.3]] [[Ethernet]] network. The standard defines a system of '''VLAN tagging''' for [[Ethernet frame]]s and the accompanying procedures to be used by [[Network bridge|bridges]] and [[Network switch|switches]] in handling such frames. The standard also contains provisions for a [[quality-of-service]] prioritization scheme commonly known as [[IEEE 802.1p]] and defines the [[Generic Attribute Registration Protocol]].
IEEE 802.1Q defines the meaning of a [[Virtual LAN|Virtual LAN (VLAN)]] with respect to the specific conceptual model underpinning bridging at the [[Media Access Control|MAC]] layer and to the [[IEEE 802.1D]] [[spanning tree protocol]]. This protocol allows for individual VLANs to communicate with one another with the use of a switch with [[Network layer|layer-3]] capabilities, or a router.


Portions of the network which are VLAN-aware (i.e., IEEE 802.1Q conformant) can include VLAN tags. When a frame enters the VLAN-aware portion of the network, a tag is added to represent the VLAN membership.{{efn|VLAN membership is determined by the frame's port or the port/protocol combination, depending on whether port-based or port-and-protocol-based VLAN classification is being used.}} Each frame must be distinguishable as being within exactly one VLAN. A frame in the VLAN-aware portion of the network that does not contain a VLAN tag is assumed to be flowing on the '''native VLAN'''.
== Example use ==
As an illustration of the utility of VLANs, consider a company whose IT department wishes to provide separate logical networks for each department in the company while using only one physical corporate network. The IT department assigns a unique VLAN per department. [[Edge switch]]es on the corporate network are configured to insert an appropriate VLAN tag into all data frames arriving from equipment in a given department. After the frames are switched through the corporate network, the VLAN tag is stripped before the frame is sent back to the department's equipment, possibly at a different geographical location. In this way, traffic from one department cannot be leaked to or [[Packet sniffer|snooped]] from another department.


The standard was developed by [[IEEE 802.1]], a [[working group]] of the [[IEEE 802]] standards committee, and continues to be actively revised with notable amendments including [[IEEE 802.1ad]], [[IEEE 802.1ak]] and [[IEEE 802.1s]]. The 802.1Q-2014 revision incorporated the [[IEEE 802.1D-2004]] standard.<ref>[http://www.ieee802.org/1/pages/802.1Q-2014.html 802.1Q-2014 - Bridges and Bridged Networks]</ref>
== Frame format ==


==Frame format==
[[Image:TCPIP 802.1Q.jpg|center|thumb|Insertion of 802.1Q Tag in Ethernet-II frame|700px]]
{{wide image|Ethernet 802.1Q Insert.svg|1328px|Insertion of 802.1Q tag in an Ethernet frame}}


802.1Q adds a 32-bit field between the source [[MAC address]] and the [[EtherType]] fields of the original frame. Under 802.1Q, the maximum frame size is extended from 1,518 bytes to 1,522 bytes. The minimum frame size remains 64 bytes, but a bridge may extend the minimum size frame from 64 to 68 bytes on transmission. This allows a tag to be popped without needing additional padding.<ref>Per IEEE 802.1Q Annex G.2.3 ''Minimum PDU size''</ref><ref>{{cite web |url=https://www.cisco.com/c/en/us/support/docs/lan-switching/8021q/17056-741-4.html |title=Inter-Switch Link and IEEE 802.1Q Frame Format |publisher=[[Cisco Systems]] |access-date=2019-09-26}}</ref> Two bytes are used for the tag protocol identifier (TPID), the other two bytes for tag control information (TCI). The TCI field is further divided into PCP, DEI, and VID.<ref>IEEE 802.1Q-2011 clause 9.6</ref>
802.1Q does not actually encapsulate the original frame. Instead, for [[Ethernet II framing|Ethernet II frames]], it adds a 32-bit field between the source [[MAC address]] and the [[EtherType]]/Length fields of the original frame. The VLAN tag field has the following format:


{| class="wikitable"
{| class="wikitable" width=400px
|+802.1Q tag format
|-
|-
! 16 bits
! width=50%|16 bits
! 3 bits
! width=9.375%|3 bits
! 1 bit
! width=3.125%|1 bit
! 12 bits
! width=37.5%|12 bits
|-
| rowspan="2" align="center" | TPID
| colspan="3" align="center" | TCI
|-
| align="center" | PCP
| align="center" | DEI
| align="center" | VID
|-
|-
| TPID
| PCP
| CFI
| VID
|}
|}


;Tag protocol identifier (TPID)
* '''Tag Protocol Identifier (TPID)''': a 16-bit field set to a value of 0x8100 in order to identify the frame as an IEEE 802.1Q-tagged frame. This field is located at the same position as the [[EtherType]]/Size field in untagged frames, and is thus used to distinguish the frame from untagged frames.
:A 16-bit field set to a value of 0x8100{{efn|The prefix ''0x'' indicates [[hexadecimal]] notation}} in order to identify the frame as an IEEE 802.1Q-tagged frame. This field is located at the same position as the EtherType field in untagged frames, and is thus used to distinguish the frame from untagged frames.
;Tag control information (TCI)
:A 16-bit field containing the following sub-fields:
:;Priority code point (PCP)
::A 3-bit field which refers to the [[IEEE 802.1p]] [[Class of service|class of service (CoS)]] and maps to the frame priority level. Different PCP values can be used to prioritize different classes of traffic.<ref>IEEE 802.1Q ''I.4 Traffic types and priority values''</ref>
:;Drop eligible indicator (DEI)
::A 1-bit field. (formerly CFI{{efn|This field was formerly designated ''Canonical Format Indicator (CFI)'' with a value of 0 indicating a MAC address in [[MAC address#Bit-reversed notation|canonical format]]. It is always set to zero for Ethernet. CFI was used for compatibility between Ethernet and [[Token Ring]] networks. If a frame received at an Ethernet port had a CFI set to 1, then that frame would not be bridged to an untagged port.<ref>IEEE 802.1Q-2005 clause 9.6</ref>}}) May be used separately or in conjunction with PCP to indicate frames eligible to be dropped in the presence of congestion.<ref>IEEE 802.1Q-2011 clause 6.9.3</ref>
:;VLAN identifier (VID)
::A 12-bit field specifying the VLAN to which the frame belongs. The values of 0 and 4095 (0x000 and 0xFFF in [[hexadecimal]]) are reserved. All other values may be used as VLAN identifiers, allowing up to 4,094 VLANs. The reserved value 0x000 indicates that the frame does not carry a VLAN ID; in this case, the 802.1Q tag specifies only a priority (in PCP and DEI fields) and is referred to as a ''priority tag''. On bridges, VID 0x001 (the default VLAN ID) is often reserved for a [[network management]] VLAN; this is vendor-specific. The VID value 0xFFF is reserved for implementation use; it must not be configured or transmitted. 0xFFF can be used to indicate a wildcard match in management operations or filtering database entries.<ref>IEEE 802.1Q-2005, 9.6 VLAN Tag Control Information</ref>


For frames (other than 802.3 frames) using [[Subnetwork Access Protocol]] (SNAP) encapsulation with an [[organizationally unique identifier]] (OUI) field of 00-00-00 (so that the protocol ID field in the SNAP header is an EtherType as specified in {{IETF RFC|1042}}), the EtherType value in the SNAP header is set to 0x8100 and the aforementioned extra 4 bytes are appended after the SNAP header.<ref>IEEE 802.1Q-2011 clause 9.4 Tag Protocol Identifier (TPID) formats</ref> In other words the VLAN tag follows the SNAP header. For 802.3 frames in LLC-SNAP format, the order is opposite; the VLAN tag is placed ''before'' the LLC-SNAP header.
* '''Priority Code Point (PCP)''': a 3-bit field which refers to the [[IEEE 802.1p]] priority. It indicates the frame priority level from 0 (lowest) to 7 (highest), which can be used to prioritize different classes of traffic (voice, video, data, etc).


Because inserting the VLAN tag changes the frame, 802.1Q encapsulation forces a recalculation of the original [[frame check sequence]] field in the Ethernet trailer.
* '''Canonical Format Indicator (CFI)''': a 1-bit field. If the value of this field is 1, the MAC address is in non-canonical format. If the value is 0, the MAC address is in [[MAC address#Bit-reversed_notation|canonical format]]. It is always set to zero for Ethernet switches. CFI is used for compatibility between Ethernet and Token Ring networks. If a frame received at an Ethernet port has a CFI set to 1, then that frame should not be bridged to an untagged port.


The IEEE 802.3ac standard increased the maximum Ethernet frame size from 1518 bytes to 1522 bytes to accommodate the four-byte VLAN tag. Some network devices that do not support the larger frame size will process these frames successfully but may report them as ''baby giant'' anomalies.<ref>{{citation |url=http://www.cisco.com/image/gif/paws/29805/175.pdf |title=Understanding Baby Giant/Jumbo Frames Support on Catalyst 4000/4500 with Supervisor III/IV |archive-url=https://web.archive.org/web/20150402195656/http://www.cisco.com/image/gif/paws/29805/175.pdf |archive-date=2015-04-02}}</ref>
* '''VLAN Identifier (VID)''': a 12-bit field specifying the VLAN to which the frame belongs. A value of 0 means that the frame doesn't belong to any VLAN; in this case the 802.1Q tag specifies only a priority and is referred to as a '''priority tag.''' A value of hex FFF is reserved for implementation use. All other values may be used as VLAN identifiers, allowing up to 4094 VLANs. On bridges, VLAN 1 is often reserved for management.


===Double tagging===
For frames using [[IEEE 802.2]]/[[Subnetwork Access Protocol|SNAP]] encapsulation with an OUI field of 00-00-00 (so that the protocol ID field in the SNAP header is an EtherType), as would be the case on LANs other than Ethernet, the EtherType value in the SNAP header is set to hex 8100 and the aforementioned extra 4 bytes are appended after the SNAP header.
[[IEEE 802.1ad]] introduced the concept of double tagging. Double tagging can be useful for [[Internet service provider]]s (ISPs), allowing them to use their VLANs internally while carrying traffic from clients that is already VLAN tagged. The outer (next to source MAC and representing ISP VLAN) S-TAG (service tag) comes first, followed by the inner C-TAG (customer tag). In such cases, 802.1ad specifies a TPID of 0x88a8 for service-provider outer S-TAG.
{{wide image|TCPIP 802.1ad DoubleTag.svg|1328px|Insertion of 802.1ad double tag in an Ethernet frame}}


==Other protocols==
Because inserting this header changes the frame, 802.1Q encapsulation forces a recalculation of the original [[Frame Check Sequence|FCS]] field in the Ethernet trailer. It also increases the maximum frame size by 4 bytes.
IEEE 802.1Q defines the [[Multiple VLAN Registration Protocol]] (MVRP), an application of the [[Multiple Registration Protocol]], allowing bridges to negotiate the set of VLANs to be used over a specific link. MVRP replaced the slower [[GARP VLAN Registration Protocol]] (GVRP) in 2007 with the IEEE 802.1ak-2007 amendment.


The 2003 revision of the standard was the first to include the [[Multiple Spanning Tree Protocol]] (MSTP) which was originally defined in [[IEEE 802.1s]].
'''Double-tagging'''([[QinQ]]) can be useful for Internet Service Providers, allowing them to use VLANs internally while mixing traffic from clients that are already VLAN-tagged. The '''outer''' (next to Source MAC and representing ISP VLAN) tag comes first, followed by the '''inner''' tag. In such cases, an alternate TPID such as hex 9100, or even 9200 or 9300, sometimes may be used for the outer tag; however this is being deprecated by [[802.1ad]], which specifies 88a8 for service-provider outer tags.
[[Image:TCPIP 802.1ad DoubleTag.jpg|center|thumb|Insertion of 802.1ad DoubleTag in Ethernet-II frame|700px]]
Triple-tagging is also possible.


==See also==
== Multiple VLAN Registration Protocol ==
* [[Cisco Inter-Switch Link]] (ISL), an older Cisco proprietary VLAN management protocol
* [[Dynamic Trunking Protocol]] (DTP), a Cisco proprietary protocol to negotiate trunking between two VLAN-aware devices
* [[Time Sensitive Networking]] (TSN), a suite of enhancements to 802.1Q for realtime and time-critical data streaming
* [[VLAN Trunking Protocol]] (VTP), a Cisco proprietary VLAN management protocol


==Notes==
In addition, IEEE 802.1Q defines [[Multiple VLAN Registration Protocol]] (MVRP), an application of the [[Multiple Registration Protocol]], allowing bridges to negotiate the set of VLANs to be used over a specific link.
{{notelist}}


==References==
MVRP replaced the slower [[GARP VLAN Registration Protocol]] (GVRP) in 2007 with the IEEE 802.1ak-2007 amendment.
{{reflist}}


==Sources==
== Multiple spanning-tree protocol ==
* {{Citation |title=IEEE Std. 802.1Q-1998, Virtual Bridged Local Area Networks |doi=10.1109/IEEESTD.1999.89204 |isbn=0-7381-1537-1}}
The 2003 revision of the standard also rolled in the '''[[Multiple Spanning Tree Protocol]]''' (MSTP) originally defined in [[IEEE 802.1s]].
* {{Citation |title=IEEE Std. 802.1Q-2003, Virtual Bridged Local Area Networks|doi=10.1109/IEEESTD.2003.94280 |isbn=0-7381-3663-8|year = 2003}}
* {{Citation |title=IEEE Std. 802.1Q-2005, Virtual Bridged Local Area Networks|doi=10.1109/IEEESTD.2006.216285 |isbn=0-7381-3662-X}}
* {{Citation |title=IEEE Std. 802.1Q-2011, Media Access Control (MAC) Bridges and Virtual Bridged Local Area Networks|doi=10.1109/IEEESTD.2011.6009146 |isbn=978-0-7381-6708-4 }}
* {{Citation |title=IEEE Std. 802.1BR-2012, Virtual Bridged Local Area Networks—Bridge Port Extension |doi=10.1109/IEEESTD.2012.6239543 |isbn=978-0-7381-7281-1}}
* {{Citation |title=IEEE Std. 802.1Q-2014, Bridges and Bridged Networks|doi=10.1109/IEEESTD.2014.6991462|isbn=978-0-7381-9433-2}}
** {{Citation |title=IEEE Std. 802.1Q-2014/Cor 1-2015, Corrigendum 1: Technical and editorial corrections |doi=10.1109/IEEESTD.2016.7374647 |isbn=978-1-5044-0112-8}}
* {{cite web|url=https://www.cisco.com/c/en/us/support/docs/lan-switching/8021q/17056-741-4.html|title=Inter-Switch Link and IEEE 802.1Q Frame Format|publisher=[[Cisco Systems]]|access-date=2019-01-10}}


{{IEEE standards}}
== See also ==
* [[VLAN Trunking Protocol]] (VTP), a Cisco proprietary VLAN management protocol
* [[Cisco Inter-Switch Link]] (ISL), an older VLAN trunking protocol that is proprietary to [[Cisco]]
* [[Dynamic_Trunking_Protocol | Dynamic Trunking Protocol]] another Cisco proprietary networking protocol.

== References ==
* {{cite book|title=IEEE Std. 802.1Q-2005, Virtual Bridged Local Area Networks|isbn=0-7381-3662-X|url=http://standards.ieee.org/getieee802/download/802.1Q-2005.pdf}}
* [http://www.cisco.com/en/US/tech/tk389/tk689/technologies_tech_note09186a0080094665.shtml ISL & 802.1q Frame Formats]


{{DEFAULTSORT:Ieee 802.1q}}
{{DEFAULTSORT:Ieee 802.1q}}
[[Category:Networking standards]]
[[Category:Ethernet]]
[[Category:IEEE 802]]
[[Category:IEEE 802]]
[[Category:Ethernet standards]]

[[de:IEEE 802.1q]]
[[Category:Link protocols]]
[[es:IEEE 802.1Q]]
[[fr:IEEE 802.1Q]]
[[it:IEEE 802.1Q]]
[[ja:IEEE 802.1Q]]
[[pl:802.1Q]]
[[pt:IEEE 802.1Q]]
[[ru:IEEE 802.1Q]]

Latest revision as of 17:27, 13 August 2024

IEEE 802.1Q, often referred to as Dot1q, is the networking standard that supports virtual local area networking (VLANs) on an IEEE 802.3 Ethernet network. The standard defines a system of VLAN tagging for Ethernet frames and the accompanying procedures to be used by bridges and switches in handling such frames. The standard also contains provisions for a quality-of-service prioritization scheme commonly known as IEEE 802.1p and defines the Generic Attribute Registration Protocol.

Portions of the network which are VLAN-aware (i.e., IEEE 802.1Q conformant) can include VLAN tags. When a frame enters the VLAN-aware portion of the network, a tag is added to represent the VLAN membership.[a] Each frame must be distinguishable as being within exactly one VLAN. A frame in the VLAN-aware portion of the network that does not contain a VLAN tag is assumed to be flowing on the native VLAN.

The standard was developed by IEEE 802.1, a working group of the IEEE 802 standards committee, and continues to be actively revised with notable amendments including IEEE 802.1ad, IEEE 802.1ak and IEEE 802.1s. The 802.1Q-2014 revision incorporated the IEEE 802.1D-2004 standard.[1]

Frame format

[edit]
Insertion of 802.1Q tag in an Ethernet frame

802.1Q adds a 32-bit field between the source MAC address and the EtherType fields of the original frame. Under 802.1Q, the maximum frame size is extended from 1,518 bytes to 1,522 bytes. The minimum frame size remains 64 bytes, but a bridge may extend the minimum size frame from 64 to 68 bytes on transmission. This allows a tag to be popped without needing additional padding.[2][3] Two bytes are used for the tag protocol identifier (TPID), the other two bytes for tag control information (TCI). The TCI field is further divided into PCP, DEI, and VID.[4]

802.1Q tag format
16 bits 3 bits 1 bit 12 bits
TPID TCI
PCP DEI VID
Tag protocol identifier (TPID)
A 16-bit field set to a value of 0x8100[b] in order to identify the frame as an IEEE 802.1Q-tagged frame. This field is located at the same position as the EtherType field in untagged frames, and is thus used to distinguish the frame from untagged frames.
Tag control information (TCI)
A 16-bit field containing the following sub-fields:
Priority code point (PCP)
A 3-bit field which refers to the IEEE 802.1p class of service (CoS) and maps to the frame priority level. Different PCP values can be used to prioritize different classes of traffic.[5]
Drop eligible indicator (DEI)
A 1-bit field. (formerly CFI[c]) May be used separately or in conjunction with PCP to indicate frames eligible to be dropped in the presence of congestion.[7]
VLAN identifier (VID)
A 12-bit field specifying the VLAN to which the frame belongs. The values of 0 and 4095 (0x000 and 0xFFF in hexadecimal) are reserved. All other values may be used as VLAN identifiers, allowing up to 4,094 VLANs. The reserved value 0x000 indicates that the frame does not carry a VLAN ID; in this case, the 802.1Q tag specifies only a priority (in PCP and DEI fields) and is referred to as a priority tag. On bridges, VID 0x001 (the default VLAN ID) is often reserved for a network management VLAN; this is vendor-specific. The VID value 0xFFF is reserved for implementation use; it must not be configured or transmitted. 0xFFF can be used to indicate a wildcard match in management operations or filtering database entries.[8]

For frames (other than 802.3 frames) using Subnetwork Access Protocol (SNAP) encapsulation with an organizationally unique identifier (OUI) field of 00-00-00 (so that the protocol ID field in the SNAP header is an EtherType as specified in RFC 1042), the EtherType value in the SNAP header is set to 0x8100 and the aforementioned extra 4 bytes are appended after the SNAP header.[9] In other words the VLAN tag follows the SNAP header. For 802.3 frames in LLC-SNAP format, the order is opposite; the VLAN tag is placed before the LLC-SNAP header.

Because inserting the VLAN tag changes the frame, 802.1Q encapsulation forces a recalculation of the original frame check sequence field in the Ethernet trailer.

The IEEE 802.3ac standard increased the maximum Ethernet frame size from 1518 bytes to 1522 bytes to accommodate the four-byte VLAN tag. Some network devices that do not support the larger frame size will process these frames successfully but may report them as baby giant anomalies.[10]

Double tagging

[edit]

IEEE 802.1ad introduced the concept of double tagging. Double tagging can be useful for Internet service providers (ISPs), allowing them to use their VLANs internally while carrying traffic from clients that is already VLAN tagged. The outer (next to source MAC and representing ISP VLAN) S-TAG (service tag) comes first, followed by the inner C-TAG (customer tag). In such cases, 802.1ad specifies a TPID of 0x88a8 for service-provider outer S-TAG.

Insertion of 802.1ad double tag in an Ethernet frame

Other protocols

[edit]

IEEE 802.1Q defines the Multiple VLAN Registration Protocol (MVRP), an application of the Multiple Registration Protocol, allowing bridges to negotiate the set of VLANs to be used over a specific link. MVRP replaced the slower GARP VLAN Registration Protocol (GVRP) in 2007 with the IEEE 802.1ak-2007 amendment.

The 2003 revision of the standard was the first to include the Multiple Spanning Tree Protocol (MSTP) which was originally defined in IEEE 802.1s.

See also

[edit]

Notes

[edit]
  1. ^ VLAN membership is determined by the frame's port or the port/protocol combination, depending on whether port-based or port-and-protocol-based VLAN classification is being used.
  2. ^ The prefix 0x indicates hexadecimal notation
  3. ^ This field was formerly designated Canonical Format Indicator (CFI) with a value of 0 indicating a MAC address in canonical format. It is always set to zero for Ethernet. CFI was used for compatibility between Ethernet and Token Ring networks. If a frame received at an Ethernet port had a CFI set to 1, then that frame would not be bridged to an untagged port.[6]

References

[edit]
  1. ^ 802.1Q-2014 - Bridges and Bridged Networks
  2. ^ Per IEEE 802.1Q Annex G.2.3 Minimum PDU size
  3. ^ "Inter-Switch Link and IEEE 802.1Q Frame Format". Cisco Systems. Retrieved 2019-09-26.
  4. ^ IEEE 802.1Q-2011 clause 9.6
  5. ^ IEEE 802.1Q I.4 Traffic types and priority values
  6. ^ IEEE 802.1Q-2005 clause 9.6
  7. ^ IEEE 802.1Q-2011 clause 6.9.3
  8. ^ IEEE 802.1Q-2005, 9.6 VLAN Tag Control Information
  9. ^ IEEE 802.1Q-2011 clause 9.4 Tag Protocol Identifier (TPID) formats
  10. ^ Understanding Baby Giant/Jumbo Frames Support on Catalyst 4000/4500 with Supervisor III/IV (PDF), archived from the original (PDF) on 2015-04-02

Sources

[edit]

Q