l2vlan

Configuring VLAN Trunking

Unassigned switch ports on SonicWALL security appliances can function as VLAN trunk ports.

You can enable or disable VLANs on the trunk ports, allowing the existing VLANs on SonicWALL security appliances to be bridged to respective VLANs on another switch connected via the trunk port. SonicWALL security appliances support 802.1Q encapsulation on the trunk ports. A maximum of 32 VLANs can be enabled on each trunk port.

The VLAN trunking feature provides the following functions:

 
Change VLAN ID’s of existing PortShield groups
 
Add/delete VLAN trunk ports
 
Enable/disable VLANs on the trunk ports

The allowed VLAN ID range is 1-4094. Some VLAN IDs are reserved for PortShield use. The reserved range is displayed in the SonicOS management interface. You can mark certain PortShield groups as “Trunked”. Once the PortShield group is dismantled, the associated VLAN is automatically disabled on the trunk ports.

VLANs can exist locally in the form of PortShield groups or can be totally remote VLANs. Below, the Network > PortShield page shows a PortShield group with X14 as the PortShield interface and X15, X16, and X17 as members of the PortShield group. X20 and X21 are VLAN trunk ports.

You can change the VLAN ID of PortShield groups on SonicWALL security appliances. This allows easy integration with existing VLAN numbering.

Unlike traditional Layer 2 switches, SonicWALL security appliances do not allow changing port VLAN membership in an ad-hoc manner. VLAN membership of a port must be configured via PortShield configuration in the SonicOS management interface. For more information about configuring PortShield groups, see “Network > PortShield Groups” section .

A virtual interface (called the VLAN Trunk Interface) is automatically created for remote VLANs. When the same remote VLAN is enabled on another trunk port, no new interface is created. All packets with the same VLAN tag ingressing on different trunk ports are handled by the same virtual interface. This is a key difference between VLAN sub-interfaces and VLAN trunk interfaces.

The Name column on the Network > Interfaces page displays the VLAN Trunk Interfaces for the VLAN trunks on which VLAN IDs 100 and 200 are enabled.

You can enable any VLAN, local or remote, on a VLAN trunk to allow bridging to to respective VLANs on another switch. For example, local VLAN 3787, created from a PortShield group, can be enabled on the VLAN trunk for port X20, which also has two remote VLANs enabled on it.

The VLAN Table on the Switching > VLAN Trunking page displays the trunk port, X20, as a member of local VLAN 3787 after the VLAN is enabled on the VLAN trunk.

The diagram illustrates a VLAN trunk with two trunk ports, bridging the Sales, Engineering, QA, and Finance VLANs through the appliance. Each remote VLAN was enabled on VLAN trunk port X20 initially, causing the creation of four virtual VLAN trunk interfaces. When these VLANs were also enabled on trunk port X21, no new virtual interfaces were created.

VLAN trunking interoperates with Rapid Spanning Tree Protocol (RSTP), Link Aggregation and Port Mirroring features. A VLAN trunk port can be mirrored, but cannot act as a mirror port itself. You cannot enable Static port security on the VLAN trunk port.

Ports configured as VLAN trunks cannot be used for any other function and are reserved for use in Layer 2 only. For example, you cannot configure an IP Address for the trunk ports.

When a Trunk VLAN interface has been configured on a particular trunk port, that trunk port cannot be deleted until the VLAN interface is removed, even though the VLAN is enabled on multiple trunk ports. This is an implementation limitation and will be addressed in a future release.

See the following procedures:

 
“Editing VLANs” section
 
“Adding a VLAN Trunk Port” section
 
“Deleting VLAN Trunk Ports” section
 
“Enabling a VLAN on a Trunk Port” section

Editing VLANs

To edit a VLAN, perform the following steps:

Step 1
On the Switching > VLAN Trunking page, click the Configure icon in the VLAN Table row for the VLAN ID you want to edit.
Step 2
In the Edit Vlan for PortShield window, do one of the following:
 
Type a different VLAN ID into the Vlan ID field. You can enter any VLAN ID except the original system-specified VLAN ID or any others in the Reserved VLAN IDs.
 
Use the VLAN ID number in the Vlan ID field, which matches the one for which you clicked the Configure icon.
Step 3
To enable trunking for this VLAN, select the Trunked checkbox. To disable trunking for this VLAN, clear the checkbox.
Step 4
Click OK .

Adding a VLAN Trunk Port

To add a VLAN trunk port, perform the following steps:

Step 1
On the Switching > VLAN Trunking page under VLAN Trunks , click the Add button.
Step 2
In the Add VLAN Truck Port window, select the port to add from the Trunk Port drop-down list.
Step 3
Click OK .

Deleting VLAN Trunk Ports

To delete one or more VLAN trunk ports, perform the following steps:

Step 1
On the Switching > VLAN Trunking page under VLAN Trunks , select one or more checkboxes for the VLAN trunk ports you want to delete.
Step 2
Click the Delete button.
Step 3
Click OK in the confirmation dialog box.