Chapter 1 VLC Overview

DHCP Snooping

DHCP snooping allows the system to identify packets with DHCP server assigned IP address(es) and block access of devices using unknown IP addresses on a subscriber port. You can also manually add static IP addresses to the DHCP snooping table.

LAN 2 LAN

LAN 2 LAN allows you to control whether or not a DHCP server connected to a subscriber port is permitted to receive and send traffic through the IES.

Anti-IP Address Spoofing

With DHCP snooping, a line card records which IP addresses are assigned on each port. The line card drops packets from a device using a different IP address.

Anti-MAC Address Spoofing

The VLC checks to make sure the MAC addresses of the devices connected to the DSL ports are not the same as MAC addresses of devices connected to the Ethernet network. This protects the network from disruptions of service caused by subscriber devices spoofing the MAC address of ISP servers.

ARP Inspection

ARP inspection drops ARP packets if the MAC address to IP address binding does not match that of a learned or manually added trusted client. This prevents many common man-in-the- middle attacks.

Transparent LAN Service (TLS)

Use TLS (also known as VLAN stacking) to add an outer VLAN tag to the inner IEEE 802.1Q tagged frames that enter the network. This allows a service provider to provide different services based on specific VLANs, for many different customers.

VDSL Double-Tag VLAN

DT VLAN (Double-Tag VLAN) adds two VLAN tags to untagged frames received on a VDSL port. These two VLAN tags consist of an inner c-tag (customer tag) and an outer s-tag (service provider tag). These double VLAN tags consist of an inner c-tag (customer tag) and an outer s-tag (service provider tag). The line card drops any tagged frames it receives from a subscriber.

Double-Tag PVC (DTPVC)

For VDSL2 ports operating in ADSL2+ connection mode, DTPVCs (Double-Tag Permanent Virtual Circuits) add double VLAN tags to untagged frames received from a DSL subscriber on the specified PVC. These double VLAN tags consist of an inner c-tag (customer tag) and an outer s-tag (service provider tag). The line card drops any tagged frames received on the DTPVC. DTPVCs support DHCP relay, IGMP, IEEE 802.1x and PPPoE agent.

 

19

VLC1324G User’s Guide