1-11To do... Use the command... RemarksExit to system view quit —z To guard against attacks, you are recommended to enable ARP detection on each CVLAN.z Before applying a QoS policy to the downlink port, enable customer-side QinQ on the port; beforedisabling customer-side QinQ on the downlink port, remove the QoS policy.z To change a VLAN mapping, you must first use the reset dhcp-snooping command to clear thecorresponding DHCP snooping address binding entry (refer to DHCP Commands in the IPServices Volume) or disable the dynamic address binding function of IP Source Guard on thedownlink port and then enable dynamic address binding again (refer to IP Source GuardCommands in the Security Volume).z When configuring many-to-one VLAN mapping, you cannot create VLAN interfaces for the involvedSVLANs and CVLANs on the switch.Configuring One-to-Two VLAN MappingPerform one-to-two VLAN mapping on the edge devices from which customer traffic enters SPnetworks, on Device A and Device D in Figure 1-2 for example.Follow these steps to configure a one-to-two VLAN mapping:To do... Use the command... RemarksEnter system view system-view —Configure an uplink policy forthe downlink port to tag CVLANtagged frames with an SVLANRefer to Table 1-4. RequiredEnter the interface view of thedownlink portinterface interface-typeinterface-number —Set the link type of the downlinkport to hybrid port link-type hybrid RequiredConfigure the downlink port topermit the specified SVLANs topass through and forwardframes after removing the outerSVLAN tagport hybrid vlan vlan-id-listuntaggedRequiredBy default, a hybrid port permitsonly VLAN 1 to pass through.Enable basic QinQ on the port qinq enable RequiredApply the uplink policy to thedownlink port in the inbounddirectionqos apply policy policy-nameinbound RequiredExit to system view quit —Enter the interface view of theuplink portinterface interface-typeinterface-number —