25-5
Software Configuration Guide—Release 15.0(2)SG
OL-23818-01
Chapter 25 Configuring 802.1Q Tunneling, VLAN Mapping, and Layer 2 Protocol Tunneling Configuring 802.1Q Tunneling
Figure 25-3 Potential Problem with 802.1Q Tunneling and Native VLANs

System MTU

The default system MTU for traffic on the Catalyst 4500 series switch is 1500 bytes. You can configure
the switch to support larger frames by using the system mtu global configuration command. Because
the 802.1Q tunneling feature increases the frame size by 4 bytes when the metro tag is added, you must
configure all switches in the service provider network to be able to process larger frames by increasing
the switch system MTU size to at least 1504 bytes. The maximum allowable system MTU for Catalyst
4500 Gigabit Ethernet switches is 9198 bytes; the maximum system MTU for Fast Ethernet switches is
1552 bytes.
802.1Q Tunneling and Other Features
Although 802.1Q tunneling works well for Layer 2 packet switching, incompatibilities exist between
some Layer 2 features and Layer 3 switching:
A tunnel port cannot be a routed port.
IP routing is not supported on a VLAN that includes 802.1Q ports. Packets received from a tunnel
port are forwarded based only on Layer 2 information. If routing is enabled on a switch virtual
interface (SVI) that includes tunnel ports, untagged IP packets received from the tunnel port are
recognized and routed by the switch. Customers can access the Internet through the native VLAN.
If this access is not needed, you should not configure SVIs on VLANs that include tunnel ports.
Tunnel ports do not support IP access control lists (ACLs).
Layer 3 quality of service (QoS) ACLs and other QoS features related to Layer 3 information are
not supported on tunnel ports. MAC-based QoS is supported on tunnel ports.
802.1Q
trunk port
VLANs 30-40
Native VLAN 40
Tunnel port
Access VLAN 30
Tunnel port
Service
provider
Tag not added
for VLAN 40 Tag
removed
VLANs 5-50
Switch 4
Customer A
VLANs 30-40
Native VLAN 40
Switch 2 Switch 3
Q
Switch 5
Customer B
Switch 1
Customer A
Native
VLAN 40
74074
Trunk
Asymmetric link
Correct path for traffic
Incorrect path for traffic due to
misconfiguration of native VLAN
by sending port on Switch 2
Q = 802.1Q trunk ports
Tunnel port
Access VLAN 40
Packet tagged
for VLAN 30
VLAN 40