vlans
语法(QFX 系列、QFabric、NFX 系列和 EX4600)
vlans { vlan-name { description text-description; dot1q-tunneling { customer-vlans (id | range); } filter input filter-name; filter output filter-name; interface interface-name { isolated; mapping (policy | tag push | native push); promiscuous; } isolation-vlan-id; l3-interface vlan.logical-interface-number; mac-limit number; no-local-switching; no-mac-learning; primary-vlan vlan-name; pvlan extend-secondary-vlan-id vlan-id; vlan-id number; vlan-range vlan-id-low-vlan-id-high; } }
语法(QFX 系列、NFX 系列和 EX4600)
vlans { vlan-name { description text-description; domain-type bridge; forwarding-options { dhcp-security { arp-inspection; group group-name { interface interface-name { static-ip ip-address { mac mac-address; } } overrides { no-option82; trusted; untrusted; } } ip-source-guard; no-dhcp-snooping; option-82 { circuit-id { prefix { host-name; logical-system-name; routing-instance-name; } use-interface-description (device | logical); use-vlan-id; } remote-id { host-name hostname; use-interface-description (device | logical); use-string string; } vendor-id { use-string string; } } } fip-security { examine-vn2vf; examine-vn2vn { beacon-period milliseconds; } fc-map fc-map-value; interface interface-name { (fcoe-trusted | no-fcoe-trusted;) } } } l3-interface irb.logical-unit-number; multicast-snooping-options { flood-groups [group-names]; forwarding-cache { threshold { reuse threshold; suppress threshold; } } graceful-restart { disable; restart-duration duration; } host-outbound-traffic { dot1p bits; forwarding-class forwarding-class; } multichassis-lag-replicate-state; nexthop-hold-time time; options { syslog { level level; mark interval; upto level; } } traceoptions { file filename { files number; no-world-readable; size file-size; world-readable; } flag flag { disable; } } } switch-options { interface interface-name { interface-mac-limit limit { packet-action action; } static-mac mac-address; } interface-mac-limit limit { packet-action action; } mac-move-limit limit { packet-action action; } mac-table-size limit { packet-action drop; } no-mac-learning; } } vlan-id number; vlan-id-list [vlan-id | vlan-id–vlan-id]; vlan-tags inner value; outer value; } vxlan { ingress-node-replication ovsdb-managed } } } }
语法(SRX 系列和 EX 系列)
vlans { vlan-name { description text-description; dot1q-tunneling { customer-vlans (id | range) layer2-protocol-tunneling all | protocol-name { drop-threshold number; shutdown-threshold number; } } filter input filter-name; filter output filter-name; interface interface-name { egress; ingress; mapping (native (push | swap) | policy | tag (push | swap)); pvlan-trunk; } isolation-id id-number; l3-interface l3-interface-name.logical-interface-number; l3-interface-ingress-counting layer-3-interface-name; mac-limit limit action action; mac-table-aging-time seconds; no-local-switching; no-mac-learning; primary-vlan vlan-name; vlan-id number; vlan-prune; vlan-range vlan-id-low-vlan-id-high; } }
语法(SRX 系列)
vlans { vlan name { (vlan-id (1..3967) | vlan-id-list [ vlan-id-numbers]); description; forwarding-options { dhcp-security { arp-inspection; dhcpv6-options { option-16 { use-string use-string; } option-18 { prefix { host-name; logical-system-name; routing-instance-name; vlan-id; vlan-name; } use-interface-description (device | logical); use-interface-index (device | logical); use-interface-mac; use-interface-name (device | logical); use-string use-string; } option-37 { prefix { host-name; logical-system-name; routing-instance-name; vlan-id; vlan-name; } use-interface-description (device | logical); use-interface-index (device | logical); use-interface-mac; use-interface-name (device | logical); use-string use-string; } } group group-name { interface interface-name { static-ip { ip-address { mac-address; } } static-ipv6 { ip-address { mac-address; } } } overrides { no-dhcpv6-options; no-option16; no-option18; no-option37; no-option82; trusted; untrusted; } } ip-source-guard; ipv6-source-guard; neighbor-discovery-inspection; no-dhcp-snooping; no-dhcpv6-snooping; option-82 { circuit-id { prefix { host-name; logical-system-name; routing-instance-name; } use-interface-description (device | logical); use-vlan-id; } remote-id { host-name; mac; use-interface-description (device | logical); use-string use-string; } vendor-id { use-string use-string; } } } filter { input filter-name; } flood { input filter-name; } } interface interface-name; l3-interface l3-interface-name; mcae-mac-flush; mcae-mac-synchronize; service-id service-id; switch-options { interface name { action-priority action-priority; encapsulation-type (ethernet | ethernet-vlan); ignore-encapsulation-mismatch; interface-mac-limit { limit; packet-action (drop | drop-and-log | log | none | shutdown); } no-mac-learning; pseudowire-status-tlv; static-mac mac-address { vlan-id value; } } interface-mac-limit { limit; packet-action (drop | drop-and-log | log | none | shutdown); } mac-table-aging-time seconds; mac-table-size { limit; packet-action { drop; } } no-mac-learning; static-rvtep-mac { mac mac_addr { remote-vtep; } } } } }
语法 (vSRX)
vlans { vlan name { (vlan-id (all | none | number) | vlan-id-list [ vlan-id-numbers] | vlan-tags <inner number> outer number); description; forwarding-options { dhcp-security { arp-inspection; dhcpv6-options { option-16 { use-string use-string; } option-18 { prefix { host-name; logical-system-name; routing-instance-name; vlan-id; vlan-name; } use-interface-description (device | logical); use-interface-index (device | logical); use-interface-mac; use-interface-name (device | logical); use-string use-string; } option-37 { prefix { host-name; logical-system-name; routing-instance-name; vlan-id; vlan-name; } use-interface-description (device | logical); use-interface-index (device | logical); use-interface-mac; use-interface-name (device | logical); use-string use-string; } } group group-name { interface interface-name { static-ip { ip-address; } static-ipv6 { ip-address; } } overrides { no-dhcpv6-options; no-option16; no-option18; no-option37; no-option82; trusted; untrusted; } } ip-source-guard; ipv6-source-guard; light-weight-dhcpv6-relay; neighbor-discovery-inspection; no-dhcp-snooping; no-dhcpv6-snooping; option-82 { circuit-id { prefix { host-name; logical-system-name; routing-instance-name; } use-interface-description (device | logical); use-vlan-id; } remote-id { host-name; mac; use-interface-description (device | logical); use-string use-string; } vendor-id { use-string use-string; } } } filter { input filter-name; } flood { input filter-name; } } interface interface-name; l3-interface l3-interface-name; mcae-mac-synchronize; no-irb-layer-2-copy; service-id service-id; switch-options { interface name { action-priority action-priority; encapsulation-type (ethernet | ethernet-vlan); ignore-encapsulation-mismatch; interface-mac-limit { disable; limit; packet-action (drop | drop-and-log | log | none | shutdown); } mac-pinning; no-mac-learning; pseudowire-status-tlv; static-mac mac-address { vlan-id value; } } interface-mac-limit { limit; packet-action (drop | drop-and-log | log | none | shutdown); } mac-statistics; mac-table-aging-time seconds; mac-table-size { limit; packet-action { drop; } } no-mac-learning; static-rvtep-mac { mac mac_addr { remote-vtep; } } } } }
层次结构级别
[edit]
[edit routing-instances routing-instance-name]
说明
配置 VLAN 属性。
在 EX 系列交换机和 SRX 系列设备上(包括 vSRX),以下配置准则适用:
当为 Q-in-Q 隧道启用 VLAN 时,只能使用专用 VLAN (PVLAN) 防火墙过滤器。
如果 VLAN 采用 Q-in-Q 隧道,并且数据包从接入接口到达,则会将 S-VLAN 标记添加到数据包中。
您不能使用防火墙过滤器将集成路由和桥接 (IRB) 接口或路由的 VLAN 接口 (RVI) 分配给 VLAN。
使用防火墙过滤器执行的 VLAN 分配将覆盖所有其他 VLAN 分配。
默认
如果使用默认的出厂配置,则所有交换机接口都将成为 VLAN default的一部分。
必需的权限级别
路由 — 在配置中查看此语句。
路由控制 — 将此语句添加到配置中。
system - 在配置中查看此语句。
system-control — 将此语句添加到配置中。
发布信息
在 Junos OS 9.0 版中引入的语句。
在适用于 QFX 系列的 Junos OS 12.1 版中引入的专用 VLAN 和 Q-in-Q 隧道语句。