VLANs, addresses and routes
VLANs are kept in the configuration and created again at every boot by dtvsol-vlans.service.
Each VLAN is made on its own: one that fails does not stop the others.
dtvsol iface # every interface: physical, VLAN, QinQ, with addressesdtvsol vlan list # the VLANs the router managesAdd a VLAN
Section titled “Add a VLAN”dtvsol vlan add is interactive:
dtvsol vlan addIt asks for:
- Parent: a port, a bond, or an S-VLAN (for an inner C-VLAN).
- VLAN id: 1–4094.
- Protocol (on a physical parent):
Qfor 802.1Q,adfor 802.1ad (a QinQ S-VLAN). - IPv4 and IPv6: the router’s address on it. You can give the network; the router takes
the first address (
100.70.9.0/24becomes100.70.9.1/24,XXXX:XXXX::/64becomesXXXX:XXXX::1/64). - Label: what it is for.
- Serve it with DHCP now: creates the DHCP subnet, the pool and IPv6 prefix delegation.
Names follow the type: vlan100 for 802.1Q on a port or bond, svlan1000 for an 802.1ad
S-VLAN, and svlan1000.116 for a C-VLAN inside it.
For a QinQ network, create the S-VLAN first (protocol ad), then one C-VLAN on it per access
segment, with the S-VLAN as parent.
Disable, enable, delete
Section titled “Disable, enable, delete”dtvsol vlan disable vlan100 "maintenance until Monday"dtvsol vlan enable vlan100dtvsol vlan del vlan100- Disable switches a VLAN off and keeps every setting. Enable puts it back exactly as it was.
- Delete is final. It takes the VLAN’s DHCP networks, static routes, NAT pool and port forwards with it. It is refused while clients are registered on the VLAN.
From the monitor
Section titled “From the monitor”Admins can do the same on Settings → VLANs in the monitor. The monitor refuses to disable or delete a VLAN that:
- carries a default route (the router would be cut off),
- holds the address your browser, an SSH session or the API came to,
- has other VLANs on top of it.
Before a disable or delete, the page lists what happens (the addresses that stop, DHCP that stops, routes that are deleted). A delete asks you to type the VLAN’s name.
Addresses
Section titled “Addresses”dtvsol ip add vlan100 100.70.1.1/24dtvsol ip del vlan100 100.70.1.1/24Without arguments, dtvsol ip add asks. An address is refused for deletion while registered
clients use it as their gateway. The monitor’s Settings → IP addresses also refuses to
delete the address you came to, or one whose network holds the default gateway.
A service VLAN’s addresses belong to its services: change them with dtvsol service ….
DHCP on a VLAN
Section titled “DHCP on a VLAN”dtvsol net list # interfaces with DHCP statusdtvsol net add # interactive: serve an interface with DHCPv4dtvsol net del # interactive: stop serving itdtvsol net6 add # the same for DHCPv6dtvsol net6 pool vlan100dtvsol net6 lease 86400 43200Every change to the DHCP configuration is tested with dhcpd -t and rolled back if it fails.
IPv6 prefix delegation
Section titled “IPv6 prefix delegation”dtvsol pd listdtvsol pd add vlan100 # delegate a prefix to every CPE on the VLANdtvsol pd resize vlan100 1024 # how many subscribers the VLAN's slice holdsdtvsol pd assign AA:BB:CC:DD:EE:FFdtvsol pd sync --dry-runThe delegated prefixes are carved from pd_pool in /opt/dtvsol/etc/config.php. The router
adds a kernel route for every live delegated prefix, following the DHCPv6 lease file.
DNS for subscribers
Section titled “DNS for subscribers”dtvsol dns # what each VLAN hands outdtvsol dns set v4=XXX.XXX.XXX.53,XXX.XXX.XXX.54 v6=XXXX:XXXX::53dtvsol dns set vlan100 v4=XXX.XXX.XXX.60 # one VLAN's overridedtvsol dns del vlan100Static routes
Section titled “Static routes”dtvsol route listdtvsol route add XXX.XXX.XXX.0/24 via 10.20.0.2 "customer block"dtvsol route add XXXX:XXXX:200::/48 via XXXX:XXXX:ffff::2dtvsol route del XXX.XXX.XXX.0/24 via 10.20.0.2Routes survive reboots.
NAT pools
Section titled “NAT pools”For plain source-NAT (not CGNAT):
dtvsol nat listdtvsol nat add bond0 XXX.XXX.XXX.20 XXX.XXX.XXX.23 exempt 10.0.0.0/8 "office NAT"dtvsol nat del bond0For subscribers, CGNAT is usually the better choice. See CGNAT.