Routelearn.net
Course menu

Course 4: VLANs and TrunksLesson 1.6 (6 of 7 in this course)14 of 91 in the CCNA series

QinQ

Carrying many customers' VLANs across one provider network, even when the customers use the same VLAN numbers.

Advanced · 6 min read · Before this: VLAN

QinQ (802.1Q-in-802.1Q tunnelling) is a technique in which a provider switch adds a second, outer 802.1Q VLAN tag to frames that may already carry a customer’s own tag. The provider network forwards on the outer tag only, so each customer’s VLANs cross it separately, even when customers use the same VLAN numbers.

In simple terms: QinQ puts each customer’s tagged traffic inside another tag, like a labelled envelope inside a bigger one. The provider only reads the outer label, so customers’ VLAN numbers never clash.

The situation

A service provider links two sites for Customer A and two sites for Customer B. Both customers use VLAN 10 internally. If the provider simply trunked their VLANs, the two VLAN 10s would merge. QinQ (802.1Q tunnelling, or VLAN stacking) adds a second, outer tag per customer and keeps the customer's own tag inside.

TagExampleIdentifies
Inner (customer, C-tag)VLAN 10The customer's own segment; left untouched
Outer (service, S-tag)500 = Customer A, 600 = Customer BWhich customer, inside the provider network

What happens

VLAN 10Customer A · site 1VLAN 10Customer B · site 1Provider edge 1Provider networkProvider edge 2VLAN 10Customer A · site 2VLAN 10Customer B · site 2
  1. 1. Customer A sends VLAN 10. The frame arrives at the provider already tagged VLAN 10 by the customer.
  2. 2. Outer tag added. Provider edge 1 adds outer tag 500 (Customer A) in front of the customer's tag.
  3. 3. Outer tag removed. Provider edge 2 strips tag 500 and hands Customer A its original VLAN 10 frame.
  4. 4. Customer B, same VLAN number. Customer B's VLAN 10 travels under outer tag 600, so it never mixes with Customer A.

Why it works: inside the provider network switches only look at the outer tag, so customers can use any VLAN numbers they like. Two cautions: every extra tag adds 4 bytes, so provider links need a larger MTU; and QinQ only separates traffic, it doesn't encrypt it. (The standard for the outer tag is IEEE 802.1ad, which uses TPID 0x88A8; Cisco's dot1q-tunnel uses 0x8100 by default.)

Cisco configuration (provider edge)

system mtu 1504 vlan 500 name CUSTOMER-A interface GigabitEthernet1/0/1 description Link to Customer A site 1 switchport access vlan 500 switchport mode dot1q-tunnel

The customer-facing port is a tunnel port in the customer's outer VLAN (500). Provider links between edges are ordinary trunks carrying VLAN 500. The MTU command and its effect vary by platform.

How to verify

Example output · based on Cisco documentation; exact format varies by platform and software version
PE1#show dot1q-tunnel
dot1q-tunnel mode LAN Port(s)
-----------------------------
Gi1/0/1
Lists the ports in tunnel mode. Then check show vlan brief (Gi1/0/1 in VLAN 500) and show interfaces trunk on the provider links (VLAN 500 allowed). A working test is Customer A's two sites reaching each other in VLAN 10 while Customer B's VLAN 10 stays invisible to them.

Practice

Predict · scenario 1

Small pings between Customer A's sites work, but large file transfers stall.

Predict · scenario 2

Inside the provider network, which tag do the switches use to forward Customer B's frames?