Port-based VLAN (PVID) Mapping and Untagged External Traffic Support in PFE L2 Bridge

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Port-based VLAN (PVID) Mapping and Untagged External Traffic Support in PFE L2 Bridge

2,468 Views
minJ
Contributor I
1. Environment

 

Platform: S32G3

 

Software:
* NXP RTD: SW32G_RTD_4.4_5.0.0_QLP04
* PFE firmware: 1.12.0
* Tool: libfci_cli

 

PFE is running in VLAN_BRIDGE mode.

 

---

 

2. Goal

 

I want to keep all external traffic untagged, while implementing port-based VLAN isolation only inside the PFE.

 

Desired behavior:

 

```
emac0 ↔ hif0   (internal VLAN 10)
emac1 ↔ hif1   (internal VLAN 20)
emac2 ↔ hif2   (internal VLAN 30)
```

 

That is,
* External PCs send/receive frames without VLAN tags
* VLAN is used only internally in the PFE for port-based traffic separation
* The purpose is to prevent unnecessary broadcast/flooding in a master/slave architecture

 

---

 

3. Current configuration

 

VLAN and Bridge Domain are configured as follows.

 

Key commands:
```sh
# Bridge Domain and interface configuration
libfci_cli bd-add --vlan 10
libfci_cli bd-add --vlan 20
libfci_cli bd-add --vlan 30

 

libfci_cli bd-update --vlan 10 --ucast-hit FORWARD --ucast-miss FLOOD --mcast-hit FORWARD --mcast-miss FLOOD
libfci_cli bd-update --vlan 20 --ucast-hit FORWARD --ucast-miss FLOOD --mcast-hit FORWARD --mcast-miss FLOOD
libfci_cli bd-update --vlan 30 --ucast-hit FORWARD --ucast-miss FLOOD --mcast-hit FORWARD --mcast-miss FLOOD

 

libfci_cli bd-insif --vlan 10 --i hif0 --tag OFF
libfci_cli bd-insif --vlan 10 --i emac0 --tag OFF
libfci_cli bd-insif --vlan 20 --i hif1 --tag OFF
libfci_cli bd-insif --vlan 20 --i emac1 --tag OFF
libfci_cli bd-insif --vlan 30 --i hif2 --tag OFF
libfci_cli bd-insif --vlan 30 --i emac2 --tag OFF

 

# PHY interface mode configuration
libfci_cli phyif-update --i emac0 -E --promisc OFF --mode VLAN_BRIDGE
libfci_cli phyif-update --i emac1 -E --promisc OFF --mode VLAN_BRIDGE
libfci_cli phyif-update --i emac2 -E --promisc OFF --mode VLAN_BRIDGE
libfci_cli phyif-update --i hif0  -E --promisc OFF --mode VLAN_BRIDGE
libfci_cli phyif-update --i hif1  -E --promisc OFF --mode VLAN_BRIDGE
libfci_cli phyif-update --i hif2  -E --promisc ON --mode VLAN_BRIDGE

 

libfci_cli bd-stent-add --vlan 10 --mac <MAC Address> --i hif0
libfci_cli bd-stent-update --vlan 10 --mac <MAC Address> --egress hif0
libfci_cli bd-stent-add --vlan 20 --mac <MAC Address> --i hif1
libfci_cli bd-stent-update --vlan 20 --mac <MAC Address> --egress hif1
libfci_cli bd-stent-add --vlan 30 --mac <MAC Address> --i hif2
libfci_cli bd-stent-update --vlan 30 --mac <MAC Address> --egress hif2
```

 

In summary:
- emac/hif pairs are assigned to each VLAN (10/20/30)
- All traffic is untagged externally
- VLAN is used only internally for separation

 

 

 

4. Problem

 

When untagged frames arrive from outside (e.g., PC → ping), the ingress counter for each domain remains zero.

 

```
domain 10 ingress: 0
domain 10 ingress: 0
domain 20 ingress: 0
```

 

That is, untagged frames are not mapped to internal VLANs, so the intended port-based separation does not work.

 

# libfci_cli bd-print
domain 01  [default]
    phyifs (tagged)   : ---
    phyifs (untagged) : ---
    ucast-hit  action : 3 (DISCARD)
    ucast-miss action : 3 (DISCARD)
    mcast-hit  action : 3 (DISCARD)
    mcast-miss action : 3 (DISCARD)
    ingress           : 4173
    ingress bytes     : 560619
    egress            : 958
    egress bytes      : 234538
domain 00  [fallback]
    phyifs (tagged)   : ---
    phyifs (untagged) : ---
    ucast-hit  action : 3 (DISCARD)
    ucast-miss action : 3 (DISCARD)
    mcast-hit  action : 3 (DISCARD)
    mcast-miss action : 3 (DISCARD)
    ingress           : 0
    ingress bytes     : 0
    egress            : 0
    egress bytes      : 0
domain 10
    phyifs (tagged)   : ---
    phyifs (untagged) : emac0,hif0
    ucast-hit  action : 0 (FORWARD)
    ucast-miss action : 1 (FLOOD)
    mcast-hit  action : 0 (FORWARD)
    mcast-miss action : 1 (FLOOD)
    ingress           : 0
    ingress bytes     : 0
    egress            : 0
    egress bytes      : 0
domain 20
    phyifs (tagged)   : ---
    phyifs (untagged) : emac1,hif1
    ucast-hit  action : 0 (FORWARD)
    ucast-miss action : 1 (FLOOD)
    mcast-hit  action : 0 (FORWARD)
    mcast-miss action : 1 (FLOOD)
    ingress           : 0
    ingress bytes     : 0
    egress            : 0
    egress bytes      : 0
domain 30
    phyifs (tagged)   : ---
    phyifs (untagged) : emac2,hif2
    ucast-hit  action : 0 (FORWARD)
    ucast-miss action : 1 (FLOOD)
    mcast-hit  action : 0 (FORWARD)
    mcast-miss action : 1 (FLOOD)
    ingress           : 0
    ingress bytes     : 0
    egress            : 0
    egress bytes      : 0
Command successfully executed.

 

---

 

5. Question

Is it possible to keep external traffic untagged, and achieve VLAN-based isolation only inside the PFE?

* Map untagged ingress frames to a specific VLAN per port (PVID function)
* VLAN is used only inside the PFE
* External devices operate without VLAN tags

In other words,
```
ingress (untagged) → VLAN 10 -> egress (untagged)
ingress (untagged) → VLAN 20 -> egress (untagged)
ingress (untagged) → VLAN 30 -> egress (untagged)
```
is the desired behavior.

1. Does the PFE support port-based VLAN?
2. If yes, which firmware feature or configuration enables it?
3. Is it related to the vlan_conf or ingress_vlan features shown in fwfeat-print?
0 Kudos
Reply
6 Replies

2,439 Views
alejandro_e
NXP TechSupport
NXP TechSupport

Hello @minJ,

Please find my answers below:

  • Is it possible to keep external traffic untagged, and achieve VLAN-based isolation only inside the PFE?
    • For what I can see in the documentation, no, you cannot use external unteagged traffic and only used VLAN tags internally. If you configure a port to a BD (Bridge domain) It can have three ways of operation, Default BD, Fall-back BD and Standard BD, in all three the VLAN is checked to either accept or discard the frame depending on certain rules. You can check section L2 Bridge VLAN Awareness and Domains of the PFE-SW_S32G_FCI_API_ReferenceManual_2.7.0. for more details on those rules.
  • Does the PFE support port-based VLAN? 
    • Not directly, you would need to create different BDs for each VLAN and configure each port to their respective domain. In summary, you can configure BD-based VLAN, where each BD uses a different port. Please check the same document and section I mentioned above.
  • If yes, which firmware feature or configuration enables it?
    • This should answered with the information from the other two questions.
  • Is it related to the vlan_conf or ingress_vlan features shown in fwfeat-print?
    • If you mean vlan_conf_check, yes both are related to this topic, however enabling/configuring this options will configure the ports so that frames without vlan are discarded.

A possible solution to avoid flooding in a master-slave configuration could be avoid using that mode and instead forward the frames using IPCF to the other domain, for example if the M7_0 is the owner of the PFE, it forwards only some frames to the A53/Linux domain. Depending on your requirements this can be a viable option. Let me know if you require more elaboration on this idea.

 

Please let me know if you have more question.

0 Kudos
Reply

2,421 Views
minJ
Contributor I

Hello,
Thank you for the detailed explanation.

I would like to confirm whether the Linux commands I described in “3. Current configuration”represent a configuration that is fundamentally unsupported, or if there might be some missing configuration on my side.

My current test environment is as follows:

• One PC

• The PC has three NICs

• Each NIC is directly connected to one of the board’s EMAC ports

 

On the PC side, I am not configuring any VLAN interface. I am simply sending a normal ping.

 

The behavior I expect is the following:

When the PC sends a ping, the board should forward the packet based on the destination IP and the corresponding Bridge Domain (BD), and then transmit it to the ports that belong to that VLAN.

 

The configuration I would like to achieve is:

VLAN10 : HIF0, EMAC0

VLAN20 : HIF1, EMAC1

VLAN30 : HIF2, EMAC2

VLAN40 : HIF3, EMAC0, EMAC1, EMAC2

In other words:

• EMAC0/1/2 are each connected to their dedicated VLANs (10/20/30).

• At the same time, they also participate in a shared VLAN40, which communicates with HIF3.

 

With the current Linux commands:

• If I put all ports into VLAN1, everything works as expected.

• However, when I separate them into VLAN10/20/30, the ingress/egress counters only increase in VLAN1, and not in VLAN10/20/30.

 

Therefore I have two questions:

1. Is this type of VLAN configuration supported by the PFE VLAN_BRIDGE model, or is there some configuration step that I may have missed?

2. Currently, the PC sends untagged packets (just a normal ping).

In this case, is it impossible for the PFE to classify the ingress traffic into a specific VLAN BD?

In other words, does this setup require the PC to send VLAN-tagged packets?

For example, should the PC be configured like this to send tagged traffic?

 

ip link add link eth0 name eth0.40 type vlan id 40

ip link set eth0.40 up

ping -I eth0.40 192.168.x.x

 

Any guidance on whether this configuration is feasible, or if there is a recommended approach for this scenario, would be greatly appreciated.

 

Thank you.

0 Kudos
Reply

2,313 Views
alejandro_e
NXP TechSupport
NXP TechSupport

Hello @minJ,

To which document are your referring when mentioning 3. Current configuration I checked all documents in the PFE Linux Documentation and I was not able to find that section. Please indicated the page of the section and revision of the document. 

Regarding the classification of untagged packages in a VLAN port, I misunderstood the documentation before, for that you would need to configure a BD with the default configuration, it has de following description:

Default BD:
Factory default VLAN ID of this bridge domain is 1. This domain processes ingress frames which either have a VLAN tag equal to the Default BD VLAN ID, or do not have a VLAN tag at all (untagged Ethernet frames).

This is the only BD configuration that can handle untagged frames, Therefore with this configuration you don't need to send tagged messages from your host. Moreover, other type of BDs will not process Frames without VLAN tag.

 

Sorry for the confusion before. Let me know if you have more questions.

0 Kudos
Reply

2,295 Views
minJ
Contributor I

Hello,

The '3. Current configuration' I mentioned refers to the Linux commands in my first question.
I apologize for not making this clear earlier.


# Bridge Domain and interface configuration
libfci_cli bd-add --vlan 10
libfci_cli bd-add --vlan 20
libfci_cli bd-add --vlan 30

libfci_cli bd-update --vlan 10 --ucast-hit FORWARD --ucast-miss FLOOD --mcast-hit FORWARD --mcast-miss FLOOD
libfci_cli bd-update --vlan 20 --ucast-hit FORWARD --ucast-miss FLOOD --mcast-hit FORWARD --mcast-miss FLOOD
libfci_cli bd-update --vlan 30 --ucast-hit FORWARD --ucast-miss FLOOD --mcast-hit FORWARD --mcast-miss FLOOD

libfci_cli bd-insif --vlan 10 --i hif0 --tag OFF
libfci_cli bd-insif --vlan 10 --i emac0 --tag OFF
libfci_cli bd-insif --vlan 20 --i hif1 --tag OFF
libfci_cli bd-insif --vlan 20 --i emac1 --tag OFF
libfci_cli bd-insif --vlan 30 --i hif2 --tag OFF
libfci_cli bd-insif --vlan 30 --i emac2 --tag OFF

# PHY interface mode configuration
libfci_cli phyif-update --i emac0 -E --promisc OFF --mode VLAN_BRIDGE
libfci_cli phyif-update --i emac1 -E --promisc OFF --mode VLAN_BRIDGE
libfci_cli phyif-update --i emac2 -E --promisc OFF --mode VLAN_BRIDGE
libfci_cli phyif-update --i hif0 -E --promisc OFF --mode VLAN_BRIDGE
libfci_cli phyif-update --i hif1 -E --promisc OFF --mode VLAN_BRIDGE
libfci_cli phyif-update --i hif2 -E --promisc ON --mode VLAN_BRIDGE

libfci_cli bd-stent-add --vlan 10 --mac <MAC Address> --i hif0
libfci_cli bd-stent-update --vlan 10 --mac <MAC Address> --egress hif0
libfci_cli bd-stent-add --vlan 20 --mac <MAC Address> --i hif1
libfci_cli bd-stent-update --vlan 20 --mac <MAC Address> --egress hif1
libfci_cli bd-stent-add --vlan 30 --mac <MAC Address> --i hif2
libfci_cli bd-stent-update --vlan 30 --mac <MAC Address> --egress hif2


The Linux commands I wrote were based on the following documents: LNX PFE Driver User Manual (Rev. 25.0) p19, p30, and demo_feature_L2_bridge_vlan.c from PFE FCI API Reference (Rev. 2.7.0) p144.

According to your answer, does it mean that if I configure the L2 bridge and VLAN as in the Linux commands above, the untagged packets sent from the PC cannot be processed?
Even if I specify a static MAC address, I would like to know if untagged packets still cannot be handled by the VLAN members (HIF, EMAC).
Additionally, I am also curious if it is possible to forward the packets back to the PC without a VLAN tag (i.e., as untagged packets).

Thanks.

0 Kudos
Reply

2,073 Views
alejandro_e
NXP TechSupport
NXP TechSupport

Hello again @minJ,

Sorry again for such a long wait. Answering to the following questions "does it mean that if I configure the L2 bridge and VLAN as in the Linux commands above, the untagged packets sent from the PC cannot be processed?" I was not able to find a direct reference to answer it, however, comparing the commands you are using and the main difference is that in the Linux PFE documentation the VLAN 1 is used, which is the Default BD (note that it cannot be removed) that VLAN catches all messages with ID 1 or without a VLAN tag. Although it is not explicitly said that the configuration you are trying is not supported, given that only the Default BD can handle untagged frames and Standard BD's will only get tagged frames with a matching ID. 

Searching in some internal documentation I noticed that there is only one Default BD and there is no option to create another one. The recommended workaround for this usecase is to use different multicast address for each port, I am aware that this may not be a viable solution, however it is worth mentioning.

 

Again, sorry for the wait.

Let me know if you have more questions.

0 Kudos
Reply

2,243 Views
alejandro_e
NXP TechSupport
NXP TechSupport

Hello @minJ,

Sorry for the late reply, I am somewhat overloaded at the moment and I will need more time to analyze your problem.

 

Thanks for your patience.

0 Kudos
Reply
%3CLINGO-SUB%20id%3D%22lingo-sub-2332632%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3EPort-based%20VLAN%20(PVID)%20Mapping%20and%20Untagged%20External%20Traffic%20Support%20in%20PFE%20L2%20Bridge%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2332632%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CDIV%3E%3CFONT%20face%3D%22arial%20black%2Cavant%20garde%22%3E%3CSPAN%3E1.%20Environment%3C%2FSPAN%3E%3C%2FFONT%3E%3C%2FDIV%3E%3CBR%20%2F%3E%3CDIV%3E%3CSPAN%3EPlatform%3A%20S32G3%3C%2FSPAN%3E%3C%2FDIV%3E%3CBR%20%2F%3E%3CDIV%3E%3CSPAN%3ESoftware%3A%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E*%20NXP%20RTD%3A%20SW32G_RTD_4.4_5.0.0_QLP04%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E*%20PFE%20firmware%3A%201.12.0%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E*%20Tool%3A%20libfci_cli%3C%2FSPAN%3E%3C%2FDIV%3E%3CBR%20%2F%3E%3CDIV%3E%3CSPAN%3EPFE%20is%20running%20in%20VLAN_BRIDGE%20mode.%3C%2FSPAN%3E%3C%2FDIV%3E%3CBR%20%2F%3E%3CDIV%3E%3CSPAN%3E---%3C%2FSPAN%3E%3C%2FDIV%3E%3CBR%20%2F%3E%3CDIV%3E%3CFONT%20face%3D%22arial%20black%2Cavant%20garde%22%3E%3CSPAN%3E2.%20Goal%3C%2FSPAN%3E%3C%2FFONT%3E%3C%2FDIV%3E%3CBR%20%2F%3E%3CDIV%3E%3CSPAN%3EI%20want%20to%20keep%20all%20external%20traffic%20untagged%2C%20while%20implementing%20port-based%20VLAN%20isolation%20only%20inside%20the%20PFE.%3C%2FSPAN%3E%3C%2FDIV%3E%3CBR%20%2F%3E%3CDIV%3E%3CSPAN%3EDesired%20behavior%3A%3C%2FSPAN%3E%3C%2FDIV%3E%3CBR%20%2F%3E%3CDIV%3E%3CSPAN%3E%60%60%60%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3Eemac0%20%E2%86%94%20hif0%20%26nbsp%3B%20(internal%20VLAN%2010)%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3Eemac1%20%E2%86%94%20hif1%20%26nbsp%3B%20(internal%20VLAN%2020)%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3Eemac2%20%E2%86%94%20hif2%20%26nbsp%3B%20(internal%20VLAN%2030)%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E%60%60%60%3C%2FSPAN%3E%3C%2FDIV%3E%3CBR%20%2F%3E%3CDIV%3E%3CSPAN%3EThat%20is%2C%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E*%20External%20PCs%20send%2Freceive%20frames%20without%20VLAN%20tags%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E*%20VLAN%20is%20used%20only%20internally%20in%20the%20PFE%20for%20port-based%20traffic%20separation%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E*%20The%20purpose%20is%20to%20prevent%20unnecessary%20broadcast%2Fflooding%20in%20a%20master%2Fslave%20architecture%3C%2FSPAN%3E%3C%2FDIV%3E%3CBR%20%2F%3E%3CDIV%3E%3CSPAN%3E---%3C%2FSPAN%3E%3C%2FDIV%3E%3CBR%20%2F%3E%3CDIV%3E%3CFONT%20face%3D%22arial%20black%2Cavant%20garde%22%3E%3CSPAN%3E3.%20Current%20configuration%3C%2FSPAN%3E%3C%2FFONT%3E%3C%2FDIV%3E%3CBR%20%2F%3E%3CDIV%3E%3CSPAN%3EVLAN%20and%20Bridge%20Domain%20are%20configured%20as%20follows.%3C%2FSPAN%3E%3C%2FDIV%3E%3CBR%20%2F%3E%3CDIV%3E%3CSPAN%3EKey%20commands%3A%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E%60%60%60sh%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E%23%20Bridge%20Domain%20and%20interface%20configuration%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3Elibfci_cli%20bd-add%20--vlan%2010%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3Elibfci_cli%20bd-add%20--vlan%2020%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3Elibfci_cli%20bd-add%20--vlan%2030%3C%2FSPAN%3E%3C%2FDIV%3E%3CBR%20%2F%3E%3CDIV%3E%3CSPAN%3Elibfci_cli%20bd-update%20--vlan%2010%20--ucast-hit%20FORWARD%20--ucast-miss%20FLOOD%20--mcast-hit%20FORWARD%20--mcast-miss%20FLOOD%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3Elibfci_cli%20bd-update%20--vlan%2020%20--ucast-hit%20FORWARD%20--ucast-miss%20FLOOD%20--mcast-hit%20FORWARD%20--mcast-miss%20FLOOD%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3Elibfci_cli%20bd-update%20--vlan%2030%20--ucast-hit%20FORWARD%20--ucast-miss%20FLOOD%20--mcast-hit%20FORWARD%20--mcast-miss%20FLOOD%3C%2FSPAN%3E%3C%2FDIV%3E%3CBR%20%2F%3E%3CDIV%3E%3CSPAN%3Elibfci_cli%20bd-insif%20--vlan%2010%20--i%20hif0%20--tag%20OFF%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3Elibfci_cli%20bd-insif%20--vlan%2010%20--i%20emac0%20--tag%20OFF%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3Elibfci_cli%20bd-insif%20--vlan%2020%20--i%20hif1%20--tag%20OFF%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3Elibfci_cli%20bd-insif%20--vlan%2020%20--i%20emac1%20--tag%20OFF%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3Elibfci_cli%20bd-insif%20--vlan%2030%20--i%20hif2%20--tag%20OFF%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3Elibfci_cli%20bd-insif%20--vlan%2030%20--i%20emac2%20--tag%20OFF%3C%2FSPAN%3E%3C%2FDIV%3E%3CBR%20%2F%3E%3CDIV%3E%3CSPAN%3E%23%20PHY%20interface%20mode%20configuration%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3Elibfci_cli%20phyif-update%20--i%20emac0%20-E%20--promisc%20OFF%20--mode%20VLAN_BRIDGE%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3Elibfci_cli%20phyif-update%20--i%20emac1%20-E%20--promisc%20OFF%20--mode%20VLAN_BRIDGE%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3Elibfci_cli%20phyif-update%20--i%20emac2%20-E%20--promisc%20OFF%20--mode%20VLAN_BRIDGE%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3Elibfci_cli%20phyif-update%20--i%20hif0%20%26nbsp%3B-E%20--promisc%20OFF%20--mode%20VLAN_BRIDGE%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3Elibfci_cli%20phyif-update%20--i%20hif1%20%26nbsp%3B-E%20--promisc%20OFF%20--mode%20VLAN_BRIDGE%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3Elibfci_cli%20phyif-update%20--i%20hif2%20%26nbsp%3B-E%20--promisc%20ON%20--mode%20VLAN_BRIDGE%3C%2FSPAN%3E%3C%2FDIV%3E%3CBR%20%2F%3E%3CDIV%3E%3CSPAN%3Elibfci_cli%20bd-stent-add%20--vlan%2010%20--mac%20%3CMAC%20address%3D%22%22%3E%20--i%20hif0%3C%2FMAC%3E%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3Elibfci_cli%20bd-stent-update%20--vlan%2010%20--mac%20%3CMAC%20address%3D%22%22%3E%20--egress%20hif0%3C%2FMAC%3E%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3Elibfci_cli%20bd-stent-add%20--vlan%2020%20--mac%20%3CMAC%20address%3D%22%22%3E%20--i%20hif1%3C%2FMAC%3E%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3Elibfci_cli%20bd-stent-update%20--vlan%2020%20--mac%20%3CMAC%20address%3D%22%22%3E%20--egress%20hif1%3C%2FMAC%3E%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3Elibfci_cli%20bd-stent-add%20--vlan%2030%20--mac%20%3CMAC%20address%3D%22%22%3E%20--i%20hif2%3C%2FMAC%3E%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3Elibfci_cli%20bd-stent-update%20--vlan%2030%20--mac%20%3CMAC%20address%3D%22%22%3E%20--egress%20hif2%3C%2FMAC%3E%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E%60%60%60%3C%2FSPAN%3E%3C%2FDIV%3E%3CBR%20%2F%3E%3CDIV%3E%3CSPAN%3EIn%20summary%3A%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E-%20emac%2Fhif%20pairs%20are%20assigned%20to%20each%20VLAN%20(10%2F20%2F30)%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E-%20All%20traffic%20is%20untagged%20externally%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E-%20VLAN%20is%20used%20only%20internally%20for%20separation%3C%2FSPAN%3E%3C%2FDIV%3E%3CBR%20%2F%3E%3CDIV%3E%26nbsp%3B%3C%2FDIV%3E%3CBR%20%2F%3E%3CDIV%3E%3CFONT%20face%3D%22arial%20black%2Cavant%20garde%22%3E%3CSPAN%3E4.%20Problem%3C%2FSPAN%3E%3C%2FFONT%3E%3C%2FDIV%3E%3CBR%20%2F%3E%3CDIV%3E%3CSPAN%3EWhen%20untagged%20frames%20arrive%20from%20outside%20(e.g.%2C%20PC%20%E2%86%92%20ping)%2C%20the%20ingress%20counter%20for%20each%20domain%20remains%20zero.%3C%2FSPAN%3E%3C%2FDIV%3E%3CBR%20%2F%3E%3CDIV%3E%3CSPAN%3E%60%60%60%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3Edomain%2010%20ingress%3A%200%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3Edomain%2010%20ingress%3A%200%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3Edomain%2020%20ingress%3A%200%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E%60%60%60%3C%2FSPAN%3E%3C%2FDIV%3E%3CBR%20%2F%3E%3CDIV%3E%3CSPAN%3EThat%20is%2C%20untagged%20frames%20are%20not%20mapped%20to%20internal%20VLANs%2C%20so%20the%20intended%20port-based%20separation%20does%20not%20work.%3C%2FSPAN%3E%3C%2FDIV%3E%3CBR%20%2F%3E%3CDIV%3E%3CSPAN%3E%23%20libfci_cli%20bd-print%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3Edomain%2001%20%26nbsp%3B%5Bdefault%5D%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E%26nbsp%3B%20%26nbsp%3B%20phyifs%20(tagged)%20%26nbsp%3B%20%3A%20---%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E%26nbsp%3B%20%26nbsp%3B%20phyifs%20(untagged)%20%3A%20---%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E%26nbsp%3B%20%26nbsp%3B%20ucast-hit%20%26nbsp%3Baction%20%3A%203%20(DISCARD)%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E%26nbsp%3B%20%26nbsp%3B%20ucast-miss%20action%20%3A%203%20(DISCARD)%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E%26nbsp%3B%20%26nbsp%3B%20mcast-hit%20%26nbsp%3Baction%20%3A%203%20(DISCARD)%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E%26nbsp%3B%20%26nbsp%3B%20mcast-miss%20action%20%3A%203%20(DISCARD)%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E%26nbsp%3B%20%26nbsp%3B%20ingress%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%3A%204173%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E%26nbsp%3B%20%26nbsp%3B%20ingress%20bytes%20%26nbsp%3B%20%26nbsp%3B%20%3A%20560619%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E%26nbsp%3B%20%26nbsp%3B%20egress%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%3A%20958%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E%26nbsp%3B%20%26nbsp%3B%20egress%20bytes%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%3A%20234538%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3Edomain%2000%20%26nbsp%3B%5Bfallback%5D%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E%26nbsp%3B%20%26nbsp%3B%20phyifs%20(tagged)%20%26nbsp%3B%20%3A%20---%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E%26nbsp%3B%20%26nbsp%3B%20phyifs%20(untagged)%20%3A%20---%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E%26nbsp%3B%20%26nbsp%3B%20ucast-hit%20%26nbsp%3Baction%20%3A%203%20(DISCARD)%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E%26nbsp%3B%20%26nbsp%3B%20ucast-miss%20action%20%3A%203%20(DISCARD)%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E%26nbsp%3B%20%26nbsp%3B%20mcast-hit%20%26nbsp%3Baction%20%3A%203%20(DISCARD)%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E%26nbsp%3B%20%26nbsp%3B%20mcast-miss%20action%20%3A%203%20(DISCARD)%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E%26nbsp%3B%20%26nbsp%3B%20ingress%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%3A%200%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E%26nbsp%3B%20%26nbsp%3B%20ingress%20bytes%20%26nbsp%3B%20%26nbsp%3B%20%3A%200%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E%26nbsp%3B%20%26nbsp%3B%20egress%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%3A%200%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E%26nbsp%3B%20%26nbsp%3B%20egress%20bytes%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%3A%200%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3Edomain%2010%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E%26nbsp%3B%20%26nbsp%3B%20phyifs%20(tagged)%20%26nbsp%3B%20%3A%20---%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E%26nbsp%3B%20%26nbsp%3B%20phyifs%20(untagged)%20%3A%20emac0%2Chif0%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E%26nbsp%3B%20%26nbsp%3B%20ucast-hit%20%26nbsp%3Baction%20%3A%200%20(FORWARD)%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E%26nbsp%3B%20%26nbsp%3B%20ucast-miss%20action%20%3A%201%20(FLOOD)%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E%26nbsp%3B%20%26nbsp%3B%20mcast-hit%20%26nbsp%3Baction%20%3A%200%20(FORWARD)%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E%26nbsp%3B%20%26nbsp%3B%20mcast-miss%20action%20%3A%201%20(FLOOD)%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E%26nbsp%3B%20%26nbsp%3B%20ingress%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%3A%200%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E%26nbsp%3B%20%26nbsp%3B%20ingress%20bytes%20%26nbsp%3B%20%26nbsp%3B%20%3A%200%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E%26nbsp%3B%20%26nbsp%3B%20egress%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%3A%200%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E%26nbsp%3B%20%26nbsp%3B%20egress%20bytes%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%3A%200%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3Edomain%2020%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E%26nbsp%3B%20%26nbsp%3B%20phyifs%20(tagged)%20%26nbsp%3B%20%3A%20---%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E%26nbsp%3B%20%26nbsp%3B%20phyifs%20(untagged)%20%3A%20emac1%2Chif1%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E%26nbsp%3B%20%26nbsp%3B%20ucast-hit%20%26nbsp%3Baction%20%3A%200%20(FORWARD)%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E%26nbsp%3B%20%26nbsp%3B%20ucast-miss%20action%20%3A%201%20(FLOOD)%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E%26nbsp%3B%20%26nbsp%3B%20mcast-hit%20%26nbsp%3Baction%20%3A%200%20(FORWARD)%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E%26nbsp%3B%20%26nbsp%3B%20mcast-miss%20action%20%3A%201%20(FLOOD)%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E%26nbsp%3B%20%26nbsp%3B%20ingress%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%3A%200%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E%26nbsp%3B%20%26nbsp%3B%20ingress%20bytes%20%26nbsp%3B%20%26nbsp%3B%20%3A%200%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E%26nbsp%3B%20%26nbsp%3B%20egress%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%3A%200%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E%26nbsp%3B%20%26nbsp%3B%20egress%20bytes%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%3A%200%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3Edomain%2030%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E%26nbsp%3B%20%26nbsp%3B%20phyifs%20(tagged)%20%26nbsp%3B%20%3A%20---%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E%26nbsp%3B%20%26nbsp%3B%20phyifs%20(untagged)%20%3A%20emac2%2Chif2%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E%26nbsp%3B%20%26nbsp%3B%20ucast-hit%20%26nbsp%3Baction%20%3A%200%20(FORWARD)%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E%26nbsp%3B%20%26nbsp%3B%20ucast-miss%20action%20%3A%201%20(FLOOD)%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E%26nbsp%3B%20%26nbsp%3B%20mcast-hit%20%26nbsp%3Baction%20%3A%200%20(FORWARD)%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E%26nbsp%3B%20%26nbsp%3B%20mcast-miss%20action%20%3A%201%20(FLOOD)%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E%26nbsp%3B%20%26nbsp%3B%20ingress%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%3A%200%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E%26nbsp%3B%20%26nbsp%3B%20ingress%20bytes%20%26nbsp%3B%20%26nbsp%3B%20%3A%200%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E%26nbsp%3B%20%26nbsp%3B%20egress%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%3A%200%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E%26nbsp%3B%20%26nbsp%3B%20egress%20bytes%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%3A%200%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3ECommand%20successfully%20executed.%3C%2FSPAN%3E%3C%2FDIV%3E%3CBR%20%2F%3E%3CDIV%3E%3CSPAN%3E---%3C%2FSPAN%3E%3C%2FDIV%3E%3CBR%20%2F%3E%3CDIV%3E%3CFONT%20face%3D%22arial%20black%2Cavant%20garde%22%3E%3CSPAN%3E5.%20Question%3C%2FSPAN%3E%3C%2FFONT%3E%3C%2FDIV%3E%3CDIV%3E%3CDIV%3E%3CBR%20%2F%3E%3CDIV%3E%3CSPAN%3EIs%20it%20possible%20to%20keep%20external%20traffic%20untagged%2C%20and%20achieve%20VLAN-based%20isolation%20only%20inside%20the%20PFE%3F%3C%2FSPAN%3E%3C%2FDIV%3E%3CBR%20%2F%3E%3CDIV%3E%3CSPAN%3E*%20Map%20untagged%20ingress%20frames%20to%20a%20specific%20VLAN%20per%20port%20(PVID%20function)%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E*%20VLAN%20is%20used%20only%20inside%20the%20PFE%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E*%20External%20devices%20operate%20without%20VLAN%20tags%3C%2FSPAN%3E%3C%2FDIV%3E%3CBR%20%2F%3E%3CDIV%3E%3CSPAN%3EIn%20other%20words%2C%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E%60%60%60%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3Eingress%20(untagged)%20%E2%86%92%20VLAN%2010%20-%26gt%3B%20egress%20(untagged)%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3Eingress%20(untagged)%20%E2%86%92%20VLAN%2020%20-%26gt%3B%20egress%20(untagged)%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3Eingress%20(untagged)%20%E2%86%92%20VLAN%2030%20-%26gt%3B%20egress%20(untagged)%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E%60%60%60%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3Eis%20the%20desired%20behavior.%3C%2FSPAN%3E%3C%2FDIV%3E%3CBR%20%2F%3E%3CDIV%3E%3CSPAN%3E1.%20Does%20the%20PFE%20support%20port-based%20VLAN%3F%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E2.%20If%20yes%2C%20which%20firmware%20feature%20or%20configuration%20enables%20it%3F%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E3.%20Is%20it%20related%20to%20the%20vlan_conf%20or%20ingress_vlan%20features%20shown%20in%20fwfeat-print%3F%3C%2FSPAN%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2332902%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%20translate%3D%22no%22%3ERe%3A%20Port-based%20VLAN%20(PVID)%20Mapping%20and%20Untagged%20External%20Traffic%20Support%20in%20PFE%20L2%20Bridge%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2332902%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%20class%3D%22%22%3E%3CSPAN%20class%3D%22%22%3EHello%2C%3CBR%20%2F%3E%3C%2FSPAN%3E%3CSPAN%3EThank%20you%20for%20the%20detailed%20explanation.%3C%2FSPAN%3E%3C%2FP%3E%3CP%20class%3D%22%22%3E%3CSPAN%20class%3D%22%22%3EI%20would%20like%20to%20confirm%20whether%20the%20Linux%20commands%20I%20described%20in%20%3C%2FSPAN%3E%3CSPAN%20class%3D%22%22%3E%E2%80%9C3.%20Current%20configuration%E2%80%9D%3C%2FSPAN%3E%3CSPAN%20class%3D%22%22%3Erepresent%20a%20configuration%20that%20is%20fundamentally%20unsupported%2C%20or%20if%20there%20might%20be%20some%20missing%20configuration%20on%20my%20side.%3C%2FSPAN%3E%3C%2FP%3E%3CP%20class%3D%22%22%3E%3CSPAN%20class%3D%22%22%3EMy%20current%20test%20environment%20is%20as%20follows%3A%3C%2FSPAN%3E%3C%2FP%3E%3CP%20class%3D%22%22%3E%3CSPAN%20class%3D%22%22%3E%E2%80%A2%20One%20PC%3C%2FSPAN%3E%3C%2FP%3E%3CP%20class%3D%22%22%3E%3CSPAN%20class%3D%22%22%3E%E2%80%A2%20The%20PC%20has%20%3C%2FSPAN%3E%3CSPAN%20class%3D%22%22%3Ethree%20NICs%3C%2FSPAN%3E%3C%2FP%3E%3CP%20class%3D%22%22%3E%3CSPAN%20class%3D%22%22%3E%E2%80%A2%20Each%20NIC%20is%20directly%20connected%20to%20one%20of%20the%20board%E2%80%99s%20%3C%2FSPAN%3E%3CSPAN%20class%3D%22%22%3EEMAC%20ports%3C%2FSPAN%3E%3C%2FP%3E%3CP%20class%3D%22%22%3E%26nbsp%3B%3C%2FP%3E%3CP%20class%3D%22%22%3E%3CSPAN%20class%3D%22%22%3EOn%20the%20PC%20side%2C%20I%20am%20%3C%2FSPAN%3E%3CSPAN%20class%3D%22%22%3Enot%20configuring%20any%20VLAN%20interface%3C%2FSPAN%3E%3CSPAN%20class%3D%22%22%3E.%20I%20am%20simply%20sending%20a%20normal%20%3C%2FSPAN%3E%3CSPAN%20class%3D%22%22%3Eping%3C%2FSPAN%3E%3CSPAN%20class%3D%22%22%3E.%3C%2FSPAN%3E%3C%2FP%3E%3CP%20class%3D%22%22%3E%26nbsp%3B%3C%2FP%3E%3CP%20class%3D%22%22%3E%3CSPAN%20class%3D%22%22%3EThe%20behavior%20I%20expect%20is%20the%20following%3A%3C%2FSPAN%3E%3C%2FP%3E%3CP%20class%3D%22%22%3E%3CSPAN%20class%3D%22%22%3EWhen%20the%20PC%20sends%20a%20ping%2C%20the%20board%20should%20forward%20the%20packet%20based%20on%20the%20%3C%2FSPAN%3E%3CSPAN%20class%3D%22%22%3Edestination%20IP%20and%20the%20corresponding%20Bridge%20Domain%20(BD)%3C%2FSPAN%3E%3CSPAN%20class%3D%22%22%3E%2C%20and%20then%20transmit%20it%20to%20the%20ports%20that%20belong%20to%20that%20VLAN.%3C%2FSPAN%3E%3C%2FP%3E%3CP%20class%3D%22%22%3E%26nbsp%3B%3C%2FP%3E%3CP%20class%3D%22%22%3E%3CSPAN%20class%3D%22%22%3EThe%20configuration%20I%20would%20like%20to%20achieve%20is%3A%3C%2FSPAN%3E%3C%2FP%3E%3CP%20class%3D%22%22%3E%3CSPAN%20class%3D%22%22%3EVLAN10%20%3A%20HIF0%2C%20EMAC0%3C%2FSPAN%3E%3C%2FP%3E%3CP%20class%3D%22%22%3E%3CSPAN%20class%3D%22%22%3EVLAN20%20%3A%20HIF1%2C%20EMAC1%3C%2FSPAN%3E%3C%2FP%3E%3CP%20class%3D%22%22%3E%3CSPAN%20class%3D%22%22%3EVLAN30%20%3A%20HIF2%2C%20EMAC2%3C%2FSPAN%3E%3C%2FP%3E%3CP%20class%3D%22%22%3E%3CSPAN%20class%3D%22%22%3EVLAN40%20%3A%20HIF3%2C%20EMAC0%2C%20EMAC1%2C%20EMAC2%3C%2FSPAN%3E%3C%2FP%3E%3CP%20class%3D%22%22%3E%3CSPAN%20class%3D%22%22%3EIn%20other%20words%3A%3C%2FSPAN%3E%3C%2FP%3E%3CP%20class%3D%22%22%3E%3CSPAN%20class%3D%22%22%3E%E2%80%A2%20EMAC0%2F1%2F2%20are%20each%20connected%20to%20their%20%3C%2FSPAN%3E%3CSPAN%20class%3D%22%22%3Ededicated%20VLANs%20(10%2F20%2F30)%3C%2FSPAN%3E%3CSPAN%20class%3D%22%22%3E.%3C%2FSPAN%3E%3C%2FP%3E%3CP%20class%3D%22%22%3E%3CSPAN%20class%3D%22%22%3E%E2%80%A2%20At%20the%20same%20time%2C%20they%20also%20participate%20in%20a%20%3C%2FSPAN%3E%3CSPAN%20class%3D%22%22%3Eshared%20VLAN40%3C%2FSPAN%3E%3CSPAN%20class%3D%22%22%3E%2C%20which%20communicates%20with%20%3C%2FSPAN%3E%3CSPAN%20class%3D%22%22%3EHIF3%3C%2FSPAN%3E%3CSPAN%20class%3D%22%22%3E.%3C%2FSPAN%3E%3C%2FP%3E%3CP%20class%3D%22%22%3E%26nbsp%3B%3C%2FP%3E%3CP%20class%3D%22%22%3E%3CSPAN%20class%3D%22%22%3EWith%20the%20current%20Linux%20commands%3A%3C%2FSPAN%3E%3C%2FP%3E%3CP%20class%3D%22%22%3E%3CSPAN%20class%3D%22%22%3E%E2%80%A2%20If%20I%20put%20all%20ports%20into%20%3C%2FSPAN%3E%3CSPAN%20class%3D%22%22%3EVLAN1%3C%2FSPAN%3E%3CSPAN%20class%3D%22%22%3E%2C%20everything%20works%20as%20expected.%3C%2FSPAN%3E%3C%2FP%3E%3CP%20class%3D%22%22%3E%3CSPAN%20class%3D%22%22%3E%E2%80%A2%20However%2C%20when%20I%20separate%20them%20into%20%3C%2FSPAN%3E%3CSPAN%20class%3D%22%22%3EVLAN10%2F20%2F30%3C%2FSPAN%3E%3CSPAN%20class%3D%22%22%3E%2C%20the%20%3C%2FSPAN%3E%3CSPAN%20class%3D%22%22%3Eingress%2Fegress%20counters%20only%20increase%20in%20VLAN1%3C%2FSPAN%3E%3CSPAN%20class%3D%22%22%3E%2C%20and%20not%20in%20VLAN10%2F20%2F30.%3C%2FSPAN%3E%3C%2FP%3E%3CP%20class%3D%22%22%3E%26nbsp%3B%3C%2FP%3E%3CP%20class%3D%22%22%3E%3CSPAN%20class%3D%22%22%3ETherefore%20I%20have%20two%20questions%3A%3C%2FSPAN%3E%3C%2FP%3E%3CP%20class%3D%22%22%3E%3CSPAN%20class%3D%22%22%3E1.%20Is%20this%20type%20of%20%3C%2FSPAN%3E%3CSPAN%20class%3D%22%22%3EVLAN%20configuration%20supported%20by%20the%20PFE%20VLAN_BRIDGE%20model%3C%2FSPAN%3E%3CSPAN%20class%3D%22%22%3E%2C%20or%20is%20there%20some%20configuration%20step%20that%20I%20may%20have%20missed%3F%3C%2FSPAN%3E%3C%2FP%3E%3CP%20class%3D%22%22%3E%3CSPAN%20class%3D%22%22%3E2.%20Currently%2C%20the%20PC%20sends%20%3C%2FSPAN%3E%3CSPAN%20class%3D%22%22%3Euntagged%20packets%20(just%20a%20normal%20ping)%3C%2FSPAN%3E%3CSPAN%20class%3D%22%22%3E.%3C%2FSPAN%3E%3C%2FP%3E%3CP%20class%3D%22%22%3E%3CSPAN%20class%3D%22%22%3EIn%20this%20case%2C%20is%20it%20impossible%20for%20the%20PFE%20to%20classify%20the%20ingress%20traffic%20into%20a%20specific%20VLAN%20BD%3F%3C%2FSPAN%3E%3C%2FP%3E%3CP%20class%3D%22%22%3E%3CSPAN%20class%3D%22%22%3EIn%20other%20words%2C%20does%20this%20setup%20require%20the%20%3C%2FSPAN%3E%3CSPAN%20class%3D%22%22%3EPC%20to%20send%20VLAN-tagged%20packets%3C%2FSPAN%3E%3CSPAN%20class%3D%22%22%3E%3F%3C%2FSPAN%3E%3C%2FP%3E%3CP%20class%3D%22%22%3E%3CSPAN%20class%3D%22%22%3EFor%20example%2C%20should%20the%20PC%20be%20configured%20like%20this%20to%20send%20tagged%20traffic%3F%3C%2FSPAN%3E%3C%2FP%3E%3CP%20class%3D%22%22%3E%26nbsp%3B%3C%2FP%3E%3CP%20class%3D%22%22%3E%3CSPAN%20class%3D%22%22%3Eip%20link%20add%20link%20eth0%20name%20eth0.40%20type%20vlan%20id%2040%3C%2FSPAN%3E%3C%2FP%3E%3CP%20class%3D%22%22%3E%3CSPAN%20class%3D%22%22%3Eip%20link%20set%20eth0.40%20up%3C%2FSPAN%3E%3C%2FP%3E%3CP%20class%3D%22%22%3E%3CSPAN%20class%3D%22%22%3Eping%20-I%20eth0.40%20192.168.x.x%3C%2FSPAN%3E%3C%2FP%3E%3CP%20class%3D%22%22%3E%26nbsp%3B%3C%2FP%3E%3CP%20class%3D%22%22%3E%3CSPAN%20class%3D%22%22%3EAny%20guidance%20on%20whether%20this%20configuration%20is%20feasible%2C%20or%20if%20there%20is%20a%20recommended%20approach%20for%20this%20scenario%2C%20would%20be%20greatly%20appreciated.%3C%2FSPAN%3E%3C%2FP%3E%3CP%20class%3D%22%22%3E%26nbsp%3B%3C%2FP%3E%3CP%20class%3D%22%22%3E%3CSPAN%20class%3D%22%22%3EThank%20you.%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2332824%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%20translate%3D%22no%22%3ERe%3A%20Port-based%20VLAN%20(PVID)%20Mapping%20and%20Untagged%20External%20Traffic%20Support%20in%20PFE%20L2%20Bridge%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2332824%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3EHello%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fcommunity.nxp.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F260071%22%20target%3D%22_blank%22%3E%40minJ%3C%2FA%3E%2C%3C%2FP%3E%0A%3CP%3EPlease%20find%20my%20answers%20below%3A%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3EIs%20it%20possible%20to%20keep%20external%20traffic%20untagged%2C%20and%20achieve%20VLAN-based%20isolation%20only%20inside%20the%20PFE%3F%0A%3CUL%3E%0A%3CLI%3EFor%20what%20I%20can%20see%20in%20the%20documentation%2C%20no%2C%20you%20cannot%20use%20external%20unteagged%20traffic%20and%20only%20used%20VLAN%20tags%20internally.%20If%20you%20configure%20a%20port%20to%20a%20BD%20(Bridge%20domain)%20It%20can%20have%20three%20ways%20of%20operation%2C%20Default%20BD%2C%20Fall-back%20BD%20and%20Standard%20BD%2C%20in%20all%20three%20the%20VLAN%20is%20checked%20to%20either%20accept%20or%20discard%20the%20frame%20depending%20on%20certain%20rules.%26nbsp%3BYou%20can%20check%20section%20%3CEM%3EL2%20Bridge%20VLAN%20Awareness%20and%20Domains%3C%2FEM%3E%20of%20the%20%3CEM%3EPFE-SW_S32G_FCI_API_ReferenceManual_2.7.0.%3C%2FEM%3E%26nbsp%3Bfor%20more%20details%20on%20those%20rules.%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3C%2FLI%3E%0A%3CLI%3EDoes%20the%20PFE%20support%20port-based%20VLAN%3F%26nbsp%3B%0A%3CUL%3E%0A%3CLI%3ENot%20directly%2C%20you%20would%20need%20to%20create%20different%20BDs%20for%20each%20VLAN%20and%20configure%20each%20port%20to%20their%20respective%20domain.%20In%20summary%2C%20you%20can%20configure%20BD-based%20VLAN%2C%20where%20each%20BD%20uses%20a%20different%20port.%20Please%20check%20the%20same%20document%20and%20section%20I%20mentioned%20above.%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3C%2FLI%3E%0A%3CLI%3EIf%20yes%2C%20which%20firmware%20feature%20or%20configuration%20enables%20it%3F%0A%3CUL%3E%0A%3CLI%3EThis%20should%20answered%20with%20the%20information%20from%20the%20other%20two%20questions.%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3C%2FLI%3E%0A%3CLI%3EIs%20it%20related%20to%20the%20vlan_conf%20or%20ingress_vlan%20features%20shown%20in%20fwfeat-print%3F%0A%3CUL%3E%0A%3CLI%3EIf%20you%20mean%26nbsp%3Bvlan_conf_check%2C%20yes%20both%20are%20related%20to%20this%20topic%2C%20however%20enabling%2Fconfiguring%20this%20options%20will%20configure%20the%20ports%20so%20that%20frames%20without%20vlan%20are%20discarded.%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3EA%20possible%20solution%20to%20avoid%20flooding%20in%20a%20master-slave%20configuration%20could%20be%20avoid%20using%20that%20mode%20and%20instead%20forward%20the%20frames%20using%20IPCF%20to%20the%20other%20domain%2C%20for%20example%20if%20the%20M7_0%20is%20the%20owner%20of%20the%20PFE%2C%20it%20forwards%20only%20some%20frames%20to%20the%20A53%2FLinux%20domain.%20Depending%20on%20your%20requirements%20this%20can%20be%20a%20viable%20option.%20Let%20me%20know%20if%20you%20require%20more%20elaboration%20on%20this%20idea.%3C%2FP%3E%0A%3CBR%20%2F%3E%0A%3CP%3EPlease%20let%20me%20know%20if%20you%20have%20more%20question.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2334253%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%20translate%3D%22no%22%3ERe%3A%20Port-based%20VLAN%20(PVID)%20Mapping%20and%20Untagged%20External%20Traffic%20Support%20in%20PFE%20L2%20Bridge%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2334253%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3EHello%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fcommunity.nxp.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F260071%22%20target%3D%22_blank%22%3E%40minJ%3C%2FA%3E%2C%3C%2FP%3E%0A%3CP%3ETo%20which%20document%20are%20your%20referring%20when%20mentioning%26nbsp%3B%3CEM%3E3.%20Current%20configuration%26nbsp%3B%3C%2FEM%3EI%20checked%20all%20documents%20in%20the%20PFE%20Linux%20Documentation%20and%20I%20was%20not%20able%20to%20find%20that%20section.%20Please%20indicated%20the%20page%20of%20the%20section%20and%20revision%20of%20the%20document.%26nbsp%3B%3C%2FP%3E%0A%3CP%3ERegarding%20the%20classification%20of%20untagged%20packages%20in%20a%20VLAN%20port%2C%20I%20misunderstood%20the%20documentation%20before%2C%20for%20that%20you%20would%20need%20to%20configure%20a%20BD%20with%20the%20default%20%3CEM%3Econfiguration%3C%2FEM%3E%2C%20it%20has%20de%20following%20description%3A%3C%2FP%3E%0A%3CP%3E%3CEM%3EDefault%20BD%3A%3C%2FEM%3E%3CBR%20%2F%3E%3CEM%3EFactory%20default%20VLAN%20ID%20of%20this%20bridge%20domain%20is%201.%20This%20domain%20processes%20ingress%20frames%20which%20either%20have%26nbsp%3B%3C%2FEM%3E%3CEM%3Ea%20VLAN%20tag%20equal%20to%20the%20Default%20BD%20VLAN%20ID%2C%20%3CSTRONG%3Eor%20do%20not%20have%20a%20VLAN%20tag%20at%20all%20(untagged%20Ethernet%20frames).%3C%2FSTRONG%3E%3C%2FEM%3E%3C%2FP%3E%0A%3CP%3EThis%20is%20the%20only%20BD%20configuration%20that%20can%20handle%20untagged%20frames%2C%20Therefore%20with%20this%20configuration%20you%20don't%20need%20to%20send%20tagged%20messages%20from%20your%20host.%20Moreover%2C%20other%20type%20of%20BDs%20will%20not%20process%20Frames%20without%20VLAN%20tag.%3C%2FP%3E%0A%3CBR%20%2F%3E%0A%3CP%3ESorry%20for%20the%20confusion%20before.%20Let%20me%20know%20if%20you%20have%20more%20questions.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2334735%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%20translate%3D%22no%22%3ERe%3A%20Port-based%20VLAN%20(PVID)%20Mapping%20and%20Untagged%20External%20Traffic%20Support%20in%20PFE%20L2%20Bridge%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2334735%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3EHello%2C%3C%2FP%3E%3CP%3EThe%20'3.%20Current%20configuration'%20I%20mentioned%20refers%20to%20the%20Linux%20commands%20in%20my%20first%20question.%3CBR%20%2F%3EI%20apologize%20for%20not%20making%20this%20clear%20earlier.%3C%2FP%3E%3CBLOCKQUOTE%3E%3CP%3E%3CBR%20%2F%3E%23%20Bridge%20Domain%20and%20interface%20configuration%3CBR%20%2F%3Elibfci_cli%20bd-add%20--vlan%2010%3CBR%20%2F%3Elibfci_cli%20bd-add%20--vlan%2020%3CBR%20%2F%3Elibfci_cli%20bd-add%20--vlan%2030%3C%2FP%3E%3CP%3Elibfci_cli%20bd-update%20--vlan%2010%20--ucast-hit%20FORWARD%20--ucast-miss%20FLOOD%20--mcast-hit%20FORWARD%20--mcast-miss%20FLOOD%3CBR%20%2F%3Elibfci_cli%20bd-update%20--vlan%2020%20--ucast-hit%20FORWARD%20--ucast-miss%20FLOOD%20--mcast-hit%20FORWARD%20--mcast-miss%20FLOOD%3CBR%20%2F%3Elibfci_cli%20bd-update%20--vlan%2030%20--ucast-hit%20FORWARD%20--ucast-miss%20FLOOD%20--mcast-hit%20FORWARD%20--mcast-miss%20FLOOD%3C%2FP%3E%3CP%3Elibfci_cli%20bd-insif%20--vlan%2010%20--i%20hif0%20--tag%20OFF%3CBR%20%2F%3Elibfci_cli%20bd-insif%20--vlan%2010%20--i%20emac0%20--tag%20OFF%3CBR%20%2F%3Elibfci_cli%20bd-insif%20--vlan%2020%20--i%20hif1%20--tag%20OFF%3CBR%20%2F%3Elibfci_cli%20bd-insif%20--vlan%2020%20--i%20emac1%20--tag%20OFF%3CBR%20%2F%3Elibfci_cli%20bd-insif%20--vlan%2030%20--i%20hif2%20--tag%20OFF%3CBR%20%2F%3Elibfci_cli%20bd-insif%20--vlan%2030%20--i%20emac2%20--tag%20OFF%3C%2FP%3E%3CP%3E%23%20PHY%20interface%20mode%20configuration%3CBR%20%2F%3Elibfci_cli%20phyif-update%20--i%20emac0%20-E%20--promisc%20OFF%20--mode%20VLAN_BRIDGE%3CBR%20%2F%3Elibfci_cli%20phyif-update%20--i%20emac1%20-E%20--promisc%20OFF%20--mode%20VLAN_BRIDGE%3CBR%20%2F%3Elibfci_cli%20phyif-update%20--i%20emac2%20-E%20--promisc%20OFF%20--mode%20VLAN_BRIDGE%3CBR%20%2F%3Elibfci_cli%20phyif-update%20--i%20hif0%20-E%20--promisc%20OFF%20--mode%20VLAN_BRIDGE%3CBR%20%2F%3Elibfci_cli%20phyif-update%20--i%20hif1%20-E%20--promisc%20OFF%20--mode%20VLAN_BRIDGE%3CBR%20%2F%3Elibfci_cli%20phyif-update%20--i%20hif2%20-E%20--promisc%20ON%20--mode%20VLAN_BRIDGE%3C%2FP%3E%3CP%3Elibfci_cli%20bd-stent-add%20--vlan%2010%20--mac%20%3CMAC%20address%3D%22%22%3E%20--i%20hif0%3CBR%20%2F%3Elibfci_cli%20bd-stent-update%20--vlan%2010%20--mac%20%3CMAC%20address%3D%22%22%3E%20--egress%20hif0%3CBR%20%2F%3Elibfci_cli%20bd-stent-add%20--vlan%2020%20--mac%20%3CMAC%20address%3D%22%22%3E%20--i%20hif1%3CBR%20%2F%3Elibfci_cli%20bd-stent-update%20--vlan%2020%20--mac%20%3CMAC%20address%3D%22%22%3E%20--egress%20hif1%3CBR%20%2F%3Elibfci_cli%20bd-stent-add%20--vlan%2030%20--mac%20%3CMAC%20address%3D%22%22%3E%20--i%20hif2%3CBR%20%2F%3Elibfci_cli%20bd-stent-update%20--vlan%2030%20--mac%20%3CMAC%20address%3D%22%22%3E%20--egress%20hif2%3C%2FMAC%3E%3C%2FMAC%3E%3C%2FMAC%3E%3C%2FMAC%3E%3C%2FMAC%3E%3C%2FMAC%3E%3C%2FP%3E%3C%2FBLOCKQUOTE%3E%3CP%3E%3CBR%20%2F%3EThe%20Linux%20commands%20I%20wrote%20were%20based%20on%20the%20following%20documents%3A%20LNX%20PFE%20Driver%20User%20Manual%20(Rev.%2025.0)%20p19%2C%20p30%2C%20and%20demo_feature_L2_bridge_vlan.c%20from%20PFE%20FCI%20API%20Reference%20(Rev.%202.7.0)%20p144.%3C%2FP%3E%3CP%3EAccording%20to%20your%20answer%2C%20does%20it%20mean%20that%20if%20I%20configure%20the%20L2%20bridge%20and%20VLAN%20as%20in%20the%20Linux%20commands%20above%2C%20the%20untagged%20packets%20sent%20from%20the%20PC%20cannot%20be%20processed%3F%3CBR%20%2F%3EEven%20if%20I%20specify%20a%20static%20MAC%20address%2C%20I%20would%20like%20to%20know%20if%20untagged%20packets%20still%20cannot%20be%20handled%20by%20the%20VLAN%20members%20(HIF%2C%20EMAC).%3CBR%20%2F%3EAdditionally%2C%20I%20am%20also%20curious%20if%20it%20is%20possible%20to%20forward%20the%20packets%20back%20to%20the%20PC%20without%20a%20VLAN%20tag%20(i.e.%2C%20as%20untagged%20packets).%3CBR%20%2F%3E%3CBR%20%2F%3EThanks.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2336212%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%20translate%3D%22no%22%3ERe%3A%20Port-based%20VLAN%20(PVID)%20Mapping%20and%20Untagged%20External%20Traffic%20Support%20in%20PFE%20L2%20Bridge%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2336212%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3EHello%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fcommunity.nxp.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F260071%22%20target%3D%22_blank%22%3E%40minJ%3C%2FA%3E%2C%3C%2FP%3E%0A%3CP%3ESorry%20for%20the%20late%20reply%2C%20I%20am%20somewhat%20overloaded%20at%20the%20moment%20and%20I%20will%20need%20more%20time%20to%20analyze%20your%20problem.%3C%2FP%3E%0A%3CBR%20%2F%3E%0A%3CP%3EThanks%20for%20your%20patience.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2339645%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%20translate%3D%22no%22%3ERe%3A%20Port-based%20VLAN%20(PVID)%20Mapping%20and%20Untagged%20External%20Traffic%20Support%20in%20PFE%20L2%20Bridge%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2339645%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3EHello%20again%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fcommunity.nxp.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F260071%22%20target%3D%22_blank%22%3E%40minJ%3C%2FA%3E%2C%3C%2FP%3E%0A%3CP%3ESorry%20again%20for%20such%20a%20long%20wait.%20Answering%20to%20the%20following%20questions%20%22%3CEM%3Edoes%20it%20mean%20that%20if%20I%20configure%20the%20L2%20bridge%20and%20VLAN%20as%20in%20the%20Linux%20commands%20above%2C%20the%20untagged%20packets%20sent%20from%20the%20PC%20cannot%20be%20processed%3F%3C%2FEM%3E%22%20I%20was%20not%20able%20to%20find%20a%20direct%20reference%20to%20answer%20it%2C%20however%2C%20comparing%20the%20commands%20you%20are%20using%20and%20the%20main%20difference%20is%20that%20in%20the%20Linux%20PFE%20documentation%20the%20VLAN%201%20is%20used%2C%20which%20is%20the%20%3CEM%3EDefault%20BD%26nbsp%3B%3C%2FEM%3E(note%20that%20it%20cannot%20be%20removed)%20that%20VLAN%20catches%20all%20messages%20with%20ID%201%20or%20without%20a%20VLAN%20tag.%20Although%20it%20is%20not%20explicitly%20said%20that%20the%20configuration%20you%20are%20trying%20is%20not%20supported%2C%20given%20that%20only%20the%20Default%20BD%20can%20handle%20untagged%20frames%20and%20%3CEM%3EStandard%20BD%3C%2FEM%3E's%20will%20only%20get%20tagged%20frames%20with%20a%20matching%20ID.%26nbsp%3B%3C%2FP%3E%0A%3CP%3ESearching%20in%20some%20internal%20documentation%20I%20noticed%20that%20there%20is%20only%20one%20%3CEM%3EDefault%20BD%3C%2FEM%3E%20and%20there%20is%20no%20option%20to%20create%20another%20one.%20The%20recommended%20workaround%20for%20this%20usecase%20is%20to%20use%20different%20multicast%20address%20for%20each%20port%2C%20I%20am%20aware%20that%20this%20may%20not%20be%20a%20viable%20solution%2C%20however%20it%20is%20worth%20mentioning.%3C%2FP%3E%0A%3CBR%20%2F%3E%0A%3CP%3EAgain%2C%20sorry%20for%20the%20wait.%3C%2FP%3E%0A%3CP%3ELet%20me%20know%20if%20you%20have%20more%20questions.%3C%2FP%3E%3C%2FLINGO-BODY%3E