Re: bridged vlan interfaces

Grant Taylor <[email protected]> Sun, 25 Nov 2007 23:19:58 -0600
Newsgroups gmane.linux.network.bridge.ebtables.user
Message-ID <[email protected]>
On 11/21/2007 1:07 PM, Jonathan Thibault wrote:
> In that situation, if I add in.3 to the bridge, the network keeps
> going without problems.  The problem will only manifest if I add 3T
> on port 1 (to the linux box) and any one or all of the ports to the
> BH and the rest of our radios.

So if you add the vlan to the interface on the Linux box either in or 
out of the bridge things are fine?  The problem only occurs when you 
program VLAN 3 access to the physical port on the switch as in you 
configure the port to be from 1U, 2T to be 1U, 2T, and 3T?  This really 
makes me think that the problem is on the switch.

To clarify things, we have eight possible combinations.  Will you please 
tell me which ones fail?

s = switch port with out vlan 3
S = switch port with vlan 3
i = interface on linux box with out vlan 3
I = interface on linux box with vlan 3
b = bridge on linux box with out in.3
B = bridge on linux box with in.3

sib = works
siB = (invalid)
sIb = ???
sIB = ???
Sib = ???
SiB = (invalid)
SIb = ???
SIB = ???

siB and SiB are invalid because you can not have in.3 in a bridge if 
in.3 does not exist on the Linux box.

> Right now, the switch linking the 'in' interface to the radio network
> is a plain switch so in essence the same as having all vlans
> enabled.on a trunk.

Agreed.

> Right.  And I'd expect the problem only to manifest when the port is
> in forwarding state.

Agreed.

> That's pretty much what I understand of things as well.

> I wouldn't put myself past that sort of mistake either, so you can be
>  sure that I checked that thoroughly already ;)  Without a managed
> switch in the way right now however, it's a non-issue.

Hey, we are all human.  I have made that mistake so I had to ask (myself).

> With the exception of the plain switches I use here and there as
> simple connecting devices (they don't know what a vlan is at all),
> yes, everything is 802.1Q as per the specification I posted before on
> the radios.  The managed switch are also 802.1Q only, and according
> to my kernel config, I'm using 802.1Q on the linux box.  I'd likely
> have a tougher time getting this setup to work otherwise ;)

Ok.  I thought so.  (Again) I just had to ask.

> Correct.  'out' has no vlan interfaces on it.  and 'in' is not part
> of the bridge.  In the working condition, the two ports on the bridge
> are 'in.2' and 'out'

> I'll have to wait a bit to perform those tests.  The manufacturer of
> our radio just told us that in order to get support on the issue, we
> have to upgrade our entire selection to their latest firmware...
> That's a major pain, especially since the upgrade path is not direct
> and I have to perform three consecutive firmware updates for each one
> of our 600-some installed radios.

Oh, my!  I'm sorry.

> It would have been nice to have updated radios shipped to us in the 
> first place :P

If your vendor is any thing like Cisco, you have to order the correct 
part number that you have to know to find to get the updated and / or 
current firmware.  Knowing which part number(s) to order is your 
responsibility though, at least according to them.  *SIGH*



Grant. . . .

-------------------------------------------------------------------------
This SF.net email is sponsored by: Microsoft
Defy all challenges. Microsoft(R) Visual Studio 2005.
http://clk.atdmt.com/MRT/go/vse0120000070mrt/direct/01/