Login
Wi-Fi Launchpad
Community Central
English
  • English
  • 日本語
  • 中文
  • 한국어
Arista
  • Solutions
    • AI Networking Center
    • Cloud Networking
    • Cloud-Grade Routing
    • Cognitive Campus Workspaces
    • Electronic Trading
    • SD-WAN & Edge Routing
    • Federal Government
    • Hybrid Cloud
    • IP Storage and Big Data
    • Media & Entertainment
    • Network Observability
    • Security
    • Telemetry and Analytics
  • Products
    • Product Overview
    • EOS
    • CloudVision
    • Featured Products
    • Featured Platforms
    • Security
    • DANZ Monitoring Fabric
    • Cognitive Wi-Fi
    • Transceivers/Cables
    • Product Families
    • Product Overview
    • EOS Overview
    • CloudVision Overview
    • CloudVision Universal Network Observability (CV UNO)
    • Platforms Overview
    • 7800R Series
    • 7700R Series
    • 7500R Series
    • 7300X Series
    • 7280R Series
    • 7200R Series
    • 7130 Series
    • 7060X Series
    • 7050X Series
    • 7020R Series
    • 7010X Series
    • 700 Series
    • Cognitive Wi-Fi
    • SD-WAN & Edge Routing
    • Universal Cloud Networking
    • Hyperscale Data Center
    • Cloud Grade Routing
    • SD-WAN & Edge Routing
    • Cognitive Campus
    • R-Series Spine & Leaf
    • X-Series Spine & Leaf
    • Programmable
    • 800G Solutions
    • 400G Solutions
    • Flexible 10G & 1G Leaf
    • Network Observability
    • Detection and Response
    • Network Access Control
    • Multi-Domain Segmentation (MSS)
    • Arista NDR
    • Wireless Intrusion Prevention System
    • Edge Threat Management
    • DMF Overview
    • Multi-Cloud Director Data Sheet
    • 7800R4 Series
    • 7800R3 Series
    • 7700R4 Series Overview
    • 7700R4 Data Sheet
    • 7500R3 Series
    • 7500R Series
    • 7388X5 Series
    • 7368X4 Series
    • 7358X4 Series
    • 7300X3 Series
    • 7280R4 Series
    • 7280R3 Series
    • 7280R3 Modular Series
    • AWE 7200R Series Overview
    • AWE 7200R Data Sheet
    • 7130 Series Overview
    • 7130 Hardware
    • 7130 Applications
    • 7130 Developer
    • 7060XE7 Series
    • 7060X6 Series
    • 7060X5 Series
    • 7060X Series
    • 7050X4 Series
    • 7050X3 Series
    • 7050X Series
    • 7020R4 Series Overview
    • 7020R4 Data Sheet
    • 7010X Series Overview
    • 7010X Data Sheet
    • 7010X Quick Look
    • 750 Series
    • 722XPM Series
    • 720XPM Series
    • 720XP Series
    • 720D Series
    • 710HXP Series
    • 710XP Series
    • 710P Series
    • Wi-Fi 7 Series
    • Wi-Fi 6E Series
    • Wi-Fi 6 Series
    • 7x0 Series, Virtual Edge
    • 4100 & 5100 Series
    • Leaf & Spine
    • Spine & Routing
    • Leaf & Routing
    • Hyperscale Data Center
    • 7700R4 Series
    • 7368X4 & 7060X4 Series
    • 7260X3 Series
    • 7060X6 Series
    • 7060X5 Series
    • 7060X2 & 7060X Series
    • Cloud Grade Routing
    • 7800R4 Series
    • 7800R3 Series
    • 7500R3 Series
    • 7280R4 Series
    • 7280R3 Series
    • 7020R4 Series
    • Spine & Edge Routing
    • Wired
    • Wireless
    • Network Access Control
    • R-Series Spine & Leaf
    • 7800R Series
    • 7700R Series
    • 7500R Series
    • 7280R Series
    • 7020R Series
    • X-Series Spine & Leaf
    • 7300X Series
    • 7060X Series
    • 7050X Series
    • Programmable
    • 7130 Series
    • 800G Solutions
    • 7800R4 Series
    • 7700R4 Series
    • 7280R4 Series
    • 7060X6 Series
    • 400G Solutions
    • 7800R4 Series
    • 7800R3 Series
    • 7700R4 Series
    • 7500R3 Series
    • 7388X5 Series
    • 7368X4 Series
    • 7358X4 Series
    • 7280R3 Series
    • 7060X6 Series
    • 7060X5 Series
    • 7060X4 Series
    • 7050X4 Series
    • Flexible 10G & 1G Leaf
    • 7020R4 Series
    • 7010X Series
    • 720XP Series
    • Observability Overview
    • DANZ Monitoring Fabric
    • Detection and Response Overview
    • 7800R4 Series Overview
    • 7800R4 AI Spine
    • 7800R4 Universal Spine
    • 7800R3 Series Overview
    • 7800R3 Quick Look
    • 7800R3 Data Sheet
    • 7500R3 Series Overview
    • 7500R3 Quick Look
    • 7500R3 Data Sheet
    • 7500R Series Overview
    • 7500R Quick Look
    • 7500R Data Sheet
    • 7388X5 Series Overview
    • 7388X5 Quick Look
    • 7388X5 Data Sheet
    • 7368X4 Series Overview
    • 7368X4 Quick Look
    • 7368X4 Data Sheet
    • 7358X4 Series Overview
    • 7358X4 Quick Look
    • 7358X4 Data Sheet
    • 7300X3 Series Overview
    • 7300X3 Quick Look
    • 7300X3 Data Sheet
    • 7280R4 Series Overview
    • 7280R4 Data Sheet
    • 7280R3 Series Overview
    • 7280R3 Data Sheet
    • 7280R3 Quick Look
    • 7280R3A Data Sheet
    • 7280R3A Quick Look
    • 7280R3 Modular Data Sheet
    • 7280R3 Modular Quick Look
    • 7130 Hardware Overview
    • 7130 Connect Series
    • 7130E Series
    • 7130L Series
    • 7130LBR Series
    • 7132LB Series
    • 7135LB Series
    • 7135V Series
    • 7130 Applications Overview
    • MetaWatch App
    • MetaMux App
    • MultiAccess App
    • MetaProtect App
    • Exchange App
    • Switch App
    • 7130 Developer Overview
    • IP Cores
    • Development Kits
    • 7060XE7 Series Overview
    • 7060XE7 Quick Look
    • 7060XE7 Data Sheet
    • 7060X6 Series Overview
    • 7060X6 Quick Look
    • 7060X6 Data Sheet
    • 7060X5 Series Overview
    • 7060X5 Quick Look
    • 7060X5 Data Sheet
    • 7060X Series Overview
    • 7060X & 7260X Quick Look
    • 7060X & 7260X Data Sheet
    • 7050X4 Series Overview
    • 7050X4 Quick Look
    • 7050X4 Data Sheet
    • 7050X3 Series Overview
    • 7050X3 Quick Look
    • 7050X3 Data Sheet
    • 7050X Series Overview
    • 7050X Quick Look
    • 7050X Data Sheet
    • 750 Series Overview
    • 750 Data Sheet
    • 722XPM Series Overview
    • 722XPM Data Sheet
    • 720XPM Series Overview
    • 720XPM Data Sheet
    • 720XP Series Overview
    • 720XP Data Sheet
    • 720D Series Overview
    • 720D Data Sheet
    • 710HXP Series Overview
    • 710HXP Data Sheet
    • 710XP Series Overview
    • 710XP Data Sheet
    • 710P Series Overview
    • 710P Data Sheet
    • 7x0 Series, Virtual Edge Overview
    • 7x0 Series, Virtual Edge Data Sheet
    • 4100 & 5100 Series Overview
    • 4100 & 5100 Series Data Sheet
    • Leaf & Spine
    • R Series
    • X Series
    • Spine & Routing
    • 7800R4 Series
    • 7800R3 Series
    • 7500R3 Series
    • 7368X4 Series
    • 7300X3 Series
    • 7300X Series
    • 7280R4 Series
    • 7280R3 Modular Series
    • Leaf & Routing
    • 7280R4 Series
    • 7280R3 Series
    • 7280R3 Modular Series
    • 7260X3 Series
    • 7060X4 Series
    • 7060X2 & 7060X Series
    • 7050X3 Series
    • 7050X Series
    • 7020R4 Series
    • 7368X4 Series
    • 7060X4 Series
    • 7280R3 Series
    • 7280R3 Modular Series
    • Spine & Edge Routing
    • 7300X Series
    • 7280R4 Series
    • 7280R3 Series
    • 7050X Series
    • 7020R4 Series
    • Wired & Wireless
    • 7300X Series
    • 7050X Series
    • 750 Series
    • 720XP Series
    • 722XPM Series
    • 720D Series
    • 710P Series
    • Cognitive Wi-Fi
    • Wi-Fi 6 Series
    • Wi-Fi 6E Series
    • 7800R Series
    • 7800R4 Series
    • 7800R3 Series
    • 7700R Series
    • 7700R4 Series
    • 7500R Series
    • 7500R3 Series
    • 7500R Series
    • 7280R Series
    • 7280R4 Series
    • 7280R3 Series
    • 7280R3 Modular Series
    • 7020R4 Series Overview
    • 7020R4 Data Sheet
    • 7300X Series Spine
    • 7388X5 Series
    • 7368X4 Series
    • 7358X4 Series
    • 7300X Series
    • 7060X Series
    • 7060XE7 Series
    • 7060X6 Series
    • 7060X5 Series
    • 7060X4 Series
    • 7060X2 and 7060X
    • 7050X Series
    • 7050X4 Series
    • 7050X3 Series
    • 7050X Series
    • 7130 Series Overview
    • 7130 Hardware
    • 7130 Applications
    • 7130 Developer
  • Partner
    • Partner Program
    • Become a Partner
    • Partner Code of Ethics and Business Conduct
    • Channel Partner Portal
    • Technology Partners
  • Support
    • Support Overview
    • Customer Support
    • Product Documentation
    • Product Certifications
    • Advisories & Notices
    • Product Lifecycle
    • Software Download
    • Transfer of Information
    • Support Portal
    • Training
    • Software Bug Portal
    • CVP Upgrade Path
    • MLAG ISSU Check
    • Tech Library Portal
  • Company
    • Company Overview
    • Corporate Responsibility
    • Management Team
    • Blogs
    • Investor Relations
    • Events Calendar
    • Webinars
    • Video Library
    • Testimonials
    • Careers
    • News
    • Contact Us
  • End of Support

View All Support
X
  • Support Overview
  • Customer Support
  • Product Documentation
  • Product Certifications
  • Advisories & Notices
  • Product Lifecycle
  • Software Download
  • Transfer of Information
  • Support Portal
  • Training
  • Software Bug Portal
  • MLAG ISSU Check
  • CVP Upgrade Path
 
 
 

EOS 4.36.2F User Manual - Layer 3 Configuration

Layer 3 Configuration

This chapter covers the following Layer 3 sections:

  • IPv4
  • IPv6
  • Ingress and Egress Per-Port for IPv4 and IPv6 Counters
  • ACLs and Route Maps
  • VRRP and VARP
  • DirectFlow
  • Decap Groups
  • Nexthop Groups
  • Setting the MTU for all Layer 3 Interfaces
  • Support for Layer 3 MTU on 7280R3/7500R3/7800R3
  • Segment Security

..

EOS 4.36.2F User Manual - Overview of Layer 2 Subinterfaces

Overview of Layer 2 Subinterfaces

A Layer 2 (L2) subinterface is a logical network endpoint associated with a physical interface, such as an Ethernet port, specifically designated to handle traffic for a single, distinct 802.1Q (VLAN) tag. Unlike a standard switchport or a Layer 3 subinterface, the L2 subinterface acts as a first-class bridging interface tied to a particular VLAN tag, and allows for granular control and isolation of that specific L2 traffic stream.

Use L2 subinterfaces on network devices in service provider or data center environments, for advanced functions like dedicated shaping/QoS or to integrate with technologies like EVPN.

Table 1. Key Concepts of Layer 2 Subinterfaces
Concept Description
Logical Bridging Endpoint The subinterface provides a virtual port that functions as a normal L2 bridge member but logically separated from the parent physical interface.
Encapsulation Matching Traffic steers to the L2 subinterface based on the 802.1Q VLAN tag (outer VID). A frame must arrive on the parent interface with the configured tag to be processed by the subinterface.
Routed Parent Port EOS typically creates Layer 2 subinterfaces on a routed port,an interface configured with no switchport, a key distinction from standard L2 trunking.
Forwarding VLAN ID The subinterface ultimately becomes placed into a forwarding VLAN or bridging domain. This allows learning MAC addresses and forwarding traffic like a standard switchport access member for that VLAN.
Traffic Control This feature enables granular Quality of Service (QoS), such as shaping or policing, to be applied directly to the traffic of a specific VLAN on that physical link, which isn't possible with a simple trunk port configuration.

Like other types of interfaces, a L2 subinterface provides a normal bridging endpoint in the bridging domain.

Figure 1. Layer 2 Subinterface

Configuring Layer 2 Subinterfaces

The following sections describe configuring Layer 2 subinterfaces.

Creating a Layer 2 Subinterface

Complete the following steps to configure a Layer 2 (L2) subinterface on an Arista switch:

  1. Configure the parent interface to be a routed port.
    switch(config)# interface et1
    switch(config-if-Et1)# no switchport

  2. Create a subinterface on the parent interface (et1.1), assign 802.1q encapsulation (vlan 100), and assign the forwarding VLAN ID (vlan 200).
    switch(config-if-Et1)# interface et1.1
    switch(config-if-Et1.1)# encapsulation dot1q vlan 100
    switch(config-if-Et1.1)# vlan id 200
    ! VLAN does not exist. Creating vlan 200

  3. Instead of configuring a forwarding VLAN id, use the VLAN name office.
    switch(config)# vlan 200
    switch(config-vlan-200)# name office
    switch(config-vlan-200)# int et1.2
    switch(config-if-Et1.2)# encapsulation dot1q vlan 101
    switch(config-if-Et1.2)# vlan name office

  4. Now subinterfaces et1.1 and et1.2 have been created and added to vlanVLAN 200.
    switch# show interface et1.1-2 status
    Port     Name   Status       Vlan     Duplex Speed  Type                  Flags Encapsulation
    Et1.1           connected    200      full   10G    dot1q-encapsulation   100
    
    Et1.2           connected    200      full   10G    dot1q-encapsulation   101

MAC Address on Layer 2 Subinterface

Configure MAC addresses as either static or dynamic as assigned behind Layer 2 (L2) subinterfaces.

Example

switch(config)# mac address-table static 0000.000a.000a vlan 200 interface et1.1

Example
switch# show mac address-table interface et1.1-2
          Mac Address Table
--------------------------------------------------------

Vlan  Mac Address     Type     Ports   Moves  Last Move
----  -----------     ----     -----   -----  ---------
 200  0000.000a.000a  STATIC   Et1.1
 200  0000.000b.000b  DYNAMIC  Et1.2   1      0:00:06 ago
Total Mac Addresses for this criterion: 2

MAC address learning can be enabled or disabled on an L2 subinterface using the following commands:

In the following example, the show interface ethernet1.1 switchport command has this running-config:
switch(config-if-Et1.1)# show interface ethernet1.1 switchport
Name: Et1.1
Switchport: Enabled
Administrative Mode: tunnel
Operational Mode: tunnel
MAC Address Learning: disabled
Dot1q ethertype/TPID: 0x8100 (active)
Dot1q VLAN Tag: Allowed
Access Mode VLAN: 1 (default)
Trunking Native Mode VLAN: 1 (default)
Administrative Native VLAN tagging: disabled
Trunking VLANs Enabled: ALL
Static Trunk Groups:
Dynamic Trunk Groups:
Source interface filtering: enabled
VLAN forwarding mode: allowedVlansOnly

To enable MAC address learning, use the no mac address learning disabled command:
switch(config-if-Et1.1)# no mac address learning disabled

QoS Feature

Supported QoS features include the following:

Shaping

After creating an L2 subinterface, you can configure a shape rate (in Kbps) on the sub-interface. For example, configure the shape rate to 50000000 Kbps.

switch(config-if-Et1.1)# shape rate 50000000

The configuration of non-default shape rate results in the allocation of dedicated virtual output queues (VOQ) for the subinterface. Each subinterface allocates four (4) VOQs. Different TC traffic goes to the VOQ according to the following mapping:
Table 2. TC Traffic Destination
TC6-7 : VOQ3
TC4-5 : VOQ2
TC2-3 : VOQ1
TC0-1 : VOQ0

VOQ3 is in strict-priority mode to the other VOQs.

VOQ2, VOQ1, and VOQ0 are in WRR with a static credit ratio 2:3:6 (higher ratio implies more credits).

The subinterface inherits the trust mode of the parent interface.

Before EOS Release 4.24.2F, EOS supported shaping only on L2 subinterfaces of parent Ethernet interfaces, for example, Et1.1. Beginning with EOS Release 4.24.2F, EOS supports shaping on L2 subinterface over a port-channel parent interface for example, Po1.1).

Note: A single parent interface supports up to 2000 shaped subinterfaces.

Guaranteed Bandwidth

After configuring shaping on an L2 sub-interface, configure a guaranteed bandwidth (in Kbps or percent) on the subinterface using the bandwidth guaranteed command.
switch(config-if-Et1.1)# bandwidth guaranteed 10000000
switch(config-if-Et1.1)# bandwidth guaranteed percent 10

Policing

For policing to work on the L2 subinterface, you must switch to the QoS profile.

Example

switch(config)# hardware tcam
switch(config-hw-tcam)# system profile qos

Sample Policy-map Configuration:

switch(config)# ip access-list a1
switch(config-acl-a1)# statistics per-entry
switch(config-acl-a1)# 10 permit ip any any

switch(config)# class-map type qos match-any c1
switch(config-cmap-qos-c1)# match ip access-group a1

switch(config)# class-map type qos match-any c2
switch(config-cmap-qos-c2)# match vlan 100 0xfff

switch(config)# ipv6 access-list a1
switch(config-ipv6-acl-a1)# statistics per-entry
switch(config-ipv6-acl-a1)# 10 permit ipv6 any any

switch(config)# class-map type qos match-any c3
switch(config-cmap-qos-c3)# match ipv6 access-group a1

switch(config)# policy-map type quality-of-service p1
switch(config-pmap-quality-of-service-p1)# class c1
switch(config-pmap-quality-of-service-p1-c1)# police cir 10 Mbps bc 100000 bytes
    exit
exit

After you create an L2 subinterface, you can configure a policy-map on the sub-interface, similar to the following example.
switch(config-if-Et1.1)# service-policy type qos input p1

Interface Counters

To enable the hardware features for counting packets on L2 subinterfaces ingress and/or egress, use the hardware counter feature command, similar to the following example. In the example, enable subinterface layer2 for ingress, and then enable for egress.

Example
switch(config)# hardware counter feature subinterface in layer2
switch(config)# hardware counter feature subinterface out layer2

To display the L2 subinterface counters, use the show interface counters command similar to the following example. In the example, subinterface et1.1 displays.
switch# show interfaces et1.1 counters

Port        InOctets      InPkts
Et1.1       0             0

Port         OutOctets    OutPkts
Et1.1        0             0

To clear all of the interface counters, use the clear counters command:
switch# clear counters

To learn counters for a specific L2 interface, use the clear counters command, and clear the L2 subinterface. In the example, clear the L2 subinterface et1.1.
switch# clear counters et1.1

Configuration Considerations

Use the following considerations to apply to the Layer 2 subinterface feature:
  • A total of 256 Layer 2 subinterfaces with shaping are supported across the entire switch and they can be distributed across any number of Ethernet ports.

  • When configuring a shape rate on an L2 subinterface over a parent port -channel interface, such as, Po1.1), traffic load-balancing is disabled and is directed to a selected port-channel member. Also, the bandwidth of the port-channel subinterface equals the selected member. However, the show interface command continues to show the bandwidth of the port-channel which is incorrect.

  • After configuring a shape rate on an L2 subinterface, the L2 subinterface must be flapped by using the shut” and no shut commands.

  • Shaping of BUM traffic on L2 subinterfaces is supported only with “ingress replication”.

  • EOS supports Layer 3 forwarding through SVIs .

  • EOS does not support control plane processing, such as IGMP snooping and STP BPDU.

  • When IGMP protocol packets are expected to be forwarded on L2 subinterfaces, then IGMP snooping must be disabled globally on the entire switch using the no ip igmp snooping command. When IGMP snooping is configured on any VLAN, then IGMP protocol packets are discarded by L2 subinterfaces.

  • Double tagged packets arriving on L2 subinterfaces with a single encapsulation dot1q vlan outer_vid command configured will match on the outer VLAN tag, and have only the outer VLAN tags terminated.

  • The encapsulation dot1q vlan outer_vid inner inner_vid command is supported for configuring double-tagged L2 subinterfaces.

  • EOS does not support the mixing of shaped and non-shaped subinterfaces under the same parent interface.

  • Traffic classification on ingress traffic to l2 subinterface is disabled by default. To enable this feature, configure using the qos trust cos command on the parent interface.

  • An MLAG environment does not support Layer 2 subinterfaces.

QoS Show Commands

Use the show interfaces status command to display the subinterface status.

Example
switch# show interfaces status sub-interfaces
Port     Name   Status       Vlan     Duplex Speed  Type                Flags Encapsulation
Et1.1           connected    200      full   10G    dot1q-encapsulation       100
Et1.2           connected    200      full   10G    dot1q-encapsulation       101

Use the show vlan command to display the VLAN membership. In the following example, vlan 200 is configured to be displayed.

Example
switch# show vlan 200
VLAN  Name                 Status    Ports
----- ------------------- --------- -------------------
200   office               active    Et1.1, Et1.2, Et5

Use the show qos interface command to display the QoS configuration on an L2 subinterface. In the following example, QoS subinterface Ethernet 1.1 is configured to be displayed.

Example
switch# show qos interface Ethernet 1.1
Ethernet1.1:

   Trust Mode: DSCP
   Default COS: 0
   Default DSCP: 0

   Port shaping rate: 50625 / 50000 kbps

Use the show interface counters with the queue keyword to display the L2 subinterface counters. For example subinterface Ethernet 1.1 is configured to display the L2 subinterface counters.

Example
switch# show interface Ethernet 1.1 counters queue
Aggregate VoQ Counters
Egress   Traffic   Pkts     Octets     DropPkts  DropOctets
Port     Class
------------------------------------------------------------
Et1.1    TC0-1      0        0          0         0
Et1.1    TC2-3      0        0          0         0
Et1.1    TC4-5      0        0          0         0
Et1.1    TC6-7      460266   276159600  109316    65589600

Use the show mac address-table command to display the MAC address on L2 subinterfaces. For example, subinterfaces Et1.1 and Et1.2 are configured to be displayed.

Example
switch# show mac address-table interface et1.1-2
          Mac Address Table
------------------------------------------------------------------

Vlan    Mac Address       Type        Ports      Moves   Last Move
----    -----------       ----        -----      -----   ---------
 200    0000.000a.000a    STATIC      Et1.1
 200    0000.000b.000b    DYNAMIC     Et1.2      1       0:00:16 ago
Total Mac Addresses for this criterion: 2
..

EOS 4.36.2F User Manual - Layer 2 Protocol Forwarding

Layer 2 Protocol Forwarding

EOS supports Layer2 (L2) Protocol Forwarding on Ethernet interfaces in addition to Type-5 PW. Also, EOS allows selective forwarding of certain L2 Protocol packets, such as tagged, untagged, and all, instead of forwarding all LACP frames, both tagged and untagged. The protocol list for L2 Protocol Forwarding also supports PAUSE, LACP, LLDP, MACsec, and STP. Additionally, L2PF supports the Per-VLAN Spanning Tree (PVST) protocol to forward, drop, or trap PVST packets on Type-2 platforms. EOS enables drop support for all supported protocols.

Configuring L2 Protocol Forwarding

Use the following commands to create a profile that allows forwarding tagged/untagged/all types of PAUSE/LACP/LLDP/MACSEC/STP/E-LMI/ ISIS/micro-BFD frames.
switch(config-l2-protocol)# forwarding profile abc
switch(config-l2-protocol-abc)# isis forward
switch(config-l2-protocol-abc)# macsec tagged forward
switch(config-l2-protocol-abc)# pause untagged forward
switch(config-l2-protocol-abc)# exit

The following commands apply the profile to an interface or subinterface:
switch(config)# int ethernet1/1
switch(config-if-Et1/1)# l2-protocol forwarding profile abc
switch(config-if-Et1/1)# exit
switch(config)# int ethernet2/1.1
switch(config-if-Et2/1.1)# l2-protocol forwarding profile def
switch(config-if-Et2/1.1)# exit

TCAM Profile

A specific TCAM profile is required to configure L2 Protocol Forwarding profiles except if the L2 Protocol Forwarding profile has only ‘lacp forward’ and is configured on Type-5 PW ports on Type-1 platforms. One such TCAM profile is as follows:
switch(config)# hardware tcam
switch(config-tcam)# profile l2protocolfwd
switch(config-tcam-profile-12protocolfwd)# feature acl port ip
switch(config-tcam-feature-acl-port-ip)# sequence 45
switch(config-tcam-feature-acl-port-ip)# key size limit 160
switch(config-tcam-feature-acl-port-ip)# key field dscp dst-ip ip-frag ip-protocol l4-dst-port l4-ops l4-src-port src-ip tcp-control ttl
switch(config-tcam-feature-acl-port-ip)# action count drop
switch(config-tcam-feature-acl-port-ip)# packet ipv4 forwarding bridged
switch(config-tcam-feature-acl-port-ip)# packet ipv4 forwarding routed
switch(config-tcam-feature-acl-port-ip)# packet ipv4 forwarding routed multicast
switch(config-tcam-feature-acl-port-ip)# packet ipv4 mpls ipv4 forwarding mpls decap
switch(config-tcam-feature-acl-port-ip)# packet ipv4 mpls ipv6 forwarding mpls decap
switch(config-tcam-feature-acl-port-ip)# packet ipv4 non-VXLAN forwarding routed decap
switch(config-tcam-feature-acl-port-ip)# packet ipv4 VXLAN eth ipv4 forwarding routed decap
switch(config-tcam-feature-acl-port-ip)# packet ipv4 VXLAN forwarding bridged decap
switch(config-tcam-feature-acl-port-ip)# feature acl port ipv6
switch(config-tcam-feature-acl-port-ipv6)# sequence 25
switch(config-tcam-feature-acl-port-ipv6)# key field dst-ipv6 ipv6-next-header ipv6-traffic-class l4-dst-port l4-ops-3b l4-src-port src-ipv6-high src-ipv6-low tcp-control
switch(config-tcam-feature-acl-port-ipv6)# action count drop
switch(config-tcam-feature-acl-port-ipv6)# packet ipv6 forwarding bridged
switch(config-tcam-feature-acl-port-ipv6)# packet ipv6 forwarding routed
switch(config-tcam-feature-acl-port-ipv6)# packet ipv6 forwarding routed multicast
switch(config-tcam-feature-acl-port-ipv6)# packet ipv6 ipv6 forwarding routed decap
switch(config-tcam-feature-acl-port-ipv6)# feature acl port mac
switch(config-tcam-feature-acl-port-mac)# sequence 55
switch(config-tcam-feature-acl-port-mac)# key size limit 160
switch(config-tcam-feature-acl-port-mac)# key field dst-mac ether-type src-mac
switch(config-tcam-feature-acl-port-mac)# action count drop
switch(config-tcam-feature-acl-port-mac)# packet ipv4 forwarding bridged
switch(config-tcam-feature-acl-port-mac)# packet ipv4 forwarding routed
switch(config-tcam-feature-acl-port-mac)# packet ipv4 forwarding routed multicast
switch(config-tcam-feature-acl-port-mac)# packet ipv4 mpls ipv4 forwarding mpls decap
switch(config-tcam-feature-acl-port-mac)# packet ipv4 mpls ipv6 forwarding mpls decap
switch(config-tcam-feature-acl-port-mac)# packet ipv4 non-VXLAN forwarding routed decap
switch(config-tcam-feature-acl-port-mac)# packet ipv4 VXLAN forwarding bridged decap
switch(config-tcam-feature-acl-port-mac)# packet ipv6 forwarding bridged
switch(config-tcam-feature-acl-port-mac)# packet ipv6 forwarding routed
switch(config-tcam-feature-acl-port-mac)# packet ipv6 forwarding routed decap
switch(config-tcam-feature-acl-port-mac)# packet ipv6 forwarding routed multicast
switch(config-tcam-feature-acl-port-mac)# packet ipv6 ipv6 forwarding routed decap
switch(config-tcam-feature-acl-port-mac)# packet mpls forwarding bridged decap
switch(config-tcam-feature-acl-port-mac)# packet mpls ipv4 forwarding mpls
switch(config-tcam-feature-acl-port-mac)# packet mpls ipv6 forwarding mpls
switch(config-tcam-feature-acl-port-mac)# packet mpls non-ip forwarding mpls
switch(config-tcam-feature-acl-port-mac)# packet non-ip forwarding bridged
switch(config-tcam-feature-acl-port-mac)# feature acl subintf ip
switch(config-tcam-feature-acl-subintf-ip)# sequence 40
switch(config-tcam-feature-acl-subintf-ip)# key size limit 160
switch(config-tcam-feature-acl-subintf-ip)# key field dscp dst-ip ip-frag ip-protocol l4-dst-port l4-ops-18b l4-src-port src-ip tcp-control ttl
switch(config-tcam-feature-acl-subintf-ip)# action count drop
switch(config-tcam-feature-acl-subintf-ip)# packet ipv4 forwarding routed
switch(config-tcam-feature-acl-subintf-ip)# feature acl subintf ipv6
switch(config-tcam-feature-acl-subintf-ipv6)# sequence 15
switch(config-tcam-feature-acl-subintf-ipv6)# key field dst-ipv6 ipv6-next-header l4-dst-port l4-src-port src-ipv6-high src-ipv6-low tcp-control
switch(config-tcam-feature-acl-subintf-ipv6)# action count drop
switch(config-tcam-feature-acl-subintf-ipv6)# packet ipv6 forwarding routed
switch(config-tcam-feature-acl-subintf-ipv6)# feature acl vlan ip
switch(config-tcam-feature-acl-vlan-ip)# sequence 35
switch(config-tcam-feature-acl-vlan-ip)# key size limit 160
switch(config-tcam-feature-acl-vlan-ip)# key field dscp dst-ip ip-frag ip-protocol l4-dst-port l4-ops-18b l4-src-port src-ip tcp-control ttl
switch(config-tcam-feature-acl-vlan-ip)# action count drop
switch(config-tcam-feature-acl-vlan-ip)# packet ipv4 forwarding routed
switch(config-tcam-feature-acl-vlan-ip)# packet ipv4 mpls ipv4 forwarding mpls decap
switch(config-tcam-feature-acl-vlan-ip)# packet ipv4 mpls ipv6 forwarding mpls decap
switch(config-tcam-feature-acl-vlan-ip)# packet ipv4 non-VXLAN forwarding routed decap
switch(config-tcam-feature-acl-vlan-ip)# packet ipv4 VXLAN eth ipv4 forwarding routed decap
switch(config-tcam-feature-acl-vlan-ip)# feature acl vlan ipv6
switch(config-tcam-feature-acl-vlan-ipv6)# sequence 10
switch(config-tcam-feature-acl-vlan-ipv6)# key field dst-ipv6 ipv6-next-header l4-dst-port l4-src-port src-ipv6-high src-ipv6-low tcp-control
switch(config-tcam-feature-acl-vlan-ipv6)# action count drop
switch(config-tcam-feature-acl-vlan-ipv6)# packet ipv6 forwarding routed
switch(config-tcam-feature-acl-vlan-ipv6)# packet ipv6 ipv6 forwarding routed decap
switch(config-tcam-feature-acl-vlan-ipv6)# feature acl vlan ipv6 egress
switch(config-tcam-feature-acl-vlan-ipv6-egress)# sequence 20
switch(config-tcam-feature-acl-vlan-ipv6-egress)# key field dst-ipv6 ipv6-next-header ipv6-traffic-class l4-dst-port l4-src-port src-ipv6-high src-ipv6-low tcp-control
switch(config-tcam-feature-acl-vlan-ipv6-egress)# action count drop
switch(config-tcam-feature-acl-vlan-ipv6-egress)# packet ipv6 forwarding routed
switch(config-tcam-feature-acl-vlan-ipv6-egress)# feature counter lfib
switch(config-tcam-feature-counter-lfib)# sequence 85
switch(config-tcam-feature-counter-lfib)# feature l2-protocol forwarding
switch(config-tcam-feature-l2-protocol-fowarding)# sequence 95
switch(config-tcam-feature-l2-protocol-fowarding)# key size limit 160
switch(config-tcam-feature-l2-protocol-fowarding)# key field dst-mac vlan-tag-format
switch(config-tcam-feature-l2-protocol-fowarding)# action mirror redirect-to-cpu set-tc
switch(config-tcam-feature-l2-protocol-fowarding)# packet non-ip forwarding bridge
switch(config-tcam-feature-l2-protocol-fowarding)# packet non-ip forwarding bridged sub-interface
switch(config-tcam-feature-l2-protocol-fowarding)# feature mirror ip
switch(config-tcam-feature-mirror-ip)# sequence 80
switch(config-tcam-feature-mirror-ip)# key size limit 160
switch(config-tcam-feature-mirror-ip)# key field dscp dst-ip ip-frag ip-protocol l4-dst-port l4-ops l4-src-port src-ip tcp-control
switch(config-tcam-feature-mirror-ip)# action count mirror set-policer
switch(config-tcam-feature-mirror-ip)# packet ipv4 forwarding bridged
switch(config-tcam-feature-mirror-ip)# packet ipv4 forwarding routed
switch(config-tcam-feature-mirror-ip)# packet ipv4 forwarding routed multicast
switch(config-tcam-feature-mirror-ip)# packet ipv4 non-VXLAN forwarding routed decap
switch(config-tcam-feature-mirror-ip)# feature mpls
switch(config-tcam-feature-mpls)# sequence 5
switch(config-tcam-feature-mpls)# key size limit 160
switch(config-tcam-feature-mpls)# action drop redirect set-ecn
switch(config-tcam-feature-mpls)# packet ipv4 mpls ipv4 forwarding mpls decap
switch(config-tcam-feature-mpls)# packet ipv4 mpls ipv6 forwarding mpls decap
switch(config-tcam-feature-mpls)# packet mpls ipv4 forwarding mpls
switch(config-tcam-feature-mpls)# packet mpls ipv6 forwarding mpls
switch(config-tcam-feature-mpls)# packet mpls non-ip forwarding mpls
switch(config-tcam-feature-mpls)# feature mpls pop ingress
switch(config-tcam-feature-mpls-pop-ingress)# sequence 90
switch(config-tcam-feature-mpls-pop-ingress)# feature pbr ip
switch(config-tcam-feature-pbr-ip)# sequence 60
switch(config-tcam-feature-pbr-ip)# key size limit 160
switch(config-tcam-feature-pbr-ip)# key field dscp dst-ip ip-frag ip-protocol l4-dst-port l4-ops-18b l4-src-port src-ip tcp-control
switch(config-tcam-feature-pbr-ip)# action count redirect
switch(config-tcam-feature-pbr-ip)# packet ipv4 forwarding routed
switch(config-tcam-feature-pbr-ip)# packet ipv4 mpls ipv4 forwarding mpls decap
switch(config-tcam-feature-pbr-ip)# packet ipv4 mpls ipv6 forwarding mpls decap
switch(config-tcam-feature-pbr-ip)# packet ipv4 non-VXLAN forwarding routed decap
switch(config-tcam-feature-pbr-ip)# packet ipv4 VXLAN forwarding bridged decap
switch(config-tcam-feature-pbr-ip)# feature pbr ipv6
switch(config-tcam-feature-pbr-ipv6)# sequence 30
switch(config-tcam-feature-pbr-ipv6)# key field dst-ipv6 ipv6-next-header l4-dst-port l4-src-port src-ipv6-high src-ipv6-low tcp-control
switch(config-tcam-feature-pbr-ipv6)# action count redirect
switch(config-tcam-feature-pbr-ipv6)# packet ipv6 forwarding routed
switch(config-tcam-feature-pbr-ipv6)# feature pbr mpls
switch(config-tcam-feature-pbr-mpls)# sequence 65
switch(config-tcam-feature-pbr-mpls)# key size limit 160
switch(config-tcam-feature-pbr-mpls)# key field mpls-inner-ip-tos
switch(config-tcam-feature-pbr-mpls)# action count drop redirect
switch(config-tcam-feature-pbr-mpls)# packet mpls ipv4 forwarding mpls
switch(config-tcam-feature-pbr-mpls)# packet mpls ipv6 forwarding mpls
switch(config-tcam-feature-pbr-mpls)# packet mpls non-ip forwarding mpls
switch(config-tcam-feature-pbr-mpls)# feature qos ip
switch(config-tcam-feature-qos-ip)# sequence 75
switch(config-tcam-feature-qos-ip)# key size limit 160
switch(config-tcam-feature-qos-ip)# key field dscp dst-ip ip-frag ip-protocol l4-dst-port l4-ops l4-src-port src-ip tcp-control
switch(config-tcam-feature-qos-ip)# action set-dscp set-policer set-tc
switch(config-tcam-feature-qos-ip)# packet ipv4 forwarding routed
switch(config-tcam-feature-qos-ip)# packet ipv4 forwarding routed multicast
switch(config-tcam-feature-qos-ip)# packet ipv4 mpls ipv4 forwarding mpls decap
switch(config-tcam-feature-qos-ip)# packet ipv4 mpls ipv6 forwarding mpls decap
switch(config-tcam-feature-qos-ip)# packet ipv4 non-VXLAN forwarding routed decap
switch(config-tcam-feature-qos-ip)# feature qos ipv6
switch(config-tcam-feature-qos-ipv6)# sequence 70
switch(config-tcam-feature-qos-ipv6)# key field dst-ipv6 ipv6-next-header ipv6-traffic-class l4-dst-port l4-src-port src-ipv6-high src-ipv6-low
switch(config-tcam-feature-qos-ipv6)# action set-dscp set-policer set-tc
switch(config-tcam-feature-qos-ipv6)# packet ipv6 forwarding routed
switch(config-tcam-feature-qos-ipv6)# feature tunnel VXLAN
switch(config-tcam-feature-tunnel-VXLAN)# sequence 50
switch(config-tcam-feature-tunnel-VXLAN)# key size limit 160
switch(config-tcam-feature-tunnel-VXLAN)# packet ipv4 VXLAN eth ipv4 forwarding routed decap
switch(config-tcam-feature-tunnel-VXLAN)# packet ipv4 VXLAN forwarding bridged decap

For ISIS protocol forwarding, “snoop” action has to be present in the TCAM profile for l2-protocol forwarding feature as follows:
switch(config-tcam)# feature l2-protocol forwarding
switch(config-tcam-l2-protocol forwarding)# sequence 95
switch(config-tcam-l2-protocol forwarding)# key size limit 160
switch(config-tcam-l2-protocol forwarding)# key field dst-mac vlan-tag-format
switch(config-tcam-l2-protocol forwarding)# action mirror redirect-to-cpu set-tc snoop
switch(config-tcam-l2-protocol forwarding)# packet non-ip forwarding bridged
switch(config-tcam-l2-protocol forwarding)# packet non-ip forwarding bridged sub-interface

For the special case of micro-BFD protocol forwarding, the following TCAM profile needs to be applied:
switch(config)# hardware tcam
switch(config-tcam)# profile l2protocolfwd-bfd-rfc-7130
switch(config-tcam-profile l2protocolfwd-bfd-rfc-7130)# feature acl port ip egress mpls-tunnelled-match
switch(config-tcam-feature-acl-port-ip-egress-mpls-tunnelled-match)# sequence 95
switch(config-tcam-feature-acl-port-ip-egress-mpls-tunnelled-match)# feature acl port ipv6 egress
switch(config-tcam-feature-acl-port-ipv6-egress)# sequence 105
switch(config-tcam-feature-acl-port-ipv6-egress)# key field dst-ipv6 ipv6-next-header ipv6-traffic-class l4-dst-port l4-src-port src-ipv6-high src-ipv6-low tcp-control
switch(config-tcam-feature-acl-port-ipv6-egress)# action count drop mirror
switch(config-tcam-feature-acl-port-ipv6-egress)# packet ipv6 forwarding bridged
switch(config-tcam-feature-acl-port-ipv6-egress)# packet ipv6 forwarding routed
switch(config-tcam-feature-acl-port-ipv6-egress)# feature acl port mac
switch(config-tcam-feature-acl-port-mac)# sequence 55
switch(config-tcam-feature-acl-port-mac)# key size limit 160
switch(config-tcam-feature-acl-port-mac)# key field dst-mac ether-type src-mac
switch(config-tcam-feature-acl-port-mac)# action count drop mirror
switch(config-tcam-feature-acl-port-mac)# packet ipv4 forwarding bridged
switch(config-tcam-feature-acl-port-mac)# packet ipv4 forwarding routed
switch(config-tcam-feature-acl-port-mac)# packet ipv4 forwarding routed multicast
switch(config-tcam-feature-acl-port-mac)# packet ipv4 mpls ipv4 forwarding mpls decap
switch(config-tcam-feature-acl-port-mac)# packet ipv4 mpls ipv6 forwarding mpls decap
switch(config-tcam-feature-acl-port-mac)# packet ipv4 non-VXLAN forwarding routed decap
switch(config-tcam-feature-acl-port-mac)# packet ipv4 VXLAN forwarding bridged decap
switch(config-tcam-feature-acl-port-mac)# packet ipv6 forwarding bridged
switch(config-tcam-feature-acl-port-mac)# packet ipv6 forwarding routed
switch(config-tcam-feature-acl-port-mac)# packet ipv6 forwarding routed decap
switch(config-tcam-feature-acl-port-mac)# packet ipv6 forwarding routed multicast
switch(config-tcam-feature-acl-port-mac)# packet ipv6 ipv6 forwarding routed decap
switch(config-tcam-feature-acl-port-mac)# packet mpls forwarding bridged decap
switch(config-tcam-feature-acl-port-mac)# packet mpls ipv4 forwarding mpls
switch(config-tcam-feature-acl-port-mac)# packet mpls ipv6 forwarding mpls
switch(config-tcam-feature-acl-port-mac)# packet mpls non-ip forwarding mpls
switch(config-tcam-feature-acl-port-mac)# packet non-ip forwarding bridged
switch(config-tcam-feature-acl-port-mac)# feature acl subintf ip
switch(config-tcam-feature-acl-subintf-ip)# sequence 40
switch(config-tcam-feature-acl-subintf-ip)# key size limit 160
switch(config-tcam-feature-acl-subintf-ip)# key field dscp dst-ip ip-frag ip-protocol l4-dst-port l4-ops-18b l4-src-port src-ip tcp-control ttl
switch(config-tcam-feature-acl-subintf-ip)# action count drop
switch(config-tcam-feature-acl-subintf-ip)# packet ipv4 forwarding routed
switch(config-tcam-feature-acl-subintf-ip)# feature acl subintf ipv6
switch(config-tcam-feature-acl-subintf-ipv6)# sequence 15
switch(config-tcam-feature-acl-subintf-ipv6)# key field dst-ipv6 ipv6-next-header l4-dst-port l4-src-port src-ipv6-high src-ipv6-low tcp-control
switch(config-tcam-feature-acl-subintf-ipv6)# action count drop
switch(config-tcam-feature-acl-subintf-ipv6)# packet ipv6 forwarding routed
switch(config-tcam-feature-acl-subintf-ipv6)# feature acl vlan ip
switch(config-tcam-feature-acl-vlan-ip)# sequence 35
switch(config-tcam-feature-acl-vlan-ip)# key size limit 160
switch(config-tcam-feature-acl-vlan-ip)# key field dscp dst-ip ip-frag ip-protocol l4-dst-port l4-ops-18b l4-src-port src-ip tcp-control ttl
switch(config-tcam-feature-acl-vlan-ip)# action count drop
switch(config-tcam-feature-acl-vlan-ip)# packet ipv4 forwarding routed
switch(config-tcam-feature-acl-vlan-ip)# packet ipv4 mpls ipv4 forwarding mpls decap
switch(config-tcam-feature-acl-vlan-ip)# packet ipv4 mpls ipv6 forwarding mpls decap
switch(config-tcam-feature-acl-vlan-ip)# packet ipv4 non-VXLAN forwarding routed decap
switch(config-tcam-feature-acl-vlan-ip)# packet ipv4 VXLAN eth ipv4 forwarding routed decap
switch(config-tcam-feature-acl-vlan-ip)# feature acl vlan ipv6
switch(config-tcam-feature-acl-vlan-ipv6)# sequence 10
switch(config-tcam-feature-acl-vlan-ipv6)# key field dst-ipv6 ipv6-next-header l4-dst-port l4-src-port src-ipv6-high src-ipv6-low tcp-control
switch(config-tcam-feature-acl-vlan-ipv6)# action count drop
switch(config-tcam-feature-acl-vlan-ipv6)# packet ipv6 forwarding routed
switch(config-tcam-feature-acl-vlan-ipv6)# packet ipv6 ipv6 forwarding routed decap
switch(config-tcam-feature-acl-vlan-ipv6)# feature acl vlan ipv6 egress
switch(config-tcam-feature-acl-vlan-ipv6-egress)# sequence 20
switch(config-tcam-feature-acl-vlan-ipv6-egress)# key field dst-ipv6 ipv6-next-header ipv6-traffic-class l4-dst-port l4-src-port src-ipv6-high src-ipv6-low tcp-control
switch(config-tcam-feature-acl-vlan-ipv6-egress)# action count drop mirror
switch(config-tcam-feature-acl-vlan-ipv6-egress)# packet ipv6 forwarding bridged
switch(config-tcam-feature-acl-vlan-ipv6-egress)# packet ipv6 forwarding routed
switch(config-tcam-feature-acl-vlan-ipv6-egress)# feature counter lfib
switch(config-tcam-feature-counter-lfib)# sequence 85
switch(config-tcam-feature-counter-lfib)# feature forwarding-destination mpls
switch(config-tcam-feature-forwarding-destination-mpls)# sequence 100
switch(config-tcam-feature-forwarding-destination-mpls)# feature l2-protocol forwarding
switch(config-tcam-feature-forwarding-l2-protocol-forwarding)# sequence 95
switch(config-tcam-feature-forwarding-l2-protocol-forwarding)# key size limit 160
switch(config-tcam-feature-forwarding-l2-protocol-forwarding)# key field dst-mac vlan-tag-format
switch(config-tcam-feature-forwarding-l2-protocol-forwarding)# action mirror redirect-to-cpu set-tc
switch(config-tcam-feature-forwarding-l2-protocol-forwarding)# packet ipv4 forwarding bridged
switch(config-tcam-feature-forwarding-l2-protocol-forwarding)# packet ipv6 forwarding bridged
switch(config-tcam-feature-forwarding-l2-protocol-forwarding)# packet non-ip forwarding bridged
switch(config-tcam-feature-forwarding-l2-protocol-forwarding)# feature mirror ip
switch(config-tcam-feature-mirror-ip)# sequence 80
switch(config-tcam-feature-mirror-ip)# key size limit 160
switch(config-tcam-feature-mirror-ip)# key field dscp dst-ip ip-frag ip-protocol l4-dst-port l4-ops l4-src-port src-ip tcp-control
switch(config-tcam-feature-mirror-ip)# action count mirror set-policer
switch(config-tcam-feature-mirror-ip)# packet ipv4 forwarding bridged
switch(config-tcam-feature-mirror-ip)# packet ipv4 forwarding routed
switch(config-tcam-feature-mirror-ip)# packet ipv4 forwarding routed multicast
switch(config-tcam-feature-mirror-ip)# packet ipv4 non-VXLAN forwarding routed decap
switch(config-tcam-feature-mirror-ip)# feature mpls
switch(config-tcam-feature-mpls)# sequence 5
switch(config-tcam-feature-mpls)# key size limit 160
switch(config-tcam-feature-mpls)# action drop redirect set-ecn
switch(config-tcam-feature-mpls)# packet ipv4 mpls ipv4 forwarding mpls decap
switch(config-tcam-feature-mpls)# packet ipv4 mpls ipv6 forwarding mpls decap
switch(config-tcam-feature-mpls)# packet mpls ipv4 forwarding mpls
switch(config-tcam-feature-mpls)# packet mpls ipv6 forwarding mpls
switch(config-tcam-feature-mpls)# packet mpls non-ip forwarding mpls
switch(config-tcam-feature-mpls)# feature mpls pop ingress
switch(config-tcam-feature-mpls-pop-ingress)# sequence 90
switch(config-tcam-feature-mpls-pop-ingress)# feature pbr ip
switch(config-tcam-feature-pbr-ip)# sequence 60
switch(config-tcam-feature-pbr-ip)# key size limit 160
switch(config-tcam-feature-pbr-ip)# key field dscp dst-ip ip-frag ip-protocol l4-dst-port l4-ops-18b l4-src-port src-ip tcp-control
switch(config-tcam-feature-pbr-ip)# action count redirect
switch(config-tcam-feature-pbr-ip)# packet ipv4 forwarding routed
switch(config-tcam-feature-pbr-ip)# packet ipv4 mpls ipv4 forwarding mpls decap
switch(config-tcam-feature-pbr-ip)# packet ipv4 mpls ipv6 forwarding mpls decap
switch(config-tcam-feature-pbr-ip)# packet ipv4 non-VXLAN forwarding routed decap
switch(config-tcam-feature-pbr-ip)# packet ipv4 VXLAN forwarding bridged decap
switch(config-tcam-feature-pbr-ip)# feature pbr ipv6
switch(config-tcam-feature-pbr-ipv6)# sequence 30
switch(config-tcam-feature-pbr-ipv6)# key field dst-ipv6 ipv6-next-header l4-dst-port l4-src-port src-ipv6-high src-ipv6-low tcp-control
switch(config-tcam-feature-pbr-ipv6)# action count redirect
switch(config-tcam-feature-pbr-ipv6)# packet ipv6 forwarding routed
switch(config-tcam-feature-pbr-ipv6)# feature pbr mpls
switch(config-tcam-feature-pbr-mpls)# sequence 65
switch(config-tcam-feature-pbr-mpls)# key size limit 160
switch(config-tcam-feature-pbr-mpls)# key field mpls-inner-ip-tos
switch(config-tcam-feature-pbr-mpls)# action count drop redirect
switch(config-tcam-feature-pbr-mpls)# packet mpls ipv4 forwarding mpls
switch(config-tcam-feature-pbr-mpls)# packet mpls ipv6 forwarding mpls
switch(config-tcam-feature-pbr-mpls)# packet mpls non-ip forwarding mpls
switch(config-tcam-feature-pbr-mpls)# feature qos ip
switch(config-tcam-feature-qos-ip)# sequence 75
switch(config-tcam-feature-qos-ip)# key size limit 160
switch(config-tcam-feature-qos-ip)# key field dscp dst-ip ip-frag ip-protocol l4-dst-port l4-ops l4-src-port src-ip tcp-control
switch(config-tcam-feature-qos-ip)# action set-dscp set-policer set-tc
switch(config-tcam-feature-qos-ip)# packet ipv4 forwarding routed
switch(config-tcam-feature-qos-ip)# packet ipv4 forwarding routed multicast
switch(config-tcam-feature-qos-ip)# packet ipv4 mpls ipv4 forwarding mpls decap
switch(config-tcam-feature-qos-ip)# packet ipv4 mpls ipv6 forwarding mpls decap
switch(config-tcam-feature-qos-ip)# packet ipv4 non-VXLAN forwarding routed decap
switch(config-tcam-feature-qos-ip)# feature qos ipv6
switch(config-tcam-feature-qos-ipv6)# sequence 70
switch(config-tcam-feature-qos-ipv6)# key field dst-ipv6 ipv6-next-header ipv6-traffic-class l4-dst-port l4-src-port src-ipv6-high src-ipv6-low
switch(config-tcam-feature-qos-ipv6)# action set-dscp set-policer set-tc
switch(config-tcam-feature-qos-ipv6)# packet ipv6 forwarding routed
switch(config-tcam-feature-qos-ipv6)# feature tunnel VXLAN
switch(config-tcam-feature-tunnel-VXLAN)# sequence 50
switch(config-tcam-feature-tunnel-VXLAN)# key size limit 160
switch(config-tcam-feature-tunnel-VXLAN)# packet ipv4 VXLAN eth ipv4 forwarding routed decap
switch(config-tcam-feature-tunnel-VXLAN)# packet ipv4 VXLAN forwarding bridged decap

Once l2protocolfwd or l2protocolfwd-bfd-rfc-7130 tcam profile is created, the profile needs to be applied to the switch using the following command under config mode:
switch(config)# hardware tcam
switch(config-tcam)# system profile l2protocolfwd

Consumption of TCAM

The following table describes how TCAM is consumed when the same L2 Protocol Forwarding profile is applied:

Table 1. TCAM Consumption
Level of application Type-1 platforms Type-2 platforms
Front panel ports Separate TCAM entries for each port Same set of TCAM entries for ports on the same fap and core
Subinterfaces Same set of TCAM entries for subinterfaces on the same fap Same set of TCAM entries for subinterfaces on the same fap and core

L2 Protocol Forwarding Considerations

  1. A maximum of 31 distinct L2 Protocol Forwarding profiles apply across multiple subinterfaces on the same FAP.
  2. A maximum of 31 distinct L2 Protocol Forwarding profiles apply across multiple subinterfaces, and front panel ports on the same FAP on Type-2 platforms.
  3. EOS does not support subinterfaces on Type-1 platforms if the TCAM profile has any of the following features:
    • feature pbr subintf ip
    • feature pbr subintf ipv6
    • feature pbr subintf mpls

Displaying L2 Protocol Forwarding

The show l2-protocol forwarding interface command displays the L2 protocol forwarding profile configuration corresponding to the interface or subinterface.
switch(config)# show l2-protocol forwarding interface

Interface     Profile
------------- -------
Ethernet1/1   abc
Ethernet2/1.1 def
 

switch> show l2-protocol forwarding interface Ethernet1/1


Interface   Profile   
----------- --------
Ethernet1/1 abc

The following show commands display all packet forwarding behavior on an interface or a subinterface:
switch(config)# show l2-protocol forwarding interface detail                                                                                                                                                                                      
Tagging Types: T: tagged U: untagged
Actions: F: forward
                      BFD RFC-7130 E-LMI ISIS LACP LLDP MACSEC PAUSE STP
Interface     Profile   T     U    T  U  T U  T U  T U  T   U  T  U  T U
------------- ------- ----- ------ -- -- - -- - -- - -- -- --- -- -- - -                                                                                                                                             
Ethernet1/1   abc       -     -    -  -  F  F - -  - -  F   -  -  F  - -
Ethernet2/2.1 def       -     -    -  -  - -  - -  - -  -   -  -  -  - -

switch> show l2-protocol forwarding interface Ethernet1/1 detail
Tagging Types: T: tagged U: untagged                                                                                                                                                                        
Actions: F: forward                                                                                                                                                                                         
                      BFD RFC-7130 E-LMI ISIS LACP LLDP MACSEC PAUSE STP
Interface     Profile   T     U    T  U  T U  T U  T U  T   U  T  U  T U
------------- ------- ----- ------ -- -- - -- - -- - -- -- --- -- -- - -                                                                                                                                                             
Ethernet1/1   abc       -     -    -  -  F F  - -  - -  F   -  -  F  - -

switch> show l2-protocol forwarding interface Ethernet2/2.1 detail
Tagging Types: T: tagged U: untagged                                                                                                                                                                        
Actions: F: forward                                                                                                                                                                                         
                      BFD RFC-7130 E-LMI ISIS LACP LLDP MACSEC PAUSE STP
Interface     Profile   T     U    T  U  T U  T U  T U  T   U  T  U  T U
------------- ------- ----- ------ -- -- - -- - -- - -- -- --- -- -- - -                                                                                                                                                             
Ethernet2/2.1 def       -     -    -  -  - -  - -  - -  -   -  -  -  - -

..

EOS 4.36.2F User Manual - IP Address Locking

IP Address Locking

EOS provides IP Address Locking capabilities when configured on an Ethernet Layer 2 port.

After enabling IP Address Locking on a Layer 2 (L2) port, the port only permits IP and ARP packets with authorized IP source addresses. Configure IP Address Locking in one of two modes:

  • IPv4
  • IPv6

IP Address Locking prevents a host on a different interface from claiming ownership of an IP address through ARP spoofing. IPv6 Locking extends this behavior to IPv6 packets, including ICMPv6 Neighbor Discovery Router Advertisement and Redirect and DHCP server-to-client packets.

On an IPv4 Locked Port, the ARP protocol performs the following actions on the network:
  • Probing with the IPv4 address 0.0.0.0 as the Sender Protocol Address (SPA).
  • Permit Duplicate Address Detection (DAD).
  • Drop incoming DHCP server response packets to avoid any rogue devices acting as DHCP servers.
  • Permit incoming DHCP client request packets on devices to complete the DHCP handshake and obtain a DHCP lease.

On an IPv6 Locked Port, the ARP protocol performs the following actions on the network:

  • Drop incoming DHCPv6 server response packets.
  • Permit incoming DHCPv6 client request packets.
  • On an incoming ICMPv6 network device, perform the following actions:
    • Drop Router Advertisement packets since only routers should send these packets.
    • Permit Router Solicitation packets.
    • Drop redirect packets as only routers should send these packets.

    Figure 1. IP Address Locking

IP Address Locking determines port authorization for IP addresses by untilizing DHCP LeaseQuery and MAC address. Ensure that DHCP servers used in the network allow LeaseQuery messages.

Alternatively, IP locking can be configured to monitor incoming DHCPACK packets on designated ports to verify IP address authorization. This specific configuration method operates independently and eliminates the need for DHCP LeaseQuery.

This chapter describes IP Address Locking configuration tasks and associated commands.
  • IP Address Locking Configuration
  • IP Address Locking Commands

IP Address Locking Configuration

This section describes IP Locking configuration tasks. Topics in this section include:

  • Preparing a Switch for IP Address Locking
  • Enabling IP Address Locking
  • Disabling IP Address Locking
  • Enabling IP Address Locking on Ports
  • Enabling IP Address Locking on All Ports of a VLAN
  • Blocking IPv4 and ARP Packets
  • Configuring IP Locking Static Leases
  • Configuring IP Address Locking Lease Query Timeout
  • Configuring Locked Address Expiration
  • Enforcing Locked IP Addresses
  • Displaying IP Address Locking Counters
  • Displaying IP Address Locking

Preparing a Switch for IP Address Locking

Before enabling IPv4 Address Locking, you must configure a DHCP Server and a Local Layer 3 interface.

Enabling a DHCP Server for IPv4 Address Locking

Add the DHCP servers used by hosts to acquire leases. IPv4 Address Locking communicates with the DHCP servers to learn the authorized IP addresses on the switch.

Example

The following commands enable DHCP servers with an IPv4 address of 10.1.1.1, and another DHCP server with the IP address, 10.30.1.3:
switch(config-address-locking)# dhcp server ipv4 10.1.1.1
switch(config-address-locking)# dhcp server ipv4 10.30.1.3

Adding a Local Layer 3 Interface

Add a local L3 interface to communicate with the DHCP server. This could be the management interface, a routed interface, or a Switch Virtual Interface (SVI). This interface requires an assigned valid IP address, routable to the configured DHCP server, and can reside in a non-default VRF. The switch packets sent to the DHCP Server use the interface IP address as the source IP address.

Examples

The following commands configure an interface with a valid IP address, 10.10.1.2/16, on VLAN2160:
switch# configure
switch(config)# interface Vlan2160
switch(config-if-Vl2160)# ip address 10.10.1.2/16

The following commands add the interface to the IP Address Locking configuration:
switch# configure 
switch(config)# address locking
switch(config-address-locking)# local-interface Vlan2160

Enabling IP Address Locking

Configure IP Address Locking for either IPv4 or IPv6 addresses, and both types of IP addresses can be enabled for IP Address Locking. IPv6 Address Locking requires a different approach outlined in this section.

Enabling IP Address Locking

Configure IPv4 Address Locking commands in the configuration mode.

Example

Use the following commands to enter IP Address Locking configuration mode and add IPv4 Address Locking:
switch# configure
switch(config)# address locking
switch(config-address-locking)# locked-address ipv4

Enabling IPv6 Address Locking

To enable IPv6 locking, disable the enforcement of IPv6 Address Locking.

Example

Use the following commands to disable IPv6 Address Locking enforcement, and then enable IPv6 for IP Address Locking:
switch# configure
switch(config)# address locking
switch(config-address-locking)# locked-address ipv6 enforcement disabled
switch(config-address-locking)# locked-address ipv6

Disabling IP Address Locking

Disable IP Address Locking using the disabled command in address-locking mode. This turns off the feature and allows a host to use any IP address, authorized or unauthorized, on any port.

Example
switch# configure
switch(config)# address locking
switch(config-address-locking)# disabled

Enabling IP Address Locking on Ports

To enable IPv4 Address Locking on ports connected to clients, IP Address Locking must be enabled in the Interface Configuration Mode. Running this command only enables IPv4 Locking and overrides the previous configuration for the interface.

Example

Use the following commands to enable IP Address Locking for the interface, Ethernet27/1:
switch(config)# interface Ethernet27/1
switch(config-if-Et27/1)# address locking
switch(config-if-Et27/1-address-locking)# address-family ipv4

Use the following commands to enable IPv6 Address Locking on ports connected to clients, use the address-family ipv6 parameter.

Example

To activate IPv6 Address Locking on interface Ethernet53 and port 4, use the following syntax:
switch(config)# interface Ethernet53/4
switch(config-if-Et53/4)# address locking
switch(config-if-Et53/4-address-locking)# address-family ipv6

Enabling IP Address Locking on All Ports of a VLAN

To activate IP Address Locking on all VLAN port members, use the VLAN address locking configuration submode.

Examples

The following commands activate IPv4 Address Locking on VLAN 20:
switch(config)# vlan 20
switch(config-vlan-20)# address locking
switch(config-vlan-20-addr-lock)# address-family ipv4

To exclude a VLAN port member, disable IP Address Locking on that port using the interface configuration submode.

The following commands exclude port 25 on Ethernet2:
switch(config)# interface Ethernet2/25
switch(config-if-Et2/25)# address locking
switch(config-if-Et2/25)# address-family ipv4 disabled

To configure IPv6 Address Locking on all ports, use the same commands, but designate the address-family as ipv6.

The following commands enable IPv6 Address Locking and override the previous configuration for the interface.
switch(config)# interface Ethernet 27/1
switch(config-if-Et27/1)# address locking
switch(config-if-Et27/1-address-locking)# address-family ipv6

To enable IPv6 Address Locking on all members of a port for VLAN 20, use the IPv6 Locking commands in the VLAN address locking configuration sub-mode.
switch(config)# vlan 20
switch(config-vlan-20)# address locking
switch(config-vlan-20-addr-lock)# address-family ipv6

Use the following command to enable both IPv4 and IPv6 Address Locking on a port:
switch(config)# interface Ethernet 27/1
switch(config-if-Et27/1)# address locking
switch(config-if-Et27/1-address-locking)# address-family ipv4 
switch(config-if-Et27/1-address-locking)# address-family ipv6

Blocking IPv4 and ARP Packets

Use the deny ip_address on IPv4 Address Locking ports to block all IPv4 and ARP packets with a specific source IPv4 address. The port denies the packet and affects only IPv4 enforcement modes. This action deauthorizes the addresses on the port and can be configured with multiple IPv4 addresses. You must configure this on an interface already configured with IPv4 Address Locking.

Note: Use only IPv4 addresses with this configuration.

Example
switch(config)# interface Ethernet27/1
switch(config-if-Et27/1)# address locking
switch(config-if-Et27/1-addr-lock)# deny 172.21.16.25

Configuring IP Locking Static Leases

The lease mac command within address locking configuration mode installs a lease into hardware for the configured IP address on the interface with the configured associated MAC address. If the MAC address does not appear in the MAC table or the MAC address on an interface without a configured IP Locking feature, the lease does not install until the interface adds the MAC address to an interface configured with IP Locking.

Note: IP Locking removes from the switch any lease from the DHCP server that matches either the same IP or MAC as a statically configured lease.

Example

Use the following commands to configure an IP address, 172.21.13.11, and MAC Address, a0:ce:c8:b1:78:d3, with a static lease:
switch# configure
switch(config)# address locking
switch(config-address-locking)# lease 172.21.13.11 mac a0:ce:c8:b1:78:d3

Clearing Leases

The clear address locking lease command removes the lease from hardware. The command removes lease bindings at different granularities.
  • The clear address locking lease ipv4 V4ADDR command removes a single lease associated with an IPv4 address.

  • The clear address locking lease ipv6 V6ADDR command removes a single lease associated with an IPv6 address.

  • The clear address locking lease intf ethernet slot command removes all leases associated with the specified interface.

  • The clear address locking lease all removes all leases on the switch.

Configuring IP Address Locking Lease Query Timeout

The command, lease query retry interval interval timeout minutes configures sending lease queries at specific retry intervals. The no lease query retry command removes the retry interval and timeout configuration.

Example

Use the following commands to configure an interval, 5, and timeout of 100 minutes:
switch(config)# address locking
switch(config-address-locking)# lease query retry interval 5 timeout 100

IP Address Locking sends out DHCP LeaseQuery requests to all configured DHCP servers in the following cases:
  • When an IP Address Locking enabled port learns a MAC address, IP Address Locking sends out a LeaseQuery request for the learned MAC address. After learning the MAC address, IP Address Locking waits one (1) second for the DHCP.

  • When an IP Address Locking enabled port removes a MAC address after enabling the locked-address expiration mac disabled feature, IP Address Locking sends a LeaseQuery request for the removed MAC address.

  • When the IP Address Locking agent restarts, EOS sends LeaseQuery requests for all MAC addresses on all IP Address Locking interfaces and for all MAC addresses in the IP Address Locking table.

  • When you add a new DHCP configuration, EOS sends new LeaseQuery requests to the new DHCP for all MAC addresses learned on all IP Address Locking interfaces and for all MAC addresses in the IP Address Locking leases table.

  • When you configure an interface with IP Address Locking, IP Address Locking sends LeaseQuery requests for all MAC addresses learned on that interface.

  • When an IP or ARP packet with a source IP address that does not exist in the IP Address Locking table arrives at an interface, EOS sends LeaseQuery requests for all MAC addresses on that interface. If the host already has a valid DHCP lease and the DHCP server sends a LeaseActive reply, IP Address Locking sends at least one (1) request every 50 seconds for that host as a result of dropped ARP or IP packets.

  • When the DHCP Lease reaches the last known expiration time, IP Address Locking sends out a LeaseQuery request for the MAC address associated with the lease. Note that this may be different from the actual expiration time. For example, if the host renewed the lease before the actual lease expires and received no LeaseQuery requests sent for the MAC address, IP Address Locking sends out a query at the original expiration time.

  • After a LeaseActive reply receives a matching MAC address of a previously received lease, IP Address Locking sends out a LeaseQuery request for the previous IP address associated with the updated MAC address.

  • After a LeaseActive reply receives a matching MAC address of a previously received lease, IP Address Locking sends out a LeaseQuery request for the previous MAC address associated with the updated IP address.

When IP Address Locking sends out a LeaseQuery request, and does not receive a LeaseActive reply, IP Address Locking sends six (6) additional retries over 64 seconds using an exponential backoff algorithm. A 0-25% delay sending requests which may take up to 80 seconds to send out all seven (7) requests.

Every LeaseQuery request includes a transaction ID. After sending the last request, and for an additional 10 seconds, IP Address Locking accepts any LeaseActive reply matching the transaction ID and then queries for the MAC address of a sent LeaseQuery request.

If a LeaseActive reply contains multiple IP addresses, IP Address Locking begins a query process for the additional IP addresses using the same retry mechanisms. However, if you configure the LeaseQuery retry interval and timeout but do not receive LeaseActive replies, IP Address Locking sends continuous lease query requests at the configured retry interval until reaching the specified timeout period.

Note: Alternatively, IP Locking can be configured to verify IP authorization by monitoring incoming DHCPACK packets on specified ports. This method eliminates the need for DHCP LeaseQuery by operating independently. However, it is only applicable when IP Address Locking uses DHCP LeaseQuery and MAC address learning to determine port authorization for IP addresses.

Configuring Locked Address Expiration

The IP addresses remain authorized and installed after the corresponding MAC addresses age out. IP Address Locking, by default, removes authorized leases after the corresponding MAC addresses age out. The locked-address expiration mac disabled command configures IP Address Locking to keep leases installed, after the corresponding MAC addresses age out.

Example

The following commands keep leases installed on the IP address:
switch# configure
switch(config)# address locking
switch(config-address-locking)# locked-address expiration mac disabled

Configuring IP Locking DHCP Server Interface

Address-locking mode can be enabled using the command dhcp server interface <INTF>. In this mode, the IP Locking agent monitors the server interface for DHCP ACK packets and tracks release packets on protected interfaces.

Configuration Priorities and DHCP Lease Management

When both a local interface and a DHCP server interface are specified, the system prioritizes the local-interface <INTF> setting. In this scenario, IP Locking disregards the DHCP server interface and utilizes the local interface for outgoing DHCP LeaseQuery messages.

Furthermore, specifying DHCP server IP addresses within the dhcp server interface <INTF> configuration is optional. If specific IP addresses are provided, IP Locking strictly learns leases from those identified servers. However, if no addresses are defined, the agent will learn leases from all DHCP server traffic detected on the configured interfaces.

Example

Use the following command to configure the dhcp server interface Ethernet 28/1:

switch#config
switch(config)#address locking
switch(config-address-locking)#dhcp server interface Ethernet28/1

Enforcing Locked IP Addresses

The locked-address ipv4 enforcement disabled command disables address filtering for all ports with IPv4 Address Locking enabled. This permits IPv4 packets while still keeping all other drop rules. When configured, IP Address Locking does not drop IP or ARP packets, and does not send out lease queries to configured DHCP servers.

Examples

The following commands disable IPv4 Address Locking globally:
switch# configure
switch(config)# address locking
switch(config-address-locking)# locked-address ipv4 enforcement disabled

The following commands configure locked address enforcement for an interface:
switch(config)# interface Ethernet27/1
switch(config-if-Et27/1)# address locking
switch(config-if-Et27/1-address-locking)# locked-address ipv4 enforcement disabled 

The following commands configure locked address enforcement for a VLAN:
switch(config)# vlan 20
switch(config-vlan-20)# address locking
switch(config-vlan-20-addr-lock)# locked-address ipv4 enforcement disabled

The locked-address ipv6 enforcement disabled command disables address filtering for all ports with IPv6 Locking enabled. This permits IPv6 packets while still keeping all other drop rules.
switch# configure
switch(config)# address locking
switch(config-address-locking)# locked-address ipv6 enforcement disabled

To configure locked address enforcement for an interface, use the following commands:
switch(config)# interface Ethernet27/1
switch(config-if-Et27/1)# address locking
switch(config-if-Et27/1-address-locking)# locked-address ipv6 enforcement disabled

To configure locked address enforcement for VLAN 20, use the following commands:
switch(config)# vlan 20
switch(config-vlan-20)# address locking
switch(config-vlan-20-addr-lock)# locked-address ipv6 enforcement disabled

Displaying IP Address Locking Counters

The show address locking counters command displays DHCP lease query messages sent, received, and dropped. The output provides two sets of counters:
  • The number of packets sent and received from each DHCP server.
  • The number of packets sent and received for each locked interface.

The output displays separate counters for the different types of messages communicated between the switch and the DHCP server.

Example
switch# show address locking counters
Lease Active Lease Unknown Lease Unassigned    	 
DHCP Server Query  Rcvd   Drop   Rcvd   Drop Rcvd     Drop    Unknown
----------- ----- ----- ------ ------ ------ -------- ------- -------
80.80.80.80 32860  8002 34     8001   32     13423     134    3234
            
            
Interface Query Lease Active Lease Unknown Lease Unassigned
--------- ----- ------------ ------------- ----------------
Ethernet2  1747 1234         189           324

The clear address locking counters command resets all the counters associated with IP Locking to zero.

Displaying IP Address Locking

Use the show address locking command to display the status of IPv4 and IPv6 locking.

Example
switch# show address locking
IP Locking is active
Interface        IPv4	                 IPv6
--------------- -------------------   ---------------------------
Ethernet27/1     yes 	                 no (not configured) 
Ethernet31/1     no (not configured)   no (not a layer 2 interface)

The show address locking command also displays interfaces with the reason IP Address Locking may not be enabled. For an interface without IP Address Locking enabled, the following priority (highest at top) imposes on the output:
  • Unconfigured.
  • Not a Layer 2 interface.
  • No local interface configured.
  • No DHCP server configured.

The show address locking table ipv4 command displays all the DHCP leases that IP Address Locking knows about, current status of installed leases, and the authorized interfaces for these IP addresses.

Example
switch# show address locking table ipv4
IP Address     MAC Address      Interface  Installed    Expiration Time
-------------- ---------------- ---------- ------------ --------------- 
10.30.4.4      ba76.a467.7ff8   Et27/1     installed     in 0:01:57 

IP Address Locking Commands

IP Address Locking Configuration Commands

  • address locking deny
  • address locking dhcp
  • address-locking disable
  • address locking lease query
  • address locking local-interface

IP Address Locking Clear Commands
  • clear address locking lease

IPv4 Static Lease Commands
  • address locking lease

IP Address Locking Address Expiration Commands
  • locked-address expiration mac disabled

IP Address Locking Address Enforcement Commands
  • locked-address ipv4 enforcement disabled
  • locked-address ipv6 enforcement disabled

IP Address Locking Show Commands
  • show address locking
  • show address locking counters
  • show address locking table ipv4

address locking deny

Use the address locking command to block IPv4 and ARP packets with specific IPv4 addresses on the switch. You must perform this command from an interface configured for IP Address Locking on the switch.

Command Mode

Interface Configuration

Address Locking Configuration

Command Syntax

address locking deny ip_address

Parameter

ip_address - Specify the IPv4 address to block packets.

Example

Use the following command to deny IPv4 and ARP packets from IPv4 address, 172.16.21.131, from Ethernet interface, Ethernet53/4:

switch(config)# interface Ethernet53/4
switch(config-if-Et53/4)# address locking 
switch(config-address-locking)# deny 172.16.21.131

address locking dhcp

Use the address locking command to enter address locking mode and then dhcp to configure the DHCP server.

Command Mode

Address Locking Configuration

Command Syntax

address locking dhcp server ipv4 ip_address

Parameters

  • dhcp server - configure a DHCP server to assign IP addresses and assign static addresses using a MAC address.
    • ipv4 ip_address - Specify the IP address for the DHCP server.
    • mac mac_address - Specify the MAC address of the DHCP server.

Example

To configure a DHCP server with an IPv4 address. 172.13.21.3, use the following command:

switch(config)# address locking 
switch(config-address-locking)# dhcp server ipv4 172.13.21.3

address-locking disable

The address-locking disable command disables IP Address Locking on a switch.

Command Mode

Address Locking Configuration

Command Syntax

address-locking disable

Example

Use the address-locking command to enter address locking mode and then disable to disable the configuration.
switch(config)# address-locking
switch(config-address-locking)# disable

address locking lease

Use the address locking command to enter the IPv4 and IPv6 locking mode and then on the switch, use the lease to configure DHCP leases.

The lease mac command within the address locking configuration mode installs a lease onto hardware for the configured IP address on the interface with the associated configured MAC address. If the MAC address does not exist in the MAC table or the MAC address appears on an interface with an IP Locking configuration feature, the lease does not install until you add the MAC address to an interface configured with IP Locking.

Command Mode

Address Locking Configuration

Command Syntax

lease ip_address mac ip_address

Parameters

  • lease
    • V4ADDR - Specify the IPv4 address to assign the lease.
    • mac MACADDR - Configure the MAC address for a static lease.

  • no lease V4ADDR mac MACADDR - Removes the retry and timeout configuration.
  • default lease V4ADDR mac MACADDR - Configures the lease with the default IPv4 address and MAC address.

Example

To configure a lease with the IPv4 address, 1.1.1.1, and the MAC address, a.b.c, use the following command:

switch(config)# address locking 
switch(config-address-locking)# lease 1.1.1.1 mac a.b.c

address locking lease query

Use the address locking command to enter the IPv4 and IPv6 locking mode and then use the lease query retry interval to configure DHCP leases.

The no lease query retry command removes the retry interval and timeout configuration.

Command Mode

Address Locking Configuration

Command Syntax

lease query retry interval interval-time

Parameters

interval interval-time - Configure the query retry interval and timeout. The interval can be from 1 - 4294967295 seconds.

Example

To configure a lease with the retry interval, 5 seconds, and a timeout, 100, use the following command:
switch(config)# address locking
switch(config-address-locking)# lease query retry interval 5 timeout 100

address locking local-interface

Use the address locking local-interface command to configure a local interface for IPv4 and IPv6 locking IP addresses on the switch.

Command Mode

Address Locking Configuration

Command Syntax

address locking local-interface [Ethernet | Loopback | Management | Port Channel | Tunnel | Vlan]

Parameters

  • local-interface
    • Ethernet slot_number - Configure an Ethernet subinterface for IPv4 and IPv6 locking IP addresses on the switch.
    • Loopback loopback_interface_number - Configure a Loopback interface for IPv4 and IPv6 locking IP addresses on the switch.
    • Management management_interface slot_number - for IPv4 and IPv6 locking IP addresses on the switch.
    • Port-Channel lag_group port_channel_subinterface - Configure a Port-Channel interface for IPv4 and IPv6 locking IP addresses on the switch.
    • Tunnel tunnel_interface - Configure a Tunnel interface for IPv4 and IPv6 locking IP addresses on the switch.
    • Vlan vlan_interface_number - Configure a VLAN interface for IPv4 and IPv6 locking IP addresses on the switch.

Example

To configure an Ethernet interface, Ethernet53/4, use the following command:

switch(config)# address locking
switch(config-address-locking)# local-interface Ethernet53/4

clear address locking lease

Use the clear address locking lease command to remove lease bindings at different granularities.

  • The clear address locking lease ipv4 V4ADDR command removes a single lease associated with an IPv4 address.

  • The clear address locking lease ipv6 V6ADDR command removes a single lease associated with an IPv6 address.

  • The clear address locking lease intf ethernet slot command removes all leases associated with the specified interface.

  • The clear address locking lease all command remove all leases on the switch.

Command Mode

Address Locking mode

Command Syntax

clear address locking lease [ all | interface [ ethernet slot ] | ipv4 V4ADDR | ipv6 V6ADDR ]

Parameters
  • all- View the entire lease table.
  • interface- interface to clear the lease.
    • ethernet slot - Ethernet interface slot number.

  • ipv4 V4ADDR- IPv4 address of the lease
  • ipv6 V6ADDR - IPv6 address of the lease

Example

Use the following command to clear all IP Address Locking leases from the switch:
switch(config-address-locking)# clear address locking lease all

dhcp server interface

Use the dhcp server interface command to monitor the server interface for DHCP ACK packets and handle release packets on the designated locked interfaces by the IP Locking agent. You must perform this command from an interface configured for IP Address Locking on the switch.
Note: That when both "dhcp server interface <INTF>" and "local-interface <INTF>" are active, IP Locking prioritizes the local interface for transmitting DHCP LeaseQuery packets and disregards the "dhcp server interface <INTF>" setting.

Command Mode

Address Locking Configuration

Command Syntax

dhcp server interface <INTF>

Parameter

<INTF> - Specify the DHCP server interface.

Example

Use the following command to configure the dhcp server interface Ethernet 28/1:

switch#conf
switch(config)#address locking
switch(config-address-locking)#dhcp server interface Ethernet28/1

locked-address expiration mac disabled

IP Address Locking, by default, removes authorization from leases after the corresponding MAC addresses age out. Use the locked-address expiration mac disabled command to configure IP Address Locking to keep the leases installed, even after the corresponding MAC addresses age out.

Command Mode

Address Locking Configuration

Command Syntax

locked-address expiration mac disabled

no locked-address expiration mac disabled

default locked-address expiration mac disabled

Parameters
  • expiration - Configures expiration mode for locked addresses.
  • mac - Configures deauthorizing locked addresses when MAC addresses age out.
  • disabled - Disables deauthorizing locked address when MAC addresses age out.

Example

Use this command to disable locked address expiration:
switch# configure
switch(config)# address locking
switch(config-address-locking)# locked-address expiration mac disabled

locked-address ipv4 enforcement disabled

The locked-address ipv4 enforcement disabled command disables address filtering for all ports with IPv4 Locking enabled. This permits IPv4 packets while still keeping all other drop rules.

Command Mode

Address Locking Configuration

Command Syntax

locked-address ipv4 enforcement disabled

no locked-address ipv4 enforcement disabled

default locked-address ipv4 enforcement disabled

Parameters
  • ipv4 - Configure the IP address family.
  • enforcement - Configure enforcement for locked addresses.
  • disabled - Disable enforcement for locked addresses.

Example

Use the following command to disable locking address enforcement for IPv4 addresses:
switch# configure
switch(config)# address locking
switch(config-address-locking)# locked-address ipv4 enforcement disabled

locked-address ipv6 enforcement disabled

The locked-address ipv6 enforcement disabled command disables address filtering for all ports with IPv6 Locking enabled. This permits IPv6 packets while retaining all other drop rules.

Command Mode

Address Locking Configuration

Command Syntax

locked-address IPv6 enforcement disabled

no locked-address IPv6 enforcement disabled

default locked-address IPv6 enforcement disabled

Parameters
  • ipv6 - IPv6 address configuration.
  • enforcement - Configure enforcement for locked addresses.
  • disabled - Disable enforcement for locked addresses.

Example

Use the following command to disable locking address enforcement for IPv6 addresses:
switch# configure
switch(config)# address locking
switch(config-address-locking)# locked-address ipv6 enforcement disabled

show address locking

Use the show address locking command to display the status of IP and IPv6 locking.

The show address locking command also displays the reason as to why IP Locking is not enabled for an interface. For an interface without IP Locking enabled, the following priority (highest at top) apply to the output:
  • Interface not configured.
  • Interface is not a Layer 2 interface.
  • No local interface configured.
  • No DHCP server configured.

Command Mode

EXEC

Command Syntax

show address locking

Example

To display information about IP locking, use the show address locking command:

switch# show address locking
         
IP Locking is active
Interface        IPv4	                 IPv6
--------------- -------------------   ---------------------------
Ethernet27/1     yes 	                 no (not configured) 
Ethernet31/1     no (not configured)    no (not a layer 2 interface)

show address locking counters

The show address locking counters command displays DHCP lease query messages sent, received, and dropped. Two sets of counters display in the output:
  • Number of packets sent and received from each DHCP server.
  • Number of packets sent and received for each locked interface.
IP Locking uses separate counters for different kinds of messages communicated between the switch and the DHCP server.

Command Mode

EXEC

Command Syntax

show address locking counters

Related Commands

The clear address locking counters command resets all the counters associated with IP Locking to zero.

Example

The following command displays IP Address Locking Counters:

switch# show address locking counters
Lease Active Lease Unknown Lease Unassigned    	 
DHCP Server Query  Rcvd   Drop   Rcvd   Drop Rcvd     Drop    Unknown
----------- ----- ----- ------ ------ ------ -------- ------- -------
80.80.80.80 32860  8002 34     8001   32     13423     134    3234
            
            
Interface Query Lease Active Lease Unknown Lease Unassigned
--------- ----- ------------ ------------- ----------------
Ethernet2  1747 1234         189           324

Add the detail parameter to display additional details about counters:

switch# show address locking counters detail
Action				                    Count
--------------------------------            --------
DHCP from client to server PERMIT                  0
DHCP from server DROP                              0
ARP (0.0.0.0) PERMIT                               3
DHCP6 to client DROP                               2                 
DHCP6 to server PERMIT                             2  
NDP Router Solicitation PERMIT                     1
NDP Router Advertisement DROP                      1
NDP Router Redirect DROP                           0
DHCP from server on VLAN DROP                      2                 
DHCP from client to server on VLAN PERMIT          2
ARP (0.0.0.0) on VLAN PERMIT                       1     
DHCP6 to client on VLAN DROP                       2                 
DHCP6 to server on VLAN PERMIT                     2     
NDP Router Solicitation on VLAN PERMIT             2    
NDP Router Advertisement on VLAN DROP              1    
NDP Router Redirect on VLAN DROP                   2

Interface    Action                   IP       MAC               Count
-----------  -----------------------  -------  ----------------  -----
Ethernet46   unknown ARP on VLAN DROP any      any                   5
Ethernet46   unknown IP on VLAN DROP  any      any                   5
Ethernet46   unknown ARP DROP         any      any                   0
Ethernet46   unknown IP DROP          any      any                   0
Ethernet49/1 ARP DROP                 10.0.0.1 any                   0
Ethernet49/1 IP DROP                  10.0.0.1 any                   5
Ethernet49/1 ARP PERMIT               10.0.0.2 c4:01:32:58:00:00     0
Ethernet49/1 IP PERMIT                10.0.0.2 c4:01:32:58:00:00     0

Add the ipv4 or ipv6 parameter to display only information for IPv4 or IPv6 counters:

switch# show address locking counters detail ipv4
Action				                    Count
--------------------------------            --------
DHCP from client to server PERMIT                  0
DHCP from server DROP                              0
ARP (0.0.0.0) PERMIT                               3
DHCP from server on VLAN DROP                      2                 
DHCP from client to server on VLAN PERMIT          2
ARP (0.0.0.0) on VLAN PERMIT                       1

Interface    Action                   IP       MAC               Count
------------ ------------------------ -------- ----------------- -----
Ethernet46   unknown ARP on VLAN DROP any      any                   5
Ethernet46   unknown IP on VLAN DROP  any      any                   5
Ethernet46   unknown ARP DROP         any      any                   0
Ethernet46   unknown IP DROP          any      any                   0
Ethernet49/1 ARP DROP                 10.0.0.1 any                   0
Ethernet49/1 IP DROP                  10.0.0.1 any                   5
Ethernet49/1 ARP PERMIT               10.0.0.2 c4:01:32:58:00:00     0
Ethernet49/1 IP PERMIT                10.0.0.2 c4:01:32:58:00:00     0

switch# show address locking counters detail ipv6
Action				                    Count
--------------------------------            --------
DHCP6 to client DROP                               2                 
DHCP6 to server PERMIT                             2  
NDP Router Solicitation PERMIT                     1
NDP Router Advertisement DROP                      1
NDP Router Redirect DROP                           0
DHCP6 to client on VLAN DROP                       2                 
DHCP6 to server on VLAN PERMIT                     2     
NDP Router Solicitation on VLAN PERMIT             2    
NDP Router Advertisement on VLAN DROP              1    
NDP Router Redirect on VLAN DROP                   2

Add the interface parameter to display counters for a specific interface, Et49/1:

switch# show address locking counters detail ipv4 interface Et49/1
Interface    Action                   IP       MAC               Count
------------ ------------------------ -------- ----------------- -----
Ethernet49/1 ARP DROP                 10.0.0.1 any                   0
Ethernet49/1 IP DROP                  10.0.0.1 any                   5
Ethernet49/1 ARP PERMIT               10.0.0.2 c4:01:32:58:00:00     0
Ethernet49/1 IP PERMIT                10.0.0.2 c4:01:32:58:00:00     0        

show address locking table ipv4

Use the show address locking table ipv4 command to display all DHCP leases with IP Locking, and the interfaces with authorized the IP addresses.

Command Mode

EXEC

Command Syntax

show address locking table ipv4 [ dynamic [ installed | [ interface Ethernet slot ] | installed | interface [ Ethernet [ slot ] | static [ installed | interface [ Ethernet slot ]]]

Parameters
  • dynamic - Display the dynamic leases.
    • installed-Display the leases installed on the hardware.
    • interface - Display the leases on a specified interface.

  • installed - Display installed leases.
  • interface - Display the leases on a specified interface.
    • Ethernet slot Specified Ethernet sub-interface.

  • static - Display static leases.
    • installed - Display the leases on the hardware.
    • interface - Display the leases on a specified interface.
      • Ethernetslot Specified Ethernet sub-interface.

Example
switch# show address locking table ipv4
IP Address     MAC Address      Interface  Installed    Expiration Time
-------------- ---------------- ---------- ------------ --------------- 
AC 10.30.4.4   ba76.a467.7ff8   Et27/1     installed     in 0:01:57 

  IP Address       Action
---------------   --------
10.30.4.4         permit
..

EOS 4.36.2F User Manual - DCBX and Flow Control

DCBX and Flow Control

This section describes Data Center Bridging Capability Exchange (DCBX) configuration tasks. Topics in this section include:
  • Introduction
  • Overview
  • DCBX Configuration and Verification
  • Configuring Priority-Flow-Control (PFC)
  • Configuring PFC Watchdog
  • DCBX and Flow Control Commands

Introduction

EOS implements Link Layer Discovery Protocol (LLDP) and the Data Center Bridging Capability Exchange (DCBX) protocol to help automate the configuration of Data Center Bridging (DCB) parameters, including the Priority-Based Flow Control (PFC) standard, which allows an end-to-end flow-control feature.

This feature enables a switch to recognize when it is connected to an iSCSI device and automatically configure the switch link parameters (such as priority flow control) to provide optimal support for that device. DCBX can be used to prioritize the handling of iSCSI traffic to help ensure that packets are not dropped or delayed. DCBX is off by default.

Overview

Data Center Bridging Capability Exchange (DCBX)

DCBX works with LLDP to allow switches to exchange information about their Data Center Bridging (DCB) capabilities and configuration and automatically negotiate common Priority-Based Flow Control (PFC) parameters.

Data is exchanged in Type-Length-Value (TLV) format. For DCBX to function on an interface LLDP must be enabled on that interface as well.

Priority-Based Flow Control (PFC)

Priority-Based Flow Control (PFC) uses a new control packet defined in IEEE 802.1Qbb and is not compatible with 802.3x Flow Control (FC). An interface that is configured for PFC will be disabled for FC. When PFC is disabled on an interface, the FC configuration for the interface becomes active. Any FC frames received on a PFC configured interface are ignored.

Each priority is configured as either drop or no-drop. If a priority that is designated as no-drop is congested, the priority is paused. Drop priorities do not participate in pause.

When PFC is disabled, the interface defaults to the IEEE 802.3x flow control setting for the interface. PFC is disabled by default.

PFC Watchdog

The PFC watchdog identifies the egress queues that are unable to transmit packets for a long time due to receiving continuous PFC pause frames. On identifying such stuck tx-queue PFC watchdog error-disables the respective port with a error-disable reason of stuck-queue. When there is an error reported on a port the traffic is re-routed through a different port to the destination.

The PFC watchdog supports the following PFC watchdog configurations:
  • PFC watchdog forced recovery of queues
  • PFC watchdog polling interval configuration
  • PFC Watchdog non-disruptive priorities configuration
  • Displaying stuck queue and recovery counters

DCBX Configuration and Verification

Set the Priority Rank to the Traffic Class

The dcbx application priority command assigns a priority rank to the specified traffic class in the application priority table. This table is transmitted on each DCBX-enabled interface.

Examples
  • These commands tell the DCBX peer that iSCSI frames (TCP ports 860 and 3260) should be assigned the given priority of 5.
    switch(config)# dcbx application tcp-sctp 860 priority 5
    switch(config)# dcbx application tcp-sctp 3260 priority 5

  • These commands specify a different priority for the two iSCSI traffic ports.
    switch(config)# dcbx application tcp-sctp 860 priority 3
    switch(config)# dcbx application tcp-sctp 3260 priority 4

  • This command is equivalent to the dcbx application tcp-sctp command. The DCBX peer that iSCSI frames are assigned are the given the priority 5.
    switch(config)# dcbx application iscsi priority 5
    switch(config)#

  • These commands prevent the peers from sending anything about the iSCSI frames.
    switch(config)# no dcbx application tcp-sctp 860 priority 5
    switch(config)# no dcbx application tcp-sctp 3260 priority 5

Configuring CEE DCBX Priority Group

The priority-flow-control priority command configures the Enhanced Transmission Selection (ETS) to the specified QoS group, and sets the traffic class priority and the bandwidth percentage for the packets in the traffic class.

Examples
  • This command configures the ETS to the QoS group map and assigns the CoS map value as 7 and sets traffic class priority to 5.
    switch(config)# dcbx ets qos map cos 7 traffic-class 5

  • This command configures the ETS to the traffic class and sets the traffic class priority as 7 and bandwidth value to 70 percent.
    switch(config)# dcbx ets traffic-class 7 bandwidth 70

DCBX Verification

To display the DCBX status and the interfaces on which DCBX is enabled, use the show dcbx command.

Example

This command displays the DCBX status for Ethernet 50.
switch# show dcbx Ethernet 50
Ethernet50:
 IEEE DCBX is enabled and active
 Last LLDPDU received on Thu Feb 14 12:06:01 2013
 No priority flow control configuration TLV received
 No application priority configuration TLV received
switch#

Configuring Priority-Flow-Control (PFC)

Enable Priority-Flow-Control (PFC)

The priority-flow-control command enables Priority-Flow-Control (PFC) on an individual port.

Example

The priority-flow-control command in DCBX mode enables PFC on an interface.
switch(config)# interface ethernet 2
switch(config-if-Et2)# priority-flow-control on

Set the Priority Flow Control Priority

The priority-flow-control priority command in DCBX mode creates a priority group that pauses priority. Each priority is configured as either drop or no-drop. If a priority that is designated as no-drop is congested, the priority is paused. Drop priorities do not participate in pause.

Examples
  • The priority-flow-control priority command in DCBX mode creates a priority group that pauses priority 5 on interface ethernet 2.
    switch(config)# interface ethernet 2
    switch(config-if-Et2)# priority-flow-control on
    switch(config-if-Et2)# priority-flow-control priority 5 no-drop

  • To enable lossy behavior, use the drop option of the priority-flow-control priority command.
    switch(config)# interface ethernet 2
    switch(config-if-Et2)# priority-flow-control on
    switch(config-if-Et2)# priority-flow-control priority 5 drop

Disable Priority-Flow-Control (PFC)

To disable Priority Flow Control (PFC) on the configuration mode interface and restore the default packet drop setting on the interface, use the priority-flow-control priority command.

Example

To disable PFC, use the no priority-flow-control command.
switch (config)# interface ethernet 2
switch(config-if-Et2)# no priority-flow-control

Configuring PFC Watchdog

Enabling PFC Watchdog

The priority-flow-control pause watchdog default timeout command starts monitoring all the egress queues which have guaranteed bandwidth enabled and for the priorities on which PFC is enabled.

Note: To enable PFC watchdog, user is required to configure guaranteed bandwidth on the tx-queue to be monitored. Also, PFC must be enabled on the port for the traffic flowing into the queue that is being monitored.

Example

These commands enable the PFC watchdog monitoring on tx-queue 3 of Ethernet 1/1, and configures a PFC congestion timeout of 10 seconds which error-disables the port if the queue is stuck.
switch# config
switch(config)# interface Ethernet1/1
switch(config-if-Et1/1)# priority-flow-control on
switch(config-if-Et1/1)# priority-flow-control priority 3 no-drop
switch(config-if-Et1/1)# tx-queue 3
switch(config-if-Et1/1-txq-3)# bandwidth guaranteed 100
switch(config-if-Et1/1-txq-3)# exit
switch(config-if-Et1/1)# exit
switch(config)# priority-flow-control pause watchdog default timeout 10

Enabling PFC Watchdog Queue Recovery

The priority-flow-control pause watchdog default recovery-time forced command recovers a stuck queue after the PFC storm ceases. PFC watchdog supports the following two recovery methods.
  • Auto Recovery – recover queue(s) after the PFC storm ceases.
  • Forced Recovery – recover queue(s) after a fixed duration, irrespective of PFC storm being received.

    Note: The default recovery mode is “auto”.

Example

This command recovers a stuck queue after a fixed duration of 10 seconds.
switch(config)# priority-flow-control pause watchdog default recovery-time 10 forced

Configuring PFC Watchdog Polling Interval

The priority-flow-control pause watchdog default polling-interval command configures the frequency at which queues should be checked for stuck or recovery detection. By default, polling interval is calculated internally or it considers the value configured through the CLI.

Note: Configuring a very low polling interval may increase load on the CPU.

Example

This command configures a polling interval of 10 seconds on the switch.
switch(config)# priority-flow-control pause watchdog default polling-interval 10

Displaying Stuck Queue and Recovery Counters

The show priority-flow-control counters watchdog command displays the value of number of times a queue is identified as stuck and recovered. These counters are maintained only for those queues that have PFC watchdog functionality enabled. These counters are cleared when either PFC or PFC watchdog configuration is disabled. Alternatively, show interfaces priority-flow-control counters watchdog command can be used to display the counters.

Examples
  • This command displays the value of number of times the queue was stuck and recovered for all the interfaces.
    switch# show priority-flow-control counters watchdog
    Port       TxQ   Total times   Total times
                     stuck         recovered
    -------   ----   -----------   -----------
    Et1/1      UC2             2             2
    Et1/1      UC3             3             3
    Et2/1      UC2            12            12
    Et2/1      UC3            31            30

  • This command displays the value of number of times the queue was stuck and recovered for a specific interface. In this case it is Et1/1.
    switch# show priority-flow-control interfaces Ethernet 1/1 counters watchdog
    Port       TxQ   Total times   Total times
                     stuck         recovered
    -------   ----   -----------   -----------
    Et1/1      UC2             2             2
    Et1/1      UC3             3             3

PFC Watchdog Non-disruptive Priorities

The PFC Watchdog acts to drop the traffic entering or leaving the port at the stuck PFC priority. Later when the queue recovers, this action is reversed. While applying these actions, some traffic (for all priorities) is dropped on that port. In such case, the priority-flow-control pause watchdog hardware non-disruptive priority command can be used to avoid the traffic drop on ports at stuck queues.

This traffic drop can be avoided by configuring specific PFC priorities as non-disruptive. When queues corresponding to these priorities are stuck/recovered, the traffic for other priorities are not impacted.

Examples
  • This command configures the specific PFC priorities as non-disruptive, and the priority is set to 3.
    switch(config)# priority-flow-control pause watchdog hardware non-disruptive priority 3

  • This command configures all the ports, having a subset of non-disruptive priorities as a part of their no-drop priorities, start in non-disruptive mode.
    switch(config)# priority-flow-control pause watchdog hardware port non-disruptive-only

Displaying PFC Watchdog Information

The show priority-flow-control command displays the PFC watchdog status information. Note, if the PFC watchdog default timeout value is non-zero then PFC watchdog is active on the switch.

Example

This command displays the PFC watchdog default timeout value, in this show example the timeout value is 3.0 which means the PFC watchdog is active.
switch# show priority-flow-control
The hardware supports PFC on priorities 0 1 2 3 4 5 6 7
The PFC watchdog default timeout is 3.0

Port   Enabled Priorities Active Note 
Et1/1   Yes       34      Yes    DCBX disabled 
Et1/2   Yes       34      Yes    DCBX disabled 
Et1/3   Yes       34      Yes    DCBX disabled 
Et1/4   Yes       34      Yes    DCBX disabled

The show interface status errdisabled command displays the port which is error-disabled due to stuck- queue condition.

Example

This command displays the interface Ethernet Eth1/1 status as errdisabled and the reason.
switch# show interface Eth1/1 status errdisabled

Port            Name          Status         Reason 
---------- ---------------- ----------------- ---------
Et1/1                        errdisabled    stuck-queue

The show priority-flow-control status command displays the current PFC watchdog details.

Example

This command displays the PFC watchdog configuration details at global and interface level.
switch# show priority-flow-control status
The hardware supports PFC on priorities 0 1 2 3 4 5 6 7
The PFC watchdog timeout is 1.0 second(s)
The PFC watchdog recovery-time is 2.0 second(s) (auto)
The PFC watchdog polling-interval is 0.1 second(s)
The PFC watchdog non-disruptive priorities are 3 4
The PFC watchdog port non-disruptive-only is False

E: PFC Enabled, D: PFC Disabled, A: PFC Active, W: PFC Watchdog Enabled
Port     Status  Priorities Note
Et1/1    E A W    1     7   DCBX disabled
Et1/2    E A -              DCBX disabled
Et1/3    D - -
Et1/4    D - -
Et2/1    D - -
.. 
..

DCBX and Flow Control Commands

Configuration Commands

  • dcbx application priority
  • dcbx ets
  • dcbx mode
  • no priority-flow-control
  • platform fm6000 pfc-wm
  • priority-flow-control
  • priority-flow-control pause watchdog action
  • priority-flow-control pause watchdog default
  • priority-flow-control pause watchdog hardware
  • priority-flow-control priority
  • priority-flow-control tagged

Show Commands

  • show dcbx
  • show dcbx application-priority-configuration
  • show dcbx priority-flow-control-configuration
  • show dcbx status
  • show interfaces priority-flow-control
  • show platform fm6000 pfc-wm
  • show priority-flow-control

dcbx application priority

The dcbx application priority command assigns a priority rank to the specified traffic class in the application priority table. This table is transmitted on each DCBX-enabled interface.

The no dcbx application priority and default dcbx application priority commands remove the specified DCBX traffic class priority assignment by deleting the corresponding dcbx application priority command from running-config. When the command does not specify a traffic class, all DCBX traffic class priority assignments are removed.

Command Mode

Global Configuration

Command Syntax

dcbx application [ APPLICATION_TYPE priority ] rank

no dcbx application [ APPLICATION_TYPE priority ]

default dcbx application [ APPLICATION_TYPE priority ]

Parameters
  • APPLICATION_TYPE traffic class receiving the priority assignment. Options include:
    • ether ethertype_number Ethernet traffic. ethertype_number varies from 1536 to 65535.
    • iscsci iSCSCI traffic. Maps to TCP/SCTP ports 860 and 3260.
    • tcp-sctp port_number TCP/SCTP traffic. Port number varies from 1 to 65535.
    • tcp-sctp-udp port_number TCP/SCTP/UDP traffic. Port number varies from 1 to 65535.
    • udp port_number UDP traffic. Port number varies from 1 to 65535.

  • rank priority assigned to traffic class. Values range from 0 to 7.

Examples
  • These commands tell the DCBX peer that iSCSI frames (TCP ports 860 and 3260) should be assigned the given priority of 5.
    switch(config)# dcbx application tcp-sctp 860 priority 5
    switch(config)# dcbx application tcp-sctp 3260 priority 5

  • These commands specify a different priority for the two iSCSI traffic ports.
    switch(config)# dcbx application tcp-sctp 860 priority 3
    switch(config)# dcbx application tcp-sctp 3260 priority 4

  • This command is equivalent to the dcbx application tcp-sctp command. The DCBX peer that iSCSI frames are assigned to is given priority 5.
    switch(config)# dcbx application iscsi priority 5
    switch(config)#

  • These commands prevent the peers from sending anything about the iSCSI frames.
    switch(config)# no dcbx application tcp-sctp 860 priority
    switch(config)# no dcbx application tcp-sctp 3260 priority

dcbx ets

The dcbx ets command configures the enhanced transmission selection (ETS) to the specified QoS group, and sets the traffic class priority and the bandwidth percentage for the packets in the traffic class.

The no dcbx ets and default dcbx ets commands remove the specified DCBX traffic classs priority assignment by deleting the corresponding dcbx ets command from the running-config.

Command Mode

Global Configuration

Command Syntax

dcbx ets [ qos map cos value traffic-class value | traffic-class value bandwidth value ]

no dcbx ets [ qos map cos value traffic-class value | traffic-class value bandwidth value ]

default dcbx ets [ qos map cos value traffic-class value | traffic-class value bandwidth value ]

Parameters
  • qos QoS to configure.(The sub options include):
    • map QoS map to configure.
    • cos CoS value assigned to port. Value ranges from 0 to 7. Default value is 0.
    • traffic-class Assigns the traffic-class priority to the QoS map. The value ranges from 0 to 7.

  • traffic-class Assigns the traffic class priority. The value ranges from 0 to 7. (The sub options include):
    • bandwidth The percentage of bandwidth assigned to the packets received from traffic class. The value ranges from 0 to 100 in percentage. The default value is 0.

Examples
  • This command configures the ETS to the QoS group map and assigns the CoS map value as 7 and sets the traffic class priority to 5.
    switch(config)# dcbx ets qos map cos 7 traffic-class 5

  • This command configures the ETS to the traffic class and sets the traffic class priority value to 7 and sets the bandwidth value to 70 percent.
    switch(config)# dcbx ets traffic-class 7 bandwidth 70

dcbx mode

The dcbx mode command enables DCBX mode on the configuration mode interface. The switch supports IEEE P802.1Qaz. When DCBX is enabled, two TLVs are added to outgoing LLDPDUs, which instruct the peer on the interface to configure PFC (priority flow control) and the application priority table in the same way as the switch.

The no dcbx mode, default dcbx mode, and dcbx mode none commands disable DCBX on the configuration mode interface by removing the corresponding dcbx mode command from running-config.

Command Mode

Interface-Ethernet Configuration

Command Syntax

dcbx mode MODE_NAME

no dcbx mode

default dcbx mode

Parameters

MODE_NAME Specifies the DCBX version. Options include:
  • ieee IEEE version.
  • cee Converged Enhanced Ethernet version.
  • none DCBX is disabled.

Examples
  • These commands enable interface ethernet 2 to use IEEE DCBX.
    switch(config)# interface ethernet 2
    switch(config-if-Et2)# dcbx mode ieee
    switch(config-if-Et2)#

  • These commands disable DCBX on interface ethernet 2.
    switch(config)# interface ethernet 2
    switch(config-if-Et2)# dcbx mode none
    switch(config-if-Et2)

no priority-flow-control

The no priority-flow-control and default priority-flow-control commands disable the priority flow control (PFC) on the configuration mode interface and restore the default packet drop setting on the interface, which takes effect when PFC is re-enabled. The commands delete all corresponding priority-flow-control commands from running-config.

Command Mode

Interface-Ethernet Configuration

Command Syntax

no priority-flow-control

default priority-flow-control

Example

These commands disable Priority Flow Control (PFC) on interface ethernet 3.
switch(config)# interface ethernet 3
switch(config-if-Et3)# no priority-flow-control
switch(config-if-Et3)#

priority-flow-control

The priority-flow-control command enables Priority Flow Control (PFC) on the configuration mode interface to pause selected traffic classes.

The no priority-flow-control and default priority-flow-control commands disable PFC on the configuration mode interface by deleting the corresponding priority-flow-control command from running-config. The priority-flow-control priority command also disables PFC on the configuration mode interface.

Command Mode

Interface-Ethernet Configuration

Command Syntax

priority-flow-control on

no priority-flow-control on

default priority-flow-control on

Examples
  • These commands enable PFC on interface ethernet 3.
    switch(config)# interface ethernet 3
    switch(config-if-Et3)# priority-flow-control on
    switch(config-if-Et3)#

  • These commands disable PFC on interface ethernet 3.
    switch(config)# interface ethernet 3
    switch(config-if-Et3)# no priority-flow-control
    switch(config-if-Et3)#

platform fm6000 pfc-wm

The platform fm6000 pfc-wm command configures the hardware buffer space allocated to the Priority Flow Control (PFC) RX-Private buffer. The command provides options to configure the buffer size and specify when PFC frames are sent to request that a neighbor stop sending traffic. The default values are as follows:
  • RX-Private: 18400 bytes
  • on (watermark): 9280 bytes
  • off (watermark): 1600 bytes

Values that are entered in the command are rounded up to the closest multiple of 160. The RX-Private value must be greater than the off value, which must be larger than the on value.

The no platform fm6000 pfc-wm and default platform fm6000 pfc-wm commands restore the default settings by removing the platform fm6000 pfc-wm command from running-config.

Command Mode

Global Configuration

Command Syntax

platform fm6000 pfc-wm [ RX-PRIVATE_SIZE ][ PFC-ON_WM ][ PFC-OFF_WM ]

no platform fm6000 pfc-wm

default platform fm6000 pfc-wm

The platform fm6000 pfc-wm command must explicitly configure at least one parameter.

Parameters
  • RX-PRIVATE_SIZE Specifies size of rx-private buffer. Options include:
    • no parameter rx-private buffer retains previously configured size.
    • rx-private 18268 to 102400 Size of rx-private buffer (bytes).

  • PFC-ON_WM Buffer capacity that triggers the switch to send PFC frames. Options include:
    • no parameter Parameter retains previously configured value.
    • on 9134 to 102400 Buffer capacity that triggers PFC frames (bytes).

  • PFC-OFF_WM Buffer capacity that triggers the switch to stop PFC frame transmissions. Options include:
    • no parameter Parameter retains previously configured value.
    • off 1536 to 102400 Buffer capacity that turns off PFC frames.

Related Command

show platform fm6000 pfc-wm displays the PFC RX-Private buffer memory allocations.

Example

This command configures the rx-private hardware buffer.
switch(config)# platform fm6000 pfc-wm rx-private 24800 on 16000 off 3200
switch(config)#

priority-flow-control pause watchdog action

The priority-flow-control pause watchdog action command either drops the traffic on a stuck queue, or error disables the port which has a stuck queue, or notifies if there is no action on the stuck queue. The following actions are performed based on the queue status.

The no priority-flow-control pause watchdog action command removes the specified priority-flow-control pause watchdog action configuration by deleting the corresponding priority-flow-control pause watchdog action command from running-config.

Command Mode

Global Configuration

Command Syntax

priority-flow-control pause watchdog action

no priority-flow-control pause watchdog action

Parameters

action PFC watchdog action for stuck transmit queues. Options include.
  • drop Drop traffic on the stuck queue.
  • errdisable Error disable port which has the stuck transmit queue.
  • notify-only No action on the stuck queue.

Guidelines

Before enabling the PFC watchdog configuration, configure the guaranteed bandwidth on the tx-queue to be monitored. Also, enable the PFC on the port for the PFC priorities for the traffic flowing into the queue that is being monitored.

Example

These commands enables the pfc-watchdog monitoring on tx-queue 3 of Ethernet 1/1, and configures a PFC watchdog action drop and drops the traffic if the queue is a stuck queue.
switch# config
switch(config)# interface Ethernet1/1
switch(config-if-Et1/1)# priority-flow-control on
switch(config-if-Et1/1)# priority-flow-control priority 3 no-drop
switch(config-if-Et1/1)# tx-queue 3
switch(config-if-Et1/1-txq-3)# bandwidth guaranteed 100
switch(config-if-Et1/1-txq-3)# exit
switch(config-if-Et1/1)# exit
switch(config)# priority-flow-control pause watchdog action drop

priority-flow-control pause watchdog default

The priority-flow-control pause watchdog default command monitors all the egress queues which have guaranteed bandwidth enabled and for the priorities on which PFC is enabled. Guaranteed bandwidth is needed to ensure starvation due to higher priority traffic is not wrongly flagged as a stuck-queue due to congestion. The stuck duration after which the port needs to be error disabled is also configurable.

The no priority-flow-control pause watchdog default command removes the specified priority-flow-control pause watchdog configuration by deleting the corresponding priority-flow-control pause watchdog command from running-config.

Command Mode

Global Configuration

Command Syntax

priority-flow-control pause watchdog default

no priority-flow-control pause watchdog default

Parameters

default Specifies the default value. Options include.
  • polling-interval Configures the interval at which the watchdog should poll the queues. The polling interval value ranges from 0.005 to 30 seconds.

  • recovery-time Configures recovery-time after which stuck queue should recover and start forwarding. The recovery-time value ranges from 0.01 to 60 seconds.
    • forced Force recover any stuck queue(s) after the recovery-time interval, irrespective of whether PFC frames are being received or not.

  • timeout Configures timeout after which port should be errdisabled or should start dropping on congested priorities. The timeout value ranges from 0.01 to 60 seconds.

Guidelines

Before enabling the PFC watchdog configuration, configure the guaranteed bandwidth on the tx-queue to be monitored. Also, enable the PFC on the port for the PFC priorities for the traffic flowing into the queue that is being monitored.
  • Polling Interval Discrepancy

    For user configured polling-interval to be valid, it must satisfy the following conditions

    When the recovery-mode is auto and timeout, recovery-time, and polling-interval are non-default, polling-interval <= min (timeout, recovery-time) / 2,

    When recovery-mode is forced or recovery-time is not configured, polling-interval <= (timeout / 2)

    For better functioning of PFC Watchdog, when user configured polling interval is too large compared to either timeout or recovery time values, Watchdog will use auto calculated value instead of user configured value until the discrepancy is resolved. Also, CLI warning and syslog messages are generated to inform user of the discrepancy.

  • CLI Warnings
    When there is discrepancy between timeout and polling-interval, the format of the message is as shown below:
    ! User configured polling interval <user-cfgd polling-interval> second(s) is 
    greater than half of timeout <user-cfgd timeout> second(s). Setting 
    polling-interval to <to-be-used polling-interval> second(s)

    When there is discrepancy between recovery-time and polling-interval, the format of the message is as shown below
    ! User configured polling interval <user-cfgd polling-interval> second(s) is 
    greater than half of recovery-time <user-cfgd recovery-time> second(s). Setting 
    polling-interval to <to-be-used polling-interval> second(s)

Examples
  • These commands enable the pfc-watchdog monitoring on tx-queue 3 of interface ethernet1/1, and configures a PFC congestion timeout of 10 seconds which error-disables the port if the queue is stuck.
    switch# config
    switch(config)# interface ethernet1/1
    switch(config-if-Et1/1)# priority-flow-control on
    switch(config-if-Et1/1)# priority-flow-control priority 3 no-drop
    switch(config-if-Et1/1)# tx-queue 3
    switch(config-if-Et1/1-txq-3)# bandwidth guaranteed 100
    switch(config-if-Et1/1-txq-3)# exit
    switch(config-if-Et1/1)# exit
    switch(config)# priority-flow-control pause watchdog default timeout 10

  • These commands enable the pfc-watchdog monitoring on tx-queue 3 of interface ethernet1/1, and configures a PFC forced recovery-time interval of 30 seconds after which the stuck queue(s) are recovered, irrespective of whether PFC frames are being received or not.
    switch# config
    switch(config)# interface ethernet1/1
    switch(config-if-Et1/1)# priority-flow-control on
    switch(config-if-Et1/1)# priority-flow-control priority 3 no-drop
    switch(config-if-Et1/1)# tx-queue 3
    switch(config-if-Et1/1-txq-3)# bandwidth guaranteed 100
    switch(config-if-Et1/1-txq-3)# exit
    switch(config-if-Et1/1)# exit
    switch(config)# priority-flow-control pause watchdog default recovery-time 30 forced

  • These commands enable the pfc-watchdog monitoring on tx-queue 3 of Ethernet 1/1, and configures a PFC polling-interval of 20 seconds after which queue is polled.
    switch# config
    switch(config)# interface Ethernet1/1
    switch(config-if-Et1/1)# priority-flow-control on
    switch(config-if-Et1/1)# priority-flow-control priority 3 no-drop
    switch(config-if-Et1/1)# tx-queue 3
    switch(config-if-Et1/1-txq-3)# bandwidth guaranteed 100
    switch(config-if-Et1/1-txq-3)# exit
    switch(config-if-Et1/1)# exit
    switch(config)# priority-flow-control pause watchdog default polling-interval 20

priority-flow-control pause watchdog hardware

The priority-flow-control pause watchdog hardware command configures specific PFC priorities as non-disruptive. This will avoid traffic drop on queues corresponding to these priorities are stuck/recovered, the traffic for other priorities are not impacted.

The no priority-flow-control pause watchdog hardware command removes the specified priority-flow-control pause watchdog non-disruptive configuration by deleting the corresponding priority-flow-control pause watchdog hardware command from running-config.

Command Mode

Global Configuration

Command Syntax

priority-flow-control pause watchdog hardware

no priority-flow-control pause watchdog hardware

Parameters

hardware Configure PFC priority through hardware. Options include:
  • non-disruptive PFC watchdog non-disruptive configuration. The priority value ranges from 0 to 7.

Guidelines

Before enabling the PFC watchdog configuration, configure the guaranteed bandwidth on the tx-queue to be monitored. Also, enable the PFC on the port for the PFC priorities for the traffic flowing into the queue that is being monitored.

Example

These commands enable the pfc-watchdog monitoring on tx-queue 3 of interface ethernet 1/1, and configures PFC priorities as non-disruptive on PFC priorities 3 and 4.
switch# config
switch(config)# interface ethernet1/1
switch(config-if-Et1/1)# priority-flow-control on
switch(config-if-Et1/1)# priority-flow-control priority 3 no-drop
switch(config-if-Et1/1)# tx-queue 3
switch(config-if-Et1/1-txq-3)# bandwidth guaranteed 100
switch(config-if-Et1/1-txq-3)# exit
switch(config-if-Et1/1)# exit
switch(config)# priority-flow-control pause watchdog hardware non-disruptive priority 3 4

priority-flow-control priority

The priority-flow-control priority command configures the packet resolution setting on the configuration mode interface. This setting determines if packets are dropped when priority flow control (PFC) is enabled on the interface. Packets are dropped by default.

The no priority-flow-control priority and default priority-flow-control priority commands restore the default packet drop setting on the configuration mode interface by deleting the corresponding priority-flow-control priority command from running-config. The priority-flow-control priority command also restores the default setting on the configuration mode interface.

Command Mode

Interface-Ethernet Configuration

Command Syntax

priority-flow-control priority pack-drop

no priority-flow-control priority

default priority-flow-control priority

Parameters

pack-drop denotes the interfaces. Options include:
  • drop Packets are dropped. Default setting.
  • no drop Packets are not dropped.

Examples
  • These commands in DCBX mode create a priority group that pauses dot1p priority 5 on interface ethernet 2.
    switch(config)# interface ethernet 2
    switch(config-if-Et2)# priority-flow-control on
    switch(config-if-Et2)# priority-flow-control priority 5 no-drop

  • These commands enable lossy behavior.
    switch(config)# interface ethernet 2
    switch(config-if-Et2)# priority-flow-control on
    switch(config-if-Et2)# priority-flow-control priority 5 drop

  • These commands remove the priority group that pauses dot1p priority 5 on interface ethernet 2.
    switch(config)# interface ethernet 2
    switch(config-if-Et2)# priority-flow-control on
    switch(config-if-Et2)# no priority-flow-control priority

priority-flow-control tagged

The priority-flow-control tagged command in the Global Configuration Mode to allow tagged packets to use the QoS trust mode for priority group selection in Priority Flow Control instead of always using the VLAN CoS.

The [no | default] versions of the command disable the feature and remove the configuration from the running-config.

Command Mode

Global Configuration

Command Syntax

priority-flow-control tagged use-qos-trust

no priority-flow-control tagged use-qos-trust

default priority-flow-control tagged use-qos-trust

Parameters

  • tagged use-qos-trust - Enables using QoS trust mode for priority group selection for Priority Flow Control.

Example

Use the following command to enable the feature:

switch(config)# priority-flow-control tagged use-qos-trust
switch(config)#

show dcbx

The show dcbx command list DCBX status and the interfaces on which DCBX is enabled.

Command Mode

EXEC

Command Syntax

show dcbx [INTERFACE]

Parameters

INTERFACE Interface type and number. Options include:
  • no parameter all configured DCBX interfaces.
  • ethernet e-num Ethernet interface specified by e-num.

Examples
  • This command displays the DCBX status for ethernet 50.
    switch# show dcbx ethernet 50
    Ethernet50:
      IEEE DCBX is enabled and active
      Last LLDPDU received on Thu Feb 14 12:06:01 2013
      No priority flow control configuration TLV received
      No application priority configuration TLV received
    switch#

  • This command displays the DCBX status for ethernet 50 when Priority Flow Control (PFC) is not enabled.
    switch# show dcbx ethernet 50
    Ethernet50:
      IEEE DCBX is enabled and active
      Last LLDPDU received on Thu Feb 14 12:08:29 2013
      - PFC configuration: willing
        not capable of bypassing MACsec
        supports PFC on up to 4 traffic classes
        PFC enabled on priorities: 5 7
        WARNING: peer PFC configuration does not match the local PFC configuration
      - Application priority configuration:
        2 application priorities configured:
          tcp-sctp 860 priority 5
          tcp-sctp 3260 priority 5
    switch#

show dcbx application-priority-configuration

The show dcbx application-priority-configuration command displays the DCBX peer application priority configuration.

Command Mode

EXEC

Command Syntax

show dcbx [INTERFACE] application-priority-configuration

Parameters

INTERFACE Interface type and number. Options include:
  • no parameter All configured DCBX interfaces.
  • ethernet e-num Ethernet interface specified by e-num.

Guidelines

This command and the show priority-flow-control command function identically.

Example

This command displays the DCBX peer application priority configuration for all DCBX-enabled interfaces.
switch# show dcbx application-priority-configuration
Ethernet1:
  Last LLDPDU received on Thu Feb 14 10:52:20 2013
  No application priority configuration TLV received
Ethernet2:
  Last LLDPDU received on Thu Feb 14 10:52:20 2013
  No application priority configuration TLV received
...
Ethernet50:
  Last LLDPDU received on Thu Feb 14 12:08:29 2013
  - Application priority configuration:
    2 application priorities configured:
      tcp-sctp 860 priority 5
      tcp-sctp 3260 priority 5
switch#

show dcbx priority-flow-control-configuration

The show dcbx priority-flow-control-configuration command displays the IEEE DCBX peer priority flow control configurations.

Command Mode

EXEC

Command Syntax

show dcbx [ INTERFACE ] priority-flow-control-configuration

Parameters

INTERFACE Interface type and number. Options include:
  • no parameter all configured DCBX interfaces.
  • ethernet e-num Ethernet interface specified by e-num.

Example

This command displays the DCBX peer priority flow control configuration for the DCBX-enabled interfaces on the device.
switch# show dcbx priority-flow-control-configuration 
Ethernet1:
  Last LLDPDU received on Thu Feb 14 10:52:20 2013
  No priority flow control configuration TLV received
Ethernet2:
  Last LLDPDU received on Thu Feb 14 10:52:20 2013
  No priority flow control configuration TLV received
...
Ethernet50:
  Last LLDPDU received on Thu Feb 14 12:11:29 2013
  - PFC configuration: willing
    not capable of bypassing MACsec
    supports PFC on up to 4 traffic classes
    PFC enabled on priorities: 5 7
    WARNING: peer PFC configuration does not match the local PFC configuration
switch# 

show dcbx status

The show dcbx status command displays the DCBX status on the interfaces on which DCBX is enabled.

Command Mode

EXEC

Command Syntax

show dcbx [INTERFACE] status

Parameters

INTERFACE Interface type and number. Options include:
  • no parameter all configured DCBX interfaces.
  • ethernet e-num Ethernet interface specified by e-num.

Example

This command displays the DCBX status for the DCBX-enabled interfaces.
switch# show dcbx status  
Ethernet1:
  Last LLDPDU received on Thu Feb 14 10:52:20 2013
Ethernet2:
  Last LLDPDU received on Thu Feb 14 10:52:20 2013
Ethernet50:
  IEEE DCBX is enabled and active
  Last LLDPDU received on Thu Feb 14 12:11:54 2013
switch#

show interfaces priority-flow-control

The show interfaces priority-flow-control command displays the status of PFC on all interfaces.

Command Mode

EXEC

Command Syntax

show interfaces [ INTERFACE ] priority-flow-control [ INFO_LEVEL ]

Parameters
  • INTERFACE Interface type and numbers. Options include:
    • no parameter Display information for all interfaces.
    • ethernet e_range Ethernet interface range specified by e_range.
    • loopback l_range Loopback interface specified by l_range.
    • management m_range Management interface range specified by m_range.
    • port-channel p_range Port-Channel Interface range specified by p_range.
    • vlan v_range VLAN interface range specified by v_range.
    • VXLAN vx_range VXLAN interface range specified by vx_range.

      Valid range formats include number, number range, or comma-delimited list of numbers and ranges.

  • INFO_LEVEL specifies the type of information displayed. Options include:
    • no parameter Displays information about all DCBX neighbor interfaces.
    • status Displays the DCBX status.
    • counters Displays the DCBX counters.

Guidelines

This command and the show priority-flow-control command function identically.

Example

This command displays the PFC for all interfaces.
switch# show interfaces priority-flow-control 
The hardware supports PFC on priorities 0 1 2 3 4 5 6 7

Port    Enabled Priorities Active Note
Et1     No                 No
Et2     No                 No
...
Et50    Yes          5     Yes
...
Port                 RxPfc           TxPfc
Et1                      0               0
Et2                      0               0
...
Et50                     0               0
...
switch#

show platform fm6000 pfc-wm

The show platform fm6000 pfc-wm command displays the buffer space allocated to the RX-Private buffer and buffer levels that trigger PFC frame transmission activities.

Command Mode

Privileged EXEC

Command Syntax

show platform fm6000 pfc-wm

Related Command

priority-flow-control priority specifies the PFC RX-Private buffer memory allocation.

Example

This command displays the rx-private hardware buffer memory allocation.
switch# show platform fm6000 pfc-wm
Pfc_Rx_Private_WM: 24800 Bytes
Pfc_On_WM: 16000 Bytes
Pfc_Off_WM: 3200 Bytes
switch#

show priority-flow-control

The show priority-flow-control command displays the status and other PFC and PFC watchdog information on all interfaces if no specific interface is specified.

Command Mode

EXEC

Command Syntax

show priority-flow-control [ status | counters | interfaces ]

Parameters
  • interfaces specifies the interface for which the information is displayed. Options include:
    • Ethernet Hardware Ethernet interface.
    • Loopback Loopback interface.
    • Management Management interface.
    • Port-Channel Lag interface.
    • Recirc-Channel Recirculation interface.
    • Tunnel Tunnel interface.
    • Vlan VLAN interface.
    • VXLAN VXLAN Tunnel Interface.

  • status - Displays the interface PFC status.

  • counters - Displays the interface PFC counters. Options include:
    • detail - Displays the DCBX counters for each priority class. This option is available only on Trident switches.
    • watchdog - Displays the PFC watchdog counters.
    • buffer counters - Displays watermarks for each interface.
    • buffer on-chip counters - Displays watermarks for each on-chip counter.
    • packet descriptor counters - Displays watermarks for each packet.

Examples
  • This command displays the PFC status on all interfaces.
    switch# show priority-flow-control
    The hardware supports PFC on priorities 0 1 2 3 4 5 6 7
    Port    Enabled Priorities Active Note                                          
    Et1     No                 No                                                   
    Et2     No                 No                                                   
    ...
    Et50    Yes          5     Yes                                                  
    ...
    Port                 RxPfc           TxPfc
    Et1                      0               0
    Et2                      0               0
    ...
    Et50                     0               0
    ...

  • This command displays the PFC watchdog status. If PFC watchdog default timeout is non-zero (in this case it is 3.0) then PFC watchdog is actively running on the switch.
    switch# show priority-flow-control
    The hardware supports PFC on priorities 0 1 2 3 4 5 6 7
    The PFC watchdog default timeout is 3.0
    
    Port   Enabled Priorities Active Note 
    Et1/1   Yes       34      Yes    DCBX disabled 
    Et1/2   Yes       34      Yes    DCBX disabled 
    Et1/3   Yes       34      Yes    DCBX disabled 
    Et1/4   Yes       34      Yes    DCBX disabled
    ...

  • This command displays the current value of these counters for all the interfaces being monitored by PFC watchdog. Alternatively, show interfaces priority-flow-control counters watchdog command can be used for the same.
    switch# show priority-flow-control counters watchdog
    Port       TxQ   Total times   Total times
                     stuck         recovered
    -------   ----   -----------   -----------
    Et1/1      UC2             2             2
    Et1/1      UC3             3             3
    Et2/1      UC2            12            12
    Et2/1      UC3            31            30

  • This command displays the current value of these counters for a specific subset of interfaces. Alternatively, show interfaces priority-flow-control counters watchdog command can be used for the same.
    switch# show priority-flow-control interfaces ethernet 1/1 counters watchdog
    Port       TxQ   Total times   Total times
                     stuck         recovered
    -------   ----   -----------   -----------
    Et1/1      UC2             2             2
    Et1/1      UC3             3             3

  • This command displays the configuration details of PFC watchdog at global and interface level.
    switch# show priority-flow-control status
    The hardware supports PFC on priorities 0 1 2 3 4 5 6 7
    The PFC watchdog timeout is 1.0 second(s)
    The PFC watchdog recovery-time is 2.0 second(s) (auto)
    The PFC watchdog polling-interval is 0.1 second(s)
    The PFC watchdog non-disruptive priorities are 3 4
    The PFC watchdog port non-disruptive-only is False
    
    E: PFC Enabled, D: PFC Disabled, A: PFC Active, W: PFC Watchdog Enabled
    Port     Status  Priorities Note
    Et1/1    E A W    1     7   DCBX disabled
    Et1/2    E A -              DCBX disabled
    Et1/3    D - -
    Et1/4    D - -
    Et2/1    D - -
    .. 

  • Display the PFC priority preferred source:
    switch(config)# show priority-flow-control status
    The hardware supports PFC on priorities 0 1 2 3 4 5 6 7
    PFC receive processing is enabled on priorities 0 1 2 3 4 5 6 7
    ! Please configure the timeout for watchdog to be operationally active
    The PFC watchdog timeout is 0.0 second(s) (default)
    The PFC watchdog recovery-time is 0.0 second(s) (auto) (default)
    The PFC watchdog polling-interval is 0.0 second(s) (default)
    The PFC watchdog action is errdisable
    The PFC watchdog override action drop is false
    The PFC watchdog non-disruptive priorities are 0 1 2 3 4 5 6 7
    The PFC watchdog non-disruptive action is not configured
    The PFC watchdog port non-disruptive-only is false
    Global PFC : Enabled
    PFC priority preferred source : QOS Trust
..

EOS 4.36.2F User Manual - Virtual LANs (VLANs)

Virtual LANs (VLANs)

This chapter describes Arista’s Virtual LANs (VLANs) implementation and MAC address tables.

Sections in this chapter include:

  • VLAN Introduction
  • VLAN Conceptual Overview
  • VLAN Configuration Procedures
  • VLAN Configuration Commands

VLAN Introduction

Arista switches support industry standard 802.1q VLANs. Arista EOS provides tools to manage and extend VLANs throughout the data center network.

VLAN Conceptual Overview

VLAN Definition

A Virtual Local Area Network (VLAN) allows a group of devices to communicate as if they were in the same network regardless of their physical location. VLANs are Layer 2 structures based on the 802.1Q standard.

These parameters are associated with a VLAN:
  • VLAN number (1-4094): VLAN numbers uniquely identify the VLAN within a network. VLAN 1 exists by default; all other VLANs only exist after configuring.

  • VLAN name (optional): The VLAN name is a text string that describes the VLAN.

  • VLAN state (active or suspended): The state specifies the VLAN transmission status within the switch. In the suspended state, VLAN traffic is blocked on all switch ports. The default state is active.

VLANs define Layer 2 broadcast domains in a Layer 2 network, in which each device can receive broadcast frames sent by any other within the domain. Switches accommodating multiple broadcast domains serve as multi-port bridges where each broadcast domain is a distinct virtual bridge. Traffic does not pass directly between different VLANs within a switch or between two switches.

VLAN Switching

Ethernet and port channel interfaces are configured as switched ports by default. Switched ports are configurable as members of one or more VLANs. Switched ports ignore all IP-level configuration commands, including IP address assignments.

VLAN Trunking and Trunk Groups

Trunking extends multiple VLANs beyond the switch through a common interface or port channel.

A trunk group is the set of physical interfaces that comprise the trunk and the collection of VLANs whose traffic is carried on the trunk. The traffic of a VLAN that belongs to one or more trunk groups is carried only on ports that are members of trunk groups to which the VLAN belongs, i.e., VLANs configured in a trunk group are pruned of all ports that are not associated with the trunk group. See the Trunk Ports example section for further details.

Note: Be cautious when using allowed VLAN lists or trunk groups to ensure that the VLAN topology is consistent with any Layer-2 control protocol topology, or unpredictable results can occur.

VLAN traffic is carried through Ethernet or LAG ports. A port’s switchport mode defines the number of VLANs for which the port can carry traffic.
  • Access ports carry traffic for one VLAN – the access VLAN. Access ports associate untagged frames with the access VLAN. Access ports drop tagged frames that are not tagged with the access VLAN.

  • Trunk ports carry traffic for multiple VLANs. Tag frames specify the VLAN for which trunk ports process packets.

Q-in-Q Trunking

A Q-in-Q network is a multi-tier layer 2 VLAN network. A typical Q-in-Q network is composed of a service provider network (tier 1) where each node connects to a customer network (tier 2).

802.1ad is a networking standard that supports Q-in-Q networks by allowing multiple 802.1Q tags in an Ethernet frame.

Each interface in a customer network is assigned to a customer-VLAN (c-VLAN). Packets in c-VLANs contain 802.1q tags that switch traffic within the network. c-VLANs access the service provider VLAN (s-VLAN) through a provider switch. Customer switch ports connect to an s-VLAN through provider switch edge ports, which are configured as dot1q ports and operate as follows:
  • Inbound traffic (from customer switches): adds an s-VLAN tag, then forwards packets to the provider network.

  • Outbound traffic (to customer switches): removes the s-VLAN tag, then forwards packets to the customer network.

Tag Protocol Identifier (TPID) Configurable Ethertypes

By default, VLAN-tagged packets carry a Tag Protocol Identifier (TPID) of 0x8100. On some Arista platforms, however, the TPID of a switchport can be modified in accordance with IEEE 802.1ad to allow for the use of 802.1q TPIDs other than 0x8100. Well known and standard tags include the following:

  • 0x8100 - Specifies the customer VLAN.
  • 0x88a8 - Specifies the service VLAN tag used in provider bridging.
  • 0x9100 - Specifies the service VLAN tag also used in provider bridging, but not a common configuration.

Other non-standard TPID values may also be configured for interoperability with legacy equipment or non-standard systems. Values range from 0x600 (1536) through 0xFFFF (65535).

Non-default TPID values are most commonly used for provider bridging on a network-to-network interface.

VLAN Routing

Each VLAN can be associated with a Switch Virtual Interface (SVI), also called a VLAN interface. The VLAN interface functions in a routed network (Layer 3) with an assigned IP subnet address. Connecting different VLANs requires Layer 3 networking.

VLAN Interfaces

A Switched Virtual Interface (SVI) connects to the VLAN segment on the switch to provide Layer 3 processing for packets from the VLAN. An SVI can be activated only after it is connected to a VLAN. SVIs are typically configured for a VLAN to a default gateway for a subnet to facilitate traffic routing with other subnets.

In a Layer 3 network, each VLAN SVI is associated with an IP subnet, with all stations in the subnet members of the VLAN. Traffic between different VLANs is routed when IP routing is enabled.

Internal VLANs

A routed port is an Ethernet or port channel interface that functions as a Layer 3 interface. Routed ports do not bridge frames nor switch VLAN traffic. Routed ports have IP addresses assigned to them and packets are routed directly to and from the port.

The switch allocates an internal VLAN for an interface when it is configured as a routed port. The internal VLAN is assigned a previously unused VLAN ID. The switch prohibits the subsequent configuration of VLANs and VLAN interfaces with IDs corresponding to allocated internal VLANs.

Support for Private VLAN

Private VLAN is a feature that segregates a regular VLAN broadcast domain while maintaining all ports in the same IP subnet. There are three types of VLAN within a private VLAN:
  1. Primary VLAN: Ports in the primary VLAN can send and or receive traffic from ports in all the corresponding PVLANs. There is only one primary VLAN in a private VLAN.

  2. Community VLAN: This is a secondary VLAN. Hosts in a community VLAN forward traffic to each other as well as ports in the primary VLAN. There are multiple community VLANs in a private VLAN.

  3. Isolated VLAN: This is a secondary VLAN. Hosts in an isolated VLAN only forward traffic to ports in the primary VLAN. Hosts within an isolated VLAN can not communicate with each other using bridging. There are multiple isolated VLANs in a private VLAN.

Limitations
On DCS-7280R, DCS-7280R2, DCS-7500R, DCS-7500R2, DCS-7020R
  • Private VLAN and Algomatch features are mutually exclusive. Disable algomatch with the hardware access-list mechanism tcam command . Note that this requires a reload of the system to take effect.
  • L2 and L3 multicast traffic is not supported.

On All Platforms except 7300X3, CCS-720XP, DCS-7050X3

Private VLAN and IPv4/IPv6 uRPF features are mutually exclusive.

On All Platforms
  • Tunnel termination on PVLAN ports is not supported.
  • Ingress IPv4/IPv6 RACLs on the primary VLAN are not honored for packets ingressing through ports in secondary VLANs.
  • Only isolated private VLAN trunks and normal trunk ports are supported. It allows trunk ports to forward and receive traffic for all primary and or secondary VLANs. An isolated trunk translates traffic coming in on a primary VLANto the lowest valued secondary VLAN on the trunk port.
  • Private VLAN is not supported on L2 subinterfaces.
  • Hardware accelerated Sflow is not supported on Private VLAN ports.
  • VLAN Mapping and or Translation is not supported with Private VLAN.

Show Commands
  • Use the show vlan private-vlan command to display the primary and secondary defined VLANs:
    switch# show vlan private-vlan
    Primary Secondary Type         Ports
    ------- --------- ----------- ------------------------
    100      101      community    Et1, Et6
    100      102      isolated     Et1, Et7, Et8
    200      201      community    Et10, Et9

  • Use the show vlan 100,101,102,200,201 command to diplay which interfaces are member of which VLANs:
    # show vlan 100,101,102,200,201
    VLAN  Name          Status    Ports
    ----- ------------- --------- -------------------------------
    100   VLAN0100      active    Et1, Et6+, Et7+, Et8+
    101   VLAN0101      active    Et1+, Et6
    102   VLAN0102      active    Et1+, Et7, Et8
    200   VLAN0200      active    Et10
    201   VLAN0201      active    Et10+, Et9
    
    + indicates a private VLAN promoted port

Promoted ports are displayed to indicate they are part of the same broadcast domain as the indicated VLAN. Interfaces in a primary VLAN are included in the display of all its associated secondary VLANs. Interfaces in secondary VLANs are included in the display of both its primary VLAN and its own domain.

On DCS-7280R, DCS-7280R2, DCS-7500R, DCS-7500R2, DCS-7020R
Use the show platform sand pvlan interfaces command to display the status of the interfaces to configure a private VLAN.
switch# show platform sand pvlan interfaces
Interface          Secondary      Primary     State
                        VLAN         VLAN
-----------------  ----------  ----------  ---------
Ethernet6                 101         100    enabled
Ethernet7                 102         100    enabled
Ethernet8                 102         100    enabled
Po1                       102         100    enabled
Ethernet9                 201         200     failed
Po2                       202         200     failed

In this output, the Secondary VLAN column indicates the VLAN which is configured on the interface. The Primary VLAN column indicates the primary VLAN to which the secondary VLAN belongs to. The State field has three possible values - enabled, failed, configured. The enabled state indicates that the private VLAN is configured and enabled on that interface. The failed state indicates that the private VLAN configuration has failed for that interface The configured state indicates that private VLAN is configured on that interface but has not taken effect. When port channels are configured in a private VLAN, it is enabled only if entries for all the member interfaces are successfully programmed in the hardware. If the hardware entries for any one of the member interfaces fails, the entries for other member interfaces are also removed from the hardware and the state is marked as failed.

VLAN Translation

VLAN translation allows you to map packets from one VLAN to another. This can be carried out only on packets having a dot1q header (tagged frames). The translation rewrites the Vlan ID field (VID) in dot1q headers on packets passing through a switched port without changing any other fields.

VLAN translation also supports the ability to translate packets with a dot1q header to the internal VLAN for a routed port. The VLAN in the incoming packets is mapped to the internal VLAN of the routed port and packets egressing the routed port are encapsulated with a dot1q header for the specified VLAN. For egress packets, no priority information is added to the dot1q header and the priority from the incoming encapsulation will be retained.

When configuring the VLAN translation mode, consider the following:

  • VLAN translation is only supported for tagged packets.
  • BPDUs from STP, LLDP and other protocols are not affected by this mapping.
  • VLAN translation is not applicable for access ports.
  • Untagged packets entering the switch on the trunk native VLAN are not mapped.
  • TPID and VLAN priority does not get re-written during the translation.

VLAN Configuration Procedures

These sections describe basic VLAN configuration tasks.
  • Creating and Configuring VLANs
  • Configuring VLAN Switching
  • Creating and Configuring VLAN Interfaces
  • Allocating Internal VLANs
  • Configuring Private VLANs
  • Configuring VLAN Translation
  • Configuring VLAN Counters

Creating and Configuring VLANs

The CLI provides two methods of creating VLANs.
  • Explicitly through the vlan command.
  • Implicitly through the switchport access vlan command.

The switchport access vlan command generates a warning message when it creates a VLAN.

To create a VLAN, use the vlan command in global configuration mode. Valid VLAN numbers range between 1 and 4094. To create multiple VLANs, specify a range of VLAN numbers.

To edit an existing VLAN, enter the vlan command with the number of the existing VLAN.

Examples
  • This command creates VLAN 45 and enters VLAN configuration mode for the new VLAN.
    switch(config)# vlan 45
    switch(config-vlan-45)#

  • Use the name (VLAN configuration mode) command to assign a name to a VLAN.

    These commands assign the name Marketing to VLAN 45.

    switch(config)# vlan 45
    switch(config-vlan-45)# name Marketing
    switch(config-vlan-45)# show vlan 45
    
    VLAN Name                             Status    Ports
    ---- -------------------------------- --------- -------
    45   Marketing                        active    Et1
    
    switch(config-vlan-45)#

  • To change the state of a VLAN, use the state command in VLAN configuration mode.
    These commands suspend VLAN 45. VLAN traffic is blocked on all switch ports.
    switch(config)# vlan 45
    switch(config-vlan-45)# state suspend
    switch(config-vlan-45)# show vlan 45
    
    VLAN Name                             Status    Ports
    ---- -------------------------------- --------- ------
    45   Marketing                        suspended
    
    switch(config-vlan-45)#

  • These commands activate VLAN 45.
    switch(config)# vlan 45 
    switch(config-vlan-45)# state active
    switch(config-vlan-45)# show vlan 45
    
    VLAN Name                             Status    Ports
    ---- -------------------------------- --------- ------
    45   Marketing                        active    Et1
    
    switch(config-vlan-45)#

VLAN Policy

The VLAN policy configuration command enables a switch to configure a VLAN policy when it receives a packet with unknown destination MAC address on a VLAN. The mac address forwarding command provides three options to configure a VLAN policy:
  • Flood the Layer 2 miss packets on the VLAN
  • Drop the Layer 2 miss packets
  • Log the Layer 2 miss packets to the CPU (while still flooding them on the VLAN)

The default behavior is to flood the L2 miss packets on all ports of the VLAN.

VLAN policy configuration is supported on the Arista 7010, 7050 (excluding 7050SX3-48YC12, 7050CX3-32S, 7050QX2-32S, 7050SX2-72Q, 7050SX2-128, 7050TX2-128), 7060, 7250, and the 7300 series platforms.

VLAN policy is not supported in the following cases:
  • STP, LLDP, and LACP packets
  • VLAN policy configurations on VXLAN-enabled VLAN
  • On a VLAN if IGMP snooping is configured with Multicast miss action is set to drop, then all multicast packets received on that VLAN are dropped.

Examples
  • These commands create a vlan 333 and then set the unicast policy to ‘drop’ and the multicast policy to ‘log’ for the specific vlan 333.
    switch(config)# vlan 333
    switch(config-vlan-333)# mac address forwarding unicast miss action drop
    switch(config-vlan-333)# mac address forwarding multicast miss action log

  • These commands display the VLAN policy that was defined when vlan 333 is created.
    switch(config)# show vlan 333 mac address forwarding
    
    VLAN  UcMissAction  McMissAction
    ----  ------------  ------------
     333  flood         flood

  • These commands display the VLAN policy type that was defined when vlan 333 is configured with the ‘drop’ unicast policy and the ‘log’ multicast policy.
    switch(config)# show vlan 333 mac address forwarding
    
    VLAN  UcMissAction  McMissAction
    ----  ------------  ------------
     333  drop          log
    
    switch(config)# show vlan mac address forwarding
     
    VLAN  UcMissAction  McMissAction
    ----  ------------  ------------
       1  flood         flood
     333  drop          log

Configuring VLAN Switching

The following describe the configuration of VLAN ports.

Access Ports

Access ports carry traffic for one VLAN, as designated by a switchport access vlan command. Access ports associate untagged frames with the access VLAN. Tagged frames received by the interface are dropped unless they are tagged with the access VLAN.

To configure an interface group as an access port, use the switchport mode command.

Examples
  • These commands configure interface ethernet 1 as an access port.
    switch(config)# interface ethernet 1
    switch(config-if-Et1)# switchport mode access
    switch(config-if-Et1)#

  • To specify the port’s access VLAN, use the switchport access vlan command.
    These commands configure vlan 15 as the access VLAN for interface ethernet 5.
    switch(config)# interface ethernet 5
    switch(config-if-Et5)# switchport access vlan 15
    switch(config-if-Et5)#

  • These commands configure interface Ethernet 1 through 3 as access ports that process untagged frames as vlan 5 traffic.
    switch(config)# interface Ethernet 1-3
    switch(config-if-Et1-3)# switchport mode access
    switch(config-if-Et1-3)# switchport access vlan 5
    switch(config-if-Et1-3)# show interfaces ethernet 1-3 vlans
    Port       Untagged Tagged
    Et1        None     23,25
    Et2        18       -
    Et3        None     14
    switch(config-if-Et1-3)#

Dot1q Tunnel Ports

Dot1q (802.1Q) is a tunneling protocol that encapsulates traffic from multiple customer (c-tag) VLANs in an additional single outer service provider (s-tag) VLAN for transit across a larger network structure that includes traffic from all customers. Tunneling eliminates the service provider requirement that every VLAN be configured from multiple customers, avoiding overlapping address space issues.

Tunneling preserves the inner VLANs through the tunneled network and these inner VLANs are ignored by intermediate devices that make forwarding decisions based only on the outermost VLAN tag (S-Tag)

A dot1q-tunnel port sits at the edge of the tunneled network. Unlike regular access ports, a dot1q-tunnel port does not drop traffic that arrives with 802.1Q tags in place; it ignores existing 802.1Q information and associates arriving traffic (with or without 802.1Q headers) with a new tunnel VLAN ID.

Packets arriving at a tunnel port are encapsulated with an additional 802.1Q tag that can be trunked between multiple devices like any traditional VLAN. When exiting a dot1-tunnel port, the S-Tag is removed to revert the customer traffic to its original tagged or untagged state.

Egress Priority Tagging allows a switch to send out priority tagged Ethernet frames in place of untagged frames. EOS sends priority tagged frames with the VLAN ID set to zero allowing downstream devices to read the 802.1p priority bits set in the VLAN header.

To configure an interface group as a dot1q tunnel port, use the switchport mode command.

Example

These commands configure interface ethernet 12 as a dot1q tunnel port.
switch(config)# interface ethernet 12
switch(config-if-Et12)# switchport mode dot1q-tunnel
switch(config-if-Et12)#

To specify the dot1q-tunnel port’s access VLAN, use the switchport access vlan command. The port then handles all inbound traffic as untagged VLAN traffic.

Example

These commands configure vlan 60 as the access VLAN for interface ethernet 12.
switch(config)# interface ethernet 12
switch(config-if-Et12)# switchport access vlan 60
switch(config-if-Et12)#

Use the following commands to configure egress priority tagging on Ethernet interface, 12 with VLAN 60:

switch(config)# interface ethernet 12
switch(config-if-Et12)# switchport dot1q priority tag transmit
switch(config-if-Et12)#

To disable the configuration, use the [no | default] version of the command:

switch(config-if-Et12)# no switchport dot1q priority tag transmit

EOS disables the feature by default.

TPID Configuration

The default Tag Protocol IDentifier (TPID, also called dot1q ethertype) on all switch ports is 0x8100. To configure a different TPID on a port, use the switchport dot1q ethertype command. This feature is available only on 7280E and 7500E platforms.

Note: If dot1q tunneling is enabled on the interface, a TPID configured on the interface becomes irrelevant.

Example

In this provider bridging example, interface ethernet 1 is the user network interface and interface ethernet 2 is the network-to-network interface. These commands configure dot1q tunneling on interface ethernet 1 and set the TPID of interface ethernet 2 to 0x9100.
switch(config)# interface ethernet 1
switch(config-if-Et1)# switchport mode dot1q-tunnel
switch(config-if-Et1)# interface ethernet 2
switch(config-if-Et2)# switchport mode trunk
switch(config-if-Et2)# switchport dot1q ethertype 0x9100
switch(config-if-Et2)#

In the above configuration, packets from Et1 to Et2 will undergo dot1q-tunneling (stacking of an additional dot1q tag), with an outer TPID of 0x9100 at egress, while packets with outer TPID 0x9100 going from Et2 to Et1 will have the outer tag removed at egress.

Layer 2 802.1Q Encapsulation

Layer 2 traffic encapsulation is enabled on the configuration mode interface for a specified VLAN through l2-protocol encapsulation dot1q vlan.

Example

These commands enable traffic encapsulation for vlan 200 traffic passing through interface ethernet 5/2.
switch(config)# interface ethernet 5/2
switch(config-if-Et5/2)# l2-protocol encapsulation dot1q vlan 200

Port VLAN Scaling on DCS-7160

Port VLAN scaling allows the user to configure a subset of ports in the scale mode. The switchport vlan forwarding command forwards packets between the ports belonging to VLAN in the interface configuration mode. Port-VLAN table is used for storing the configuration on a per port/VLAN combination. The scaling configuration is applicable on a per-port basis and supports a maximum of 128 ports.

Note: The configuration is applicable to trunk ports only.

Example
  • This command enables VLAN scaling on a port with an interface ethernet 2.
    switch# config terminal
    switch(config)# interface ethernet 2
    switch(config-if-Et2)# switchport vlan forwarding accept all

  • This command disables VLAN scaling on a port.
    switch# config
    switch(config)# interface ethernet 2
    switch(config-if-Et2)# no switchport vlan forwarding accept all

Creating and Configuring VLAN Interfaces

The interface vlan command places the switch in VLAN-interface configuration mode for modifying an SVI. An SVI provides a management address point and Layer 3 processing for packets from all VLAN ports.

Example

This command enters VLAN-interface configuration mode for vlan 12. The command also creates vlan 12 interface if it was not previously created.
switch# config t
switch(config)# interface vlan 12
switch(config-if-Vl12)#

Allocating Internal VLANs

The vlan internal order command specifies the VLANs that the switch allocates as internal VLANs when configuring routed ports and the order of their allocation. By default, the switch allocates VLANs in ascending order. The default allocation range is between VLAN 1006 and VLAN 4094.

The no switchport command converts an Ethernet or port channel interface into a routed port, disabling Layer 2 switching for the interface.

Examples
  • This command configures the switch to allocate internal VLANs in ascending order starting with 1006.
    switch(config)# vlan internal order ascending
    switch(config)#

  • This command configures the switch to allocate internal VLANs in descending order starting with 4094.
    switch(config)# vlan internal order descending
    switch(config)#

  • This command configures the switch to allocate internal VLANs in descending order from 4094 through 4000.
    switch(config)# vlan internal order descending range 4000 4094
    switch(config)#

Configuring Private VLANs

Configuring Private VLANs on Platforms with Algomatch Hardware

The following platforms contain algomatch hardware-based systems:

  • DCS-7280R
  • DCS-7280R2
  • DCS-7500R2
  • DCS-7020
On systems with algomatch hardware, the access-list mechanism must explicitly be set to TCAM using the following command.
switch(config)# hardware access-list mechanism tcam

To enable the private VLAN feature, you must also enable the forwarding-ID feature.
switch(config)# platform sand l2 forwarding-id sharing

Configuring TCAMs for Private VLANs

Support for private VLANs on the following platforms:
  • DCS-7280R3
  • DCS-7500R3
  • DCS-7800R3

Use the following commands to add private VLANs to these platforms:

switch(config)# hardware tcam
switch(config-tcam)# system profile private-vlan

OR

switch(config)# hardware tcam
switch(config-tcam)# profile pvlanprofile copy default
switch(config-tcam-profile-pvlanprofile)# feature private-vlan
switch(config-tcam-feature-private-vlan)# system profile pvlanprofile

Configuring Private VLANs On All Platforms

  • Any regular VLAN can act as a primary without any extra configuration, and requires an active VLAN. Use the following command to configure a VLAN as active or inactive:
    switch(config)# vlan 100
    switch(config)# no vlan 100
    switch(config)# default vlan 100

  • Configure VLANs as secondary inside the VLAN configuration mode. Use the configuration to specify the primary VLAN as isolated and the type of secondary VLAN:
    switch(config)# vlan 20
    switch(config-vlan-20)# private-vlan isolated primary vlan 10
    switch(config)# vlan 30
    switch(config-vlan-30)# private-vlan community primary vlan 10

    Figure 1. Support for Private VLANs

  • EOS assigns interfaces to primary or secondary VLANs in the same manner as regular VLANs. It works with both access and trunk ports. Use the following switchport command to configure an access interface to the secondary VLAN:
    switch(config)# interface ethernet 1/1
    switch(config-if-Et1/1)# switchport access vlan 20

  • Trunk ports forward any traffic within the allowed VLANs configured on the interface whether primary or secondary VLANs. To configure secondary trunk ports to translate traffic from the primary VLAN to the lowest numbered secondary VLAN, use the following commands on the switch:
    switch(config)# interface ethernet 1/1
    switch(config-if-Et1/1)# switchport trunk private-vlan secondary

Adding Promiscuous Trunk Ports

Promiscuous trunk ports translate traffic from the primary VLAN to the lowest numbered secondary VLAN. Use the following commands for a primary VLAN, VLAN10, with an isolated VLAN, VLAN20, and a community VLAN, VLAN30, on Ethernet interface, Et16/1, and create a promiscuous port:

switch(config)# int Et16/1
switch(config-if-Et16/1)#switchport mode trunk
switch(config-if-Et16/1)#switchport trunk allowed vlan 10,20,30
switch(config-if-Et16/1)#switchport vlan translation out 20,30 10

Removing a Private VLAN

  • The no private-vlan command reverts the VLAN back to a regular VLAN. At this point, the broadcast domain for this VLAN adjusts and all hosts start learning from the regular VLAN, as opposed to the primary VLAN. The switch no longer uses the MAC table entries learned previouslyon the primary VLAN for forwarding. To remove a private VLAN, use the following command.
    switch(config-vlan-20)# no private-vlan

  • To restore trunk port behavior to allow traffic on all primary and secondary VLANs, use the following commands:
    switch(config)# interface ethernet1/1
    switch(config-if-Et1/1)# no switchport trunk private-vlan secondary

Removing Private VLANs from Platforms with Algomatch Hardware

The following platforms contain algomatch hardware-based systems:

  • DCS-7280R
  • DCS-7280R2
  • DCS-7500R2
  • DCS-7020

To remove forwarding-id sharing from the configuration, use the following command:
switch(config)# no platform sand l2 forwarding-id sharing
Note: This configuration needs the device to be rebooted to take effect.

Disabling Private VLANs on TCAMs

Support for private VLANs on the following platforms:
  • DCS-7280R3
  • DCS-7500R3
  • DCS-7800R3

Disable the private VLAN on the TCAM profile of the switch using the following command:

switch(config)# hardware tcam
switch(config-tcam)# no system profile private-vlan

OR

switch(config)# hardware tcam
switch(config-tcam)# profile pvlanprofile
smv418(config-tcam-profile-pvlanprofile)# no system profile pvlanprofile

Configuring VLAN Translation

VLAN translation changes the VLAN ID of specified packets entering or leaving a port. The following sections describe the configuration of VLAN translation.

Per-port VLAN Translation on Switched Ports

The switchport vlan translation command allows translation of the VLAN tag of traffic entering or exiting a switched port.

To use VLAN translation on a switched port, the port must be configured as a trunk port using the switchport mode command.

Examples
  • This command configures interface ethernet 5 as a trunk port.

    switch(config)# interface ethernet 5
    switch(config-if-Et5)# switchport mode trunk
    switch(config-if-Et5)#

  • By default, the translation is bidirectional: packets ingressing an interface through vlan A are internally mapped to vlan B; vlan B packets egressing the same interface are mapped to vlan A.
    • These commands map interface ethernet 5 traffic with dot1q tag 50 to bridging vlan 60.
      switch(config)# interface ethernet 5
      switch(config-if-Et5)# switchport vlan translation 50 60
      switch(config-if-Et5)#

    • These commands provides multiple 1:1 VLAN mappings under an interface.
      switch(config)# interface ethernet 5
      switch(config-if-Et5)# switchport vlan translation 50 60
      switch(config-if-Et5)# switchport vlan translation 61 71
      switch(config-if-Et5)# switchport vlan translation 62 72
      switch(config-if-Et5)#

    • These commands translate only incoming packets.
      switch(config)# interface ethernet 5
      switch(config-if-Et5)# switchport vlan translation in 50 60
      switch(config-if-Et5)#

    • These commands translate only egress packets.
      switch(config)# interface ethernet 5
      switch(config-if-Et5)# switchport vlan translation out 60 50
      switch(config-if-Et5)#

Dropping VLAN Translations

Dropping Mismatched VLAN Translations on a Routed Port

On routed ports, the encapsulation dot1q vlan command, permitted only on routed ports, configures the VLAN on the interface to act as the native VLAN. This command maps packets ingressing with the specified VLAN ID to the internal VLAN ID of the routed port. All traffic egressing out of the routed port tagged with the VLAN ID specified in the command.

Example

These commands translate between vlan 50 and the internal VLAN for interface ethernet 5 (a routed port).
switch(config)# interface ethernet 5
switch(config-if-Et5)# no switchport
switch(config-if-Et5)#encapsulation dot1q vlan 50
switch(config-if-Et5)#
Dropping Unmatched VLAN Translations on an Interface

Configure an Ethernet interface to drop unmatched VLAN translation packets from ingress and egress ports.

Example

Use the following commands to drop invalid VLAN translations from Ethernet1:
switch(config)# interface Ethernet1
switch(config-if-Et2)# switchport vlan translation out required
switch(config-if-Et2)# switchport vlan translation in required

Double VLAN Translation

Double VLAN translation creates mappings between an inner and outer VLAN ID pair of a double-tagged packet and a single bridging VLAN. On ingress, specified double-tagged packets are mapped to the bridging VLAN, and on egress packets with the ID of the bridging VLAN are double tagged as specified. By default, the translation is bidirectional, but it can be applied only on ingress or egress.

Example

These commands causes packets entering interface ethernet 3/1 with an outer VLAN ID of 1000 and an inner VLAN ID of 100 to be processed in bridging vlan 200.
switch(config)# interface ethernet 3/1
switch(config-if-Et3/1)# switchport vlan translation in 1000 inner 100 200
switch(config-if-Et3/1)#

Configuring VLAN Counters

Add VLAN ingress and egress counters that provide the ability to count packets and bytes ingressing or egressing a bridge domain for a VLAN.

Note: Only R Series platforms support this configuration.

Use the following commands to add VLAN ingress and egress counters to the switch:

switch(config)# hardware counter feature vlan in
switch(config)# hardware counter feature vlan out

To display the configuration, use the show hardware counter.

switch(config)# show hardware counter feature
Feature         Direction  Counter Resource (Engine) Status   Detail
--------------- ---------- ------------------------- -------- ------------------------------
Queue           out        Jericho2C+: 16            up       Not user-configurable.
VLAN            out        Jericho2C+: 2             up
VLAN            in         Jericho2C+: 1             up
VOQ             in         Jericho2C+: 0, 8          up       Not user-configurable.

Verify the counter status using the show vlan counters command.

switch# show vlan counters
Vlan                 InOctets          InPkts
Vlan1                       0               0
Vlan100                   186               2
Vlan200                     0               0
Vlan300                    64               1
       
       
Vlan                OutOctets         OutPkts
Vlan1                       0               0
Vlan100                     0               0
Vlan200                   114               1
Vlan300                    70               1

To clear the counter status, use the following command:

switch(config)# clear vlan counters
switch(config)# show vlan counters
            
Vlan                 InOctets          InPkts
Vlan1                       0               0
Vlan100                     0               0
Vlan200                     0               0
Vlan300                     0               0
            
            
Vlan                OutOctets         OutPkts
Vlan1                       0               0
Vlan100                     0               0
Vlan200                     0               0
Vlan300                     0               0

VLAN Configuration Commands

Global VLAN Configuration Commands

  • interface vlan
  • vlan
  • vlan internal order

VLAN Configuration Mode Commands

  • mac address forwarding
  • name (VLAN configuration mode)
  • state
  • trunk group

Layer 2 Interface (Ethernet and Port Channel) Configuration Commands

  • switchport access vlan
  • switchport dot1q ethertype
  • switchport mode
  • switchport trunk allowed vlan
  • switchport trunk group
  • switchport trunk native vlan
  • switchport vlan forwarding
  • switchport vlan translation
  • switchport vlan translation required

VLAN Interface Configuration Mode Commands

  • autostate
  • encapsulation dot1q vlan
  • l2-protocol encapsulation dot1q vlan
  • pvlan mapping

Show Commands

  • show dot1q-tunnel
  • show interfaces switchport
  • show interfaces switchport backup-link
  • show interfaces switchport vlan mapping
  • show interfaces trunk
  • show interfaces vlans
  • show pvlan mapping interfaces
  • show vlan
  • show vlan brief count
  • show vlan counters
  • show vlan dynamic
  • show vlan internal allocation policy
  • show vlan internal usage
  • show vlan trunk group

autostate

When autostate is enabled, the VLAN interface will be up when:
  • the corresponding VLAN exists and is in the active state.
  • one or more Layer 2 ports in the VLAN are up and in spanning-tree forwarding state.
  • the VLAN interface exists and is not in a shutdown state.

Autostate is enabled by default. When autostate is disabled, the VLAN interface is forced to be active.
  • The no autostate command disables autostate on the configuration mode interface. The no autostate command is stored to running-config.

  • The autostate command enables the autostate function on the configuration mode VLAN SVI by removing the corresponding no autostate statement from running-config.

  • The default autostate command restores the autostate default state of enabled by removing the corresponding no autostate statement from running-config.

Command Mode

Interface-VLAN Configuration

Command Syntax

autostate

no autostate

default autostate

Guidelines

Autostate should be disabled on SVIs configured as an MLAG local interface.

Examples
  • These commands disable autostate on vlan 100.
    switch(config)# interface vlan 100
    switch(config-if-Vl100)# no autostate
    switch(config-if-Vl100)#

  • These commands enable autostate on vlan 100.
    switch(config)# interface vlan 100
    switch(config-if-Vl100)# autostate
    switch(config-if-Vl100)#

encapsulation dot1q vlan

Routed Port VLAN Translation

In the configuration mode for an Ethernet or port channel interface, the encapsulation dot1q vlan translates packets with a dot1q header to the internal VLAN for a routed port. The VLAN in the incoming packets is mapped to the internal VLAN of the routed port, and packets egressing the routed port are encapsulated with a dot1q header for the specified VLAN. For egress packets, no priority information is added to the dot1q header and the priority from the incoming encapsulation will be retained.

Subinterface VLAN Assignment

When used in the configuration mode for an Ethernet or port channel subinterface, however, the encapsulation dot1q vlan command assigns a dot1q tag to the subinterface. Traffic ingressing on the parent interface with that dot1q tag will then be sent to the configured subinterface. See Subinterfaces and Subinterface Configuration for details.

The no encapsulation dot1q vlan and default encapsulation dot1q vlan commands restore the default VLAN to the configuration mode interface by removing the corresponding encapsulation dot1q vlan command from running-config.

Command Mode

Interface-Ethernet Configuration

Interface-port-channel Configuration

Subinterface-Ethernet Configuration

Subinterface-port-channel Configuration

Command Syntax

encapsulation dot1q vlan vlan_id

no encapsulation dot1q vlan

default encapsulation dot1q vlan

Parameter

vlan_id For VLAN translation, the ID of the external VLAN to be translated; for subinterface configuration, the VLAN of the subinterface. Values range from 1 to 4094.

Examples
  • These commands translate between vlan 50 and the internal VLAN for interface ethernet 5 (a routed port).
    switch(config)# interface ethernet 5
    switch(config-if-Et5)# no switchport
    switch(config-if-Et5)# encapsulation dot1q vlan 50
    switch(config-if-Et5)#

  • These commands assign packets ingressing on interface ethernet 1/1 with vlan ID 100 to subinterface ethernet 1/1.1.
    switch(config)# interface ethernet1/1.1
    switch(config-if-Et1/1.1)# no switchport
    switch(config-if-Et1/1.1)# encapsulation dot1q vlan 100
    switch(config-if-Et1/1.1)#

interface vlan

The interface vlan command places the switch in VLAN-interface configuration mode for modifying parameters of the Switch Virtual Interface (SVI). An SVI provides Layer 3 processing for packets from all ports associated with the VLAN. There is no physical interface for the VLAN.

When entering configuration mode to modify existing SVIs, the command can specify multiple interfaces. The command creates an SVI if the specified interface does not exist prior to issuing the command. When creating an SVI, the command can only specify a single interface.

The no interface vlan command deletes the specified SVI interfaces from running-config. The default interface vlan commands remove all configuration statements for the specified SVI interfaces from running-config without deleting the interfaces.

Command Mode

Global Configuration

Command Syntax

interface vlan v_range

no interface vlan v_range

default interface vlan v_range

Parameter

v_range     VLAN interfaces (number, range, or comma-delimited list of numbers and ranges). VLAN number ranges from 1 to 4094.

Restrictions

Internal VLANs: A VLAN interface cannot be created or configured for internal VLAN IDs. The switch rejects any interface vlan command that specifies an internal VLAN ID.

Example

This example creates an SVI for vlan 12:

switch# config
switch(config)# interface vlan 12
switch(config-if-Vl12)#

l2-protocol encapsulation dot1q vlan

The l2-protocol encapsulation dot1q vlan command enables Layer 2 802.1Q traffic encapsulation on the configuration mode interface for a specified VLAN. The default VLAN for all interfaces is VLAN 1.

The no l2-protocol encapsulation dot1q vlan and default l2-protocol encapsulation dot1q vlan commands disable the specified encapsulation on the configuration mode interface by removing the corresponding l2-protocol encapsulation dot1q vlan command from running-config.

Command Mode

Interface-Ethernet Configuration

Interface-Port-channel Configuration

Command Syntax

l2-protocol encapsulation dot1q vlan vlan_id

no l2-protocol encapsulation dot1q vlan

default l2-protocol encapsulation dot1q vlan

Parameter

vlan_id  the ID of the native VLAN. Values range from 1 to 4094.

Example

These commands enable 802.1Q encapsulation of traffic on vlan 200.

switch(config)# interface ethernet 5/2
switch(config-if-Et5/2)# l2-protocol encapsulation dot1q vlan 200
switch(config-if-Et5/2)# show active
interface Ethernet5/2
   l2-protocol encapsulation dot1q vlan 200
switch(config-if-Et5/2)#

mac address forwarding

The mac address forwarding command enables a switch to configure a VLAN policy when it receives a packet with an unknown destination MAC address on a VLAN. The command provides three options to configure a VLAN policy:
  • Flood the Layer 2 miss packets on the VLAN
  • Drop the Layer 2 miss packets
  • Log the Layer 2 miss packets to the CPU (while still flooding them on the VLAN)

The default state behavior floods the L2 miss packets on all ports of the VLAN.

The show vlan command displays information about the configured VLAN policy.

The no form and the default form of the command removes the previously configured VLAN policy on the VLAN.

Command Mode

VLAN Configuration

Command Syntax

mac address forwarding [unicast | multicast] miss action [drop | flood | log]

no mac address forwarding [unicast | multicast] miss action [drop | flood | log]

default mac address forwarding [unicast | multicast] miss action [drop | flood | log]

Parameters
  • unicast - Specify the unicast type of transmission.
  • multicast - Specify the multicast type of transmission.
  • drop - Specify the selected packets to drop.
  • flood - Specify the selected packets to flood in the specific VLAN.
  • log - Specify the selected packets to send to the CPU for logging purpose.

Guidelines

EOS does not support VLAN policy in the following cases:
  • STP, LLDP, and LACP packets
  • VLAN policy configurations on VXLAN-enabled VLAN
  • On a VLAN if IGMP snooping with Multicast miss action set to drop, then drops all multicast packets received on that VLAN.

Examples
  • These commands create a vlan 333 and then set the unicast policy to drop and the multicast policy to log for the specific vlan 333.
    switch(config)# vlan 333
    switch(config-vlan-333)# mac address forwarding unicast miss action drop
    switch(config-vlan-333)# mac address forwarding multicast miss action log

  • These commands display the VLAN policy defined when creating vlan 333.
    switch(config)# show vlan 333 mac address forwarding
    
    VLAN  UcMissAction  McMissAction
    ----  ------------  ------------
     333  flood         flood

  • These commands display the VLAN policy type defined when configuring vlan 333 with the drop unicast policy and the log multicast policy.
    switch(config)# show vlan 333 mac address forwarding
    
    VLAN  UcMissAction  McMissAction
    ----  ------------  ------------
     333  drop          log
    
    switch(config)#show vlan mac address forwarding
    
    VLAN  UcMissAction  McMissAction
    ----  ------------  ------------
       1  flood         flood
     333  drop          log

name (VLAN configuration mode)

The name command configures the VLAN name. The name can have up to 32 characters. The default name for VLAN 1 is default. The default name for all other VLANs is VLANxxxx, where xxxx is the VLAN number. The default name for vlan 55 is VLAN0055. The show vlan command displays the VLAN name.

The name command accepts all characters except the space.

The no name and default name commands restore the default name by removing the name command from running-config.

Command Mode

VLAN Configuration

Command Syntax

name label_text

no name

default name

Parameter

label_text     character string assigned to name attribute. Maximum length is 32 characters. The space character is not permitted in the name string.

Example

These commands assign corporate_100 as the name for vlan 25, then displays the VLAN name.

switch(config)# vlan 25
switch(config-vlan-25)# name corporate_100
switch(config-vlan-25)# show vlan 25
VLAN  Name                             Status    Ports
----- -------------------------------- --------- ---------
25    corporate_100                    active

switch(config-vlan-25)#

pvlan mapping

The pvlan mapping command maps a Switch Virtual Interface (SVI) available in the primary VLAN to the secondary VLAN or VLANs in the VLAN configuration mode. The show pvlan mapping interfaces command displays the list of mapped VLANs.

The no pvlan mapping and default pvlan mapping commands restore the default state of the private VLAN mapping.

Command Mode

VLAN Configuration

Command Syntax

pvlan mapping {add | remove | vlan ID}

no pvlan mapping {add | remove | vlan ID}

default pvlan mapping {add | remove | vlan ID}

Parameters
  • add     adding VLANs to the PVLAN mapping of the current VLAN interface.
  • remove     removing VLANs from the PVLAN mapping of the current VLAN interface.
  • vlan ID     The secondary VLAN IDs of the private VLAN mapping. The IDs range from 1 to 4094.

Related Commands

show pvlan mapping interfaces

Example

These commands assign a secondary VLAN ID of 50 to the primary VLAN.

switch(config)# vlan 25
switch(config-vlan-25)# pvlan mapping 50
switch(config-vlan-25)#

show dot1q-tunnel

The show dot1q-tunnel command displays the ports that are configured in dot1q-tunnel switching mode. The switchport mode command configures the switching mode for the configuration mode interface.

Command Mode

EXEC

Command Syntax

show dot1q-tunnel [INTERFACE]

Parameters

INTERFACE     Interface type and numbers. Options include:
  • no parameter     Display information for all interfaces.
  • ethernet e_range     Ethernet interface range specified by e_range.
  • loopback l_range     Loopback interface specified by l_range.
  • management m_range     Management interface range specified by m_range.
  • port-channel p_range     Port-Channel Interface range specified by p_range.
  • vlan v_range     VLAN interface range specified by v_range.
  • VXLAN vx_range     VXLAN interface range specified by vx_range.

    Valid range formats include number, number range, or comma-delimited list of numbers and ranges.

Example

This command displays the ports that are configured in dot1q-tunnel switching mode.

switch> show dot1q-tunnel
dot1q-tunnel mode LAN Port (s)
------------------------------
Po4
Po21
Po22
switch>

show interfaces switchport backup-link

The show interfaces switchport backup-link command displays interfaces that are configured as switchport backup pairs and the operational status of each interface. For each pair, the command displays the names, roles, status, and VLAN traffic of each interface.

Command Mode

EXEC

Command Syntax

show interfaces [INTERFACE] switchport backup-link

show interfaces switchport backup-link [module {Fabric f_num | Linecard lc_num | Supervisor svr_num | Switchcard | 1-2 | 3-6 }]

Parameters
  • INTERFACE     Interface type and numbers. Options include:
    • no parameter     Display information for all interfaces.
    • ethernet e_range     Ethernet interface range specified by e_range.
    • loopback l_range     Loopback interface specified by l_range.
    • management m_range     Management interface range specified by m_range.
    • port-channel p_range     Port-Channel Interface range specified by p_range.
    • vlan v_range     VLAN interface range specified by v_range.

      Valid e_range, l_range, m_range, p_range, and v_range formats include number, number range, or comma-delimited list of numbers and ranges.

  • module     Displays interfaces of the specified module. Options include:
    • Fabric f_num     Displays interfaces of the specified fabric module. Value ranges from 1 to 6.
    • Linecard lc_num     Displays interfaces of the specified linecard module. Value ranges from 3 to 6.
    • Supervisor svr_num     Displays interfaces of the specified supervisor module. Accepted values are 1 and 2.
    • Switchcard     Displays interfaces of switchcard modules.
    • 1-2     Displays interfaces of the specified supervisor module.
    • 3-6     Displays interfaces of the specified linecard module.

Display Values
  • State     Operational status of the interface. Values include:
    • Up     Spanning tree mode is backup, interface status is up.
    • Down      Spanning tree mode is backup, interface status is down.
    • Inactive Configuration     The spanning tree mode is not backup.

  • Forwarding vlans      VLANs forwarded by the interface. Depends on interface operation status and prefer option specified by the switchport backup command.

Examples
  • This command displays the configured switchport primary-backup pairs.
    switch> show interfaces switchport backup-link
    Switch backup interface pair: Ethernet3/17, Ethernet3/8
    Primary Interface: Ethernet3/17     State:  Inactive Configuration
    Backup Interface:  Ethernet3/8      State:  Inactive Configuration
    Preemption delay: 0 milliseconds
    Mac move burst size: 0
    Mac move burst interval: 20 milliseconds
    Mac move destination: ff:ff:ff:ff:ff:ff

  • This command displays interfaces of the module for linecard 4.
    switch(config)# show int switchport backup-link module Linecard 4
    Switch backup interface pair: Ethernet4/19/1, Ethernet4/19/2
    Primary Interface: Ethernet4/19/1   State:  Inactive Configuration
    Backup Interface:  Ethernet4/19/2   State:  Inactive Configuration
    Preemption delay: 0 milliseconds
    Mac move burst size: 0
    Mac move burst interval: 20 milliseconds
    Mac move destination: ff:ff:ff:ff:ff:ff

show interfaces switchport vlan mapping

The show interfaces switchport vlan mapping command displays mapping information of the configured VLANs in an interface mode.

Command Mode

EXEC

Command Syntax

show interfaces switchport vlan mapping

Examples
  • This command displays mapping information of the configured VLAN IDs.
    switch# show interfaces switchport vlan mapping
    --------------
    Ethernet3
                                       Direction   Direction
    Original Vlan  New Vlan  Status    Configured  Active
    -------------- --------- --------- ----------- -----------
    10             100       Active    In/Out      In/Out
    11             200       Active    In          In
    300            12        Active    Out         Out

  • This command displays dual tag mapping information of the configured VLAN IDs.
    switch(config)# show interfaces switchport vlan mapping
    --------------
    Ethernet3/1
    Direction     Direction
    Outer Tag     Inner Tag     VLAN ID     Status      Configured    Active Dot1  qTunnel
    -----------   -----------   ---------   ---------   -----------   -----------  -----------
    1000          100           200         active        In/Out        In/Out      -
    
    1001          101           201         active        In            In          -
    
    1002          102           202         active        Out           Out          -

  • This command displays dual tag mapping information of the configured VLAN IDs.
    switch(config)# show interfaces switchport vlan mapping
    --------------
    Ethernet1/1
                                                       Direction     Direction 
    Outer Tag    Inner Tag     VLAN ID     Status      Configured    Active         
    ----------- -----------   ---------   ---------   -----------   ----------- 
    70            -             300         Active      In/Out        In/Out             
    10            50            100         Active      In/Out        In/Out            
    20            60            100         Active      In            In                
    30            40            200         Active      Out           Out                

show interfaces switchport

The show interfaces switchport command displays the switching configuration and operational status of the specified ports.

Command Mode

EXEC

Command Syntax

show interfaces [INTERFACE] switchport

Parameters

INTERFACE     Interface type and numbers. Options include:
  • no parameter     Display the switching status for all interfaces.
  • ethernet e_range     Ethernet interface range specified by e_range.
  • loopback l_range     Loopback interface specified by l_range.
  • management m_range     Management interface range specified by m_range.
  • port-channel p_range     Port-Channel Interface range specified by p_range.
  • vlan v_range     VLAN interface range specified by v_range.

    Valid e_range, l_range, m_range, p_range, and v_range formats include number, number range, or comma-delimited list of numbers and ranges.

Examples
  • This command displays the switching status for all interfaces.
    switch(config)# show interface switchport
    Default switchport mode: access
    
    Name: Et5/1
    Switchport: Enabled
    Administrative Mode: static access
    Operational Mode: static access
    MAC Address Learning: enabled
    Access Mode VLAN: 1 (default)
    Trunking Native Mode VLAN: 1 (default)
    Administrative Native VLAN tagging: disabled
    Trunking VLANs Enabled: ALL
    Static Trunk Groups: 
    Dynamic Trunk Groups: 
    
    Name: Et5/2
    Switchport: Enabled
    Administrative Mode: static access
    Operational Mode: static access
    MAC Address Learning: enabled
    Access Mode VLAN: 1 (default)
    Trunking Native Mode VLAN: 1 (default)
    Administrative Native VLAN tagging: disabled
    Trunking VLANs Enabled: ALL
    Static Trunk Groups: 
    Dynamic Trunk Groups: 
    
    [...]
    
    switch(config)#

  • This command displays the switching status of port channel interfaces 21 and 22.
    switch> show interface port-channel 21-22 switchport
    Name: Po21
    Switchport: Enabled
    Administrative Mode: tunnel
    Operational Mode: tunnel
    Access Mode VLAN: 1 (inactive)
    Trunking Native Mode VLAN: 100 (VLAN0100)
    Administrative Native VLAN tagging: disabled
    Trunking VLANs Enabled: ALL
    Trunk Groups: foo
    
    Name: Po22
    Switchport: Enabled
    Administrative Mode: tunnel
    Operational Mode: tunnel
    Access Mode VLAN: 1 (inactive)
    Trunking Native Mode VLAN: 1 (inactive)
    Administrative Native VLAN tagging: disabled
    Trunking VLANs Enabled: ALL
    Trunk Groups:
    
    switch>

  • This command displays the configured status of VLAN scaling for the interface ethernet 2/1 port.
    switch# show interface Ethernet 2/1 switchport 
    Name: Ethernet 2/1
    Switchport: Enabled
    Administrative Mode: trunk
    Operational Mode: trunk
    MAC Address Learning: enabled
    Dot1q ethertype/TPID: 0x8100 (active)
    Dot1q VLAN Tag: Allowed
    Access Mode VLAN: 1 (default)
    Trunking Native Mode VLAN: 1 (default)
    Administrative Native VLAN tagging: disabled
    Trunking VLANs Enabled: ALL
    Static Trunk Groups: 
    Dynamic Trunk Groups: 
    Source interface filtering: enabled
    VLAN forwarding mode: allConfiguredVlans
    
    switch>

show interfaces trunk

The show interfaces trunk command displays configuration and status information for interfaces configured in switchport trunk mode.

Command Mode

EXEC

Command Syntax

show interfaces [INTERFACE] trunk

Parameters

INTERFACE     Interface type and numbers. Options include:
  • no parameter     Display information for all interfaces.
  • ethernet e_range     Ethernet interface range specified by e_range.
  • management m_range     Management interface range specified by m_range.
  • port-channel p_range     Port-Channel Interface range specified by p_range.

    Valid e_range, m_range, and p_range formats include number, number range, or comma-delimited list of numbers and ranges.

Example

This command displays the trunk status for all interfaces configured in switchport trunk mode.

switch> show interfaces trunk
Port            Mode            Status          Native vlan
Po1             trunk           trunking        1
Po2             trunk           trunking        1

Port            Vlans allowed
Po1             1-15
Po2             16-30

Port            Vlans allowed and active in management domain
Po1             1-10
Po2             21-30


Port            Vlans in spanning tree forwarding state
Po1             1-10
Po2             21-30

switch>

show interfaces vlans

The show interfaces vlans command displays a table that lists the VLANs that are carried by the specified interfaces. Interfaces that do not carry VLANs are not listed in the table. The table lists the untagged (native or access) and tagged VLANs for each interface.

Command Mode

EXEC

Command Syntax

show interfaces [INT_NAME] vlans

Parameters

INT_NAME     Interface type and number. Values include:
  • ethernet e_num     Ethernet interface specified by e_num.
  • management m_num     Management interface specified by m_num.
  • port-channel p_num     Port-Channel Interface specified by p_num.

Example

This command displays the VLANs carried by all L2 ports.
switch> show interfaces vlans
Port       Untagged Tagged
Et9        3910     -
Et11       3912     -
Et16       500      -
Et17       3908     -
Et18       3908     -
Po1        1        101-102,500,721,3000,
Po2        101      -
Po4        3902     -
Po5        3903     -
Po6        3992     -
Po7        661      -
Po8        3911     -

show pvlan mapping interfaces

The show pvlan mapping interfaces command displays information about the private VLAN mapping interfaces.

Command Mode

EXEC

Command Syntax

show pvlan mapping interfaces

Example

This command displays information about the private VLAN mapping interfaces.
switch(config)# int vlan 50
switch(config-if-Vl50)# pvlan mapping 70
switch(config-if-Vl50)# show pvlan mapping interfaces 
Interface    Secondary Vlans
---------    ---------------        
Vlan50       70 

show vlan

The show vlan command displays the VLAN ID, name, status, and member ports of all configured VLANs. The command only displays active ports by default; by specifying configured-ports, the command displays all ports that are members of a configured VLAN regardless of their activity status, including Ethernet ports that are members of a port channel.

Command Mode

EXEC

Command Syntax

show vlan [VLAN_LIST] [PORT_ACTIVITY]

Parameters
  • VLAN_LIST      List of VLANs displayed by command. Options include:
    • no parameter      all VLANs.
    • v_range     VLANs specified by v_range.
    • id v_range     VLANs specified by v_range.
    • name v_name     VLANs specified by the VLAN name v_name.

      v_range formats include number, number range, or comma-delimited list of numbers and ranges.

  • PORT_ACTIVITY      Ports listed in table. Options include:
    • no parameter      table displays only active ports (same as active-configuration option).
    • active-configuration      table displays only active ports.
    • configured-ports      table displays all configured ports.

Display Values
  • VLAN     The VLAN ID.
  • Name     The name of the VLAN.
  • Status     The status of the VLAN.
  • Ports     The ports that are members of the VLAN.

Examples
  • This command displays status and ports of VLANs 1-1000.
    switch> show vlan 1-1000
    VLAN  Name                     Status    Ports
    ----- ------------------------ --------- --------------
    1     default                  active    Po1
    184   fet.arka                 active    Cpu, Po1, Po2
    262   mgq.net                  active    PPo2, Po1
    512   sant.test                active    Cpu, Et16, Po1
    821   ipv6.net                 active    Cpu, Po1, Po7
    
    switch>

  • This command displays the list of all the member interfaces under each SVI.
    switch# show vlan
    VLAN  Name                     Status    Ports
    ----- ------------------------ --------- ----------------
    1     default                  active
    2148  VLAN2148                 active    Cpu, Et1, Et26
    2700  VLAN2700                 active    Cpu, Et18

show vlan brief count

The show vlan brief count command displays the number of VLANs that are configured on the switch.

Command Mode

EXEC

Command Syntax

show vlan brief count

Example

This command displays the number of VLANs on the switch.
switch> show vlan brief count
Number of existing VLANs           : 18

switch>

show vlan counters

Displays information about configured ingress and egress VLAN counters on the switch.

Configuration Mode

EXEC

Command Syntax

show vlan counters

Example

Use the following command to display VLAN counters configured on the switch:
switch# show vlan counters
Vlan                 InOctets          InPkts
Vlan1                       0               0
Vlan100                   186               2
Vlan200                     0               0
Vlan300                    64               1
                
                
Vlan                OutOctets         OutPkts
Vlan1                       0               0
Vlan100                     0               0
Vlan200                   114               1
Vlan300                    70               1

show vlan dynamic

The show vlan dynamic command displays the source and quantity of dynamic VLANs on the switch. Dynamic VLANs support VM Tracer monitoring sessions.

Command Mode

EXEC

Command Syntax

show vlan dynamic

Example

This command displays the source and quantity of dynamic VLANs on the switch.
switch> show vlan dynamic
Dynamic VLAN source       VLANS
vmtracer-poc              88
switch>

show vlan internal allocation policy

The show vlan internal allocation policy command displays the method the switch uses to allocate VLANs to routed ports. The vlan internal order command configures the allocation method.

The allocation method consists of two configurable components:
  • range: the list of VLANs that are allocated to routed ports.
  • direction: the direction by which VLANs are allocated (ascending or descending).

Command Mode

EXEC

Command Syntax

show vlan internal allocation policy

Example

This command displays the internal allocation policy.
switch> show vlan internal allocation policy
Internal VLAN Allocation Policy: ascending
Internal VLAN Allocation Range: 1006-4094
switch>

show vlan internal usage

The show vlan internal usage command shows the VLANs that are allocated as internal VLANs for routed ports.

A routed port is an Ethernet or port channel interface that is configured as a layer 3 interface. Routed ports do not bridge frames and are not members of any VLANs. Routed ports can have IP addresses assigned to them and packets are routed directly to and from the port.

When an interface is configured as a routed port, the switch allocates an SVI with a previously unused VLAN ID. The switch prohibits the configuration of VLANs with numbers corresponding to internal VLAN interfaces allocated to a routed port. VLAN interfaces corresponding to SVIs allocated to a routed port cannot be configured by VLAN interface configuration mode commands.

Command Mode

EXEC

Command Syntax

show vlan internal usage

Example

This command displays the VLANs that are allocated to routed ports.
switch> show vlan internal usage
1006  Ethernet3
1007  Ethernet4
switch>

show vlan trunk group

The show vlan trunk group command displays the trunk group membership of the specified VLANs.

Command Mode

EXEC

Command Syntax

show vlan [ VLAN_LIST ] trunk group

Parameters

VLAN_LIST      VLAN list. Options include:
  • no parameter      all VLANs.
  • v_range     VLANs specified by v_range.
  • id v_range     VLANs specified by v_range.
  • name v_name     VLANs specified by the VLAN name v_name.

Display Values
  • VLAN      VLAN ID.
  • Trunk Groups      Trunk groups associated with the listed VLANs.

Example

This command displays the trunk group membership of all configured VLANs.
switch> show vlan trunk group
VLAN     Trunk Groups
----     -------------------------------------
5
10       first_group
12
40       second_group
100      third_group
101      middle_group
102
200

switch>

state

The state command configures the VLAN transmission state of the configuration mode VLAN.
  • Active state: Ports forward VLAN traffic.
  • Suspend state: Ports block VLAN traffic.

The default transmission status is active.

The no state command restores the default VLAN transmission state to the configuration mode VLAN by removing the corresponding state command from running-config.

Command Mode

VLAN Configuration

Command Syntax

state OPERATION_STATE

no state

default state

Parameters

OPERATION_STATE      VLAN transmission state. Options include:
  • active     VLAN traffic is forwarded.
  • suspend      VLAN traffic is blocked.

Example

These commands suspend VLAN traffic on VLANs 100-102.
switch(config)# vlan 100-102
switch(config-vlan-100-102)# state suspend
switch(config-vlan-100-102)#

switchport access vlan

The switchport access vlan command specifies the access VLAN of the configuration mode interface. Ethernet or port channel interfaces that are in access mode are members of only the access VLAN. Untagged frames that the interface receives are associated with the access VLAN. Frames tagged with the access VLAN are also associated with the access VLAN. The interface drops all other tagged frames that it receives. By default, VLAN 1 is the access VLAN of all Ethernet and port channel interfaces.

An interface's access mode is effective only when the interface is in access mode or dot1q-tunnel mode, as specified by the switchport mode command. Interfaces in dot1q-tunnel mode handle inbound traffic as untagged traffic and associate all traffic with the access VLAN. Interfaces configured to switchport trunk mode maintain and ignore existing switchport access commands.

The no switchport access vlan and default switchport access vlan commands restore VLAN 1 as the access VLAN of the configuration mode interface by removing the corresponding switchport access vlan statement from running-config.

Command Mode

Interface-Ethernet Configuration

Interface-Port-channel Configuration

Command Syntax

switchport access vlan v_num

no switchport access vlan

default switchport access vlan

Parameter

v_num     number of access VLAN. Value ranges from 1 to 4094. Default is 1.

Example

These commands assign VLAN 100 as the access VLAN to interface ethernet 5.

switch(config)# interface ethernet 5
switch(config-if-Et5)# switchport access vlan 100
switch(config-if-Et5)#

switchport dot1q ethertype

The switchport dot1q ethertype command configures the tag protocol identifier (TPID, also known as a dot1q ethertype), of the configuration mode interface. By default, all switch ports use the standard TPID of 0x8100.

The no switchport dot1q ethertype and default switchport dot1q ethertype commands restore the TPID to 0x8100 by removing the corresponding switchport dot1q ethertype statement from running-config.

Command Mode

Interface-Ethernet Configuration

Command Syntax

switchport dot1q ethertype ethertype

no switchport dot1q ethertype

default switchport dot1q ethertype

Parameter

ethertype     ethertype number (TPID). Value ranges from 0x600 (1536) through 0xFFFF (65535), and can be entered in decimal or hexadecimal notation. Value is stored and displayed in hexadecimal form; the default value is 0x8100.

Example

These commands configure 0x9100 as the TPID of interface ethernet 5.

switch(config)# interface ethernet 5
switch(config-if-Et5)# switchport dot1q ethertype 0x9100
switch(config-if-Et5)#

switchport mode

The switchport mode command specifies the switching mode of the configuration mode interface. The switch supports five switching modes: access, trunk, dot1q-tunnel, tap, and tool.
  • Access switching mode: The interface is a member of one VLAN, called the access VLAN, as specified by the switchport access vlan command. Tagged frames received on the interface are dropped unless they are tagged with the access VLAN. Frames transmitted from the interface are always untagged.

  • Trunk switching mode: The interface may be a member of multiple VLANs, as configured by the switchport trunk allowed vlan command. Untagged traffic is associated with the interface's native VLAN, as configured with the switchport trunk native vlan command.

  • Dot1q-tunnel switching mode: The interface treats all inbound packets as untagged traffic and handles them as traffic of its access VLAN, as specified by the switchport access vlan command.

  • Tap mode: The interface operates as a tap port. Tap ports receive traffic for replication on one or more tool ports.The interface may be a member of multiple VLANs, as configured by the switchport tap allowed vlan command. Untagged traffic is associated with the interface's native VLAN, as configured with the switchport tap native vlan command.

Tap ports are in STP forwarding state and prohibit egress traffic. MAC learning, control plane interaction and traps for inbound traffic are disabled.

Tool mode: The interface operates as a tool port. Tool ports replicate traffic received by tap ports. The interface may be a member of multiple VLANs, as configured by the switchport tool allowed vlan command. MAC learning, control plane interaction and traps for inbound traffic are disabled.

Tool ports are in STP forwarding state and prohibit ingress traffic that uses port settings.

The status of switchport configured ports depends on the switch tap aggregation mode which can be viewed by using the mode command:
  • tap aggregation mode enabled: tap and tool ports are enabled. Switching ports are errdisabled.

  • tap aggregation mode disabled: tap and tool ports are errdisabled. Switching ports are enabled.

Adding Egress Priority Tagging

EOS supports Egress Priority Tagging that allows a switch to send out priority tagged Ethernet frames in place of untagged frames. EOS sends priority tagged frames with the VLAN ID set to zero allowing downstream devices to read the 802.1p priority bits set in the VLAN header.

Configure egress priority tagging in the following modes:

  • access
  • dot1q
  • trunk

When configured, access or native VLAN traffic leaving the interfaces has a priority tag.

The no switchport mode and default switchport mode commands return the configuration mode interface to its default setting as an access port by deleting the corresponding switchport mode command from running-config.

Command Mode

Interface-Ethernet Configuration

Interface-Port-channel Configuration

Command Syntax

switchport mode MODE_TYPE priority tag transmit

no switchport mode

default switchport mode

Parameters

MODE_TYPE - Specify the switching mode of the configuration mode: interfaces. Options include:
  • access access switching mode.
  • dot1q-tunnel dot1q-tunnel switching mode.
  • tap tap switching mode.
  • tool tool switching mode.
  • trunk trunk switching mode.
  • priority tag transmit - Specify priority tagged egress Ethernet frames.

Restrictions

Dot1q-tunnel switching mode is not available on Petra platform switches.

Tap aggregation (tap and tool modes) is available on FM6000 and Arad platform switches.

Example

These commands configure interface ethernet 4 as a trunk port.
switch(config)# interface ethernet 4
switch(config-if-Et4)# switchport mode trunk
switch(config-if-Et4)#

switchport trunk allowed vlan

The switchport trunk allowed vlan command creates or modifies the list of VLANs for which the configuration mode interface, in trunk mode, handles tagged traffic. By default, interfaces handle tagged traffic for all VLANs. Command settings persist in running-config without taking effect when the switch is in tap aggregation mode or the interface is not in trunk mode.

The no switchport trunk allowed vlan and default switchport trunk allowed vlan commands restore the trunk mode default allowed VLAN setting of all by removing the corresponding switchport trunk allowed vlan statement from running-config.

Command Mode

Interface-Ethernet Configuration

Interface-Port-channel Configuration

Command Syntax

switchport trunk allowed vlan EDIT_ACTION

no switchport trunk allowed vlan

default switchport trunk allowed vlan

Parameters

EDIT_ACTION     modifications to the VLAN list.
  • v_range     Creates VLAN list from v_range.
  • add v_range     Adds specified VLANs to current list.
  • all     VLAN list contains all VLANs.
  • except v_range     VLAN list contains all VLANs except those specified.
  • none     VLAN list is empty (no VLANs).
  • remove v_range     Removes specified VLANs from current list.

    Valid v_range formats include number, range, or comma-delimited list of numbers and ranges.

Example

These commands create the trunk mode allowed VLAN list of 6-10 for interface ethernet 14, then verifies the VLAN list.
switch(config)# interface ethernet 14
switch(config-if-Et14)# switchport trunk allowed vlan 6-10
switch(config-if-Et14)# show interfaces ethernet 14 switchport
Name: Et14
Switchport: Enabled
Administrative Mode: trunk
Operational Mode: trunk
Access Mode VLAN: 1 (inactive)
Trunking Native Mode VLAN: 1 (inactive)
Administrative Native VLAN tagging: disabled
Trunking VLANs Enabled: 6-10
Trunk Groups:

switch(config-if-Et14)#

switchport trunk group

The switchport trunk group command assigns the configuration mode interface to the specified trunk group. Trunk group ports handle traffic of the VLANs assigned to the group.

The no switchport trunk group and default switchport trunk group commands remove the configuration mode interface from the specified trunk group by deleting the corresponding statement from running-config. If the command does not specify a trunk group, the interface is removed from all trunk groups to which it is assigned.

Note: On platforms which support the use of port channels as mirror destinations, a port channel which is being used as a mirror destination must not be assigned to an MLAG.

Command Mode

Interface-Ethernet Configuration

Interface-Port-channel Configuration

Command Syntax

switchport trunk group [ group_name ]

no switchport trunk group [ group_name ]

default switchport trunk group [ group_name ]

Parameter

group_name    trunk group name.

Example

These commands assign port channel 4 to trunk group fe-1.
switch(config)# interface port-channel 4
switch(config-if-Po4)# switchport trunk group fe-1
switch(config-if-Po4)#

switchport trunk native vlan

The switchport trunk native vlan command specifies the trunk mode native VLAN for the configuration mode interface. Interfaces in trunk mode associate untagged frames with the native VLAN. Trunk mode interfaces can also be configured to drop untagged frames. The default native VLAN for all interfaces is VLAN 1.

The no switchport trunk native vlan and default switchport trunk native vlan commands restore vlan 1 as the trunk mode native VLAN to the configuration mode interface by removing the corresponding switchport trunk native vlan command from running-config.

Command Mode

Interface-Ethernet Configuration

Interface-Port-channel Configuration

Command Syntax

switchport trunk native vlan VLAN_ID

no switchport trunk native vlan

default switchport trunk native vlan

Parameters
  • VLAN_ID the ID of the native VLAN. Options include:
    • v_num VLAN number. Value ranges from 1 to 4094.
    • tag interface drops all untagged frames.

Example

These commands configure vlan 100 as the native VLAN for port channel 21.
switch(config)# interface port-channel 21
switch(config-if-Po21)# switchport trunk native vlan 100
switch(config-if-Po21)#

switchport vlan forwarding

The switchport vlan forwarding command forwards packets between the ports belonging to VLAN in the interface configuration mode. The scaling configuration is applicable on a per-port basis. In the 7160 platform, the hardware uses a Port-VLAN table for storing the configuration on a per port/VLAN combination and supports a maximum of 128 ports.

Note: The configuration is applicable to trunk ports only.

Command Mode

Interface-Ethernet Configuration

Command Syntax

switchport vlan forwarding [ accept | all ]

Parameters
  • accept     accepts packets for VLAN.
  • all      all VLANs.

Example

This command forwards and accepts all the packets of VLAN of interface ethernet 2.
switch(config)# interface ethernet 2
switch(config-if-Et2)# switchport vlan forwarding accept all
switch(config-if-Et2)#

switchport vlan translation

The switchport vlan translation command allows you to map packets from one VLAN to another using VLAN translation. This is carried out on packets having a dot1q header (tagged frames) only. The translation rewrites the VLAN ID (VID) field in dot1q headers on packets passing through a switched port without changing any other fields.

By default, the translation is bidirectional. The packets ingressing an interface through vlan A are internally mapped to vlan B; vlan B packets egressing the same interface are mapped to vlan A.

To use VLAN translation on a switched port, the port must be configured as a trunk port using the switchport mode command.

VLAN translation on routed ports is accomplished through the encapsulation dot1q vlan command.

The no switchport vlan translation and default switchport vlan translation commands remove VLAN mapping by removing the switchport vlan translation command from running-config.

Command Mode

Interface-Ethernet Configuration

Interface-Port-channel Configuration

Command Syntax

switchport vlan translation [DIRECTION] incoming_vlanid new_vlanid

no switchport vlan translation incoming_vlanid new_vlanid

no switchport vlan translation DIRECTION incoming_vlanid

default switchport vlan translation incoming_vlanid new_vlanid

default switchport vlan translation DIRECTION incoming_vlanid

Parameters
  • DIRECTION     direction of traffic to be translated.
    • no parameter     translates the specified VLAN IDs for transmitted and received traffic.
    • in     translates the specified VLAN IDs for received traffic only.
    • out     translates the specified VLAN IDs for transmitted traffic only.
    • incoming_vlanid     Enter the VLAN ID to be translated. Value ranges from 1 to 4094.

  • new_vlanid     The new VLAN ID or bridging VLAN ID that will be used internally. Value ranges from 1 to 4094.

Example
  • These commands translate only incoming packets, changing the VLAN ID to 2008 in the dot1q header of packets ingressing on vlan 201.
    switch(config)# interface ethernet 5
    switch(config-if-Et5)# switchport vlan translation in 201 2008 
    switch(config-if-Et5)#

  • These commands translate multiple VLAN mappings on an interface ethernet 5.
    switch(config)# interface ethernet 5
    switch(config-if-Et5)# switchport vlan translation 50 60
    switch(config-if-Et5)# switchport vlan translation 61 71
    switch(config-if-Et5)# switchport vlan translation 62 72
    switch(config-if-Et5)#

switchport vlan translation required

On routed ports, the switchport vlan translation required command (permitted only on routed ports) configures the VLAN on the interface to act as the native VLAN.

Command Mode

Interface-Ethernet Configuration

Command Syntax

switchport vlan translation [in | out] required

Parameters

  • in - Ingress packets without a matching VLAN drop from the port.
  • out - Egress packets without a matching VLAN drop from the port.

Examples
  • The following command places the switch in switchport configuration mode and sets the requirement that egress VLAN translations must match or drop from the port.
    switch(config)# interface Ethernet1
    switch(config-if-Et1)# switchport vlan translation out required

  • The following command places the switch in switchport configuration mode and sets the requirement that ingress VLAN translations must match or drop from the port.
    switch(config)# interface Ethernet1
    switch(config-if-Et1)# switchport vlan translation in required

trunk group

The trunk group command assigns the configuration mode VLAN to a specified trunk group.

A trunk group is the set of physical interfaces that comprise the trunk and the collection of VLANs whose traffic is carried on the trunk. The traffic of a VLAN that belongs to one or more trunk groups is carried only on ports that are members of trunk groups to which the VLAN belongs. Switchport commands specify the physical interfaces that carry trunk group traffic.

The no trunk group and default trunk group commands remove the configuration mode VLAN from the specified trunk group by removing the corresponding trunk group statement from running-config. If a trunk group is not specified, the commands remove the configuration mode VLAN from all trunk groups.

Command Mode

VLAN Configuration

Command Syntax

trunk group [name]

no trunk group [name]

default trunk group [name]

Parameter

name     a name representing the trunk group.

Example

These commands assigns vlan 49 to the trunk group mlagpeer:
switch(config)# vlan 49
switch(config-vlan-49)# trunk group mlagpeer
switch(config-vlan-49)#

vlan

The vlan command places the switch in VLAN configuration mode to configure a set of virtual LANs. The command creates the specified VLANs if they do not exist prior to issuing the command. A VLAN in use as an internal VLAN may not be created or configured. The switch rejects any vlan command that specifies an internal VLAN ID.

The default vlan and no vlan commands removes the VLAN statements from running-config for the specified VLANs.

The exit command returns the switch to global configuration mode.

Command Mode

Global Configuration

Command Syntax

vlan vlan_range

no vlan vlan_range

default vlan vlan_range

Parameter

vlan_range     VLAN list.

Formats include a name, number, number range, or comma-delimited list of numbers and ranges.

Commands Available in VLAN Configuration Mode
  • name (VLAN configuration mode)
  • state
  • trunk group

Guidelines

In MLAG configurations, VLANs operate as follows:
  • The VLAN must be configured identically on both MLAG peer switches.
  • The port-specific bridging configuration originates on the switch where the port is physically located. This configuration includes the switchport access VLAN, switchport mode (trunk or access), trunk-allowed VLANs, the trunk native VLAN, and the switchport trunk groups.

Example

This command creates vlan 49 and enters VLAN configuration mode for the new VLAN:

switch(config)# vlan 49
switch(config-vlan-49)#

vlan internal order

The vlan internal order command specifies the range that the switch can allocate as internal VLANs when configuring routed ports and the order of their allocation. By default, the switch allocates VLANs in ascending order from VLAN 1006 to VLAN 4094.

The no vlan internal order and default vlan internal order commands revert the policy to its default.

Command Mode

Global Configuration

Command Syntax

vlan internal order DIRECTION [RANGE_VLAN]

no vlan internal order

default vlan internal order

Parameters
  • DIRECTION     VLAN allocation number direction. Options include:
    • ascending     allocates internal VLANs from lower VLAN bound to upper VLAN bound.
    • descending     allocates internal VLAN from upper VLAN bound to lower VLAN bound.

  • RANGE_VLAN     allocation range. Options include:
    • no parameter     1006 (lower bound) to 4094 (upper bound).
    • range, lower, upper    specifies lower bound (lower) and upper bound (upper).

Examples
  • This command configures the switch to allocate internal VLANS from 3000 through 3999.
    switch(config)# vlan internal order ascending range 3000 3999
    switch(config)#

  • This command configures the switch to allocate internal VLANS from 4094 through 1006.
    switch(config)# vlan internal order descending
    switch(config)#

  • This command configures the switch to allocate internal VLANS from 4094 down through 4000.
    switch(config)# vlan internal order descending range 4000 4094
    switch(config)#

  • This command reverts the allocation policy to its default (ascending, between 1006 and 4094).
    switch(config)# no vlan internal order
    switch(config)#

..

EOS 4.36.2F User Manual - Link Layer Discovery Protocol

Link Layer Discovery Protocol

This section describes Link Layer Discovery Protocol (LLDP) configuration tasks. Refer to the command descriptions for information about commands used in this chapter.

Topics in this section include:
  • LLDP Introduction
  • LLDP Overview
  • LLDP Configuration Procedures
  • LLDP Configuration Commands

LLDP Introduction

Link Layer Discovery Protocol (LLDP) lets Ethernet network devices to advertise details about themselves, such as capabilities, identification, and device configurations to directly connected devices on the network that are also using LLDP.

LLDP Overview

LLDP is a discovery protocol that allows devices to advertise information about themselves to peer devices that are on the same physical LAN and store information about the network. LLDP allows a device to learn higher layer management reachability and connection endpoint information from adjacent devices.

Each switch with an active LLDP agent sends and receives messages on all physical interfaces enabled for LLDP transmission. These messages are sent periodically and are typically configured for short intervals to ensure that accurate information is always available. These messages are then stored for a configurable period of time, and contained within the received packet. The system discards the message information when it reaches the configured value. The system sends an advertisement only when a relevant change occurs in the switch. If information changes for any reason, the LLDP agent is notified and sends out and updates the new values.

LLDP Data Units

A single LLDP Data Unit (LLDPDU) is transmitted in a single 802.3 Ethernet frame. The basic LLDPDU includes a header and a series of Type-Length-Value elements (TLVs). Each TLV advertises different types of information, such as its device ID, type, or management addresses.

LLDP advertises the following TLVs by default:
  • port-description
  • system-capabilities
  • system-description
  • system-name
  • management-address
  • port-vlan

Transmission and Reception

Every device that uses LLDP has its own LLDP agent. The LLDP agent is responsible for the reception, transmission, and management of LLDP. When you enable LLDP on a port, the system enables the transmission and reception of LLDPDUs by default. However, the agent can be configured only to transmit or receive.

Transmission

When LLDP transmission is enabled, the LLDP agent advertises information about the switch to neighbors at regular intervals. Each transmitted LLDPDU contains the mandatory TLVs and any enabled optional TLVs.

Reception

When LLDP reception is enabled, the LLDP agent receives and stores advertised information from neighboring devices.

Storing LLDP Information

Whenever the switch receives a valid and current LLDP advertisement from a neighbor, it stores the information in a Simple Network Management Protocol (SNMP) Management Information Base (MIB).

Guidelines and Limitations

LLDP has the following configuration limitations:
  • LLDP must be enabled globally before enabling it on an interface.
  • LLDP is not supported on virtual interfaces.
  • LLDP can discover only one device per port.

LLDP Configuration Procedures

These sections describe the following configuration processes:
  • Enabling LLDP Globally
  • Enabling LLDP on an Interface
  • Optional LLDP Parameters
  • Clearing LLDP Statistics
  • Displaying LLDP Information

Enabling LLDP Globally

The lldp run command globally enables LLDP on the Arista switch. Once LLDP is enabled, the switch will transmit advertisements from the ports that are configured to send TLVs. The neighbor information table is populated as advertisements from the neighbors arrive on the ports.

Example

This command enables LLDP globally on the Arista switch.

switch(config)# lldp run
switch(config)#

Enabling LLDP on an Interface

When enabling LLDP, it is enabled on all interfaces by default. By using the lldp transmit and lldp receive commands, LLDP can be enabled or disabled on individual interfaces or configured to only send or only receive LLDP packets.

Examples
  • These commands enable interface ethernet port 3/1 to transmit LLDP packets.

    switch(config)# interface ethernet 3/1
    switch(config-if-Et3/1)# lldp transmit
    switch(config-if-Et3/1)#

  • These commands enable interface ethernet port 3/1 to receive LLDP packets.

    switch(config)# interface ethernet 3/1
    switch(config-if-Et3/1)# lldp receive 
    switch(config-if-Et3/1)#

Optional LLDP Parameters

The following sections describe these tasks:
  • Setting the LLDP Timer
  • Setting the LLDP Hold Time
  • Setting the LLDP Re-initialization Timer
  • Setting the IP Management Address to be used in the TLV
  • Selecting the LLDP TLVs
  • Configuring LLDP for Power over Ethernet

Setting the LLDP Timer

The lldp timer command specifies the time in seconds between LLDP updates sent by the switch.

Examples
  • This command specifies that the LLDP updates should be sent every 120 seconds.
    switch(config)# lldp timer 120
    switch(config)#

  • This command reverts the LLDP timer to its default value of 30 seconds.

    switch(config)# no lldp timer 120
    switch(config)#

Setting the LLDP Hold Time

The lldp hold-time command sets the amount of time a receiving device should retain the information sent by the device.

Examples
  • This command specifies that the receiving device should retain the information for 180 seconds before discarding it.
    switch(config)# lldp hold-time 180
    switch(config)#

  • This command reverts the LLDP hold time and to the default value of 120 seconds.
    switch(config)# no lldp hold-time 180
    switch(config)#

Setting the LLDP Re-initialization Timer

The lldp run command specifies the amount of time in seconds to delay the re-initialization attempt by the switch.

Example

This command specifies that the switch waits 10 seconds before attempting to re-initialize.
switch(config)# lldp timer reinitialization 10
switch(config)#

Setting the IP Management Address to be used in the TLV

The lldp management-address command specifies the IP management address or the IP address of the VRF interface in LLDP Type-Length-Value (TLV) triplets.

Example

This command specifies the IP management address to be used in the TLV.
switch(config)# lldp management-address ethernet 3/1
switch(config)#

Selecting the LLDP TLVs

The lldp tlv transmit command specifies which Type, Length, and Value (TLVs) elements include in LLDP packets. The no lldp tlv transmit command removes the TLV configuration.

Example

This command enables the system descriptions to be included in the TLVs.
switch(config)# lldp tlv transmit system-description
switch(config)#

Configuring LLDP for Power over Ethernet

Initial Power over Ethernet (PoE) power-level negotiation with a Powered Device (PD) takes place in hardware (see Configuring Power over Ethernet (PoE)). Once hardware negotiation has taken place, IEEE 802.3at Power Via MDI Type-Length-Value elements (TLVs) are included by default in LLDP packets sent to connected PDs to allow LLDP to negotiate power needs further. LLDP allows the switch to deal with more granular power requests from PDs, and also allows dynamic power-level setting. TLVs received from connected Power-Sourcing Equipment (PSE) are ignored.

Note: Power Via MDI TLVs are not sent (even when enabled) under the following circumstances:
  1. there is a user-configured power limit on the port, or
  2. hardware negotiation sets the power to higher than class 4 because IEEE 802.3bt, which increases the maximum power output for PoE, is not yet supported by LLDP.

To disable Power Via MDI TLVs globally, use the no lldp tlv transmit command and specify the Power Via MDI TLV. Hardware negotiation and manual power limits will remain in effect.

Example

This command disables the sending of Power Via MDI TLVs globally.
switch(config)# no lldp tlv transmit power-via-mdi
switch(config)#

To disable Power Via MDI TLVs on an individual interface, use the poe negotiation lldp disabled command. Hardware negotiation and manual power limits will remain in effect.

Example

These commands disable the sending of Power Via MDI TLVs on interface ethernet 5.
switch(config)# interface ethernet 5
switch(config-if-Et5)# poe negotiation lldp disabled
switch(config-if-Et5)#

New LLDP Fields Defined by IEEE 802.3at-2009
Arista switches do not support the following new LLDP/SNMP fields defined in IEEE standard 802.3at-2009:
  • Power type a LldpXdot3RemPowerType
  • Power source a LldpXdot3RemPowerSource
  • Power priority a LldpXdot3RemPowerPriority
  • PD requested power value a LldpXdot3RemPDRequestedPowerValue
  • PSE allocated power value a LldpXdot3RemPSEAllocatedPowerValue

Clearing LLDP Statistics

  • clear lldp counters
  • clear lldp table

Displaying LLDP Information

  • Viewing LLDP Global Information
  • Viewing LLDP Local Information
  • Viewing LLDP Neighbors
  • Viewing LLDP Traffic

Viewing LLDP Global Information

The show lldp command displays LLDP information.

Examples
  • This command displays global information about LLDP.
    switch# show lldp
    LLDP transmit interval      : 60 seconds
    LLDP transmit holdtime      : 120 seconds
    LLDP reinitialization delay : 2 seconds
    LLDP Management Address VRF : default
    Enabled optional TLVs:
      Port Description
      System Name
      System Description
      System Capabilities
      Management Address (Management0)
      IEEE802.1 Port VLAN ID
      IEEE802.3 Link Aggregation
      IEEE802.3 Maximum Frame Size
    Port       Tx Enabled  Rx Enabled
    Et3/1      Yes         Yes
    
    switch#

  • This command displays LLDP information.
    switch# show lldp ethernet interface 3/1
    LLDP transmit interval      : 30 seconds
    LLDP transmit holdtime      : 120 seconds
    LLDP reinitialization delay : 2 seconds
    LLDP Management Address VRF : default
    Enabled optional TLVs:
      Port Description
      System Name
      System Description
      System Capabilities
    switch#

Viewing LLDP Local Information

The show lldp local-info command displays the information contained in the LLDP TLVs to be sent about the local system.

Example

This command displays information contained in the TLVs about the local systems.
switch# show lldp local-info management 1   
Local System:
  - Chassis ID type: MAC address (4)
    Chassis ID     : 001c.730f.11a8
  - System Name: "switch.aristanetworks.com"
  - System Description: "Arista Networks EOS version 4.13.2F running on an Arista 
Networks DCS-7150S-64-CL"
  - System Capabilities : Bridge, Router
    Enabled Capabilities: Bridge

Interface Management1:
  - Port ID type: Interface name (5)
    Port ID     : "Management1"
  - Port Description: ""
  - Management Address Subtype: IPv4 (1)
    Management Address        : 172.22.30.154
    Interface Number Subtype  : ifIndex (2)
    Interface Number          : 999001
    OID String                :
  - IEEE802.1 Port VLAN ID: 0
  - IEEE802.1/IEEE802.3 Link Aggregation
    Link Aggregation Status: Not Capable (0x00)
    Port ID                : 0
  - IEEE802.3 Maximum Frame Size: 1518 bytes
switch(config)#

Viewing LLDP Neighbors

The show lldp neighbors command displays information about LLDP neighbors.

Examples
  • This command shows information about LLDP neighbors.
    switch# show lldp neighbor
    Last table change time   : 0:12:33 ago
    Number of table inserts  : 33
    Number of table deletes  : 0
    Number of table drops    : 0
    Number of table age-outs : 0
    
    Port      Neighbor Device ID             Neighbor Port ID           TTL
    Et3/1     tg104.sjc.aristanetworks.com   Ethernet3/2                120
    
    Ma1/1     dc1-rack11-tor1.sjc            1/1                        120

  • This command displays detailed information about the neighbor ethernet 3/1.
    switch# show lldp neighbor ethernet 3/1
    Last table change time   : 0:16:24 ago
    Number of table inserts  : 33
    Number of table deletes  : 0
    Number of table drops    : 0
    Number of table age-outs : 0
    
    Port      Neighbor Device ID             Neighbor Port ID           TTL
    Et3/1     tg104.sjc.aristanetworks.com   Ethernet3/2                120

Viewing LLDP Traffic

The show lldp counters command displays the LLDP traffic information for the switch.

Example

This command displays the LLDP counters on the switch.
switch# show lldp counters
Port          Tx Frames Tx Length Exceeded

Et20              69485                  0
Et21              69394                  0
Et22              69203                  0
Et23              57546                  0
Et24                  0                  0
Ma1               69665                  0
Port      Rx Frames     Rx Errors    Rx Discard  TLVs Discard  TLVs Unknown

Et20          69470             0             0             0             0
Et21          69383             0             0             0             0
Et22          69143             0             0             0             0
Et23          55370             0             0             0             0
Et24              0             0             0             0             0
Ma1           69078         69078             0         69078             0

LLDP Configuration Commands

Global Configuration Commands

  • lldp hold-time
  • lldp management-address
  • lldp management-address vrf
  • lldp receive packet tagged drop
  • lldp run
  • lldp timer
  • lldp timer reinitialization
  • lldp tlv transmit

Interface Configuration Commands – Ethernet Interface

  • lldp receive
  • lldp transmit
  • poe negotiation lldp disabled

Privileged EXEC Commands

  • clear lldp counters
  • clear lldp table

EXEC Commands

  • show lldp
  • show lldp counters
  • show lldp local-info
  • show lldp neighbors

clear lldp counters

The clear lldp counters command resets the LLDP counters to zero.

Command Mode

Privileged EXEC

Command Syntax

clear lldp counters [SCOPE]

Parameters

SCOPE Session affected by command. Options include:
  • no parameter command affects counters on all CLI sessions.
  • session clears LLDP counters for the current CLI session only.

Examples
  • This command resets all the LLDP counters to zero.
    switch(config)# clear lldp counters
    switch(config)#

  • This command resets only the LLDP counters for the current CLI session.
    switch(config)# clear lldp counters session
    switch(config)#

clear lldp table

The clear lldp table command clears neighbor information from the LLDP table.

Command Mode

Privileged EXEC

Command Syntax

clear lldp table

Example
This command clears neighbor information from the LLDP table.
switch(config)# clear lldp table
switch(config)#

lldp hold-time

The lldp hold-time command specifies the amount of time a receiving device should maintain the information sent by the device before discarding it.

Command Mode

Global Configuration

Command Syntax

lldp hold-time period

no lldp hold-time

default lldp hold-time

Parameters

period     The amount of time a receiving device should hold LLDPDU information before discarding it. Value ranges from 10 to 65535 second; default value is 120 seconds.

Examples
  • This command sets the amount of time before the receiving device discards LLDPDU information to 180 seconds.
    switch(config)# lldp hold-time 180
    switch(config)#

  • This command restores the hold-time to its default value of 120 seconds.
    switch(config)# no lldp hold-time 180
    switch(config)#

lldp management-address

The lldp management-address command enables the user to add the IP management address used for LLDP Type-Length-Value (TLV).

Command Mode

Global Configuration

Command Syntax

lldp management-address [INTERFACE]

no lldp management-address [INTERFACE]

default lldp management-address [INTERFACE]

Parameters

INTERFACE Interface type and number. Options include:
  • all     all interfaces.
  • ethernet e_num     Ethernet interface specified by e_num.
  • loopback l_num     Loopback interface specified by l_num.
  • management m_num     Management interface specified by m_num.
  • port-channel p_num     Port-Channel Interface specified by p_num.
  • vlan v_num     VLAN interface specified by v_num.

Examples
  • This command specifies the IP management address to be used in the TLV.
    switch(config)# lldp management-address ethernet 3/1
    switch(config)#

  • This command removes the IP management address used in the TLV.
    switch(config)# no lldp management-address ethernet 3/1
    switch(config)#

  • This command specifies that vlan200 is used in the TLV.
    switch(config)# lldp management-address vlan 200
    switch(config)#

  • This command removes the VLAN ID used in the TLV.
    switch(config)# no lldp management-address vlan 200
    switch(config)#

lldp management-address vrf

The lldp management-address vrf command enables the user to add the IP address of the VRF interface used in LLDP Type-Length-Value (TLV).

Command Mode

Global Configuration

Command Syntax

lldp management-address vrf VRF_INSTANCE

no lldp management-address vrf VRF_INSTANCE

default lldp management-address vrf VRF_INSTANCE

Parameter

VRF_INSTANCE     specifies the VRF instance.

Examples
  • This command specifies the management address VRF to be used in the TLV.
    switch(config)# lldp management-address vrf test 1
    switch(config)#

  • This command removes the management VRF used in the TLV.
    switch(config)# no lldp management-address vrf test 1
    switch(config)#

lldp receive

The lldp receive command enables LLDP packets on an interface. The no lldp receive command disables the acceptance of LLDP packets.

Command Mode

Interface-Ethernet configuration

Interface-Management configuration

Command Syntax

lldp receive

no lldp receive

default lldp receive

Examples
  • These commands enable the reception of LLDP packets on interface ethernet 4/1.
    switch(config)# interface ethernet 4/1
    switch(config-if-Et4/1)# lldp receive
    switch(config-if-Et4/1)#

  • These commands disable the reception of LLDP packets on interface ethernet 4/1.
    switch(config)# interface ethernet 4/1
    switch(config-if-Et4/1)# no lldp receive
    switch(config-if-Et4/1)#

lldp receive packet tagged drop

The lldp receive packet tagged drop command is a global configuration command and when configured, the LLDP ignores all the packets with VLAN-tag. By default, this command is disabled.

Command Mode

Global Configuration

Command Syntax

lldp receive packet tagged drop

Example

This command when configured, the LLDP ignores all the packets with VLAN-tag.
switch(config)# lldp receive packet tagged drop

lldp run

The lldp run command enables LLDP on the switch.

Command Mode

Global Configuration

Command Syntax

lldp run

no lldp run

default lldp run

Examples
  • This command enables LLDP globally on the switch.
    switch(config)# lldp run
    switch(config)#

  • This command disables LLDP globally on the switch.
    switch(config)# no lldp run
    switch(config)#

lldp timer reinitialization

The lldp timer reinitialization command sets the time delay in seconds for LLDP to initialize.

Command Mode

Global Configuration

Command Syntax

lldp timer reinitialization delay

no lldp timer reinitialization

default lldp timer reinitialization

Parameter

delay the amount of time the device should wait before re-initialization is attempted. Value ranges from 1 to 20 seconds; default value is 2 seconds.

Examples
  • This command specifies that the switch should wait 10 seconds before attempting to re-initialize.
    switch(config)# lldp timer reinitialization 10
    switch(config)#

  • This command restores the default initialization delay of 2 seconds.
    switch(config)# no lldp timer reinitialization 10
    switch(config)#

lldp timer

The lldp timer command specifies the amount of time a receiving device should maintain the information sent by the device before discarding it. The no lldp timer command removes the configured LLDP timer.

Command Mode

Global Configuration

Command Syntax

lldp timer transmission_time

no lldp timer

default lldp timer

Parameter

transmission_time the period of time at which LLDPDUs are transmitted. Values range from 5 to 32768 seconds; the default is 30 seconds.

Examples
  • This command configures a period of 180 seconds at which the LLDPDUs are transmitted.
    switch(config)# lldp timer 180
    switch(config)#

  • This command removes the configured period of time at which the LLDPDUs are transmitted.
    switch(config)# no lldp timer 180
    switch(config)#

lldp tlv transmit

The lldp tlv transmit command allows the user to specify the Type-Length-Values (TLVs) to include in LLDP packets.

Command Mode

Global Configuration

Command Syntax

lldp tlv transmit tlv_name

no lldp tlv transmit tlv_name

default lldp tlv transmit tlv_name

Parameters

tlv_name -Options include the following:
  • link-aggregation - Specifies the link aggregation TLV.
  • management-address - Specifies the management address TLV.
  • max-frame-size - Specifies the Frame size TLV.
  • port-description - Specifies the port description TLV.
  • port-vlan - Specifies the port VLAN ID TLV.
  • power-via-mdi - Specifies the power over Ethernet TLV.
  • system-capabilities - Specifies the system capabilities TLV.
  • system-description - Specifies the system description TLV.
  • system-name - Specifies the system name TLV.
  • vlan-name - Specifies the VLAN name TLV.

Examples
  • This command enables the system description TLV:
    switch(config)# lldp tlv transmit system-description
    switch(config)#

  • This command disables the system description TLV:
    switch(config)# no lldp tlv transmit system-description
    switch(config)#

  • This command enables the max-frame-size TLV:

    switch(config)# lldp tlv transmit max-frame-size
    switch(config)#

  • This command disables the max-frame-size TLV:

    switch(config)# no lldp tlv transmit max-frame-size
    switch(config)#

lldp transmit

The lldp transmit command enables the transit of LLDP packets on an interface.

Command Mode

Interface-Ethernet configuration

Interface-Management configuration

Command Syntax

lldp transmit

no lldp transmit

default lldp transmit

Examples
  • These commands enable the transmission of LLDP packets.
    switch(config)# interface ethernet 4/1
    switch(config-if-Et4/1)# lldp transmit
    switch(config-if-Et4/1)#

  • These commands disable the transmission of LLDP packets.
    switch(config)# interface ethernet 4/1
    switch(config-if-Et4/1)# no lldp transmit
    switch(config-if-Et4/1)#

poe negotiation lldp disabled

Power Via MDI TLVs are included by default in LLDP packets sent to Power over Ethernet (PoE) Powered Devices (PDs) to allow dynamic negotiation of power levels. The poe negotiation lldp disabled command disables the sending of Power Via MDI TLVs from the configuration-mode interface.

The no poe negotiation lldp disabled and default poe negotiation lldp disabled commands restore the default behavior (sending Power Via MDI TLVs) by removing the corresponding poe negotiation lldp disabled command from running-config.

To disable Power Via MDI TLVs globally, use the no lldp tlv transmit command and specify the Power Via MDI TLV.

Command Mode

Interface-Ethernet configuration

Command Syntax

poe negotiation lldp disabled

no poe negotiation lldp disabled

default poe negotiation lldp disabled

Example

These commands disable the sending of power via MDI TLVs on interface ethernet 5.
switch(config)# interface ethernet 5
switch(config-if-Et5)# poe negotiation lldp disabled
switch(config-if-Et5)#

show lldp counters

The show lldp counters command displays LLDP traffic information for the switch.

Command Mode

EXEC

Command Syntax

show lldp counters [INTERFACE]

Parameters

INTERFACE     Interface type and numbers. Options include:
  • no parameter     Display information for all interfaces.
  • ethernet e_range     Ethernet interface range specified by e_range.
  • management m_range Management interface range specified by m_range.

    Valid e_range and m_range formats include number, number range, or comma-delimited list of numbers and ranges.

Example

This command displays the LLDP counters on the switch.
switch# show lldp counters 

Port          Tx Frames Tx Length Exceeded

Et20              69485                  0
Et21              69394                  0
Et22              69203                  0
Et23              57546                  0
Et24                  0                  0
Ma1               69665                  0

Port          Rx Frames     Rx Errors    Rx Discard  TLVs Discard  TLVs Unknown

Et20              69470             0             0             0             0
Et21              69383             0             0             0             0
Et22              69143             0             0             0             0
Et23              55370             0             0             0             0
Et24                  0             0             0             0             0
Ma1               69078         69078             0         69078             0 

show lldp local-info

The show lldp local-info command displays LLDP errors and overflows.

Command Mode

EXEC

Command Syntax

show lldp local-info [INTERFACE]

Parameters

INTERFACE     Interface type and numbers. Options include:
  • no parameter     Display information for all interfaces.
  • ethernet e_range     Ethernet interface range specified by e_range.
  • management m_range Management interface range specified by m_range.

    Valid e_range and m_range formats include number, number range, or comma-delimited list of numbers and ranges.

Example

This command displays the specific LLDP errors and overflows on management interface 1.
switch# show lldp local-info management 1
Local System:
  - Chassis ID type: MAC address (4)
    Chassis ID     : 001c.730f.11a8qqq
  - System Name: "switch.aristanetworks.com"
  - System Description: "Arista Networks EOS version 4.13.2F running on an Arista 
Networks DCS-7150S-64-CL"
  - System Capabilities : Bridge, Router
    Enabled Capabilities: Bridge

Interface Management1:
  - Port ID type: Interface name (5)
    Port ID     : "Management1"
  - Port Description: ""
  - Management Address Subtype: IPv4 (1)
    Management Address        : 172.22.30.154
    Interface Number Subtype  : ifIndex (2)
    Interface Number          : 999001
    OID String                :
  - IEEE802.1 Port VLAN ID: 0
  - IEEE802.1/IEEE802.3 Link Aggregation
    Link Aggregation Status: Not Capable (0x00)
    Port ID                : 0
  - IEEE802.3 Maximum Frame Size: 1518 bytes
se505.16:01:44#
switch#

show lldp neighbors

The show lldp neighbors command displays information about the switch’s LLDP neighbors.

Command Mode

EXEC

Command Syntax

show lldp neighbors [INTERFACE][INFO_LEVEL]

Parameters
  • INTERFACE     Interface type and numbers. Options include:
    • no parameter     displays information for all interfaces.
    • ethernet e_range     Ethernet interface range specified by e_range.
    • management m_range Management interface range specified by m_range.
    • Valid e_range and m_range formats include number, number range, or comma-delimited list of numbers and ranges.

  • INFO_LEVEL     amount of information that is displayed. Options include:
    • no parameter     Displays information for all interfaces.
    • detailed     LLDP information for all the adjacent LLDP devices.

Examples
  • This command displays the neighbor’s information about LLDP.
    switch(config)# show lldp neighbors
    Last table change time   : 0:12:33 ago
    Number of table inserts  : 33
    Number of table deletes  : 0
    Number of table drops    : 0
    Number of table age-outs : 0
    
    Port      Neighbor Device ID             Neighbor Port ID      TTL
    Et3/1     tg104.sjc.aristanetworks.com   Ethernet3/2           120
    
    Ma1/1     dc1-rack11-tor1.sjc            1/1                   120
    switch#

  • This command displays LLDP neighbor information for interface ethernet 3/1.
    switch# show lldp neighbors ethernet 3/1              
    Last table change time   : 0:16:24 ago
    Number of table inserts  : 33
    Number of table deletes  : 0
    Number of table drops    : 0
    Number of table age-outs : 0
    
    Port      Neighbor Device ID             Neighbor Port ID       TTL
    Et3/1     tg104.sjc.aristanetworks.com   Ethernet3/2            120
    switch#

  • This command displays detailed LLDP neighbor information for interface ethernet 3/1.
    switch# show lldp neighbors 3/1 detail
    
    Interface Ethernet 3/1 detected 1 LLDP neighbors:
    
      Neighbor 001c.7300.1506/Ethernet6/25, age 8 seconds
      Discovered 5 days, 3:58:58 ago; Last changed 5 days, 3:56:57 ago
        - Chassis ID type: MAC address (4)
          Chassis ID     : 001c.7300.1506
        - Port ID type: Interface name (5)
          Port ID     : "Ethernet6/25"
        - Time To Live: 120 seconds
     - Port Description: "Ethernet6/25"
     - IEEE802.3 Power Via MDI
        Port Class               : PD
        PSE MDI Power Support    : Not Supported
        PSE MDI Power State      : Disabled
        - System Name: "Leaf-Switch1.aristanetworks.com"
        - System Description: "Arista Networks EOS version 4.10.1-SSO running on an Arista Networks DCS-7504"
        - System Capabilities : Bridge, Router
          Enabled Capabilities: Bridge
        - Management Address Subtype: IPv4 (1)
          Management Address        : 172.22.30.116
          Interface Number Subtype  : ifIndex (2)
          Interface Number          : 999999
          OID String                :
        - IEEE802.1 Port VLAN ID: 1
        - IEEE802.1/IEEE802.3 Link Aggregation
          Link Aggregation Status: Capable, Disabled (0x01)
          Port ID                : 0
        - IEEE802.3 Maximum Frame Size: 9236 bytes
    switch# 

show lldp

The show lldp command displays LLDP information.

Command Mode

EXEC

Command Syntax

show lldp [INTERFACE]

Parameters

INTERFACE     Interface type and numbers. Options include:
  • no parameter     Display information for all interfaces.
  • ethernet e_range     Ethernet interface range specified by e_range.
  • management m_range Management interface range specified by m_range.

    Valid e_range and m_range formats include number, number range, or comma-delimited list of numbers and ranges.

Examples
  • This command displays all LLDP information.
    switch# show lldp 
    LLDP transmit interval      : 60 seconds
    LLDP transmit holdtime      : 120 seconds
    LLDP reinitialization delay : 2 seconds
    LLDP Management Address VRF : test
    
    Enabled optional TLVs:
      Port Description
      System Name
      System Description
      System Capabilities
      Management Address (Management0)
      IEEE802.1 Port VLAN ID
      IEEE802.3 Link Aggregation
      IEEE802.3 Maximum Frame Size
      IEEE802.1 VLAN Name 
      VLAN ID: 1, VLAN Name: "VLAN1" 
      VLAN ID: 2, VLAN Name: "VLAN2" 
      VLAN ID: 3, VLAN Name: "VLAN3" 
      VLAN ID: 8, VLAN Name: "VLAN8" 
      VLAN ID: 9, VLAN Name: "MyVlan9" 
      VLAN ID: 10, VLAN Name: "VLAN10" 
      VLAN ID: 12, VLAN Name: "VLAN12"
    
    Port       Tx Enabled  Rx Enabled
    Et3/1      Yes         Yes
    
    switch# 

  • This command displays specific information about LLDP for interface ethernet 3/1.
    switch# show lldp ethernet 3/1
    LLDP transmit interval      : 30 seconds
    LLDP transmit holdtime      : 120 seconds
    LLDP reinitialization delay : 2 seconds
    LLDP Management Address VRF : default
    
    Enabled optional TLVs:
      Port Description
      System Name
      System Description
      System Capabilities
    switch#

  • This command displays specific information about LLDP for management interface 1/1.
    switch# show lldp management 1/1
    LLDP transmit interval      : 60 seconds
    LLDP transmit holdtime      : 120 seconds
    LLDP reinitialization delay : 2 seconds
    LLDP Management Address VRF : default
    
    Enabled optional TLVs:
      Port Description
      System Name
      System Description
      System Capabilities
      Management Address (Management0)
      IEEE802.1 Port VLAN ID
      IEEE802.3 Link Aggregation
      IEEE802.3 Maximum Frame Size
    
    Port       Tx Enabled  Rx Enabled
    Ma1/1      Yes         Yes
    switch#
..

EOS 4.36.2F User Manual - Port Channels and LACP

Port Channels and LACP

This chapter describes channel groups, port channels, port channel interfaces, and the Link Aggregation Control Protocol (LACP). This chapter contains the following sections:
  • Port Channel Introduction
  • Port Channel Conceptual Overview
  • Port Channel Configuration Procedures
  • Load Balancing Hash Algorithms
  • Port Channel and LACP Configuration Commands

     

Port Channel Introduction

Arista’s switching platforms support industry-standard link aggregation protocols. Arista switches optimize traffic throughput by using MAC addressing, IP addressing, and services fields to effectively load share traffic across aggregated links. Managers can configure multiple ports into a logical port channel, either statically or dynamically through the IEEE Link Aggregation Control Protocol (LACP). Various negotiation modes are supported to accommodate different configurations and peripheral requirements, including LACP fallback to support devices that need simple network connectivity to retrieve images or configurations prior to engaging port channel aggregation modes.

Arista’s Multi-chassis Link Aggregation protocol (MLAG) supports LAGs across paired Arista switches to provide both link aggregation and active/active redundancy.

Port Channel Conceptual Overview

Channel Groups and Port Channels

A port channel is a communication link between two switches supported by matching channel group interfaces on each switch. A port channel is also referred to as a Link Aggregation Group (LAG). Port channels combine the bandwidth of multiple Ethernet ports into a single logical link.

A channel group is a collection of Ethernet interfaces on a single switch. A port channel interface is a virtual interface that serves a corresponding channel group and connects to a compatible interface on another switch to form a port channel. Port channel interfaces can be configured and used in a manner similar to Ethernet interfaces. Port channel interfaces are configurable as Layer 2 interfaces, Layer 3 (routable) interfaces, and VLAN members. Most Ethernet interface configuration options are also available to port channel interfaces.

Port Channel Subinterfaces

Port channel subinterfaces divide a single port channel interface into multiple logical L3 interfaces based on the 802.1q tag (VLAN ID) of incoming traffic. Subinterfaces are commonly used in the L2/L3 boundary device, but they can also be used to isolate traffic with 802.1q tags between L3 peers by assigning each subinterface to a different VRF.

For further details about subinterfaces, see Subinterfaces.

Link Aggregation Control Protocol (LACP)

The Link Aggregation Control Protocol (LACP), described by IEEE 802.3ad, defines a method for two switches to automatically establish and maintain link aggregation groups (LAGs, also called channel groups or port channels). Using LACP, a switch can configure LACP-compatible ports into a dynamic LAG. The ports try to complete LACP negotiation automatically with the linked ports (also configured as a dynamic LAG) on the partner switch. The maximum number of ports per LAG varies by platform; numbers for each platform in the latest EOS release are available here: https://www.arista.com/en/support/product-documentation/supported-features.

Static LAGs

In static mode (with the channel-group mode configured as on on the member interfaces), the switch aggregates links without an awareness of LAGs on the partner switch and without LACP negotiation. The member ports do not send LACP packets or process inbound LACP packets on static LAGs. Packets may drop when static LAG configurations differ between switches.

Dynamic LAGs

Dynamic LAGs are aware of their partners’ port-channel states. Interfaces configured as dynamic LAGs are designated as active or passive.
  • Active interfaces send LACP Protocol Data Units (LACP PDUs) at a rate of one per second when forming a channel with an interface on the peer switch. An aggregate forms if the peer runs LACP in active or passive mode.

     

  • Passive interfaces only send LACP PDUs in response to PDUs received from the partner. The partner switch must be in active mode and initiates negotiation by sending a LACP packet. The passive mode switch receives and responds to the packet to form a LAG.

     

An active interface can form port channels with passive or active partner interfaces, but port channels are not formed when the interface on each switch is passive.

Table 1 - LACP Mode Combinations summarizes the effect of different LACP mode combinations:

Table 1. LACP Mode Combinations
Switch 1 Switch 2 Comments
active active Links aggregate when LACP negotiation is successful.
active passive Links aggregate when LACP negotiation is successful.
passive passive Links do not aggregate because LACP negotiation is not initiated.
on (static) on (static) Links aggregate without LACP.
on (static) active or passive Links aggregate on the static switch without LACP; links do not aggregate on the other switch, and no port-channel connection is established with the partner.

 

During synchronization, interfaces in dynamic LAGs transmit one LACP PDU per second. After synchronization is complete, interfaces exchange one PDU every thirty seconds, facilitated by a default timeout of 30 seconds and a failure tolerance of three. Under these parameters, when the switch does not receive a LACP PDU for an interface during a ninety-second period, it records the partner interface as failed and removes the interface from the port channel.

Fallback Mode

An active interface that is not in fallback mode does not form a LAG until it receives PDUs from, and negotiates with its peer. Fallback mode allows an active LACP interface to maintain a LAG without receiving PDUs from its peer. The fallback timer specifies the period the LAG waits to receive a peer PDU. Upon timer expiry, the port channel reverts to its configured fallback mode if one is configured.

 

Static fallback: the port channel maintains one active port while in fallback mode; all its other member ports are in standby mode until a LACP PDU is received by the port channel. All member ports send (and can receive) LACP PDUs, but only the active port sends or receives data.

 

Individual fallback: all member ports act as individual switch ports while in fallback mode. Individual port configuration (rather than port channel configuration) is active while the port channel is in fallback mode, with the exception of ACLs. This includes VLAN membership. All member ports send and receive data, and continue to send LACP PDUs. As soon as a LACP PDU is received by a member of the port channel, all ports revert to normal port-channel operation.

The switch uses a link aggregation hash algorithm to determine the forwarding path within a link aggregation group. The IP and MAC header fields can be selected as components of the hash algorithm.

Port Channel Mirroring

EOS supports Port Channels as mirroring destinations for both ingress and egress source directions. Traffic mirrors to a port channel and load-balances based on the global port channel load balancing configuration.

Configure port channel members as a mirroring source port for both ingress and egress source directions. A port channel has higher privileges in mirroring source membership than its members. When configuring a port channel and members as mirroring source ports, only the port channel source port becomes active.

Port Channel Configuration Procedures

These sections describe channel group and port channel configuration procedures:
  • Configuring a Channel Group
  • Configuring a Port Channel Interface
  • Configuring Port Channel Mirroring
  • Maximum Port Channel ID Increase
  • Configuring Port Channel Subinterfaces
  • Configuring LACP
  • Displaying Port Channel Information

     

Configuring a Channel Group

Creating a Channel Group

The channel-group command assigns the configuration-mode Ethernet interfaces to a channel group, creates the channel group if it does not already exist, and specifies LACP attributes for the channel.

Channel groups are associated with a port channel interface immediately upon their creation. A command that creates a new channel group also creates a port channel with a matching ID. The port channel is configured in port-channel configuration mode. Configuration changes to a port channel interface propagate to all Ethernet interfaces in the corresponding channel group.

LACP is enabled on the member interfaces by setting the channel-group mode to active or passive. Setting the mode to on disabled LACP on the member interfaces and creates a static channel group.

 

Example
These commands assign Ethernet interfaces 1 and 2 to channel group 10 (creating the channel group if it does not already exist), enable LACP on those interfaces, and place the channel group in a negotiating state.
switch(config)# interface ethernet 1-2
switch(config-if-Et1-2)# channel-group 10 mode active
switch(config-if-Et1-2)#

 

Adding an Interface to a Channel Group

The channel-group command is also used to add the configuration mode interface to an existing channel group. When adding channels to a previously created channel group, the channel-group mode for the new channel must match the mode for the existing group.

 

Example
These commands add Ethernet interfaces 7 through 10 to previously created channel group 10, using the channel-group mode (active) under which it was created.
switch(config)# interface ethernet 7-10
switch(config-if-Et7-10)# channel-group 10 mode active
switch(config-if-Et7-10)#

 

Removing an Interface from a Channel Group

The no channel-group command removes the configuration mode interface from the specified channel group. Deleting all members of a channel group does not remove the associated port channel interface from running-config.

 

Example
These commands removes interface ethernet 8 from previously created channel group 10.
switch(config)# interface ethernet 8
switch(config-if-Et8)# no channel-group
switch(config-if-Et8)#

 

Configuring a Port-Channel as Mixed-Speed

By default, only configured members of the same speed become active. The port-channel speed mixed command configures a port channel with the ability to have active members of multiple speeds.

 

Note: Available on the 7020, 7280, 7500, and 7800 platforms. Minimum links is not available on mixed-speed port channels.

 

 

Example
switch(config)# interface port-channel 1
switch(config-if-Po1)# port-channel speed mixed

 

Configuring Minimum Links

 

Note: Minimum links is not available on Mixed-Speed Port-Channels. If a minimum requirement is desired for a Mixed-Speed Port-Channel, consider Minimum Speed instead. On Port-Channels that are not mixed-speed, if both Minimum Links and Minimum Speed are configured, then Minimum Speed will take precedence.

 

Configuring Minimum Speed

The port-channel speed minimum command specifies the cumulative minimum speed of all active members in order for a port channel to become active. If there is less than the specified by this command, the port channel interface does not become active.

 

Note: If both minimum speed and minimum links are configured, minimum speed will take precedence.

 

 

Example

These command sets 100 Gbps as the minimum speed needed for port channel 1 to become active.

switch(config)# interface port-channel 1
switch(config-if-Po1)# port-channel speed minimum 100 gbps

 

Deleting a Channel Group

A channel group is deleted by removing all Ethernet interfaces from the channel group. A channel group’s LACP mode can be changed only by deleting the channel group and then creating an equivalent group with a different LACP mode. Deleting a channel group by removing all Ethernet interfaces from the group preserves the port channel interface and its configuration settings.

View running-config to verify the deletion of all Ethernet interfaces from a channel group.

Configuring a Port Channel Interface

Creating a Port Channel Interface

The switch provides two methods for creating port channel interfaces:
  • creating a channel group simultaneously creates an associated port channel.

     

  • the interface port-channel command creates a port channel without assigning Ethernet channels to the new interface.

     

The interface port-channel command places the switch in interface-port channel configuration mode.

Example

This command creates interface port-channel 8 and places the switch in port channel interface configuration mode.
switch(config)# interface port-channel 8
switch(config-if-Po8)#

Deleting a Port Channel Interface

The no interface port-channel command deletes the configuration mode port channel interface and removes the channel group assignment for each Ethernet interface assigned to the group associated with the port channel interface. Removing all Ethernet interfaces from a channel group does not remove the associated port channel interface from running-config.

Configuring Port Channel Mirroring

Port Channels can be configured as a mirroring destination or a mirroring source.

Note: On Sand platforms, only static ports can be used to configure port mirroring destinations.

Configuring a Port Channel as a Mirroring Destination

Use the following command to configure a port channel as a mirroring destination:

switch(config)# monitor session 1 destination Port-Channel 1

Unconfigured port channel interfaces can be configured as mirroring destinations, but do not become active until after configuring the port channel. Use the show monitor session to display the status of the configured mirroring destination.

Configuring a Port Channel as a Mirroring Source

Configure an interface member, Ethernet3/3/1 and Ethernet4/32/1, of a port channel as a mirroring source interface, with the session name, testmember:

switch# show Port-Channel 10
Port Channel Port-Channel10:
 Active Ports: Ethernet4/32/1 Ethernet3/3/1
 
switch(config)# monitor session testmember source et3/3/1
switch(config)# monitor session testmember source et4/32/1
switch(config)# monitor session testmember destination po1

 

Configuring a new monitor session testlag with the port channel interface as a mirroring source inactivates previously the port-channel member testmember monitor session.

switch(config)# monitor session testlag source po10
switch(config)# monitor session testlag destination et5/22/1

 

Use the show monitor session to display the status of the configured mirroring sources. Port channel member now displays a status of inactive.

switch(config)# show monitor session
                
Session testlag
------------------------
Source Ports:
   Both:    Po10
Destination Ports:
    Et5/22/1 :  active
                
Session testmember
------------------------
Source Ports:
   Both:        Et4/32/1
   Inactive:    Et3/3/1 ( Lag configured as source ) 
Destination Ports:
   Po1 :  active

 

Removing port channel member Et3/3/1 from port channel 10 reactivates the interface as a mirroring source interface.

switch(config)# interface ethernet 3/3/1
switch(config-if-Et3/3/1)# no channel-group 10
switch(config-if-Et3/3/1)# exit
                
switch(config)# show port-channel 10
Port Channel Port-Channel10:
  Active Ports: Ethernet4/32/1

 

Interface Et3/3/1 no longer displays as an inactive port in the show monitor session output.

switch(config)# show monitor session 
                
Session testlag
-----------------------
Source Ports:
  Both:        Po10
Destination Ports:
    Et5/22/1 :  active
                
Session testmember
----------------------
Source Ports:
  Both:        Et3/3/1, Et4/32/1
Destination Ports:
  Po1 :  active

Displaying Port Channel Mirroring Information

Use the following command to display information about mirroring to a destination:

switch# show Port-Channel 1
Port Channel Port-Channel1
 Active Ports: Ethernet1/1
                
switch#show monitor session
Session 1
------------------------
Source Ports:
Destination Ports:
   Po1 :  active

 

Use the following command to display information about mirroring to a source:

switch# show monitor session
Session testmember
------------------------
                
Source Ports:
  Both:        Et3/3/1, Et4/32/1
                
Destination Ports:
  Po1 :  active

Maximum Port Channel ID Increase

Previously, the maximum valid port channel ID was equal to the maximum number of port channels configurable on the system, 2000, and this feature increases the maximum ID to 999,999 while maintaining the same limit of 2000 port channels on the system.

Configuration

This feature does not involve any specific configuration procedure, but it does include visible changes to port channel configuration commands. In the following examples, suppose port channels 1-2000 have already been configured, so creating Port-Channel 2001 would exceed the configuration limit.
switch(config)# interface create port-channel 2001
Port channel config limit 2000 reached. No interfaces were created.

 

 

switch(config-ifEtX)# channel-group 2001 mode 
Port channel config limit 2000 reached. No interfaces were created.

 

Show Commands

Changes to existing show commands simply involve displaying when a port channel is inactive. In the following examples, suppose port channels 2001-4001 are configured, Port-Channel 4001 is inactive, and Ethernet1 is a member of Port-Channel 4001.
switch(config)# show lacp 1-$ aggregates
Port channel 4001 is inactive. The number of configured port channels exceeds the config limit 2000.
Port-Channels1-2000,4002-999999 not configured as LAG
Port Channel Port-Channel2001:
Aggregate ID: [(8000,00-1c-73-04-36-d7,0001,0000,0000),(8000,00-1c-73-09-a0-f3,0001,0000,0000)]
  Bundled Ports: Ethernet43 Ethernet44 Ethernet45 Ethernet46
Port Channel Port-Channel2002:
Aggregate ID: [(8000,00-1c-73-01-02-1e,0002,0000,0000),(8000,00-1c-73-04-36-d7,0002,0000,0000)]
  Bundled Ports: Ethernet47 Ethernet48
Port Channel Port-Channel2003:
Aggregate ID: [(8000,00-1c-73-04-36-d7,0003,0000,0000),(8000,00-1c-73-0c-02-7d,0001,0000,0000)]
  Bundled Ports: Ethernet3 Ethernet4
Port Channel Port-Channel2004:
Aggregate ID: [(0001,00-22-b0-57-23-be,0031,0000,0000),(8000,00-1c-73-04-36-d7,0004,0000,0000)]
  Bundled Ports: Ethernet42
Port Channel Port-Channel2005:
Aggregate ID: [(0001,00-22-b0-5a-0c-51,0033,0000,0000),(8000,00-1c-73-04-36-d7,0005,0000,0000)]
  Bundled Ports: Ethernet41




switch(config)# show lacp 1-$ counters
Port channel 4001 is inactive. The number of configured port channels exceeds the config limit 2000.
Port-Channels1-2000,4002-999999 not configured as LAG


switch(config)# show lacp 1-$ internal
Port channel 4001 is inactive. The number of configured port channels exceeds the config limit 2000.
Port-Channels1-2000,4002-999999 not configured as LAG
LACP System-identifier: 8000,00-1c-73-04-36-d7
State: A = Active, P = Passive; S=ShortTimeout, L=LongTimeout;
       G = Aggregable, I = Individual; s+=InSync, s-=OutOfSync;
       C = Collecting, X = state machine expired,
       D = Distributing, d = default neighbor state
             |Partner                                 Actor
Port Status  | Sys-id                 Port#  State    OperKey  PortPriority
----------------------------------------------------------------------------
Port Channel Port-Channel2001:
Et43 Bundled | 8000,00-1c-73-09-a0-f3    43  ALGs+CD   0x0001         32768
Et44 Bundled | 8000,00-1c-73-09-a0-f3    44  ALGs+CD   0x0001         32768
Et45 Bundled | 8000,00-1c-73-09-a0-f3    45  ALGs+CD   0x0001         32768
Et46 Bundled | 8000,00-1c-73-09-a0-f3    46  ALGs+CD   0x0001         32768

switch(config)# show lacp 1-$ peer
Port channel 4001 is inactive. The number of configured port channels exceeds the config limit 2000.
Port-Channels1-2000,4002-999999 not configured as LAG
State: A = Active, P = Passive; S=ShortTimeout, L=LongTimeout;
       G = Aggregable, I = Individual; s+=InSync, s-=OutOfSync;
       C = Collecting, X = state machine expired,
       D = Distributing, d = default neighbor state
               |                          Partner
Port   Status  | Sys-id                  Port#   State     OperKey  PortPri
----------------------------------------------------------------------------
Port Channel Port-Channel2001:
Et1    Bundled | 8000,00-1c-73-00-13-19      1   ALGs+CD    0x0001    32768
Et2    Bundled | 8000,00-1c-73-00-13-19      2   ALGs+CD    0x0001    32768
Port Channel Port-Channel2002:
Et23   Bundled | 8000,00-1c-73-04-36-d7     47   ALGs+CD    0x0002    32768
Et24   Bundled | 8000,00-1c-73-04-36-d7     48   ALGs+CD    0x0002    32768
Port Channel Port-Channel2004*:
Et3    Bundled | 8000,00-1c-73-0b-a8-0e     45   ALGs+CD    0x0001    32768
Et4    Bundled | 8000,00-1c-73-0b-a8-0e     46   ALGs+CD    0x0001    32768
Port Channel Port-Channel2005*:
Et19   Bundled | 8000,00-1c-73-0c-30-09     49   ALGs+CD    0x0005    32768
Et20   Bundled | 8000,00-1c-73-0c-30-09     50   ALGs+CD    0x0005    32768
Port Channel Port-Channel2006*:
Et6    Bundled | 8000,00-1c-73-01-07-b9     49   ALGs+CD    0x0001    32768
Port Channel Port-Channel2007*:
Et5    Bundled | 8000,00-1c-73-0f-6b-22     51   ALGs+CD    0x0001    32768
Port Channel Port-Channel2008*:
Et10   Bundled | 8000,00-1c-73-10-40-fa     51   ALGs+CD    0x0001    32768
 
* - Only local interfaces for MLAGs are displayed. Connect to the peer to
    see the state for peer interfaces.

switch(config)# show lacp interface Ethernet1 [(internal|neighbor|peer)]
Interface Ethernet1 is a member of an inactive LACP port channel. The number of configured port channels exceeds the config limit 2000.

switch(config)# show port-channel 1-$
Port Channel Port-Channel2001:
  No Active Ports
...
Port Channel Port-Channel4000:
  No Active Ports
Port Channel Port-Channel4001:
  Inactive, The number of configured port channels exceeds the config limit 2000.

switch(config)# show port-channel (dense|summary)

                  Flags
-------------------------- ----------------------------- -------------------------
   a - LACP Active            p - LACP Passive           * - static fallback
   F - Fallback enabled       f - Fallback configured    ^ - individual fallback
   U - In Use                 D - Down                   
   + - In-Sync                - - Out-of-Sync            i - incompatible with agg
   P - bundled in Po          s - suspended              G - Aggregable
   I - Individual             S - ShortTimeout           w - wait for agg
   E - Inactive. The number of configured port channels exceeds the config limit

Number of channels in use: ...
Number of aggregators: ...

   Port-Channel       Protocol    Ports
------------------ -------------- -------------------
   Po2001(U)          LACP(a)     Et47(PG+) Et48(PG+)
   Po2002(U)          LACP(a)     Et39(PG+) Et40(PG+)
   Po4001(E)          Static      Et7(P)

 

Limitations

  • The number of configured port channels can exceed the configurable limit if two configuration sessions simultaneously create two different port channels. In this scenario, port channels that exceed the limit are inactive. This is uncommon and does not impact traffic in any way. If an inactive port channel exists and an active port channel is deleted, then the inactive port channel is activated.

     

  • Only port channels with ID from 1 to 2000 are configured as MLAG port channels.

     

Configuring Port Channel Subinterfaces

When configuring subinterfaces on a port channel interface (the virtual interface associated with a port channel), the following restrictions apply:

An L3 interface with subinterfaces configured on it should not be made a member of a port channel.
  • An interface that is a member of a port channel should not have subinterfaces configured on it.

     

  • A subinterface cannot be made a member of a port channel.

     

Port channel subinterfaces are otherwise configured similarly to Ethernet subinterfaces. For additional information, see Subinterfaces.

Configuring LACP

Configuring the Channel-group Mode

The channel-group mode is configured when a channel group is created using the channel-group command. A channel group’s mode cannot be modified without deleting the entire channel group, but it can be modified without deleting the port channel interface associated with the channel group. The mode setting defines whether the port channel is static or dynamic, and whether a dynamic port channel is active or passive.

Examples
  • These commands create a dynamic channel group and place it in LACP active mode.
    switch(config)# interface ethernet 1-2
    switch(config-if-Et1-2)# channel-group 10 mode active
    switch(config-if-Et1-2)#

     

  • These commands create a static channel group.
    switch(config)# interface ethernet 4-5
    switch(config-if-Et4-5)# channel-group 11 mode on
    switch(config-if-Et4-5)#

     

Configuring the System Priority

Each switch is assigned a globally unique system identifier by concatenating the system priority (16 bits) to the MAC address of one of its physical ports (48 bits). The system identifier is used by peer devices when forming an aggregation to verify that all links are from the same switch. The system identifier is also used when dynamically changing aggregation capabilities in response to LACP information; the system with the numerically lower system identifier is permitted to dynamically change advertised aggregation capabilities.

The lacp system-priority command configures the switch’s LACP system priority.

Example

This command assigns the system priority of 8192 to the switch.
switch(config)# lacp system-priority 8192
switch(config)#

Configuring Port Priority

LACP port priority determines the port that is active in a LAG in fallback mode. Numerically lower values have higher priority. Port priority is supported on port channels that are enabled with LACP physical interfaces.

The lacp port-priority command sets the aggregating port priority for the configuration mode interface.

Example

This command assigns the port priority of 4096 to Ethernet interface 1.
switch(config-if-Et1)# lacp port-priority 4096
switch(config-if-Et1)#

Configuring the LACP Packet Reception Rate

The lacp timer command sets the reception rate of LACP packets on the local device for the interface being configured. This command supports the following reception rates:
  • normal: LACP packets are received at the following rates:
    • 30 seconds for synchronized interfaces.
    • One second for interfaces that are being synchronized.

       

  • fast: LACP packets are received every second.

     

Example

This command sets the LACP reception rate to one second on the Ethernet interface 4.
switch(config-if-Et4)# lacp timer fast
switch(config-if-Et4)#

Configuring LACP Fallback

Fallback mode (static or individual) is configured on a port channel interface with the port-channel lacp fallback command. The fallback timeout interval is configured with the port-channel lacp fallback timeout command. Fallback timeout settings persist in running-config without taking effect for interfaces that are not configured into fallback mode. The default fallback timeout period is 90 seconds.

Examples
  • These commands enable LACP static fallback mode, then configure an LACP fallback timeout of 100 seconds on port channel interface 13. If LACP negotiation fails, only the member port with the lowest LACP priority will remain active until an LACP PDU is received by one of the member ports.
    switch(config)# interface port-channel 13
    switch(config-if-Po13)# port-channel lacp fallback static
    switch(config-if-Po13)# port-channel lacp fallback timeout 100
    switch(config-if-Po13)# show active
    interface Port-Channel13
       port-channel lacp fallback static
       port-channel lacp fallback timeout 100
    switch(config-if-Po13)#

     

  • These commands enable LACP individual fallback mode, then configure an LACP fallback timeout of 50 seconds on port channel interface 17. If LACP negotiation fails, all member ports will act as individual switch ports, using port-specific configuration, until a LACP PDU is received by one of the member ports.
    switch(config)# interface port-channel 17
    switch(config-if-Po17)# port-channel lacp fallback individual
    switch(config-if-Po17)# port-channel lacp fallback timeout 50
    switch(config-if-Po17)# show active
    interface Port-Channel17
       port-channel lacp fallback individual
       port-channel lacp fallback timeout 50
    switch(config-if-Po17)#

     

Configuring Minimum Links

The port-channel min-links command specifies the minimum number of interfaces that the configuration mode LAG requires to be active. If there are fewer ports than specified by this command, the port channel interface does not become active.

 

Note: In static LAGs, the min-links value must be met for the LAG to be active. The LAG will not become active until it has at least the min-links number of functioning links in the channel group. If failed links cause the number to drop below the minimum, the LAG will go down and administrator action will be required to bring it back up. In dynamic LAGs, the LACP protocol must determine that at least min-links physical ports are aggregable (they are physically compatible and have the same keys both remotely and locally) before it begins negotiating to make any ports active members of the port-channel. However once negotiation begins, an error on the partner’s side or an error in programming of member interfaces can cause the LAG to become active with fewer than the minimum number of links. EOS evaluates min-links after min-links-review-timeout (linearly proportional to configured min-links) when LACP protocol collecting and/or distributing state changes. If the number of active member interfaces in a port-channel is less than configured min-links, it brings the corresponding port-channel Link Down and syslogs LAG-4-MINLINK_INTF_INSUFFICIENT message. If additional interfaces get programmed as collecting and distributing, EOS re-evaluates min-links on the port-channel. If sufficient number of interfaces are available to be a part of port-channel, then all interfaces of the corresponding port-channel are re-enabled for LACP negotiation and the port-channel becomes Link Up. LAG-4-MINLINK_INTF_NORMAL is syslogged after min-links-review-timeout if the min-links condition is satisfied; otherwise LAG-4-MINLINK_INTF_INSUFFICIENT is syslogged and the port-channel goes Link Down. If an interface remains in collecting state but not in distributing state for min-links-review-timeout, it is moved out of collecting state. It is periodically re-enabled after min-links-retry-timeout (which is 360 seconds) till it progresses to collecting and distributing. Meanwhile, if a port-channel becomes Link Up because sufficient number of interfaces progressed to collecting and distributing states, then this interface is enabled for LACP negotiation.

 

 

Example

This command sets four as the minimum number of ports required for port channel 5 to become active.
switch(config-if-Po5)# port-channel min-links 4
switch(config-if-Po5)#

Configuring Minimum Links Review Interval

The port-channel min-links review interval command enables or disables timer based min-links review feature for all port-channels. The timer based min-links feature is enabled when all of the following conditions are true. It is disabled otherwise:
  • The min-links configured is greater than 1.
  • LACP fallback is disabled.
  • The number of interfaces configured in the port-channel is more than min-links.
  • The number of active member interfaces in the port-channel is less than min-links.
  • The default timer values are:
    • min-links-review-timeout = min-links-timeout-base + f (configured min-links).
    • min-links-timeout-base = 180 seconds.
    • min-links-retry-timeout = 360 seconds.

       

Configuring Maximum Links per Port Channel

The maximum links feature allows you to specify the number of active members in both LACP and static port channels. If active members become inactive due to configuration changes or link failure, previously restricted members become active on the switch. This ensures continual operation for port channels and prevents disruptions on the network.

For LACP port channels, the pre-emptive priority feature allows you to control which members become active. If enabled, the switch considers the ports in a descending order of priority. The port channel member priority can be configure, but by default, all members have the same priority.

Note: Configuring member priority causes a disruption and members to flap. Static port channels do not support this feature.

Use the following commands to specify the maximum number of links, 10 for a port channel, 1:

switch(config)# interface Port-Channel1
      switch(config-if-Po1)# port-channel max-links 25
         switch(config-if-Po1)#

For LACP ports, enable pre-emptive priority for port channel members. By default, all member ports have the same priority value of 32768. To configure the LACP port channel member priority, use the lacp port-priority command.

switch(config)# interface Port-Channel1
         switch(config-if-Po1)# port-channel member priority preemptive
         switch(config-if-Po1)#

Displaying Port Channel Information

Port channel information is accessed using some of the show commands listed under Interface Display Commands. Ensure that while using the show interfaces counters rates command to view the rate information of a port channel, rate values for the individual member ports are less inaccurate than rate values of the port channel.

Both the port channel rate and the individual port rates are calculated approximations; the rate value of a port channel might vary from the total of the rates for the member ports. The discrepancy is likely to be larger for port channels with fewer ports, and will be most obvious in single-port port channels.

Load Balancing Hash Algorithms

The switch balances packet load across multiple links in a port channel by calculating a hash value based on packet header fields. The hash value determines the active member link through which the packet is transmitted. This method, in addition to balancing the load in the LAG, ensures that all packets in a data stream follow the same network path.

In network topologies that include MLAGs or Multiple Paths with Equal Cost (ECMP), programming all switches to perform the same hash calculation increases the risk of hash polarization, which leads to uneven load distribution among LAG and MLAG member links. This uneven distribution is avoided by performing different hash calculations on each switch routing the paths.

The port-channel load-balance command specifies the seed for hashing algorithms that balance the load across ports comprising a port channel. Available seed values vary by switch platform.

Example

This command configures the hash seed of 10 on 7150 Series (FM6000 platform) switches.
switch(config)# port-channel load-balance fm6000 10
switch(config)#

 

Hashing algorithm inputs varies by switch platform. These sections describe hashing algorithm inputs for each platform.
  • Load Balance Hash Algorithms on 7048 and 7500 Series Switches
  • Load Balance Hash Algorithms on 7500E Series Switches
  • Load Balance Hash Algorithms on 7050 Series Switches
  • Load Balance Hash Algorithms on 7150 Series Switches

Load Balance Hash Algorithms on 7048 and 7500 Series Switches

One command configures the load balance hash algorithm on 7048 and 7500 Series switches:

  • port-channel load-balance petraA fields ip: controls the hash algorithm for IP packets by specifying the algorithm’s use of IP and MAC header fields. Fields that the command can specify include source and destination IP addresses, source and destination port fields (for TCP and UDP packets), and the entire MAC address header.

The hash algorithm for non-IP packets is not configurable and always includes the entire MAC header.

Example

These commands configure the load balance algorithm for IP packets by using the entire MAC header.
switch(config)# port-channel load-balance petraA fields ip mac-header
switch(config)#

Load Balance Hash Algorithms on 7500E Series Switches

One command configures the load balance hash algorithm on 7500E Series switches:

port-channel load-balance arad fields ip: controls the hash algorithm for IP packets by specifying the algorithm’s use of IP and MAC header fields. Fields that the command can specify include source and destination IP addresses, source and destination port fields (for TCP and UDP packets), and the entire MAC address header.

The hash algorithm for non-IP packets is not configurable and always includes the entire MAC header.

Example

These commands configure the load balance algorithm for IP packets by using the entire MAC header.
switch(config)# port-channel load-balance arad fields ip mac-header
switch(config)#

Dynamic and Symmetric LAG Hashing

Dynamic LAG hashing enables high link utilization and highly even distribution among LAG members by employing a randomized hashing algorithm. Symmetric LAG hashing allows the two flows of a bidirectional communication link, even when the two flows enter the switch on different ingress ports, to be hashed to the same member of a LAG on egress.

Dynamic and symmetric LAG hashing policies are enabled via named port-channel load-balancing profiles. LAG load-balancing policies can be provisioned on per line-card basis using these profiles. Load-balancing profiles can be used to provision all LAG load-balance attributes, including hash polynomials, hash seeds, and hash fields.

When no specific LAG hashing profile is assigned to a line card, then a global LAG hashing profile can be defined and applied to all the line cards with no LAG hashing defined on them.

Note, if no profile is selected as global profile then the default profile takes the precedence and set as a global profile. The default profile is reserved and if it is set as a global profile it cannot be deleted, if the profile is deleted then the following warning message is displayed.

 

Note: When a global profile is already set and if some other profile is tried to configured as a default profile the following warning message is displayed “! A global load balancing profile myProfile is currently active. This setting will not take effect.”

 

 

Examples
  • These commands configure a load balance profile for symmetric hashing.
    switch(config)# load-balance policies
    switch(config-load-balance-policies)# load-balance arad profile
    switch(config-sand-load-balance-profile-symmetric-profile-1)# hash symmetric
    switch(config-sand-load-balance-profile-symmetric-profile-1)# show active
    load-balance policies
       load-balance arad profile symmetric-profile-1
          hash symmetric

     

  • These commands configure a load balance profile for dynamic hashing.
    switch(config)# load-balance policies
    switch(config-load-balance-policies)# load-balance arad profile
    switch(config-sand-load-balance-profile-dynamic-hash-profile-1)# distribution clock
    switch(config-sand-load-balance-profile-dynamic-hash-profile-1)# show active load-balance policies
       load-balance arad profile dynamic-hash-profile-1
          distribution clock

     

  • This command assigns a named load-balancing profile to a linecard.
    switch(config)# port-channel load-balance module 3-7 sand profile Linecard5
    switch(config)#

     

  • This command unassigns a named load-balancing profile to a linecard.
    switch(config)# no port-channel load-balance module 3-7 sand profile Linecard5
    switch(config)#

     

  • This command configures a global profile on all line cards on which LAG hashing is not defined.
    switch(config)# port-channel load-balance sand profile myGlobalProfile

     

  • These commands designates a default profile as a global profile, if no other profile is set as a global profile.
    switch(config)# load-balance policies
    switch(config-load-balance-policies)# load-balance sand profile default

     

  • These commands configure a hash seed in a profile and assigns it as a global profile.
    switch(config)# load-balance policies
    switch(config-load-balance-policies)# load-balance sand profile myGlobalProfile
    switch(config-sand-load-balance-profile-myGlobalProfile)# hash seed 20
    switch(config)# port-channel load-balance sand profile myGlobalProfile

     

  • This command assigns a named load-balancing profile to a linecard.
    switch(config)# port-channel load-balance module 3-7 sand profile Linecard5
    switch(config)#

     

  • This command unassigns a named load-balancing profile to a linecard.
    switch(config)# no port-channel load-balance module 3-7 sand profile Linecard5
    switch(config)#

     

Load Balance Hash Algorithms on 7050 Series Switches

Three commands configure the load balance hash algorithm on 7050 Series switches:
  • port-channel load-balance trident fields ip controls the hash algorithm for IP packets by specifying the algorithm’s use of IP and MAC header fields. Fields that the command can specify include source and destination IP addresses, source and destination port fields (for TCP and UDP packets), and fields specified by the port-channel load-balance trident fields mac command.

     

  • port-channel load-balance trident fields ipv6 controls the hash algorithm for IPv6 packets by specifying the algorithm’s use of IP and MAC header fields. Fields that the command can specify include source and destination IP addresses, source and destination port fields (for TCP and UDP packets), and fields specified by the port-channel load-balance trident fields mac command.

     

  • port-channel load-balance trident fields mac controls the hash algorithm for non-IP packets b specifying the algorithm’s use of MAC header fields. Fields that the command can specify include the MAC source address, MAC destination address, and Ethernet type fields.

     

Example

These commands configure the switch’s port channel load balance for non IP packets by using the MAC destination and Ethernet type fields in the hashing algorithm.
switch(config)# port-channel load-balance trident fields mac dst-mac eth-type
switch(config)#

Load Balance Hash Algorithms on 7150 Series Switches

Load balance profiles specify parameters used by hashing algorithms that distribute traffic across ports comprising a port channel or among component ECMP routes. The switch supports 16 load balance profiles, including the default profile. The default load balance profile is configured through port-channel load-balance fm6000 fields ip and port-channel load-balance fm6000 fields mac commands.

Load Balance Profiles

Load balance profiles are managed in load-balance-policies configuration mode. The load-balance-policies configuration mode provides commands that display the contents of all configured profiles and place the switch in load-balance-profile command. Load balance profiles are created by entering the load-balance-profile mode and edited while in that mode.

The load-balance policies command places the switch in load-balance-policies configuration mode. Load balance profiles specify the inputs used by the hashing algorithms that distribute traffic across ports comprising a port channel or among ECMP routes.

Examples
  • This command places the switch in load-balance-policies configuration mode.
    switch(config)# load-balance policies
    switch(config-load-balance-policies)#

     

  • This command displays the contents of the four load balance profiles configured on the switch.
    switch(config-load-balance-policies)# show active
    
    load-balance policies
       load-balance fm6000 profile F-01
          port-channel hash-seed 22
          fields ip dscp
          distribution random port-channel
       !
       load-balance fm6000 profile F-02
          fields ip protocol dst-ip
          distribution random port-channel
       !
       load-balance fm6000 profile F-03
          fields ip protocol dst-ip
          fields mac dst-mac eth-type
          distribution random ecmp port-channel
       !
       load-balance fm6000 profile F-04
    
    switch(config-load-balance-policies)#

     

Creating a Load Balance Profile

The load-balance fm6000 profile command places the switch in load-balance-profile configuration mode to configure a specified load balance profile. The command specifies the name of the profile that subsequent commands modify. It creates a profile if the profile it references does not exist.

Example

These commands enter load-balance-profile configuration mode, creates the LB-5 profile, and lists the default settings for the profile.
switch(config)# load-balance policies
switch(config-load-balance-policies)# load-balance fm6000 profile LB-5
switch(config-load-balance-profile-LB-5)# show active all

load-balance policies
   load-balance fm6000 profile LB-5
      port-channel hash-seed 0
      fields mac dst-mac src-mac eth-type vlan-priority vlan-id
      fields ip protocol dst-ip dst-port src-ip src-port dscp
      no distribution symmetric-hash
      no distribution random

switch(config-load-balance-profile-LB-5)#
Configuring a Load Balance Profile
These commands are available in load-balance-profile configuration mode to specify the parameters that comprise a profile.
  • The fields ip command specifies the L3/L4 data fields used by the hash algorithm defined by the configuration mode load balance profile.

     

  • The fields mac command specifies the L2 data fields used by the hash algorithm defined by the configuration mode load balance profile.

     

  • The distribution symmetric-hash command enforces traffic symmetry on data distributed by the hash algorithm defined by the configuration mode load balance profile. Symmetric traffic is the flow of both directions of a data stream across the same physical link.

     

  • The distribution random command specifies the random distribution of data packets handled by the hash algorithm defined by the configuration mode load balance profile.

     

Example

These commands configure the following components of the hash algorithm defined by the LB-7 load balance profile:
  • L2 header fields: MAC destination address, VLAN priority.

     

  • L3/L4 header fields: Source IP address, protocol field.

     

  • Symmetric hash distribution of IP and non-IP packets.
    switch(config)# load-balance policies
    switch(config-load-balance-policies)# load-balance fm6000 profile LB-7
    switch(config-load-balance-profile-LB-7)# fields ip src-ip protocol
    switch(config-load-balance-profile-LB-7)# fields mac dst-mac vlan-priority
    switch(config-load-balance-profile-LB-7)# distribution symmetric-hash mac-ip
    switch(config-load-balance-profile-LB-7)# show active
    load-balance policies
       load-balance fm6000 profile LB-7
          fields mac dst-mac vlan-priority
          fields ip protocol src-ip
          distribution symmetric-hash mac-ip
    switch(config-load-balance-profile-LB-7)# exit
    switch(config-load-balance-policies)# exit
    switch(config)# exit

     

Assigning a Load Balance Profile to an Interface

The ingress load-balance profile command applies a specified load-balance profile to the configuration mode interface. Load balance profiles specify parameters used by hashing algorithms that distribute traffic across ports comprising a port channel or among ECMP routes. The switch supports 16 load balance profiles, including the default profile.

Example

This command applies the LB-1 load balance profile to interface port-channel 100.
switch(config)# interface port-channel 100
switch(config-if-Po100)# ingress load-balance profile LB-1
switch(config-if-Po100)# show active
interface Port-Channel100
   ingress load-balance profile LB-1
switch(config-if-Po100)#

Default Load Balance Profile

Two commands configure the load balance default profile on 7150 Series switches:
  • port-channel load-balance fm6000 fields ip controls the hash algorithm for IP packets by specifying the algorithm’s use of IP and MAC header fields. Fields that the command can specify include source and destination IP addresses, source and destination port fields (for TCP and UDP packets).

     

  • port-channel load-balance fm6000 fields mac controls the hash algorithm for non-IP packets by specifying the algorithm’s use of MAC header fields. Fields that the command can specify include include the MAC source address, MAC destination address, and Ethernet type, VLAN-ID, and VLAN-priority fields.

     

Examples
  • These commands configure the load balance default profile for IP packets by using source and destination IP address fields, along with source and destination port fields for TCP, and UDP packets.
    switch(config)# port-channel load-balance fm6000 fields ip ip-tcp-udp-header
    switch(config)#

     

  • This command applies the default load balance profile to interface port-channel 100.
    switch(config)# interface port-channel 100
    switch(config-if-Po100)# no ingress load-balance profile
    switch(config-if-Po100)# show active
    interface Port-Channel100
    switch(config-if-Po100)#

Conditional UDP Payload Hashing

EOS supports an alternative set of bytes used for calculating the LAG and ECMP hash if a 16-bit field in the payload matches a provided pattern.

Supported Platforms

  • DCS-7280R3 series
  • DCS-7500R3 series
  • DCS-7800R3 series

Configuring Conditional UDP Payload Hashing

Configure UDP conditional payload hashing as part of a load balancing profile on the switch. Use the following commands to enter Load Balance Profile Configuration Mode:

switch(config)# load-balance policies
switch(config-load-balance-policies)# load-balance sand profile udp-profile
switch(config-sand-load-balance-profile-udp-profile)#

 

Use the fields udp dst-port command and add the destination port, 1234, for the configuration:

switch(config-sand-load-balance-profile-udp-profile)# fields udp dst-port 1234

 

Use the match payload bits bitrange pattern pattern hash payload bytes byterange to specify the conditional matching criteria and the bytes to hash if the payload matches the pattern and offset. The bitrange parameter can be up to 16 bits long from anywhere in the first 63 bytes of the payload, and the byterange allows any of the first 63 bytes of the UDP payload to use in the hash.

Example

Use the following command to set bytes 0-9 for hashing if bytes 2 and 3 match 0xbeef:

switch(config-sand-lb-udp-dst-port)# match payload bits 16-31 pattern 0xbeef hash payload bytes 10-19

 

Apply the load-balance profile, udp-profile, using the port-channel load-balance sand profile PROFILENAME command:

switch(config)# port-channel load-balance sand profile udp-profile

Displaying the Conditional UDP Payload Hashing Information

Use the show load-balance profile udp-profile command to display information about the configuration:

switch# show load-balance profile udp-profile
udp-profile:
----------------
LAG hashing on IP-TCP-UDP headers for IP packets is ON
LAG hashing on MAC header for IP packets is ON
...
UDP hash fields:
    Payload bytes for destination port 1234 is 10-19 if payload bits 16 to 31 match 0xbeef
    Payload bytes for destination port 1234 is 0-9
...
Profile udp-profile (global) is applied on the following
Linecard3
Linecard4
Linecard5

Port Channel and LACP Configuration Commands

Global Port Channel and LACP Configuration Commands

  • interface port-channel
  • lacp system-priority

     

Interface Configuration Commands – Ethernet Interface

  • channel-group
  • lacp port-priority
  • lacp timer
  • monitor session destination
  • monitor session source
  • port-channel lacp fallback
  • port-channel lacp fallback timeout
  • port-channel min-links
  • port-channel min-links review interval
  • port-channel speed minimum
  • port-channel speed mixed

     

Load Balance (Default) Commands

  • port-channel load-balance
  • port-channel load-balance arad fields ip
  • port-channel load-balance fm6000 fields ip
  • port-channel load-balance fm6000 fields mac
  • port-channel load-balance module
  • port-channel load-balance petraA fields ip
  • port-channel load-balance sand profile (7500E/7500R)
  • port-channel load-balance trident fields ip
  • port-channel load-balance trident fields ipv6
  • port-channel load-balance trident fields mac

Load Balance Policies Commands

  • distribution random
  • distribution symmetric-hash
  • fields ip
  • fields mac
  • hash-seed
  • ingress load-balance profile
  • load-balance fm6000 profile
  • load-balance policies
  • load-balance sand profile (7500E/7500R)
  • port-channel hash-seed

     

EXEC Commands

  • show lacp aggregates
  • show lacp counters
  • show lacp interface
  • show lacp internal
  • show lacp peer
  • show lacp sys-id
  • show load-balance profile
  • show port-channel
  • show port-channel dense
  • show port-channel limits
  • show port-channel load-balance
  • show port-channel load-balance fields

     

channel-group

The channel-group command assigns the configuration mode Ethernet interfaces to a channel group, creates the group if it does not already exist, and sets the port-channel mode for the group. When adding interfaces to a previously created channel group, the port-channel mode for the newly added interfaces must match the mode for the existing group.

Channel groups are associated with a port channel interface immediately upon their creation. A command that creates a new channel group also creates a port channel with a matching ID. The port channel is configured in Port-channel Configuration Mode. Configuration changes to a port channel interface propagate to all Ethernet interfaces in the corresponding channel group. The interface port-channel command places the switch in the interface-port-channel configuration mode.

The no channel-group and default channel group commands remove the configuration-mode interface from the specified channel group.

 

Command Mode

Interface-Ethernet Configuration

 

Command Syntax

channel-group number mode group_mode

no channel-group

default channel-group

 

Parameters
  • number     Specifies a channel group ID. Values range from 1 through 2000.
  • group_mode      Specifies the channel-group mode for the channel group. Values include:
    • on       Port channel is static and LACP is disabled on member interfaces. Port neither verifies nor negotiates port channel membership.
      • active       Port channel is dynamic and member interfaces are active LACP ports that transmit and receive LACP negotiation packets.
      • passive      Port channel is dynamic and member interfaces are passive LACP ports that respond to LACP negotiation packets but do not generate them.

         

Guidelines: Port Channels

You can configure a port channel to contain many ports, but only a subset may be active at a time. All active ports in a port channel must be compatible. Compatibility includes many factors and is platform-specific. For example, compatibility may require identical operating parameters such as speed and Maximum Transmission Unit (MTU). Compatibility may only be possible between specific ports because of the internal organization of the switch.

 

Guidelines: MLAG Configurations

Static LAG is not recommended in MLAG configurations. However, these considerations apply when the channel group mode is on while configuring static MLAG:
  • When configuring multiple interfaces on the same static port channel:
    • all interfaces must physically connect to the same neighboring switch.
    • the neighboring switch must configure all interfaces into the same port channel.

       

The switches are misconfigured when these conditions are not met.

Disable the static port channel membership before moving any cables connected to these interfaces or changing a static port channel membership on the remote switch.

Examples
  • These commands assign Ethernet interfaces 8 and 9 to channel group 10, and enable LACP in negotiating mode.
    switch(config)# interface ethernet 8-9
    switch(config-if-Et8-9)# channel-group 10 mode active
    switch(config-if-Et8-9)# show active
    interface Ethernet8
       channel-group 10 mode active
    interface Ethernet9
       channel-group 10 mode active
    switch(config-if-Et8-9)#

     

  • These commands assign Ethernet interfaces 12 and 13 to static channel group 11. LACP is disabled on these interfaces.
    switch(config)# interface ethernet 12-13
    switch(config-if-Et12-13)# channel-group 11 mode on
    switch(config-if-Et12-13)# show active
    interface Ethernet12
       channel-group 11 mode on
    interface Ethernet13
       channel-group 11 mode on
    switch(config-if-Et12-13)#

distribution random

The distribution random command specifies the random distribution of data packets handled by the hash algorithm defined by the configuration mode load balance profile. All data fields and hash seeds that are configured for the profile are used as seeds for the random number generator that defines the distribution of individual packets.

Command options allow for the random distribution of traffic across port channel links and ECMP routes. Random distribution can be enabled for either, both, or neither.

The no distribution random and default distribution random commands remove random distribution on the configuration mode load balance profile by deleting the corresponding distribution random command from the configuration.

 

Command Mode

Load-balance-profile Configuration

 

Command Syntax

distribution random BALANCE_TYPE

no distribution random

default distribution random

 

Parameters

SCOPE       Specifies use of random distribution for port channels and ECMP routes. Options include:
  • no parameter      Random distribution is enabled for ECMP routes and port channel links.
  • ecmp      Random distribution is enabled for ECMP routes.
  • port-channel      Random distribution is enabled for port channel links.
  • port-channel ecmp      Random distribution is enabled for ECMP routes and port channel links.
  • ecmp port-channel      Random distribution is enabled for ECMP routes and port channel links.

     

Guidelines

The distribution random command takes precedence over the distribution symmetric-hash command when both methods are simultaneously enabled.

 

Related Commands

load-balance fm6000 profile places the switch in the load-balance-profile configuration mode.

Example

These commands configure symmetric hashing on all traffic distributed through the algorithm defined by the LB-1 load balance profile.
switch(config)# load-balance policies
switch(config-load-balance-policies)# load-balance fm6000 profile LB-1
switch(config-load-balance-profile-LB-1)# distribution random ecmp port-channel
switch(config-load-balance-profile-LB-1)# show active
load-balance policies
   load-balance fm6000 profile LB-1
      distribution random ecmp port-channel
switch(config-load-balance-profile-LB-1)#

distribution symmetric-hash

The distribution symmetric-hash command enforces traffic symmetry on data distributed by the hash algorithm defined by the configuration mode load balance profile. Symmetric traffic is the flow of both directions of a data stream across the same physical link.

Two symmetric-hash options specify the traffic upon which symmetry is enforced:
  • distribution symmetric-hash mac specifies that only non-IP traffic is hashed symmetrically. IP traffic is hashed normally without regard to symmetry.

     

  • distribution symmetric-hash mac-ip specifies that all traffic is hashed symmetrically.

     

The no distribution symmetric-hash and default distribution symmetric-hash commands remove the specified hashing symmetry restriction on the configuration mode load balance profile by deleting the corresponding distribution symmetric-hash command from running-config.

 

Command Mode

Load-balance-profile

 

Command Syntax

distribution symmetric-hash FIELD_TYPE

no distribution symmetric-hash

default distribution symmetric-hash

 

 

Parameters

FIELD_TYPE      Fields the hashing algorithm uses for Layer 3 routing. Options include:
  • mac      Non-IP traffic is hashed symmetrically.
  • mac-ip      All traffic is hashed symmetrically.

     

Guidelines

The distribution random command takes precedence over the distribution symmetric-hash command when both methods are simultaneously enabled.

 

Related Commands

load-balance fm6000 profile places the switch in the load-balance-profile configuration mode.

Example

These commands configure symmetric hashing on all traffic distributed through the algorithm defined by the LB-1 load balance profile.
switch(config)# load-balance policies
switch(config-load-balance-policies)# load-balance fm6000 profile LB-1
switch(config-load-balance-profile-LB-1)# distribution symmetric-hash mac-ip
switch(config-load-balance-profile-LB-1)# show active
load-balance policies
   load-balance fm6000 profile LB-1
      distribution symmetric-hash mac-ip
switch(config-load-balance-profile-LB-1)#

fields ip

The fields ip command specifies the L3/L4 data fields used by the hash algorithm defined by the configuration mode load balance profile. When a load balance profile is assigned to a port channel or Ethernet interface, its associated hash algorithm determines the distribution of packets that ingress the interface. Profile algorithms can load balance packets across port channel links or ECMP routes.

The switch calculates a hash value by using the packet header fields to balance packets across links. The hash value determines the link through which the packet is transmitted. This method also ensures that all packets in a flow follow the same network path. Packet flow is modified by changing the inputs to the port channel hash algorithm.

In network topologies that include MLAGs, programming all switches to perform the same hash calculation increases the risk of hash polarization, which leads to uneven load distribution among LAG and MLAG member links in MLAG switches. This problem is avoided by performing different hash calculations between the MLAG switch, and a non-peer switch connected to it.

The no fields ip configures the algorithm not to use L3/L4 data fields. The default fields ip command restores the default data L3/L4 fields to the load balancing algorithm defined by the configuration mode profile by removing the corresponding fields ip or no fields ip command from running-config.

 

Command Mode

Load-balance-profile Configuration

 

Command Syntax

fields ip IP_FIELD

no fields ip

default fields ip

 

Parameters

IP_FIELD       Specifies the L3/L4 fields the hashing algorithm uses. Options include:
  • dscp      Algorithm uses dscp field.
  • dst-ip      Algorithm uses destination IP address field.
  • dst-port      Algorithm uses destination TCP/UDP port field.
  • protocol      Algorithm uses protocol field.
  • src-ip      Algorithm uses source IP address field.
  • src-port      Algorithm uses source TCP/UDP port field.

     

Command may include from one to six fields, in any combination and listed in any order. The default setting is the selection of all fields.

 

Related Commands

load-balance fm6000 profile places the switch in the load-balance-profile configuration mode.

Example

These commands specify the IP source and protocol fields as components of the hash algorithm defined by the LB-1 load balance profile.
switch(config)# load-balance policies
switch(config-load-balance-policies)# load-balance fm6000 profile LB-1
switch(config-load-balance-profile-LB-1)# fields ip src-ip protocol
switch(config-load-balance-profile-LB-1)# show active
load-balance policies
   load-balance fm6000 profile LB-1
      fields ip protocol src-ip
switch(config-load-balance-profile-LB-1)#

fields mac

The fields mac command specifies the L2 data fields used by the hash algorithm defined by the configuration mode load balance profile. When a load balance profile is assigned to a port channel or Ethernet interface, its associated hash algorithm determines the distribution of packets that ingress the interface. Profile algorithms can load balance packets across port channel links or ECMP routes.

The switch calculates a hash value using the packet header fields to balance packets across links. The hash value determines the link through which the packet is transmitted. This method also ensures that all packets in a flow follow the same network path. Packet flow is modified by changing the inputs to the port channel hash algorithm.

In network topologies that include MLAGs, programming all switches to perform the same hash calculation increases the risk of hash polarization, which leads to uneven load distribution among LAG and MLAG member links in MLAG switches. This problem is avoided by performing different hash calculations between the MLAG switch, and a non-peer switch connected to it.

The no fields mac configures the algorithm not to use L2 data fields. The default fields mac command restores the default data L2 fields to the load balancing algorithm defined by the configuration mode profile by removing the corresponding fields mac or no fields mac command from running-config.

 

Command Mode

Load-balance-profile Configuration

 

Command Syntax

fields mac MAC_FIELD

no fields mac

default fields mac

 

Parameters

MAC_FIELD       Specifies the L2 fields the hashing algorithm uses. Options include:
  • dst-mac      Algorithm uses the MAC destination field.
  • eth-type      Algorithm uses the Ethernet port type field.
  • src-mac      Algorithm uses MAC source field.
  • vlan-id      Algorithm uses VLAN ID field.
  • vlan-priority      Algorithm uses VLAN priority field.

     

Related Commands

The load-balance fm6000 profile command places the switch in to the load-balance-profile configuration mode.

Example

These commands specify the MAC destination and VLAN priority fields as components of the hash algorithm defined by the LB-1 load balance profile.
switch(config)# load-balance policies
switch(config-load-balance-policies)# load-balance fm6000 profile LB-1
switch(config-load-balance-profile-LB-1)# fields mac dst-mac vlan-priority
switch(config-load-balance-profile-LB-1)# show active
load-balance policies
   load-balance fm6000 profile LB-1
      fields mac dst-mac vlan-priority
switch(config-load-balance-profile-LB-1)#

hash-seed

The hash-seed command specifies the seed used by the hash algorithm defined by the configuration mode load balance profile. Profile algorithms can load balance packets across port channel links or ECMP routes.

The no hash-seed and default hash-seed commands restore the default hash seed value of 0 to the load balancing algorithm defined by the configuration mode profile by removing the corresponding hash-seed command from running-config.

 

Command Mode

Load-balance-profile Configuration

 

Command Syntax

hash-seed number

no hash-seed number

default hash-seed number

 

Parameters

number      Specifies the value of the hash seed. Value ranges from 0 to 39.

Example

These commands configure the hash seed 20 in a profile and assign it as the global profile.
switch(config)# load-balance policies
switch(config-load-balance-policies)# load-balance sand profile myGlobalProfile
switch(config-sand-load-balance-profile-myGlobalProfile)# hash-seed 20
switch(config)# port-channel load-balance sand profile myGlobalProfile

ingress load-balance profile

The ingress load-balance profile command applies the specified load-balance profile to the configuration mode interface. Load balance profiles specify parameters used by hashing algorithms that distribute traffic across ports comprising a port channel or among ECMP routes. The switch supports 16 load balance profiles, including the default profile.

Load balance profiles can be assigned to Ethernet and port channel interfaces. Profiles define the distribution method of traffic that ingresses the interface among the ports comprising a port channel or routes comprising an ECMP.

The default load balance profile is configured through port-channel load-balance fm6000 fields ip and port-channel load-balance fm6000 fields mac commands.

The no ingress load-balance profile and default ingress load-balance profile commands restore the default load balance profile for the configuration mode interface by removing the corresponding ingress load-balance profile command from running-config.

 

Command Mode

Interface-Ethernet Configuration

Interface-Port-Channel Configuration

 

Command Syntax

ingress load-balance profile profile_name

no ingress load-balance profile

default ingress load-balance profile

 

Parameter

profile_name      Name of profile assigned to interface.

 

Example

This command applies the LB-1 load balance profile to port channel interface 100.
switch(config)# interface port-channel 100
switch(config-if-Po100)# show active
interface Port-Channel100

switch(config-if-Po100)# ingress load-balance profile LB-1
switch(config-if-Po100)#
interface Port-Channel100
   ingress load-balance profile LB-1

switch(config-if-Po100)#

interface port-channel

The interface port-channel command places the switch in port-channel interface configuration mode for modifying parameters of specified link aggregation (LAG) interfaces. When entering configuration mode to modify existing port channel interfaces, the command can specify multiple interfaces.

The command creates a port channel interface if the specified interface does not exist prior to issuing the command. When creating an interface, the command can only specify a single interface.

The no interface port-channel and default interface port-channel commands delete the specified LAG interfaces from running-config.

 

Command Mode

Global Configuration

 

Command Syntax

interface port-channel p_range

no interface port-channel p_range

default interface port-channel p_range

 

Parameter

p_range  Port channel interfaces (number, range, or comma-delimited list of numbers and ranges).

Port channel numbers range from 1 to 2000.

 

Guidelines

When configuring a port channel, you do not need to issue the interface port-channel command before assigning a port to the port channel (see the channel-group command). The port channel number is implicitly created when a port is added to the specified port channel with the channel-group number command.

To display ports that are members of a port channel, enter show port-channel. To view information about hardware limitations for a port channel, enter show port-channel limits.

All active ports in a port channel must be compatible. Compatibility comprises many factors and is specific to a given platform. For example, compatibility may require identical operating parameters such as speed and/or Maximum Transmission Unit (MTU). Compatibility may only be possible between specific ports because of internal organization of the switch.

You can configure a port channel with a set of ports such that more than one subset of the member ports are mutually compatible. Port channels in EOS are designed to activate the compatible subset of ports with the largest aggregate capacity. A subset with two 40 Gbps ports (aggregate capacity 80 Gbps) has preference to a subset with five active 10 Gbps ports (aggregate capacity 50 Gbps).

Example

This example creates interface port-channel 3:
switch(config)# interface port-channel 3
switch(config-if-Po3)#

lacp port-priority

The lacp port-priority command sets the aggregating port priority for the configuration mode interface. Priority is supported on port channels with LACP-enabled physical interfaces. LACP port priority determines the port that is active in a LAG in fallback mode. Numerically lower values have higher priority.

Each port in an aggregation is assigned a 32-bit port identifier by prepending the port priority (16 bits) to the port number (16 bits). Port priority determines the ports that are placed in standby mode when hardware limitations prevent a single aggregation of all compatible ports.

Priority numbers range from 0 to 65535. The default is 32768. Interfaces with higher priority numbers are placed in standby mode before interfaces with lower priority numbers.

The no lacp port-priority and default lacp port-priority commands restore the default port-priority to the configuration mode interface by removing the corresponding lacp port-priority command from running-config.

 

Command Mode

Interface-Ethernet Configuration

 

Command Syntax

lacp port-priority priority_value

no lacp port-priority

default lacp port-priority

 

Parameters

priority_level Port priority. Values range from 0 to 65535. Default is 32768

 

Example

These commands assign the port priority of 4096 to interface ethernet 8.
switch(config)# interface ethernet 8
switch(config-if-Et8)# lacp port-priority 4096
switch(config-if-Et8)# show active
interface Ethernet8
   lacp port-priority 4096
switch(config-if-Et8)#

lacp system-priority

The lacp system-priority command configures the switch’s LACP system priority. Values range between 0 and 65535. Default value is 32768.

Each switch is assigned a globally unique 64-bit system identifier by prepending the system priority (16 bits) to the MAC address of one of its physical ports (48 bits). Peer devices use the system identifier when forming an aggregation to verify that all links are from the same switch. The system identifier is also used when dynamically changing aggregation capabilities resulting from LACP data; the system with the numerically lower system identifier can dynamically change advertised aggregation parameters.

The no lacp system-priority and default lacp system-priority commands restore the default system priority by removing the lacp system-priority command from running-config.

 

Command Mode

Global Configuration

 

Command Syntax

lacp system-priority priority_value

no lacp system-priority

default lacp system-priority

 

Parameters

priority_value System priority number. Values range from 0 to 65535. Default is 32768.

 

Example

This command assigns the system priority of 8192 to the switch.
switch(config)# lacp system-priority 8192
switch(config)#

lacp timer

The lacp timer command configures the LACP reception interval on the configuration mode interface. The LACP timeout specifies the reception rate of LACP packets at interfaces supporting LACP. Supported rates include:
  • normal: 30 seconds with synchronized interfaces; one second while interfaces are synchronizing.

     

  • fast: one second.

     

This command is supported on LACP-enabled interfaces. The default value is normal.

The no lacp timer and default lacp timer commands restore the default value of normal on the configuration mode interface by deleting the corresponding lacp timer command from running-config.

 

Command Mode

Interface-Ethernet Configuration

 

Command Syntax

lacp timer RATE_LEVEL

no lacp timer

default lacp timer

 

Parameters

RATE_LEVEL LACP reception interval. Options include:
  • fast One second.

     

  • normal 30 seconds for synchronized interfaces; 1 second while interfaces synchronize.

     

 

Example

This command sets the LACP timer to 1 second on ethernet interface 4.
switch(config-if-Et4)# lacp timer fast
switch(config-if-Et4)#

load-balance fm6000 profile

The load-balance fm6000 profile command places the switch in load-balance-profile configuration mode to configure a specified load balance profile. The command specifies the name of the profile that subsequent commands modify. It creates a profile if the profile it references does not exist.

Load balance profiles specify parameters used by hashing algorithms that distribute traffic across ports comprising a port channel or among component ECMP routes. The switch supports 16 load balance profiles, including the default profile. The default load balance profile is configured through port-channel load-balance fm6000 fields ip and port-channel load-balance fm6000 fields mac commands.

The load balance profile name is referenced when it is applied to an interface. The default profile is not associated with a name and is applied to an interface in the absence of a named profile assignment.

The no load-balance fm6000 profile and default load-balance fm6000 profile commands delete the specified load balance profile from running-config. Profiles that are assigned to an interface cannot be deleted. Attempts to delete an assigned profile generate a profile in use error messages.

The load-balance fm6000 profile command is accessible from load-balance-policies configuration mode. The load-balance-profile configuration mode is not a group change mode; running-config is changed immediately upon entering commands. Exiting the load-balance-policies configuration mode does not affect the configuration. The exit command returns the switch to the load-balance-policies configuration mode.

 

Command Mode

Load-balance-policies Configuration

 

Command Syntax

load-balance fm6000 profile profile_name

no load-balance fm6000 profile profile_name

default load-balance fm6000 profile profile_name

 

Parameters

profile_name      Name of the load-balance profile.

 

Commands Available in Load-balance-profile Configuration Mode
  • fields ip
  • fields mac
  • distribution random
  • distribution symmetric-hash
  • port-channel hash-seed
  • show active displays the contents of the configuration mode profile.

     

Related Commands
  • The load-balance policies command places the switch in to theload-balance-policies configuration mode.
  • The ingress load-balance profile command applies a load-balance profile to an Ethernet or port channel interface.
  • The show load-balance profile command displays the contents of load balance profiles.

     

 

Example

These commands enters the load-balance-profile configuration mode, creates the LB-1 profile, and lists the default settings for the profile.
switch(config)# load-balance policies
switch(config-load-balance-policies)# load-balance fm6000 profile LB-1
switch(config-load-balance-profile-LB-1)# show active all
load-balance policies
   load-balance fm6000 profile LB-1
      port-channel hash-seed 0
      fields mac dst-mac src-mac eth-type vlan-priority vlan-id
      fields ip protocol dst-ip dst-port src-ip src-port dscp
      no distribution symmetric-hash
      no distribution random
switch(config-load-balance-profile-LB-1)#

load-balance policies

The load-balance policies command places the switch in Load-Balance-Policies Configuration Mode. Load-balance-policies configuration mode provides commands for managing load-balance profiles. Load balance profiles specify the inputs used by the hashing algorithms that distribute traffic across ports comprising a port channel or among ECMP routes.

The no load-balance policies and default load-balance policies commands delete all load balance profiles from running-config. The command generates an error message when at least one profile is assigned to an interface.

Load-balance-policies configuration mode is not a group change mode; running-config is changed immediately upon entering commands. Exiting the load-balance-policies configuration mode does not affect running-config. The exit command returns the switch to global configuration mode.

 

Command Mode

Global Configuration

 

Command Syntax

load-balance policies

no load-balance policies

default load-balance policies

 

Commands Available in Load-Balance-Policies Configuration Mode
  • The load-balance fm6000 profile command places the switch inLoad-Balance-Policies Configuration Mode.

     

  • show active displays contents of all load balance profiles.

     

Related Commands
  • The ingress load-balance profile command applies a load-balance profile to an Ethernet or port channel interface.

     

  • The show load-balance profile command displays the contents of load balance profiles.

     

 

Examples
  • This command places the switch in the Load-Balance-Policies Configuration Mode.
    switch(config)# load-balance policies
    switch(config-load-balance-policies)#

     

  • This command displays the contents of the three configured load balance profiles.
    switch(config-load-balance-policies)# show active
    
    load-balance policies
       load-balance fm6000 profile F-01
          port-channel hash-seed 22
          fields ip dscp
          distribution random port-channel
       !
       load-balance fm6000 profile F-02
          fields ip protocol dst-ip
          fields mac dst-mac eth-type
          distribution random ecmp port-channel
       !
       load-balance fm6000 profile F-03
    
    switch(config-load-balance-policies)#

load-balance sand profile (7500E/7500R)

The load-balance sand profile command configures a load-balance profile on a sand module switch. A default profile is designated as a global profile when no other profile is set as global profile. Note, a warning message is displayed when a profile is entered or deleted.

If no load-balance sand profile command is executed when the profile set is default then the following warning message is displayed:
! profile default is a reserved profile and cannot be deleted

 

Command Mode

Global Configuration

 

Command Syntax

load-balance sand profile profile_name

no load-balance sand profile profile_name

 

Parameter

profile_name Name of the profile assigned to the selected module.

 

Examples
  • These commands designate a default profile as a global profile on sand module platform switch. Note, a warning message is displayed when a profile is entered or deleted.
    switch(config)# load-balance policies
    switch(config-load-balance-policies)# load-balance sand profile default
     ! profile default is a reserved profile
    ! profile default is the current global profile

     

  • When no form of the command is executed it displays the following warning message.
    switch(config)# load-balance policies
    switch(config-load-balance-policies)# no load-balance sand profile default
    ! profile default is a reserved profile and cannot be deleted

monitor session destination

The monitor session destination configures Port Channel interfaces as a mirroring destination for both ingress and egress traffic.

The no | default versions of the command removes the configuration from the running-configuration.

 

Command Mode

Global Configuration

 

Command Syntax

monitor session session_name destination Port-Channel interface_number

 

Parameters

  • session session_name - Configure a name for the session.
  • destination - Specify the mirroring for Port Channel traffic as the destination.
  • Port-Channel interface_number - Specify the Port Channel to be the destination.

 

Example

Use the following command to configure Port Channel 1 as a mirroring destination:
switch(config)#monitor session 1 destination Port-Channel 1

monitor session source

The monitor session source configures Port Channel interfaces as a mirroring source for both ingress and egress traffic.

The no | default versions of the command removes the configuration from the running-configuration.

 

Command Mode

Global Configuration

 

Command Syntax

monitor session session_name source interface_number

 

Parameters

  • session session_name - Configure a name for the session.
  • source - Specify the mirroring for Port Channel traffic as the source.
  • interface_number - Specify the Ethernet interface to be the source of the ingress and egress traffic.

 

Example

Use the following command to configure a session, testmember with the Ethernet interface Et3/3/1:
switch(config)#monitor session testmember source Et3/3/1

port-channel hash-seed

The port-channel hash-seed command specifies the seed used by the hash algorithm defined by the configuration mode load balance profile when distributing the load across ports comprising a port channel. When a load balance profile is assigned to a port channel or Ethernet interface, its associated hash algorithm determines the distribution of packets that ingress the interface. Profile algorithms can load balance packets across port channel links or ECMP routes.

The hash seed that the algorithm uses to select port channel links or ECMP routes is configured by the ip load-sharing command.

The no port-channel hash-seed and default port-channel hash-seed commands restore the default hash seed value of 0 to the load balancing algorithm defined by the configuration mode profile by removing the corresponding port-channel hash-seed command from running-config.

 

Command Mode

Load-balance-profile configuration

 

Command Syntax

port-channel hash-seed number

no port-channel hash-seed

default port-channel hash-seed

 

Parameters

number The hash seed. Value ranges from 0 to 39.

 

Related Command

The load-balance fm6000 profile command places the switch in to the load-balance-profile configuration mode.

 

Example

These commands configure the port-channel hash seed of 22 for the hash algorithm defined by the LB-1 load balance profile.
switch(config)# load-balance policies
switch(config-load-balance-policies)# load-balance fm6000 profile LB-1
switch(config-load-balance-profile-LB-1)# port-channel hash-seed 22
switch(config-load-balance-profile-LB-1)# show active
load-balance policies
   load-balance fm6000 profile LB-1
      port-channel hash-seed 22
switch(config-load-balance-profile-LB-1)#

port-channel lacp fallback

The port-channel lacp fallback command enables the LACP fallback mode on the interface.

LACP fallback is unconfigured and disabled by default. An LACP interface without fallback enabled does not form a LAG until it receives PDUs from its peer.

LACP fallback can be configured on an interface in static or individual mode:
  • static mode      The port channel member with the lowest LACP port priority is active and maintains contact with the peer (sending and receiving data) while other port channel members remain in standby mode until a LACP PDU is received. All members continue to send (and can receive) LACP PDUs.

     

  • individual mode      All port channel members act as individual ports, reverting to their port-specific configuration while the channel is in fallback mode, and continue to send and receive data. All members continue to send LACP PDUs until a LACP PDU is received by one of the member ports.

     

The no port-channel lacp fallback and default port-channel lacp fallback commands disable LACP fallback mode on the configuration mode interface by removing the corresponding port-channel lacp fallback command from running-config.

 

Command Mode

Interface-Port-Channel Configuration

 

Command Syntax

port-channel lacp fallback [MODE]

no port-channel lacp fallback

default port-channel lacp fallback

 

Parameters

MODE LACP fallback mode. Options include:
  • no parameter Enables static LACP fallback mode.
    • static Enables static LACP fallback mode.
    • individual Enables individual LACP fallback mode.

       

Related Commands
  • The port-channel lacp fallback timeout command configures the fallback timeout period for a port channel interface. The default LACP fallback timeout period is 90 seconds.

     

  • The lacp port-priority command configures the port priority for an individual interface.

     

 

Examples
  • These commands enable LACP static fallback mode, then configure an LACP fallback timeout of 100 seconds on interface port-channel 13. If LACP negotiation fails, only the member port with the lowest LACP priority will remain active until an LACP PDU is received by one of the member ports.
    switch(config)# interface port-channel 13
    switch(config-if-Po13)# port-channel lacp fallback static
    switch(config-if-Po13)# port-channel lacp fallback timeout 100
    switch(config-if-Po13)# show active
    interface Port-Channel13
       port-channel lacp fallback static
       port-channel lacp fallback timeout 100
    switch(config-if-Po13)#

     

  • These commands enable LACP individual fallback mode, then configure an LACP fallback timeout of 50 seconds on interface port-channel 17. If LACP negotiation fails, all member ports will act as individual switch ports, using port-specific configuration, until a LACP PDU is received by one of the member ports.
    switch(config)# interface port-channel 17
    switch(config-if-Po17)# port-channel lacp fallback individual
    switch(config-if-Po17)# port-channel lacp fallback timeout 50
    switch(config-if-Po17)# show active
    interface Port-Channel17
       port-channel lacp fallback individual
       port-channel lacp fallback timeout 50
    switch(config-if-Po17)#

port-channel lacp fallback timeout

The port-channel lacp fallback timeout command specifies the fallback timeout period for the configuration mode interface.

Fallback timeout settings persist in running-config without taking effect for interfaces that are not configured into fallback mode. The default fallback timeout period is 90 seconds.

The no port-channel lacp fallback timeout and default port-channel lacp fallback timeout commands restore the default fallback timeout of 90 seconds for the configuration mode interface by removing the corresponding port-channel lacp fallback timeout command from running-config.

 

Command Mode

Interface-Port-Channel configuration

 

Command Syntax

port-channel lacp fallback timeout period

no port-channel lacp fallback timeout

default port-channel lacp fallback timeout

 

Parameters

period Maximum interval between receipt of LACP PDU packets (seconds). Value ranges from 1 to 300 seconds. Default value is 90.

 

Related Command

The port-channel lacp fallback command configures fallback mode for a port channel interface.

 

Guidelines

The fallback timeout period should not be shorter than the LACP reception interval (lacp timer). The default LACP reception interval is 30 seconds.

 

Example

This command enables LACP fallback mode, then configures an LACP fallback timeout of 100 seconds on interface port-channel 13.
switch(config)# interface port-channel 13
switch(config-if-Po13)# port-channel lacp fallback
switch(config-if-Po13)# port-channel lacp fallback timeout 100
switch(config-if-Po13)# show active
interface Port-Channel13
   port-channel lacp fallback
   port-channel lacp fallback timeout 100
switch(config-if-Po13)#

port-channel load-balance

The port-channel load-balance command specifies the seed in the hashing algorithm that balances the load across ports comprising a port channel. Available seed values vary by switch platform.

The no port-channel load-balance and default port-channel load-balance commands remove the port-channel load-balance command from running-config, restoring the default hash seed value of 0.

 

Command Mode

Global Configuration

 

Command Syntax

port-channel load-balance platform { hash_seed | fields ip fields | hash hash_function }

no port-channel load-balance platform [ hash_seed ]

default port-channel load-balance platform [ hash_seed ]

 

Parameters

 

Note: Parameter options vary by switch model. Verify available options with the ? command.

 

  • platform ASIC switching device. Value depends on the switch model.
  • hash_seed The numerical seed for the hash function. Value range varies by switch platform:
    • arad 0 to 65535.
    • fm6000 0 to 39.
    • petraA Uses field inputs only.
    • trident 0 to 47.

       

    For trident platform switches, algorithms using hash seeds between 0 and 15 typically result in more effective distribution of data streams across the port channels.

  • fields Which fields will be used as inputs to the port channel hash.
    • gre Configure which GRE fields are inputs to the hash.
    • ip Configure which fields are inputs to the hash for IPv4 packets.
    • ipv6 Configure which fields are inputs to the hash for IPv6 packets.
    • mac Configure which MAC fields are inputs to the hash.
    • mac-in-mac Configure which MAC-in-MAC fields are inputs to the hash.
    • mpls Configure which MPLS fields are inputs to the hash.
    • destination-ip Use the Layer 3 IP destination address in the hash.
    • destination-port Use the Layer 4 TCP/UDP destination port in the hash.
    • dst-ip Use the destination IP address in the hash.
    • dst-mac Use the destination Payload MAC in the hash (or the destination MAC address in the MAC hash).
    • eth-type Use the Ethernet type in the MAC hash.
    • ip-in-ip Use the outer IP header in the hash for IPv4 over IPv4 GRE tunnel.
    • ip-in-ipv6 Use the outer IP header in the hash for IPv4 over IPv6 GRE tunnel.
    • ipv6-in-ip Use the outer IP header in the hash for IPv6 over IPv4 GRE tunnel.
    • ipv6-in-ipv6 Use the outer IP header in the hash for IPv6 over IPv6 GRE tunnel.
    • ip-tcp-udp-header Use the Layer 3 and Layer 4 hashes.
    • isid Use the MAC-in-MAC ISID in the hash.
    • label Use the MPLS label in the hash.
    • mac-header Use the MAC hash.
    • outer-mac Use the outer MAC of source and destination in the hash.
    • source-ip Use the Layer 3 IP source address in the hash.
    • src-ip Use the source IP address in the hash.
    • source-port Use l\Layer 4 TCP/UDP source port in the hash.
    • src-mac Use the source payload MAC in the hash (or the source MAC address in the MAC hash).

       

  • hash_function Specifies the hash polynomial function. Values range from 0-2.

     

 

Example

This command configures a hash seed of 10 on an FM6000 platform switch.
switch(config)# port-channel load-balance fm6000 10
switch(config)#

port-channel load-balance arad fields ip

The port-channel load-balance arad fields ip command specifies the data fields that the port channel load balance hash algorithm uses for distributing IP packets on Arad platform switches. The hashing algorithm fields used for IP packets differ from the fields used for non-IP packets.

The switch calculates a hash value using the packet header fields to load balance packets across links in a port channel. The hash value determines the link through which the packet is transmitted. This method also ensures that all packets in a flow follow the same network path. Packet flow is modified by changing the inputs to the port channel hash algorithm.

In network topologies that include MLAGs, programming all switches to perform the same hash calculation increases the risk of hash polarization, which leads to uneven load distribution among LAG and MLAG member links in MLAG switches. This problem is avoided by performing different hash calculations between the MLAG switch, and a non-peer switch connected to it.

The no port-channel load-balance arad fields ip and default port-channel load-balance arad fields ip commands restore the default data fields for the IP packet load balancing algorithm by removing the port-channel load-balance arad A fields ip command from running-config.

 

Command Mode

Global Configuration

 

Command Syntax

port-channel load-balance arad fields ip IP_FIELD_NAME

no port-channel load-balance arad fields ip

default port-channel load-balance arad fields ip

 

Parameters

IP_FIELD_NAME      Fields the hashing algorithm uses for Layer 3 routing. Options include:
  • ip-tcp-udp-header  Algorithm uses source and destination IP address fields. Source and destination port fields are included for TCP and UDP packets.
    • mac-header  Algorithm uses entire MAC header.

      A command can only specify one option. The default setting is ip-tcp-udp-header.

       

Guidelines

The port channel hash algorithm for non-IP packets is not configurable and always includes the entire MAC header.

 

Related Command

The port-channel load-balance command configures the hash seed for the algorithm.

 

Example

These commands configure the switch’s port channel load balance hash algorithm for IP packets to use source and destination IP address (and port) fields.
switch(config)# port-channel load-balance fm6000 fields ip ip-tcp-udp-header
switch(config)#

port-channel load-balance fm6000 fields ip

The port-channel load-balance fm6000 fields ip command specifies the data fields that the port channel load balance hash algorithm uses for distributing IP packets on FM6000 platform switches. The hashing algorithm fields used for IP packets differ from the fields used for non-IP packets.

The switch calculates a hash value using the packet header fields to load balance packets across links in a port channel. The hash value determines the link through which the packet is transmitted. This method also ensures that all packets in a flow follow the same network path. Packet flow is modified by changing the inputs to the port channel hash algorithm.

In network topologies that include MLAGs, programming all switches to perform the same hash calculation increases the risk of hash polarization, which leads to uneven load distribution among LAG and MLAG member links in MLAG switches. This problem is avoided by performing different hash calculations between the MLAG switch, and a non-peer switch connected to it.

The no port-channel load-balance fm6000 fields ip and default port-channel load-balance fm6000 fields ip commands restore the default data fields for the IP packet load balancing algorithm by removing the port-channel load-balance fm6000 fields ip command from running-config.

 

Command Mode

Global Configuration

 

Command Syntax

port-channel load-balance fm6000 fields ip IP_FIELD_NAME

no port-channel load-balance fm6000 fields ip

default port-channel load-balance fm6000 fields ip

 

Parameters

IP_FIELD_NAME       Specifies fields the hashing algorithm uses for layer 3 routing. Options include:
  • ip-tcp-udp-header  Algorithm uses source and destination IP address fields. Source and destination port fields are included for TCP and UDP packets.

     

A command can only specify one option. The default setting is ip-tcp-udp-header.

 

Related Commands
  • The port-channel load-balance command configures the hash seed for the algorithm.
  • The port-channel load-balance fm6000 fields mac command controls the hash algorithm for non-IP packets.

     

 

Example

These commands configure the switch’s port channel load balance for IP packets by source and destination IP address and port fields.
switch(config)# port-channel load-balance fm6000 fields ip ip-tcp-udp-header
switch(config)#

port-channel load-balance fm6000 fields mac

The port-channel load-balance fm6000 fields mac command specifies data fields that configure the port channel load balance hash algorithm for non-IP packets on FM6000 platform switches. The hashing algorithm fields used for balancing non-IP packets differ from the fields used for IP packets.

The switch calculates a hash value using the packet header fields to load balance packets across links in a port channel. The hash value determines the link through which the packet is transmitted. This method also ensures that all packets in a flow follow the same network path. Packet flow is modified by changing the inputs to the port channel hash algorithm.

In network topologies that include MLAGs, programming all switches to perform the same hash calculation increases the risk of hash polarization, which leads to uneven load distribution among LAG and MLAG member links in MLAG switches. This problem is avoided by performing different hash calculations between the MLAG switch, and a non-peer switch connected to it.

The no port-channel load-balance fm6000 fields mac and default port-channel load-balance fm6000 fields mac commands restore the default data fields for the non-IP packet load balancing algorithm by removing the port-channel load-balance fm6000 fields mac command from running-config.

 

Command Mode

Global Configuration

 

Command Syntax

port-channel load-balance fm6000 fields mac MAC_FIELD_NAME

no port-channel load-balance fm6000 fields mac

default port-channel load-balance fm6000 fields mac

Parameters

 

MAC_FIELD_NAME Fields the hashing algorithm uses for Layer 2 routing. Options include:
  • dst-mac MAC destination field.
  • eth-type EtherType field.
  • src-mac MAC source field.
  • vlan-id VLAN ID field.
  • vlan-priority VLAN priority field.

     

Command may include from one to five fields, in any combination and listed in any order. The default setting is the selection of all fields.

Related Commands
  • The port-channel load-balance command configures the hash seed for the algorithm.
  • The port-channel load-balance fm6000 fields ip command controls the hash algorithm for IP packets.

     

 

Example

These commands configure the switch’s port channel load balance for non-IP packets by using the MAC destination and Ethernet type fields in the hashing algorithm.
switch(config)# port-channel load-balance fm6000 fields mac dst-mac eth-type 
switch(config)#

port-channel load-balance module

The port-channel load-balance module command assigns a named load-balancing profile to a linecard.

 

Note: Available on the 7500E platform.

 

 

The no port-channel load-balance module and default port-channel load-balance module commands unassigns the load balancing module, or restores the default data fields for the load balancing module.

 

Command Mode

Global Configuration

 

Command Syntax

port-channel load-balance module LINECARD_RANGE sand profile PROFILE_NAME

no port-channel load-balance module LINECARD_RANGE sand profile PROFILE_NAME

default port-channel load-balance module LINECARD_RANGE sand profile PROFILE_NAME

 

Parameters
  • LINECARD_RANGE Linecard number range includes:
    • 3-10 Linecard number range.

       

  • PROFILE_NAME Load-balance profile name.

     

 

Examples
  • This command assigns a named load-balancing profile to a linecard.
    switch(config)# port-channel load-balance module 3-7 sand profile Linecard5
    switch(config)#

     

  • This command unassigns a named load-balancing profile to a linecard.
    switch(config)# no port-channel load-balance module 3-7 sand profile Linecard5
    switch(config)#

     

port-channel load-balance petraA fields ip

The port-channel load-balance petraA fields ip command specifies the data fields that the port channel load balance hash algorithm uses for distributing IP packets on Petra platform switches. The hashing algorithm fields used for IP packets differ from the fields used for non-IP packets.

The switch calculates a hash value using the packet header fields to load balance packets across links in a port channel. The hash value determines the link through which the packet is transmitted. This method also ensures that all packets in a flow follow the same network path. Packet flow is modified by changing the inputs to the port channel hash algorithm.

In network topologies that include MLAGs, programming all switches to perform the same hash calculation increases the risk of hash polarization, which leads to uneven load distribution among LAG and MLAG member links in MLAG switches. This problem is avoided by performing different hash calculations between the MLAG switch, and a non-peer switch connected to it.

The no port-channel load-balance petraA fields ip and default port-channel load-balance petraA fields ip commands restore the default data fields for the IP packet load balancing algorithm by removing the port-channel load-balance petraA fields ip command from running-config.

 

Command Mode

Global Configuration

 

Command Syntax

port-channel load-balance petraA fields ip IP_FIELD_NAME

no port-channel load-balance petraA fields ip

default port-channel load-balance petraA fields ip

 

Parameters

IP_FIELD_NAME Fields the hashing algorithm uses for Layer 3 routing. Options include:
  • ip-tcp-udp-header Algorithm uses source and destination IP address fields. Source and destination port fields are included for TCP and UDP packets.
  • mac-header Algorithm uses entire MAC header.

     

A command can only specify one option. The default setting is ip-tcp-udp-header.

 

Guidelines

The port channel hash algorithm for non-IP packets is not configurable and always includes the entire MAC header.

 

Related Command

The port-channel load-balance command configures the hash seed for the algorithm.

 

Example

These commands configure the switch’s port channel load balance hash algorithm for IP packets to use source and destination IP address (and port) fields.
switch(config)# port-channel load-balance fm6000 fields ip ip-tcp-udp-header
switch(config)#

port-channel load-balance sand profile (7500E/7500R)

The port-channel load-balance sand profile command configures a global LAG hashing profile on the port channel interface. A default profile is set as a global profile when no other profile is set as global.

The no port-channel load-balance sand profile command removes the active profile from the port-channel load-balance command from running-config, restoring the default profile.

 

Command Mode

Global Configuration

 

Command Syntax

port-channel load-balance sand profile profile_name

no port-channel load-balance sand profile profile_name

 

Parameter

profile_name Name of the profile assigned to the selected module.

 

Example

This command configures a global LAG hashing profile on 7500 series platform switch.
switch(config)# port-channel load-balance sand profile myGlobalProfile
switch(config)#

port-channel load-balance trident fields ip

The port-channel load-balance trident fields ip command specifies the data fields that the port channel load balance hash algorithm uses for distributing IP packets on Trident platform switches. The hashing algorithm fields used for IP packets differ from the fields used for non-IP packets.

The switch calculates a hash value using the packet header fields to load balance packets across links in a port channel. The hash value determines the link through which the packet is transmitted. This method also ensures that all packets in a flow follow the same network path. Packet flow is modified by changing the inputs to the port channel hash algorithm.

In network topologies that include MLAGs, programming all switches to perform the same hash calculation increases the risk of hash polarization, which leads to uneven load distribution among LAG and MLAG member links in MLAG switches. This problem is avoided by performing different hash calculations between the MLAG switch, and a non-peer switch connected to it.

The no port-channel load-balance trident fields ip and default port-channel load-balance trident fields ip commands restore the default data fields for the IP packet load balancing algorithm by removing the port-channel load-balance trident fields ip command from running-config.

 

Command Mode

Global Configuration

 

Command Syntax

port-channel load-balance trident fields ip IP_FIELD_NAME

no port-channel load-balance trident fields ip

default port-channel load-balance trident fields ip

default port-channel load-balance trident fields ip ingress-interface disabled

 

Parameters
  • IP_FIELD_NAME Specifies fields the hashing algorithm uses for Layer 3 routing. Command may include from one to four of the following four options, in any combination and listed in any order.
    • destination-ip Algorithm uses destination IP address field.
    • source-ip  Algorithm uses source IP address field.
    • destination-port Agorithm uses destination TCP/UDP port field.
    • source-port Algorithm uses source TCP/UDP port field.
      • ip-tcp-udp-header  Algorithm uses source and destination IP address fields. Source and destination port fields are included for TCP and UDP packets.
        Note: This option cannot be used in combination with any other option.

         

         

    • mac-header  Algorithm uses fields specified by port-channel load-balance trident fields mac.
      Note: This option cannot be used in combination with any other option.

       

       

    • ingress-interface Disable from LAG hashing.

       

Default setting is ip-tcp-udp-header.

 

Related Commands
  • The port-channel load-balance command configures the hash seed for the algorithm.
  • The port-channel load-balance trident fields ipv6 command controls the hash algorithm for IPv6 packets.
  • The port-channel load-balance trident fields mac command controls the hash algorithm for non-IP/IPv6 packets.

 

Examples
  • These commands configure the switch’s port channel load balance for IP packets by using the IPv6 destination field in the hashing algorithm.
    switch(config)# port-channel load-balance trident fields ip destination-ip
    switch(config)#

     

  • This command disables the ingress interface for IPv4 traffic.
    switch(config)# port-channel load-balance trident fields ip ingress-interface disabled
    switch(config)#

port-channel load-balance trident fields ipv6

The port-channel load-balance trident fields ipv6 command specifies the data fields that the port channel load balance hash algorithm uses for distributing IPv6 packets on Trident platform switches. The hashing algorithm fields used for IPv6 packets differ from the fields used for non-IPv6 packets.

The switch calculates a hash value using the packet header fields to load balance packets across links in a port channel. The hash value determines the link through which the packet is transmitted. This method also ensures that all packets in a flow follow the same network path. Packet flow is modified by changing the inputs to the port channel hash algorithm.

In network topologies that include MLAGs, programming all switches to perform the same hash calculation increases the risk of hash polarization, which leads to uneven load distribution among LAG and MLAG member links in MLAG switches. This problem is avoided by performing different hash calculations between the MLAG switch, and a non-peer switch connected to it.

The no port-channel load-balance trident fields ipv6 and default port-channel load-balance trident fields ipv6 commands restore the default data fields for the IPv6 packet load balancing algorithm by removing the port-channel load-balance trident fields ipv6 command from running-config.

 

Command Mode

Global Configuration

 

Command Syntax

port-channel load-balance trident fields ipv6 IP_FIELD_NAME

no port-channel load-balance trident fields ipv6

default port-channel load-balance trident fields ipv6

 

Parameters
  • IP_FIELD_NAME Specifies fields the hashing algorithm uses for Layer 3 routing. Command may include from one to four of the following four options, in any combination and listed in any order.
    • destination-ip Algorithm uses destination IPv6 address field.
    • source-ip  Algorithm uses source IPv6 address field.
    • destination-port  Algorithm uses destination TCP/UDP port field.
    • source-port Algorithm uses source TCP/UDP port field.
      • ip-tcp-udp-header  Algorithm uses source and destination IPv6 address fields. Source and destination port fields are included for TCP and UDP packets.
        Note: This option can’t be used in combination with any other option.

         

         

      • mac-header  Algorithm uses fields specified by port-channel load-balance trident fields mac.
        Note: This option can’t be used in combination with any other option.

         

         

      • ingress-interface Disable from LAG hashing.

         

      Default setting is ip-tcp-udp-header

       

Related Commands
  • The port-channel load-balance command configures the hash seed for the algorithm.
  • The port-channel load-balance trident fields ipv6 commands controls the hash algorithm for non-IP packets.
  • The port-channel load-balance trident fields mac command controls the hash algorithm for non-IP packets.

     

Examples
  • These commands configure the switch’s port channel load balance for IP packets by using the IPv6 source field in the hashing algorithm.
    switch(config)# port-channel load-balance trident fields ipv6 source-ip
    switch(config)#

     

  • This command disables the ingress interface for IPv6 traffic.
    switch(config)# port-channel load-balance trident fields ipv6 ingress-interface disabled
    switch(config)#

port-channel load-balance trident fields mac

The port-channel load-balance trident fields mac command specifies data fields that the port channel load balance hash algorithm uses for distributing non-IP packets on Trident platform switches. The hashing algorithm fields used for non-IP packets differ from the fields used for IP packets.

The switch calculates a hash value using the packet header fields to load balance packets across links in a port channel. The hash value determines the link through which the packet is transmitted. This method also ensures that all packets in a flow follow the same network path. Packet flow is modified by changing the inputs to the port channel hash algorithm.

In network topologies that include MLAGs, programming all switches to perform the same hash calculation increases the risk of hash polarization, which leads to uneven load distribution among LAG and MLAG member links in MLAG switches. This problem is avoided by performing different hash calculations between the MLAG switch, and a non-peer switch connected to it.

The no port-channel load-balance trident fields mac and default port-channel load-balance trident fields mac commands restore the default data fields for the non-IP packet load balancing algorithm by removing the port-channel load-balance trident fields mac command from running-config.

 

Command Mode

Global Configuration

 

Command Syntax

port-channel load-balance trident fields mac MAC_FIELD_NAME

no port-channel load-balance trident fields mac

default port-channel load-balance trident fields mac

default port-channel load-balance trident fields mac ingress-interface disabled

 

Parameters
  • MAC_FIELD_NAME Fields the hashing algorithm uses for Layer 2 routing. Options include:
    • dst-mac MAC destination field.
    • eth-type EtherType field.
    • src-mac MAC source field.
    • ingress-interface Disable from LAG hashing.

       

    Command may include from one to three fields, in any combination and listed in any order. The default setting is the selection of all fields.

     

Related Commands
  • port-channel load-balance configures the hash seed for the algorithm.
  • port-channel load-balance trident fields ip controls the hash algorithm for IP packets.
  • port-channel load-balance trident fields ipv6 controls the hash algorithm for IP packets.

 

Examples
  • These commands configure the switch’s port channel load balance for non-IP packets by using the MAC destination and Ethernet type fields in the hashing algorithm.
    switch(config)# port-channel load-balance trident fields mac dst-mac eth-type  
    switch(config)#

     

  • This command disables the ingress interface for IPv4 traffic.
    switch(config)# port-channel load-balance trident fields mac ingress-interface disabled
    switch(config)#

port-channel min-links

The port-channel min-links command specifies the minimum number of interfaces that the configuration mode LAG requires to become active. If there are fewer ports than specified by this command, the port channel interface does not become active. The default min-links value is 0.

The no port-channel min-links and default port-channel min-links commands restore the default min-links setting for the configuration mode LAG by removing the corresponding port-channel min-links command from the configuration.

 

Note: In static LAGs, the min-links value must be met for the LAG to be active. The LAG will not become active until it has at least the min-links number of functioning links in the channel group. If failed links cause the number to drop below the minimum, the LAG will go down and administrator action will be required to bring it back up. In dynamic LAGs, the LACP protocol must determine that at least min-links physical ports are aggregable (they are physically compatible and have the same keys both remotely and locally) before it begins negotiating to make any ports active members of the port-channel. However once negotiation begins, an error on the partner’s side or an error in programming of member interfaces can cause the LAG to become active with fewer than the minimum number of links. EOS evaluates min-links after min-links-review-timeout (linearly proportional to configured min-links) when LACP protocol collecting and/or distributing state changes. If the number of active member interfaces in a port-channel is less than configured min-links, it brings the corresponding port-channel Link Down and syslogs LAG-4-MINLINK_INTF_INSUFFICIENT message. If additional interfaces get programmed as collecting and distributing, EOS re-evaluates min-links on the port-channel. If sufficient number of interfaces are available to be a part of port-channel, then all interfaces of the corresponding port-channel are re-enabled for LACP negotiation and the port-channel becomes Link Up. LAG-4-MINLINK_INTF_NORMAL is syslogged after min-links-review-timeout if the min-links condition is satisfied; otherwise LAG-4-MINLINK_INTF_INSUFFICIENT is syslogged and the port-channel goes Link Down. If an interface remains in collecting state but not in distributing state for min-links-review-timeout, it is moved out of collecting state. It is periodically re-enabled after min-links-retry-timeout (which is 360s seconds) till it progresses to collecting and distributing. Meanwhile, if a port-channel becomes Link Up because sufficient number of interfaces progressed to collecting and distributing states, then this interface is enabled for LACP negotiation.

 

 

Command Mode

Interface-Port-Channel Configuration

 

Command Syntax

port-channel min-links quantity

no port-channel min-links

default port-channel min-links

 

Parameters

quantity Minimum number of interfaces. Value range varies by platform. Default value is 0.

 

Example

These commands set 4 as the minimum number of ports required for port channel 13 to become active.
switch(config)# interface port-channel 13
switch(config-if-Po13)# port-channel min-links 4
switch(config-if-Po13)# show active
interface Port-Channel13
   port-channel min-links 4
switch(config-if-Po13)#

port-channel min-links review interval

The port-channel min-links review interval command enables or disables timer based min-links review feature for all port-channels.

The no port-channel min-links review interval and default port-channel min-links review intervalcommands restore the default min-links-timeout-base to 180 seconds by removing the corresponding port-channel min-links review interval command from running-config.

 

Command Mode

Global Configuration

 

Command Syntax

port-channel min-links review interval timeout (seconds)

no port-channel min-links review interval

default port-channel min-links review interval

 

Guidelines

The min-links-timeout-base interval for port-channels can be set within the range of 0 to 600 seconds. When setting the review interval to zero, the command has the following effect:
  • Disables the timer-based min-links review feature for all port-channels.
    • For LACP port-channels, it prevents the port-channel from bringing link up (even after one or more member ports were negotiated to collect or distribute (rx or tx)) until there are sufficient member interfaces ready to join the port-channel. Meanwhile, the partner can enable the port-channel link with fewer than required member interfaces. This configuration does not impact port-channels without min-links configuration.

       

Related Command

port-channel min-links

 

Example

This command sets the port-channel min-links interval to 200 seconds.
switch(config)# port-channel min-links review interval 200

port-channel speed mixed

The port-channel speed mixed command configures a port channel with the ability to have active members of multiple speeds.

Note: Available on the 7020, 7280, 7500, and 7800 platforms. Minimum links is not available on mixed-speed port channels.

 

 

Command Mode

Interface-Port-Channel Configuration

 

Command Syntax

port-channel speed mixed

 

Related Commands

The interface port-channel command places the switch in the interface-port-channel configuration mode.

 

Example
These commands place the switch in the interface port-channel mode and configure the mixed speed port-channel.
switch(config)# interface port-channel 1
switch(config-if-Po1)# port-channel speed mixed

port-channel speed minimum

The port-channel speed minimum command specifies the cumulative minimum speed of all active members in order for a port channel to become active. If there is less than the specified by this command, the port channel interface does not become active.

Note: If both minimum speed and minimum links are configured, minimum speed will take precedence.

 

 

Command Mode

Interface-Port-Channel configuration

 

Command Syntax

port-channel speed minimum speed-value

 

Parameter

speed-value Minimum speed value. The value ranges from 1 to 65535.

 

Related Command

The interface port-channel command places the switch in interface-port-channel configuration mode.

 

Example
These command sets 100 Gbps as the minimum speed needed for port channel 1 to become active.
switch(config)# interface port-channel 1
switch(config-if-Po1)# port-channel speed minimum 100 gbps

show lacp aggregates

The show lacp aggregates command displays aggregate IDs and the list of bundled ports for all specified port channels.

 

Command Mode

EXEC

 

Command Syntax

show lacp [PORT_LIST] aggregates [PORT_LEVEL] [INFO_LEVEL]

Note: PORT_LEVEL and INFO_LEVEL parameters can be placed in any order.

 

 

Parameters
  • PORT_LIST Port channels for which aggregate information is displayed. Options include:
    • <no parameter>      All configured port channels.
    • c_range Channel list (number, range, or comma-delimited list of numbers and ranges).

       

  • PORT_LEVEL Ports displayed, in terms of aggregation status. Options include:
    • no parameter      Ports bundled by LACP into the port channel.
    • all-ports All channel group ports, including channel group members not bundled into the port channel interface.

       

  • INFO_LEVEL Amount of information that is displayed. Options include:
    • no parameter      Aggregate ID and bundled ports for each channel.
    • brief      Aggregate ID and bundled ports for each channel.
    • detailed      Aggregate ID and bundled ports for each channel.

       

 

Example

This command lists aggregate information for all configured port channels.
switch> show lacp aggregates

Port Channel Port-Channel1:
 Aggregate ID: 
[(8000,00-1c-73-04-36-d7,0001,0000,0000),(8000,00-1c-73-09-a0-f3,0001,0000,0000)]
  Bundled Ports: Ethernet43 Ethernet44 Ethernet45 Ethernet46
Port Channel Port-Channel2:
 Aggregate ID: 
[(8000,00-1c-73-01-02-1e,0002,0000,0000),(8000,00-1c-73-04-36-d7,0002,0000,0000)]
  Bundled Ports: Ethernet47 Ethernet48
Port Channel Port-Channel3:
 Aggregate ID: 
[(8000,00-1c-73-04-36-d7,0003,0000,0000),(8000,00-1c-73-0c-02-7d,0001,0000,0000)]
  Bundled Ports: Ethernet3 Ethernet4
Port Channel Port-Channel4:
 Aggregate ID: 
[(0001,00-22-b0-57-23-be,0031,0000,0000),(8000,00-1c-73-04-36-d7,0004,0000,0000)]
  Bundled Ports: Ethernet1 Ethernet2
Port Channel Port-Channel5:
 Aggregate ID: 
[(0001,00-22-b0-5a-0c-51,0033,0000,0000),(8000,00-1c-73-04-36-d7,0005,0000,0000)]
  Bundled Ports: Ethernet41
switch>

show lacp counters

The show lacp counters command displays LACP traffic statistics.

 

Command Mode

EXEC

Command Syntax

show lacp [PORT_LIST] counters [PORT_LEVEL] [INFO_LEVEL]

Note: PORT_LEVEL and INFO_LEVEL parameters can be interchanged while running the command.

 

 

Parameters
  • PORT_LIST Ports for which port information is displayed. Options include:
    • no parameter      All configured port channels.
    • c_rangePorts in specified channel list (number, number range, or list of numbers and ranges).
    • interface      Ports on all interfaces.
    • interface ethernet e_num      Port on Ethernet interface specified by e_num.
    • interface port-channel p_num      Port on port channel interface specified by p_num.

       

  • PORT_LEVELPorts displayed, in terms of aggregation status. Options include:
    • no parameter      Only ports bundled by LACP into an aggregate.
    • all-ports      All ports, including LACP candidates that are not bundled.

       

  • INFO_LEVEL Amount of information that is displayed. Options include:
    • no parameter      Displays packet transmission (TX and RX) statistics.
    • brief      Displays packet transmission (TX and RX) statistics.
    • detailed      Displays packet transmission (TX and RX) statistics and actor-partner statistics.

       

Example

This command displays transmission statistics for all configured port channels.
switch> show lacp counters brief

                      LACPDUs         Markers   Marker Response
Port   Status        RX         TX   RX    TX   RX    TX   Illegal
------------------------------------------------------------------
Port Channel Port-Channel1:
Et43   Bundled   396979     396959    0     0    0     0    0
Et44   Bundled   396979     396959    0     0    0     0    0
Et45   Bundled   396979     396959    0     0    0     0    0
Et46   Bundled   396979     396959    0     0    0     0    0

Port Channel Port-Channel2:
Et47   Bundled   396836     396883    0     0    0     0    0
Et48   Bundled   396838     396883    0     0    0     0    0

switch>

show lacp interface

The show lacp interface command displays port status for all port channels that include the specified interfaces. Within the displays for each listed port channel, the output displays sys-id, partner port, state, actor port, and port priority for each interface in the channel.

 

Command Mode

EXEC

 

Command Syntax

show lacp interface [INTERFACE_PORT] [PORT_LEVEL] [INFO_LEVEL]

Note: INTERFACE_PORT is listed first when present. Other parameters can be listed in any order.

 

 

Parameters
  • INTERFACE_PORT Interfaces for which information is displayed. Options include:
    • no parameter      All interfaces in channel groups.
    • ethernet e_num      Ethernet interface specified by e_num.
    • port-channel p_num      Port channel interface specified by p_num.

       

  • PORT_LEVEL Ports displayed, in terms of aggregation status. Options include:
    • no parameter      Command lists data for ports bundled by LACP into the aggregate.
    • all-ports      Command lists data for all ports, including LACP candidates that are not bundled.

       

  • INFO_LEVEL Amount of information that is displayed. Options include:
    • no parameter      Displays same information as brief option.
    • brief      Displays LACP configuration data, including sys-id, actor, priorities, and keys.
    • detailed      Includes brief option information plus state machine data.

       

Example

This command displays LACP configuration information for all ethernet interfaces.
switch> show lacp interface
State: A = Active, P = Passive; S=ShortTimeout, L=LongTimeout;
       G = Aggregable, I = Individual; s+=InSync, s-=OutOfSync;
       C = Collecting, X = state machine expired,
       D = Distributing, d = default neighbor state

             |                       Partner                         Actor
Port Status  | Sys-id                 Port# State   OperKey PortPri  Port#
----------------------------------------------------------------------------
Port Channel Port-Channel1:
Et43 Bundled | 8000,00-1c-73-09-a0-f3    43 ALGs+CD  0x0001   32768   43
Et44 Bundled | 8000,00-1c-73-09-a0-f3    44 ALGs+CD  0x0001   32768   44
Et45 Bundled | 8000,00-1c-73-09-a0-f3    45 ALGs+CD  0x0001   32768   45
Et46 Bundled | 8000,00-1c-73-09-a0-f3    46 ALGs+CD  0x0001   32768   46
Port Channel Port-Channel2:
Et47 Bundled | 8000,00-1c-73-01-02-1e    23 ALGs+CD  0x0002   32768   47
Et48 Bundled | 8000,00-1c-73-01-02-1e    24 ALGs+CD  0x0002   32768   48

             |                 Actor
Port Status  |   State         OperKey    PortPriority
-------------------------------------------------------
Port Channel Port-Channel1:
Et43 Bundled |   ALGs+CD        0x0001           32768
Et44 Bundled |   ALGs+CD        0x0001           32768
Et45 Bundled |   ALGs+CD        0x0001           32768
Et46 Bundled |   ALGs+CD        0x0001           32768
Port Channel Port-Channel2:
Et47 Bundled |   ALGs+CD        0x0002           32768
Et48 Bundled |   ALGs+CD        0x0002           32768

switch>

show lacp internal

The show lacp internal command displays the local LACP state for all specified channels. Local state data includes the state machines and LACP protocol information.

 

Command Mode

EXEC

 

Command Syntax

show lacp [PORT_LIST] internal [PORT_LEVEL] [INFO_LEVEL]

 

Parameters
  • PORT_LIST Interface for which port information is displayed. Options include:
    • no parameter      All configured port channels.
    • c_rangePorts in specified channel list (number, number range, or list of numbers and ranges).
    • interface     Ports on all interfaces.
    • interface ethernet e_num      Ethernet interface specified by e_num.
    • interface port-channel p_num      Port channel interface specified by p_num.

       

  • PORT_LEVEL Ports displayed, in terms of aggregation status. Options include:
    • no parameter      Command lists data for ports bundled by LACP into an aggregate.
    • all-ports      Command lists data for all ports, including LACP candidates that are not bundled.

       

  • INFO_LEVEL Amount of information that is displayed. Options include:
    • no parameter      Displays same information as brief option.
    • brief      Displays LACP configuration data, including sys-id, actor, priorities, and keys.
    • detailed      Includes brief option information plus state machine data.

       

     

    Note: PORT_LEVEL and INFO_LEVEL parameters can be placed in any order.

     

 

Example

This command displays internal data for all configured port channels.
switch> show lacp internal

LACP System-identifier: 8000,00-1c-73-04-36-d7
State: A = Active, P = Passive; S=ShortTimeout, L=LongTimeout;
       G = Aggregable, I = Individual; s+=InSync, s-=OutOfSync;
       C = Collecting, X = state machine expired,
       D = Distributing, d = default neighbor state
             |Partner                                 Actor
Port Status  | Sys-id                 Port#  State    OperKey  PortPriority
----------------------------------------------------------------------------
Port Channel Port-Channel1:
Et43 Bundled | 8000,00-1c-73-09-a0-f3    43  ALGs+CD   0x0001   32768
Et44 Bundled | 8000,00-1c-73-09-a0-f3    44  ALGs+CD   0x0001   32768
Et45 Bundled | 8000,00-1c-73-09-a0-f3    45  ALGs+CD   0x0001   32768
Et46 Bundled | 8000,00-1c-73-09-a0-f3    46  ALGs+CD   0x0001   32768

show lacp peer

The show lacp peer command displays the LACP protocol state of the remote neighbor for all specified port channels.

 

Command Mode

EXEC

 

Command Syntax

show lacp [PORT_LIST] peer [PORT_LEVEL] [INFO_LEVEL]

Note: PORT_LEVEL and INFO_LEVEL parameters can be placed in any order.

 

 

Parameters
  • PORT_LISTInterface for which port information is displayed. Options include:
    • no parameter      Displays information for all configured port channels.
    • c_range Ports in specified channel list (number, number range, or list of numbers and ranges).
    • interface      Ports on all interfaces.
    • interface ethernet e_num      Ethernet interface specified by e_num.
    • interface port-channel p_num      Port channel interface specified by p_num.

       

  • PORT_LEVEL Ports displayed, in terms of aggregation status. Options include:
    • no parameter      Command lists data for ports bundled by LACP into an aggregate.
    • all-ports      Command lists data for all ports, including LACP candidates that are not bundled.

       

  • INFO_LEVEL Amount of information that is displayed. Options include:
    • no parameter      Displays same information as brief option.
    • brief      Displays LACP configuration data, including sys-id, actor, priorities, and keys.
    • detailed      Includes brief option information plus state machine data.

       

 

Example

This command displays the LACP protocol state of the remote neighbor for all port channels.
switch> show lacp peer
 
State: A = Active, P = Passive; S=ShortTimeout, L=LongTimeout;
       G = Aggregable, I = Individual; s+=InSync, s-=OutOfSync;
       C = Collecting, X = state machine expired,
       D = Distributing, d = default neighbor state
               |                          Partner
Port   Status  | Sys-id                  Port#   State     OperKey  PortPri
----------------------------------------------------------------------------
Port Channel Port-Channel1:
Et1    Bundled | 8000,00-1c-73-00-13-19      1   ALGs+CD    0x0001    32768
Et2    Bundled | 8000,00-1c-73-00-13-19      2   ALGs+CD    0x0001    32768
Port Channel Port-Channel2:
Et23   Bundled | 8000,00-1c-73-04-36-d7     47   ALGs+CD    0x0002    32768
Et24   Bundled | 8000,00-1c-73-04-36-d7     48   ALGs+CD    0x0002    32768
Port Channel Port-Channel4*:
Et3    Bundled | 8000,00-1c-73-0b-a8-0e     45   ALGs+CD    0x0001    32768
Et4    Bundled | 8000,00-1c-73-0b-a8-0e     46   ALGs+CD    0x0001    32768
Port Channel Port-Channel5*:
Et19   Bundled | 8000,00-1c-73-0c-30-09     49   ALGs+CD    0x0005    32768
Et20   Bundled | 8000,00-1c-73-0c-30-09     50   ALGs+CD    0x0005    32768
Port Channel Port-Channel6*:
Et6    Bundled | 8000,00-1c-73-01-07-b9     49   ALGs+CD    0x0001    32768
Port Channel Port-Channel7*:
Et5    Bundled | 8000,00-1c-73-0f-6b-22     51   ALGs+CD    0x0001    32768
Port Channel Port-Channel8*:
Et10   Bundled | 8000,00-1c-73-10-40-fa     51   ALGs+CD    0x0001    32768

* - Only local interfaces for MLAGs are displayed. Connect to the peer to
    see the state for peer interfaces.
switch>

show lacp sys-id

The show lacp sys-id command displays the System Identifier the switch uses when negotiating remote LACP implementations.

 

Command Mode

EXEC

 

Command Syntax

show lacp sys-id [INFO_LEVEL]

 

Parameters

INFO_LEVEL Amount of information that is displayed. Options include:
  • no parameter      Displays system identifier.
  • brief      Displays system identifier.
  • detailed      Displays system identifier and system priority, including the MAC address.

     

Examples
  • This command displays the system identifier.
    switch> show lacp sys-id brief
    8000,00-1c-73-04-36-d7

     

  • This command displays the system identifier and system priority.
    switch> show lacp sys-id detailed
    System Identifier used by LACP:
    System priority: 32768  Switch MAC Address: 00:1c:73:04:36:d7
      802.11.43 representation: 8000,00-1c-73-04-36-d7

show load-balance profile

The show load-balance profile command displays the contents of the specified load balance profiles. Load balance profiles specify parameters used by hashing algorithms that distribute traffic across ports comprising a port channel or among component ECMP routes.

 

Command Mode

EXEC

 

Command Syntax

show load-balance profile [PROFILES]

 

Parameters

PROFILES Load balance profiles for which command displays contents. Options include:
  • no parameter      Displays all load balance profiles.
  • profile_name      Displays specified profile.

     

Related Commands
  • load-balance policies places the switch in load-balance-policies configuration mode.
  • ingress load-balance profile applies a load-balance profile to an Ethernet or port channel interface.

     

Example

This command displays the contents of the LB-1 load balance profile.
switch> show load-balance profile LB-1

---------- LB-1 ----------

Source MAC address hashing               ON
Destination MAC address hashing          ON
Ethernet type hashing                    ON
VLAN ID hashing                          ON
IP protocol field hashing                ON
DSCP field hashing is                    ON
Symmetric hashing for non-IP packets     OFF
Symmetric hashing for IP packets         OFF
Random distribution for port-channel     ON
Random distribution for ecmp             ON

Profile LB-1 is applied on the following
    Port-Channel100

---------- myGlobalProfile (global) ----------
L3 hashing is ON
Symmetric hashing is OFF
Hashing mode is flow-based
Hash polynomial is 3
Hash seed is 0
Profile myGlobalProfile (global) is applied on the following
Linecard3
Linecard4
Linecard5
Linecard6

switch>

show port-channel

The show port-channel command displays information about members the specified port channels.

 

Command Mode

EXEC

 

Command Syntax

show port-channel [MEMBERS] [PORT_LIST] [INFO_LEVEL]

 

Parameters
  • MEMBERSList of port channels for which information is displayed. Options include:
    • no parameterAll configured port channels.
    • p_range Ports in specified channel list (number, number range, or list of numbers and ranges).

       

  • PORT_LEVELPorts displayed, in terms of aggregation status. Options include:
    • no parameterDisplays information on ports that are active members of the LAG.
    • active-portsDisplays information on ports that are active members of the LAG.
    • all-ports       Displays information on all ports (active or inactive) configured for LAG.

       

  • INFO_LEVELAmount of information that is displayed. Options include:
    • no parameterDisplays information at the brief level.
    • briefDisplays information at the brief level.
    • detailed Displays information at the detail level.

       

Display Values
  • Port Channel Type and name of the port channel.
  • Time became active Time when the port channel came up.
  • Protocol Protocol operating on the port channel.
  • Mode Status of the Ethernet interface on the port. The status value is Active or Inactive.
  • No active ports Number of active ports on the port channel.
  • Configured but inactive ports Ports configured but that are not actively up.
  • Reason unconfigured Reason why the port is not part of the LAG.

     

Guidelines

You can configure a port channel to contain many ports, but only a subset may be active at a time. All active ports in a port channel must be compatible. Compatibility includes many factors and is platform specific. For example, compatibility may require identical operating parameters such as speed and Maximum Transmission Unit (MTU). Compatibility may only be possible between specific ports because of the internal organization of the switch.

 

Examples
  • This command displays output from the show port-channel command.
    switch> show port-channel 3
    Port Channel Port-Channel3: 
      Active Ports: 
           Port                Time became active       Protocol    Mode    
        ----------------------------------------------------------------------- 
           Ethernet3           15:33:41                 LACP        Active 
           PeerEthernet3       15:33:41                 LACP        Active 
    

     

  • This command displays output from the show port-channel active-ports command.
    switch> show port-channel active-ports
    Port Channel Port-Channel3:
      No Active Ports
    Port Channel Port-Channel11:
      No Active Ports
    switch>

     

  • This command displays output from the show port-channel all-ports command.
    switch> show port-channel all-ports
    Port Channel Port-Channel3:
      No Active Ports
      Configured, but inactive ports:
          Port            Time became inactive    Reason unconfigured
        ----------------------------------------------------------------------------
          Ethernet3       Always                  not compatible with aggregate
    
    Port Channel Port-Channel11:
      No Active Ports
      Configured, but inactive ports:
          Port            Time became inactive    Reason unconfigured
        ----------------------------------------------------------------------------
          Ethernet25      Always                  not compatible with aggregate
          Ethernet26      Always                  not compatible with aggregate

     

  • This command displays details about the port-channel configuration:
    switch#show port-channel 50 detailed 
    Port Channel Port-Channel50 (Fallback State: Unconfigured): 
    Minimum links: unconfigured Minimum speed: unconfigured 
    Current weight/Max weight: 1/16 
    
    Active Ports: 
    Port                  Time Became Active        Protocol       Mode         Weight      State
    -------------------- ------------------------ -------------- ------------ ------------ ------
    Ethernet51            Wed 15:19:30              LACP           Active       1           Rx,Tx 
    PeerEthernet52        Wed 15:19:28              LACP           Active       0           Unknown

     

    This output displays the following information:
    • Port - the Active ports on an interface.
    • Time Became Active - The time when a port came up on the network.
    • Protocol - the network protocol associated with the port.
    • Mode - the current mode of the port as Active or Inactive.
    • Weight - The member port weight is directly proportional to other members speeds and determines the number of packets sent over the member port when it becomes active. For same speed port-channels, all members have a weight of one (1).
    • State - the state of the port as receiving (Rx) traffic, transmitting (Tx) traffic, or Unknown.

show port-channel dense

The show port-channel dense command displays the port-channels on the switch and lists their component interfaces, LACP status, and set flags.

 

Command Mode

EXEC

 

Command Syntax

show port-channel dense

 

Example

This command displays the show port-channel dense output:
switch> show port-channel dense

    Flags
---------------------------------------------------------------------
a - LACP Active        p - LACP Passive
U - In Use             D - Down
+ - In-Sync            - - Out-of-Sync      i - incompatible with agg
P - bundled in Po      s - suspended        G - Aggregable
I - Individual         S - ShortTimeout     w - wait for agg

Number of channels in use: 2
Number of aggregators:2

   Port-Channel       Protocol    Ports
-------------------------------------------------------
   Po1(U)             LACP(a)      Et47(PG+) Et48(PG+)
   Po2(U)             LACP(a)      Et39(PG+) Et40(PG+)

show port-channel limits

The show port-channel limits command displays groups of ports that are compatible and may be joined into port channels. Each group of compatible ports is called a LAG group. For each LAG group, the command also displays Max interfaces and Max ports per interface.
  • Max interfaces defines the maximum number of active port channels that may be formed out of these ports.

     

  • Max ports per interface defines the maximum number of active ports allowed in a port channel from the compatibility group.

     

All active ports in a port channel must be compatible. Compatibility comprises many factors and is specific to a given platform. For example, compatibility may require identical operating parameters such as speed and/or Maximum Transmission Unit (MTU). Compatibility may only be possible between specific ports because of internal organization of the switch.

 

Command Mode

EXEC

 

Command Syntax

show port-channel limits

 

Example

This command displays the show port-channel list output:
switch> show port-channel limits

LAG Group: focalpoint
--------------------------------------------------------------------------
  Max port-channels per group: 24, Max ports per port-channel: 16
  24 compatible ports: Ethernet1  Ethernet2  Ethernet3  Ethernet4
                       Ethernet5  Ethernet6  Ethernet7  Ethernet8
                       Ethernet9  Ethernet10 Ethernet11 Ethernet12
                       Ethernet13 Ethernet14 Ethernet15 Ethernet16
                       Ethernet17 Ethernet18 Ethernet19 Ethernet20
                       Ethernet21 Ethernet22 Ethernet23 Ethernet24
--------------------------------------------------------------------------

show port-channel load-balance fields

The show port-channel load-balance fields command displays the fields that the hashing algorithm uses to distribute traffic across the interfaces that comprise the port channels.

 

Command Mode

EXEC

 

Command Syntax

show port-channel load-balance HARDWARE fields

 

Parameters

HARDWARE ASIC switching device. Selection options depend on the switch model and include:
  • arad
  • fm6000
  • petraA
  • trident

     

Example

This command displays the hashing fields used for balancing port channel traffic.
switch> show port-channel load-balance fm6000 fields

Source MAC address hashing for non-IP packets is ON
Destination MAC address hashing for non-IP packets is ON
Ethernet type hashing for non-IP packets is ON
VLAN ID hashing for non-IP packets is ON
VLAN priority hashing for non-IP packets is ON
Source MAC address hashing for IP packets is ON
Destination MAC address hashing for IP packets is ON
Ethernet type hashing for IP packets is ON
VLAN ID hashing for IP packets is ON
VLAN priority hashing for IP packets is ON
IP source address hashing is ON
IP destination address hashing is ON
IP protocol field hashing is ON
TCP/UDP source port hashing is ON
TCP/UDP destination port hashing is ON

switch>

show port-channel load-balance

The show port-channel load-balance command displays the traffic distribution between the member ports of the specified port channels. The command displays distribution for unicast, multicast, and broadcast streams.

The distribution values displayed are based on the total interface counters which start from 0 at boot time or when the counters are cleared. For more current traffic distribution values, clear the interface counters of the member interfaces using the clear counters command.

 

Command Mode

EXEC

 

Command Syntax

show port-channel load-balance [MEMBERS]

 

Parameters

MEMBERS list of port channels for which information is displayed. Options include:
  • no parameter all configured port channels.
  • c_range ports in specified channel list (number, number range, or list of numbers and ranges).

     

Example

This command displays traffic distribution for all configured port channels.
switch> show port-channel load-balance
ChanId      Port Rx-Ucst Tx-Ucst Rx-Mcst Tx-Mcst Rx-Bcst Tx-Bcst
------ --------- ------- ------- ------- ------- ------- -------
     8      Et10 100.00% 100.00% 100.00% 100.00%   0.00% 100.00%
------ --------- ------- ------- ------- ------- ------- -------
     1       Et1  13.97%  42.37%  47.71%  30.94%   0.43%  99.84%
     1       Et2  86.03%  57.63%  52.29%  69.06%  99.57%   0.16%
------ --------- ------- ------- ------- ------- ------- -------
     2      Et23  48.27%  50.71%  26.79%  73.22%   0.00% 100.00%
     2      Et24  51.73%  49.29%  73.21%  26.78%   0.00%   0.00%
------ --------- ------- ------- ------- ------- ------- -------
     4       Et3  55.97%  63.29%  51.32%  73.49%   0.00%   0.00%
     4       Et4  44.03%  36.71%  48.68%  26.51%   0.00%   0.00%
------ --------- ------- ------- ------- ------- ------- -------
     5      Et19  39.64%  37.71%  50.00%  90.71%   0.00%   0.00%
     5      Et20  60.36%  62.29%  50.00%   9.29%   0.00% 100.00%
------ --------- ------- ------- ------- ------- ------- -------
     6       Et6 100.00% 100.00% 100.00% 100.00%   0.00% 100.00%
------ --------- ------- ------- ------- ------- ------- -------
     7       Et5 100.00%   0.00% 100.00% 100.00%   0.00%   0.00%
switch>
..

EOS 4.36.2F User Manual - Layer 1 Commands

Layer 1 Commands

  • system l1 module profile
  • show l1 modules profile status
  • system l1 module
  • system l1 unsupported

system l1 module

The system l1 module command enters the configuration mode for Layer 1 parameters. The no and default versions of the command restore the switch to the default settings.

Configuration Mode

System Layer 1 Configuration Mode

Command Syntax

system l1 module linecard linecard_name switch switch_name

Parameters

  • linecard linecard_name - Specify a linecard to configure L1 parameters.
  • switch switch_name - Specify a switch to configure L1 parameters.

Example

  • Use the following command to enter the System L1 Configuration mode and add the linecard, 3, to the configuration:
    switch(config)# system l1
    switch(config-system-l1)# module linecard 3

system l1 module profile

The system l1 module profile command configures Layer 1 module profiles on a switch. The no and default versions of the command remove the configuration from the running-config.

Command Mode

System Layer 1 Configuration Mode

Command Syntax

system l1 module module_name profile profile_name

Parameters

  • system l1 module module_name - Specify the module name to apply the profile. On modular systems, use the parameter Linecard. On a fixed system, use the parameter, switch.
  • profile profile_name - Specify the built-in profile name.

Examples

  • Configure the built-in profile, Uniform-4x100g-2-R, on a modular system with Linecard3, Linecard4, and Linecard6:
    switch(config)# system l1
    switch(config-system-l1)# module Linecard3-4,6 profile Uniform-4x100G2-R
  • Configure the built-in profile, Uniform-4x100g-2-R, on a fixed system:
    switch(config)# system l1
    switch(config-system-l1)# module switch profile Uniform-4x100G2-R

system l1 unsupported

The system l1 unsupported command enters the configuration mode for Layer 1 parameters and configures the response to unsupported L1 configurations. The no and default versions of the command restore the switch to the default settings.

Configuration Mode

System Layer 1 Configuration Mode

Command Syntax

system l1 unsupported [error-correction | speed] action [error | warn]

Parameters

  • error-correction - Specify error correction forwarding on the switch.
  • speed - Specify the speed on the switch.
  • error - Specify to return an error message for unsupported configurations.
  • warn - Specify to return a warning for unsupported configurations.

Examples

  • Use the following command to enter the System L1 Configuration mode and specify to return a warning for unsupported speeds on the switch:
    switch(config)# system l1
    switch(config-system-l1)# unsupported speed action warn
  • When attempting to add an unsupported speed to the switch, EOS returns a warning message:
    switch(config-if-ET1/2)# speed 200g-4
    ! Speed and duplex settings are not compatible with transceiver for interface EthernetX/Y.
    Do you wish to proceed with this command? [y/N]

show l1 modules profile status

The show l1 modules profile status command displays the status of configured Layer 1 profiles on the switch.

Command Mode

EXEC

Command Syntax

show l1 modules profile status

Examples

  • Use the show l1 modules profile status to display the status. On a modular system, the command returns the following output:
    switch# show l1 modules profiles status
    * Indicates that the configured profile definition has changed
    
    Module    Operational        Configured         Status
    --------- ------------------ ------------------ ------------
    linecard3 Uniform-4x100G-2-R Uniform-4x100G-2-R applied
    linecard4 n/a                Uniform-4x100G-2-R not inserted
    linecard5 n/a                Uniform-4x10G-1    pending
    linecard6 n/a                Uniform-4x10G-1    error
    linecard7 n/a                n/a                applied
  • On a fixed system, the command returns the following output:
    switch# show l1 modules profiles status
    * Indicates that the configured profile definition has changed
    
    Module Operational        Configured         Status
    ------ ------------------ ------------------ -------
    switch Uniform-4x100G-2-R Uniform-4x100G-2-R applied
  • The Status column has one of the following entries:
    • applied - Operational and configured profiles match. No action needed.
    • not inserted - Module not inserted and nothing to configure.
    • pending - Requires a card reinsertion or switch powercycle before module becomes operational. Reboot the switch or simulate reinserting the cards.
    • error - Configured profile on an unsupported module. Double-check the platform compatibility list.

..

EOS 4.36.2F User Manual - Layer 1 CLI Guard Relaxation

Layer 1 CLI Guard Relaxation

EOS supports relaxing Layer 1 CLI guards to configure the handling ofunsupported Layer 1 configurations such as incorrect speed and error correction. EOS rejects the unsupported configurations with error messages or prompts for confirmation using warning messages.

Configuring Layer 1 CLI Guard Relaxation

Configure EOS to handle unsupported Layer 1 configurations with the command, system l1 unsupported. The command supports the following options:

  • speed - Specify the action for unsupported speed configurations.
  • error-correction - Specify the action for unsupported error-correction configurations.
  • error - Configure the switch to reject unsupported configurations with error messages.
  • warn - Configure the switch to warn and prompt for confirmation for unsupported configurations.

Examples

Use the following command to reject an unsupported speed configuration:

switch(config)# system l1
switch(config-system-l1)# unsupported speed action error

When configured with an unsupported speed, the switch returns the following error message:

switch(config-if-ET1/2)# speed 200g-4
% Speed and duplex settings are not compatible with transceiver for interface Ethernet1/2.

Use the following commands to warn and prompt for unsupported speed configuration:

switch(config)# system l1
switch(config-system-l1)# unsupported speed action warn

When configured with an unsupported speed, the switch returns the following warning message:

switch(config-if-ET1/2)# speed 200g-4
! Speed and duplex settings are not compatible with transceiver for interface EthernetX/Y.
Do you wish to proceed with this command? [y/N]

Suppress the prompt asking confirmation with the terminal dont-ask command. Add this configuration for systems using automation for configuration.

Displaying L1 CLI Guard Relaxation Information

To display the current configured actions for unsupported configurations, use the show running-config command:

switch# show running-config
system l1
   unsupported speed action error
   unsupported error-correction action error
..

Page 9 of 17

  • First
  • Prev
  • ...
  • 5
  • 6
  • 7
  • 8
  • 9
  • ...
  • 11
  • 12
  • 13
  • Next
  • Last
Contact Us
Arista
Facebook Twitter LinkedInYouTube
  • Support
    • Support & Services
    • Training
    • Product Documentation
    • Software Downloads
  • Contacts & Help
    • Contact Arista
    • Contact Technical Support
    • Order Status
  • News
    • News Room
    • Events Calendar
    • Blogs
  • About Arista
    • Company
    • Management Team
    • Careers
    • Investor Relations
    • Reports
  • Terms of Use
  • Privacy Policy
  • Fraud Alert
  • Trust Center
  • Sitemap