Skip to content

VLANs, addresses and routes

VLANs are kept in the configuration and created again at every boot by dtvsol-vlans.service. Each VLAN is made on its own: one that fails does not stop the others.

Terminal window
dtvsol iface # every interface: physical, VLAN, QinQ, with addresses
dtvsol vlan list # the VLANs the router manages

dtvsol vlan add is interactive:

Terminal window
dtvsol vlan add

It asks for:

  • Parent: a port, a bond, or an S-VLAN (for an inner C-VLAN).
  • VLAN id: 1–4094.
  • Protocol (on a physical parent): Q for 802.1Q, ad for 802.1ad (a QinQ S-VLAN).
  • IPv4 and IPv6: the router’s address on it. You can give the network; the router takes the first address (100.70.9.0/24 becomes 100.70.9.1/24, XXXX:XXXX::/64 becomes XXXX:XXXX::1/64).
  • Label: what it is for.
  • Serve it with DHCP now: creates the DHCP subnet, the pool and IPv6 prefix delegation.

Names follow the type: vlan100 for 802.1Q on a port or bond, svlan1000 for an 802.1ad S-VLAN, and svlan1000.116 for a C-VLAN inside it.

For a QinQ network, create the S-VLAN first (protocol ad), then one C-VLAN on it per access segment, with the S-VLAN as parent.

Terminal window
dtvsol vlan disable vlan100 "maintenance until Monday"
dtvsol vlan enable vlan100
dtvsol vlan del vlan100
  • Disable switches a VLAN off and keeps every setting. Enable puts it back exactly as it was.
  • Delete is final. It takes the VLAN’s DHCP networks, static routes, NAT pool and port forwards with it. It is refused while clients are registered on the VLAN.

Admins can do the same on Settings → VLANs in the monitor. The monitor refuses to disable or delete a VLAN that:

  • carries a default route (the router would be cut off),
  • holds the address your browser, an SSH session or the API came to,
  • has other VLANs on top of it.

Before a disable or delete, the page lists what happens (the addresses that stop, DHCP that stops, routes that are deleted). A delete asks you to type the VLAN’s name.

Terminal window
dtvsol ip add vlan100 100.70.1.1/24
dtvsol ip del vlan100 100.70.1.1/24

Without arguments, dtvsol ip add asks. An address is refused for deletion while registered clients use it as their gateway. The monitor’s Settings → IP addresses also refuses to delete the address you came to, or one whose network holds the default gateway.

A service VLAN’s addresses belong to its services: change them with dtvsol service ….

Terminal window
dtvsol net list # interfaces with DHCP status
dtvsol net add # interactive: serve an interface with DHCPv4
dtvsol net del # interactive: stop serving it
dtvsol net6 add # the same for DHCPv6
dtvsol net6 pool vlan100
dtvsol net6 lease 86400 43200

Every change to the DHCP configuration is tested with dhcpd -t and rolled back if it fails.

Terminal window
dtvsol pd list
dtvsol pd add vlan100 # delegate a prefix to every CPE on the VLAN
dtvsol pd resize vlan100 1024 # how many subscribers the VLAN's slice holds
dtvsol pd assign AA:BB:CC:DD:EE:FF
dtvsol pd sync --dry-run

The delegated prefixes are carved from pd_pool in /opt/dtvsol/etc/config.php. The router adds a kernel route for every live delegated prefix, following the DHCPv6 lease file.

Terminal window
dtvsol dns # what each VLAN hands out
dtvsol dns set v4=XXX.XXX.XXX.53,XXX.XXX.XXX.54 v6=XXXX:XXXX::53
dtvsol dns set vlan100 v4=XXX.XXX.XXX.60 # one VLAN's override
dtvsol dns del vlan100
Terminal window
dtvsol route list
dtvsol route add XXX.XXX.XXX.0/24 via 10.20.0.2 "customer block"
dtvsol route add XXXX:XXXX:200::/48 via XXXX:XXXX:ffff::2
dtvsol route del XXX.XXX.XXX.0/24 via 10.20.0.2

Routes survive reboots.

For plain source-NAT (not CGNAT):

Terminal window
dtvsol nat list
dtvsol nat add bond0 XXX.XXX.XXX.20 XXX.XXX.XXX.23 exempt 10.0.0.0/8 "office NAT"
dtvsol nat del bond0

For subscribers, CGNAT is usually the better choice. See CGNAT.

This site was written with the help of AI and checked by our team.