Wired Intelligent Edge

last person joined: 23 hours ago 

Bring performance and reliability to your network with the HPE Aruba Networking Core, Aggregation, and Access layer switches. Discuss the latest features and functionality of your switching devices, and find ways to improve security across your network to bring together a mobile-first solution
Expand all | Collapse all

Why vlan user config with Dynamic Seg

This thread has been viewed 1 times
  • 1.  Why vlan user config with Dynamic Seg

    Posted May 27, 2020 03:28 PM

    Hello, I have a question about the necessity to have the secondary role vlan configured in the switch for the user.

     

    As I don't need to configure in any interface this vlan, and as the traffic is tunneled to the controller. Why I need to have the user vlan(that will be used in the controller) created in the switch?

     

    In the guide of dyn seg config:

    "Please note that the VLAN ID specified here must exist on the switch, but you cannot apply it to any physical or virtual port either tagged or untagged"



  • 2.  RE: Why vlan user config with Dynamic Seg

    Posted May 27, 2020 04:06 PM
    “The reserved VLAN is where all tunneled traffic will traverse to and from the switch. This VLAN is automatically created once defined here and connectivity between switch and controller is established.”

    https://community.arubanetworks.com/aruba/attachments/aruba/CampusSwitching/4032/2/ArubaOS-Switch%20User-Based%20Tunneling%20Technical%20Whitepaper.pdf


    Sent from Mail for Windows 10


  • 3.  RE: Why vlan user config with Dynamic Seg

    Posted May 27, 2020 04:25 PM

    Hi Victor, but in this case I'm not talking about the tunnel VLAN.

    I'm talking about the User VLAN that will be assigned in the controller.

     

    When I create the user-role in the switch, I must set the vlan-id (user VLAN) for that role. 



  • 4.  RE: Why vlan user config with Dynamic Seg
    Best Answer

    EMPLOYEE
    Posted May 27, 2020 05:54 PM

    Hi, 

     

    The user VLAN does not have to exist in the switch user role if using the reserved VLAN mode (UBT 2.0).  You merely need to indicate in the switch user role that the traffic will be tunneled.  VLAN assignment and policy will occur with the secondary or gateway role.



  • 5.  RE: Why vlan user config with Dynamic Seg
    Best Answer

    Posted May 27, 2020 06:21 PM
    The user VLAN only needs to exist on the controller side



    Thank you

    Victor Fabian

    Pardon typos sent from Mobile