The situation
A service provider links two sites for Customer A and two sites for Customer B. Both customers use VLAN 10 internally. If the provider simply trunked their VLANs, the two VLAN 10s would merge. QinQ (802.1Q tunnelling, or VLAN stacking) adds a second, outer tag per customer and keeps the customer's own tag inside.
| Tag | Example | Identifies |
|---|---|---|
| Inner (customer, C-tag) | VLAN 10 | The customer's own segment; left untouched |
| Outer (service, S-tag) | 500 = Customer A, 600 = Customer B | Which customer, inside the provider network |
What happens
- 1. Customer A sends VLAN 10. The frame arrives at the provider already tagged VLAN 10 by the customer.
- 2. Outer tag added. Provider edge 1 adds outer tag 500 (Customer A) in front of the customer's tag.
- 3. Outer tag removed. Provider edge 2 strips tag 500 and hands Customer A its original VLAN 10 frame.
- 4. Customer B, same VLAN number. Customer B's VLAN 10 travels under outer tag 600, so it never mixes with Customer A.
Why it works: inside the provider network switches only look at the outer tag, so customers can use any VLAN numbers they like. Two cautions: every extra tag adds 4 bytes, so provider links need a larger MTU; and QinQ only separates traffic, it doesn't encrypt it. (The standard for the outer tag is IEEE 802.1ad, which uses TPID 0x88A8; Cisco's dot1q-tunnel uses 0x8100 by default.)
Cisco configuration (provider edge)
system mtu 1504
vlan 500
name CUSTOMER-A
interface GigabitEthernet1/0/1
description Link to Customer A site 1
switchport access vlan 500
switchport mode dot1q-tunnelThe customer-facing port is a tunnel port in the customer's outer VLAN (500). Provider links between edges are ordinary trunks carrying VLAN 500. The MTU command and its effect vary by platform.
How to verify
PE1#show dot1q-tunnel dot1q-tunnel mode LAN Port(s) ----------------------------- Gi1/0/1
show vlan brief (Gi1/0/1 in VLAN 500) and show interfaces trunk on the provider links (VLAN 500 allowed). A working test is Customer A's two sites reaching each other in VLAN 10 while Customer B's VLAN 10 stays invisible to them.Practice
Small pings between Customer A's sites work, but large file transfers stall.
Inside the provider network, which tag do the switches use to forward Customer B's frames?