Вы находитесь на странице: 1из 7

Broadband Multiplay Project

VPN VLAN CONFIGURATION IN UTSTAR DSLAM v 1.0

HCL Infosystems Ltd. This document contains proprietary information of HCL Infosystems Ltd. No part of this document may be reproduced, stored, copied, or transmitted in any form or by means electronic, mechanical, photocopying or otherwise, without the express consent of HCL Infosystems Ltd. These services are provided by HCL Infosystems Limited System Support Organisation InfoStructure Services under the controls established by a quality management system that meets the requirements of ISO 9001:2000 which has been independently certified by BVQI under certificate number: 131026

VPN VLAN CONFIGURATION IN UTSTAR DSLAM

v1.0

Page1 of 7

VPN VLAN Configuration


In the multiplay network, a combination of one outer VLAN & one inner VLAN is used for establishing the connectivity between a BB-VPN customer premises equipment & the network. So as per the Multiplay network design, the outer VLAN will be configured in the core equipments like BNG, RPR T1/T2 & OCLAN & the inner VLAN will be configured in DSLAM only. For each VPN customer, one inner VLAN needs to be configured in DSLAM. In the following section, we will be going through the various configuration steps that needs to be executed in a UTStar DSLAM for the VPN Connectivity. The VPN VLAN configuration in the DSLAM involves basically two steps. Step-1:VPN VLAN Configuration in ICM card Step-2: VPN VLAN Configuration in IP ADSL card VPN VLAN Configuration in ICM card

Before going directly into the VLAN configuration, it is a must to identify the ADSL Card/ADSL Port location of the VPN customer in the particular DSLAM. The VPN customer configuration in DSLAM is solely depends on this information only. The user VLAN identification has to be done in ICM card as well as in ADSL card. In the following sections, we are using an example of internet vlan 128 for checking/configuring of BB-VPN Vlan
(a)User VLAN Identification in ICM Card If a BB-VPN configuration request comes from a customer whose internet user vlan is 128,initially we have to track the customers ADSL card location in the ICM card .This can be checked using the following command

CONFIDENTIAL

VPN VLAN CONFIGURATION IN UTSTAR DSLAM

v1.0

Page2 of 7

Steps: AN2000_IB#slot icm AN2000_IB(ICM-A)#vlan AN2000_IB(ICM-A/VLAN)#show <user-vlanid> Ex: AN2000_IB#slot icm AN2000_IB(ICM-A)#vlan AN2000_IB(ICM-A/VLAN)#show 128 ---------- Information for VLAN 128 -----------VLAN ID VLAN Name Mode L2 ARP proxy status : 128 : vlan128 : Full-Bridge : DISABLE : 00:00:00:00:00:00 : 0.0.0.0

L2 ARP proxy MAC ADDR L2 ARP proxy IP ADDR Network Ports: ge 1; Subscriber Ports: internal 1; Tagged Ports: internal 1;ge 1; Untagged Ports: AN2000_IB(ICM-A/VLAN)#

L2 ARP proxy local status : DISABLE

In the above example, we can see under the Tagged ports one internal 1 & ge 1 ports are available. Internal 1 denotes that the customer is connected to the first ADSL card & ge 1 denotes the Uplink port towards the Tier-1/Tier-2.

CONFIDENTIAL

VPN VLAN CONFIGURATION IN UTSTAR DSLAM

v1.0

Page3 of 7

(b) Configure VPN VLAN in ICM Card Configure the allotted VPN VLAN for the customer in the ICM card using the following commands. Configuration steps are given below. Note:(The unique VPN inner VLAN for each customer under the DSLAM will be allotted from the Bangalore NOC only.) Steps: AN2000_IB#slot icm AN2000_IB(ICM-A)#vlan AN2000_IB(ICM-A/VLAN)#vid <VPN-vlan-id> name <vlan-name> Eg: AN2000_IB(ICM-A/VLAN)#vid 1650 name G-TEL (Please configure the customer name as vlan name) (c)Add the Uplink & Downlink interface to the VPN VLAN. Assign the ICM cards uplink & downlink interface to the VPN vlan. Normally Uplink interface in ICM card is GE-1 only. It may change from site to site. Downlink interface will depend on the ADSL card to which the subscriber is connected. In the above example shown in section (a), we have seen that vlan 128 is having internal 1 as the downlink interface & GE 1 as the uplink towards the Tier-1/Tier-2. Configure the same parameters for the VPN Vlan allotted for the same customer. Configuration steps are below. Steps: AN2000_IB(ICM-A/VLAN)#interface ge <interface> vid <VPN-vlanid> tag AN2000_IB(ICM-A/VLAN)#interface internal <interface> vid < VPN-vlanid > tag Eg: AN2000_IB(ICM-A/VLAN)#interface ge 1 vid 1650 tag AN2000_IB(ICM-A/VLAN)#interface internal 1 vid 1650 tag (In the above example GE -1 is the uplink towards the BNG & internal-1 is the downlink towards the first ADSL card.
CONFIDENTIAL

VPN VLAN CONFIGURATION IN UTSTAR DSLAM

v1.0

Page4 of 7

(d) User VLAN/ADSL Port Identification in ADSL card In this section, we are going to identify the ADSL port to which the customer is connected. The steps are given below. Steps: AN2000_IB#slot <slot-no> AN2000_IB(IPADSL8A-1)#vlan AN2000_IB(IPADSL8A-1/VLAN)#show <user-vlan> Ex: AN2000_IB#slot 1 AN2000_IB(IPADSL8A-1)#vlan AN2000_IB(IPADSL8A-1/VLAN)#show 128 VLAN Unknown Forward Bridge Port internal 1 1:0:0.35 2:0:0.35 3:0:0.35 47:0:0.35 48:0:0.35 VLAN ID VLAN Name Tagged Ports: Internal 1 Untagged Ports: 1:0:0.35 AN2000_IB (IPADSL8A-1/VLAN) # : Off Egress Tag Tag Tag Tag Tag Tag Ingress Check Only Configured Only Configured Only Configured Only Configured Only Configured Only Configured : 128 : vlan128

<------------Output Omitted----------->

---------- Information for VLAN 128 ------------

User Isolation : Enabled

CONFIDENTIAL

VPN VLAN CONFIGURATION IN UTSTAR DSLAM

v1.0

Page5 of 7

In the above example, it is shown that under the untagged ports, 1:0:0.35 is given. 1:0:0.35 denotes that the customer is connected to the first port of this ADSL card & using a 0:35 VPI/VCI for internet vlan 128. Now the customers ADSL port location is also tracked & is ready for configuring the VPN Vlan in ADSL card. (e)Configure VPI/VCI for the VPN connectivity As a standard, in Multiplay network we are using a 0/ 32 as VPI/VCI for the VPN configuration. Use the following steps for configuring the ATM port with 0/32 VPI/VCI. AN2000_IB#slot 1 AN2000_IB(IPADSL8A-1)#port AN2000_IB(IPADSL8A-1/PORT)#interface encapsulation llc-bridge Eg: AN2000_IB#slot 1 AN2000_IB(IPADSL8A-1)#port AN2000_IB(IPADSL8A-1/PORT)#interface atm 1:0.32 qos ubr encapsulation llcbridge (In the above example, atm port is configured in the first ADSL port of the first ADSL slot with 0/32 VPI/VCI.) (f)Configure the VPN Vlan in ADSL card The VPN vlan should be configured in the ADSL card also. Configuration steps are below. Steps: AN2000_IB(IPADSL8A-1)#vlan AN2000_IB(IPADSL8A-1/VLAN)# vid <VPN-vlan-id> name <vlan-name> Eg: AN2000_IB(ICM-A/VLAN)#vid 1650 name G-TEL (Please configure the customer name as vlan name) atm <port-no>:0.32 qos ubr

CONFIDENTIAL

VPN VLAN CONFIGURATION IN UTSTAR DSLAM

v1.0

Page6 of 7

(g)Add the atm interface to the Multicast vlan The atm interface has to be assigned to the VPN vlan as an untag port. Configuration steps are below. Steps: AN2000_IB#slot 1 AN2000_IB(IPADSL8A-1)#vlan AN2000_IB(IPADSL8A-1/VLAN)#interface atm <port-no>:0.32 vid <VPN-vlanid> untag Eg: AN2000_IB#slot 1 AN2000_IB(IPADSL8A-1)#vlan AN2000_IB(IPADSL8A-1/VLAN)#interface atm 1:0.32 vid 1650 untag

CONFIDENTIAL