Forum Discussion

Vadim_Yakovlev_'s avatar
Vadim_Yakovlev_
Icon for Nimbostratus rankNimbostratus
Jul 21, 2018

VLAN tagging on non-tagged interfaces

We have a BIG-IP VE running under ESXi. All its virtual NICs are connected to virtual switch port groups configured for EST (External Switch Tagging) - that is, with VLAN ID 0. Correspondingly, in BIG-IP configuration all VLANs (there are only two) are assigned to NICs in untagged mode. As far as I understand, that means BIG-IP should never receive or generate 802.1Q tagged packets. However, when I do some traffic capture on the BIG-IP with tcpdump and then open it in Wireshark, I see 802.1Q layer between Ethernet and IP, and it contains correct VLAN IDs as set in system config. That totally puzzles me. The only idea I have, this layer is a kind of "virtual" - not really sent or received by the NIC, but added and used internally to facilitate traffic handling within TMOS. Is that correct?

 

1 Reply

  • Surgeon's avatar
    Surgeon
    Ret. Employee

    Hi Vadim,

     

    VLAN tagging is added to the packet capture when you do it on the big-ip. This is expected. Big-ip uses modified tcpdump and capturing mode data (including internal tmm) then regular tcpdump