- Written by David Mirabito
- Posted on December 30, 2021
- Updated on July 1, 2026
- 33332 Views
MetaWatch is an FPGA-based feature available for Arista 7130 Series platforms. It provides precise timestamping of packets, aggregation and deep buffering for Ethernet links. Timestamp information and other metadata such as device and port identifiers are appended to the end of the packet as a trailer.
- Written by Dickson Chum
- Posted on January 3, 2023
- Updated on July 7, 2026
- 17789 Views
Mirroring to a GRE tunnel allows mirrored packets to transit to a L3 network using GRE encapsulation.
- Written by Ayush Gupta
- Posted on July 27, 2026
- Updated on July 27, 2026
- 176 Views
The Egress Encapsulation Database (EEDB) is a hardware resource used to store encapsulation information for various networking features. As of EOS-4.36.1F, a new CLI command is available to display MPLS tunnel EEDB capacity usage on a per-forwarding engine basis. The command reports the number of in-use, free, and maximum entries for MPLS tunnels, grouped by label count.
- Written by Jeffrey Nelson
- Posted on June 21, 2021
- Updated on July 17, 2026
- 52849 Views
This feature provides the ability to interconnect EVPN VXLAN domains. Domains may or may not be within the same data center network, and the decision to stretch/interconnect a subnet between domains is configurable. The following diagram shows a multi-domain deployment using symmetric IRB. Note that two domains are shown for simplicity, but this solution supports any number of domains.
- Written by Dana Cook
- Posted on June 26, 2026
- Updated on June 26, 2026
- 277 Views
EOS now exposes ASIC integrated-circuit memory health metrics via gNMI, under the vendor-augmented OpenConfig component tree. Two categories of memory are reported per chip instance: DRAM Bulk Data Block (BDB) free counts and SRAM buffer free counts. Each category provides three views: current value, minimum observed since last reset, and minimum observed in the latest polling interval.
- Written by Preethika Muthupurushothaman
- Posted on December 19, 2019
- Updated on June 25, 2026
- 13800 Views
EOS 4.22.1F added support for multiple OSPFv2 instances to be configured in the default VRF. This feature provides isolation and allows for segregating/dividing the link state database based on interface.
- Written by Johnny Chen
- Posted on April 25, 2022
- Updated on July 9, 2026
- 13363 Views
The Per-MAC ACL feature provides the functionality to apply an IPv4/IPv6 ACL to a 802.1x supplicant instead of applying them on the port that the supplicant is behind. This allows for more flexible and specific traffic policies to be defined for supplicants trying to access certain resources on the network.
- Written by Chunxi Yu
- Posted on January 21, 2019
- Updated on July 13, 2026
- 5815 Views
Similar to reconfiguring the traffic-class to transmit-queue map, the traffic-class to priority-group mapping can also be changed using the CLI. This enables configuration capability to the user who can adjust the mapping based on the nature of the traffic. This configuration change doesn’t inhibit the flow of traffic.
- Written by Emil Maric
- Posted on February 16, 2021
- Updated on June 19, 2026
- 13258 Views
Routes covered by a resilient equal-cost multi-path (RECMP) prefix are types of routes that make use of hardware tables dedicated for equal-cost multi-path (ECMP) routing. Resilient ECMP deduping is a new feature wherein the switch will reactively attempt to reduce the number of ECMP hardware table entries allocated by forcing routes that share the same set of next hops but point to different hardware table entries to point to the same hardware table entry when hardware resource utilization is high. Forcing RECMP routes to change the hardware table entry that they point to may potentially cause a traffic flow disruption for any existing flows going over that route. The deduping process will attempt to minimize the amount of potential traffic loss caused.
- Written by Jeff Hornsberger
- Posted on April 1, 2026
- Updated on July 17, 2026
- 861 Views
RDMA over converged ethernet version 2 (RoCEv2) is a UDP protocol for transferring memory blocks between compute nodes. It is used for AI applications. RoCEv2 aware sampled flow tracking with IPFIX export is an enhancement that allows customers access to RoCEv2 flow information, for the purposes of analyzing and monitoring traffic associated with AI workloads.
- Written by David Cronin
- Posted on March 3, 2022
- Updated on September 7, 2026
- 35187 Views
Routing control functions (RCF) is a language that can be used to express route filtering and attribute modification logic in a powerful and programmatic fashion. This document serves as a reference guide for: Routing protocol attributes , Operators for comparing and modifying attributes
- Written by David Cronin
- Posted on March 3, 2022
- Updated on September 7, 2026
- 21622 Views
Routing control functions (RCF) is a language that can be used to express route filtering and attribute modification logic in a powerful and programmatic fashion. This document serves as a reference guide for: Routing protocol attributes , Operators for comparing and modifying attributes
- Written by Paraic Gallagher
- Posted on March 17, 2025
- Updated on September 7, 2026
- 4109 Views
Routing control functions (RCF) is a language that can be used to express route filtering and attribute modification logic in a powerful and programmatic fashion. This document serves as a reference guide for IpRib agent points of application Configuration of RCF
- Written by Kalash Nainwal
- Posted on December 14, 2020
- Updated on July 13, 2026
- 19357 Views
RSVP-TE, the Resource Reservation Protocol (RSVP) for Traffic Engineering (TE), is used to distribute MPLS labels for steering traffic and reserving bandwidth. The Label Edge Router (LER) feature implements the headend functionality, i.e., RSVP-TE tunnels can originate at an LER which can steer traffic into the tunnel.
- Written by Martin Stigge
- Posted on October 22, 2018
- Updated on July 13, 2026
- 16670 Views
RSVP-TE applies the Resource Reservation Protocol (RSVP) for Traffic Engineering (TE), i.e., to distribute MPLS labels for steering traffic and reserving bandwidth.The EOS implementation supports:
- Written by Basil Saji
- Posted on January 17, 2022
- Updated on August 3, 2026
- 16192 Views
VXLAN UDP-ESP support allows the customer to encrypt traffic between two VXLAN VTEPs.
- Written by Manoharan Sundaramoorthy
- Posted on September 4, 2018
- Updated on July 23, 2026
- 20537 Views
Segment Routing Traffic Engineering Policy (SR-TE) aka SR Policy makes use of Segment Routing (SR) to allow a headend to steer traffic along any path without maintaining per flow state in every node. A headend steers traffic into an “SR Policy”. EOS 4.21.0F adds support for SR Policy for the MPLS dataplane (SR-MPLS) for Type-1 SR Policy segments with BGP and locally configured policies as sources of SR Policies on Arista’s 7500, 7280 families of switches.
- Written by Athish Rao
- Posted on March 5, 2021
- Updated on July 16, 2026
- 18797 Views
Segment Routing Traffic Engineering Policy (SR-TE) aka SR Policy makes use of Segment Routing (SR) to allow a headend to steer traffic along any path without maintaining per flow state in every node. A headend steers traffic into an “SR Policy”. EOS 4.21.0F adds support for SR Policy for the MPLS dataplane (SR-MPLS) for Type-1 SR Policy segments with BGP and locally configured policies as sources of SR Policies on Arista’s 7500, 7280 families of switches.
- Written by Aayush Gupta
- Posted on July 6, 2026
- Updated on July 6, 2026
- 184 Views
Subinterfaces divide a single ethernet or port channel interface into multiple logical L3 interfaces based on the 802.1q tag (VLAN ID) of incoming traffic. Subinterfaces are commonly used in the L2/L3 boundary device, but they can also be used to isolate traffic with 802.1q tags between L3 peers by assigning each subinterface to a different VRF
- Written by Joel Sam
- Posted on July 6, 2026
- Updated on July 7, 2026
- 197 Views
A mechanism to verify the authenticity and integrity of EOS Virtual Machine (VM) images is provided for supported virtual platforms. While EOS hardware images (EOS.swi) contain embedded signatures verified by Aboot during secure boot, VM platforms use bundled file formats. To ensure these images are genuine Arista product releases, a detached Cryptographic Message Syntax (CMS) signature is published alongside the VM image files.
- Written by Naina Jalan
- Posted on October 20, 2022
- Updated on July 16, 2026
- 12333 Views
Unicast Reverse Path Forwarding (uRPF) can help limit malicious IPv4/IPv6 traffic on a network. uRPF works by enabling the router to verify reachability (routing) of the source IP address (SIP) in the packet being forwarded. If the SIP is determined to be an invalid address, the packet is dropped.
- Written by Hari Prasad S R
- Posted on August 19, 2025
- Updated on July 17, 2026
- 3916 Views
"Micro segment" (SRv6 uSID or uSID for short) is an extension of SRv6 architecture, specifically designed to represent SRv6 SIDs in an extremely compact way. It addresses the overhead of using full 128-bit IPv6 SIDs for routing. Instead of using a 128-bit address for single SID, multiple uSIDs are packed into a single 128-bit address. Each 128-bit address comprises a block value representing the domain followed by multiple uSIDs, each of the same bit length. If there are bits left they are filled with trailing zeros. This allows for a complete SRv6 path to be represented by a 128-bit IPv6 address. Like a regular SID, each uSID is associated with a specific behavior on the SRv6 capable node. SRv6 uN refers to the End behavior with uSIDs.
- Written by Ram Prasad
- Posted on July 6, 2026
- Updated on July 7, 2026
- 261 Views
The EOS-4.36.1 release introduces SSU support for SRv6 uN. This allows for SSU with SRv6 uN configuration, with negligible impact on active traffic flows.
- Written by Ashit Tandon
- Posted on November 6, 2025
- Updated on July 1, 2026
- 1911 Views
Static NAT allows a switch to modify the source or destination IP address, and optionally the Layer 4 port, of packets traversing it. Each static NAT rule is explicitly defined by the user and specifies a one-to-one mapping between an original IP address and a translated IP address.
- Written by Vincent (Chia Hsuan)
- Posted on September 24, 2024
- Updated on July 3, 2026
- 7867 Views
A traffic storm is a flood of packets entering a network, resulting in excessive traffic and degraded performance. Storm control prevents network disruptions by limiting traffic beyond specified thresholds on individual physical LAN interfaces. Storm control monitors inbound traffic levels over one-second intervals and compares the traffic level with a specified benchmark. The storm-control command configures and enables storm control on the configuration mode physical interface.
- Written by Josh Pfosi
- Posted on June 11, 2019
- Updated on July 27, 2026
- 19848 Views
This feature adds support for CPU traffic policy capable of matching and acting on IP traffic which would otherwise hit the CPU. This policy is capable of permitting traffic from trusted sources, while rejecting untrusted traffic. It supports matching on a variety of IP packet header information such as DSCP, L4 port values, fragmentation bits, etc. as well as a number of actions such as permit, deny, and police. To prevent a malicious source from overloading the CPU, this traffic policy will take effect in the switching hardware, before the traffic is processed by the kernel. This feature provides a shorthand syntax for securing L3 protocol peers, in particular, BGP neighbors.
- Written by Dongping Zhu
- Posted on June 26, 2026
- Updated on July 7, 2026
- 290 Views
This feature adds support to configure the following decap group OpenConfig models via gNMI. GRE decap group for incoming traffic with IPv4 or IPv6 inner packets , UDP decap group for incoming traffic with IPv4 or IPv6 inner packets , UDP decap group for incoming traffic with MPLS inner packets
- Written by Ashit Tandon
- Posted on May 5, 2025
- Updated on July 13, 2026
- 3793 Views
Dynamic Twice NAT is a variant of the dynamic NAT feature where both the source and destination IP can be modified while forwarding a packet. One of the IP addresses will be dynamically assigned, while the other will be statically assigned.
- Written by Mingchao Lian
- Posted on June 26, 2026
- Updated on June 26, 2026
- 273 Views
In order to support PIM/IPv4 multicast routing on EOS switches with Broadcom Tomahawk5 ASICs, multicast support using ALPM tables is required. This works in both 3-level Algorithmic Longest Prefix Match (ALPM) capabilities and 2-level ALPM.
- Written by Mingchao Lian
- Posted on September 11, 2024
- Updated on June 26, 2026
- 5560 Views
In order to support PIM/IPv4 multicast routing on EOS switches with Broadcom Tomahawk4 ASICs, multicast support using ALPM is required. This works in both 3-level Algorithmic Longest Prefix Match (ALPM) capabilities and 2-level ALPM.
- Written by Basil Saji
- Posted on November 9, 2020
- Updated on July 13, 2026
- 18446 Views
Private VLAN is a feature that segregates a regular VLAN broadcast domain while maintaining all ports in the same IP subnet. There are three types of VLAN within a private VLAN
- Written by Gaofeng Yue
- Posted on December 20, 2021
- Updated on July 21, 2026
- 12813 Views
Currently EOS supports redistribution into BGP at the global ( instance ) level. Also EOS supports redistribution in BGP at Address Family Identifier/Subsequent Address Family Identifier(AFI/SAFI) level to some extent. But the current redistribution mechanism is not flexible and does not provide full control at AFI/SAFI level ( some redistribution protocols are only supported at global level, or at some AFI/SAFI level ). This feature will support redistribution at AFI/SAFI level as well as at the global level. This will simplify the configuration requirements and supportability for complex and granular configurations when subsequent address family configurations co-exist. This will also give more control at AFI/SAFI level ( for example, route-map/rcf can be configured at AFI/SAFI level while they are not configured at global level ). This feature only works in multi-agent routing model.
- Written by Girish Dasari
- Posted on July 6, 2026
- Updated on July 7, 2026
- 426 Views
SRv6 is the segment routing using IP v6 Data plane. The segment ID is encoded as an IPv6 address. The Micro-Segment extension to SRv6 has representation of SIDs to enable compressing multiple of them into a single IPv6 address.
- Written by Ram Prasad
- Posted on March 12, 2026
- Updated on July 17, 2026
- 1103 Views
In Segment Routing, Adjacency Segment (Adj-SID) directs a node to forward the packet over a specific link or a set of links to the remote node. This feature adds support for statically configured SRv6 Adj-SIDs using micro-SIDs, also referred to as uA. This feature builds on the base SRv6 support described in SRv6 uN Support TOI.
- Written by Jeff Chan
- Posted on August 19, 2020
- Updated on July 16, 2026
- 39089 Views
Access Control Lists (ACL) use packet classification to mark certain packets going through the packet processor pipeline and then take configured action against them. Rules are defined based on various fields of packets and usually TCAM is used to match packets to rules. For example, there can be a rule to match the packet source IP address against a list of IP addresses, and drop the packet if there is a match. This will be expressed in TCAM with multiple entries matching the list of IP addresses. The number of entries is reduced by masking off bits, if possible. TCAM is a limited resource, so with classifiers having a large number of rules and a big field list, TCAM runs out of resources.
- Written by Daniel
- Posted on September 10, 2024
- Updated on July 17, 2026
- 5565 Views
This document describes the availability of VLAN ingress and egress counters on R Series platforms. VLAN counters provide the ability to count packets and bytes ingressing or egressing a bridge domain (VLAN).
- Written by Anirudh Sathiya Narayanan
- Posted on June 26, 2026
- Updated on June 26, 2026
- 286 Views
This document describes the availability of VLAN interface ingress and egress counters on R Series platforms. VLAN interface counters provide the ability to count packets and bytes ingressing or egressing a VLAN interface.
- Written by Matthew Carrington-Fair
- Posted on March 3, 2023
- Updated on July 7, 2026
- 9677 Views
This feature allows the export of IP FIB (Forwarding Information Base) through the OpenConfig AFT YANG models.
- Written by Prasanna Parthasarathy
- Posted on December 23, 2021
- Updated on August 5, 2026
- 28257 Views
SwitchApp is an FPGA-based feature available on compatible Arista 7130 devices. It performs ultra low latency Ethernet packet switching. Its packet switching feature set, port count, and port to port latency are a function of the selected SwitchApp profile.
- Written by Radek Szymanski
- Posted on June 26, 2026
- Updated on June 26, 2026
- 318 Views
This feature adds TLS support to TACACS+. With the new CLI commands, users can set an SSL profile and enable using TLS to communicate with TACACS+ servers. Once configured, all TACACS+ traffic is transmitted over TLS 1.3 connections with mutual certificate authentication, providing confidentiality, data integrity, and authenticity for AAA communications.
- Written by Travis Hammond
- Posted on April 13, 2015
- Updated on July 13, 2026
- 11425 Views
This article describes the Tap Aggregation MPLS Pop feature. The purpose of this feature is to support tools that do not parse MPLS labels and therefore need the switch to remove (pop) the MPLS header. This feature supports both IPv4 and IPv6 over MPLS.
- Written by Will Li
- Posted on April 18, 2022
- Updated on July 27, 2026
- 11710 Views
The ‘redirect’ action used in TCAM profile has lower priority than system rules, if packets match both TCAM rule using ‘redirect’ action and system rules. Hence ‘redirect’ action does not take effect on these packets. This improvement allows ‘redirect’ action in TCAM profile to override system rules, so that the aforementioned packets will always be redirected even if they match system rules.
- Written by Niall Sauvage
- Posted on July 1, 2026
- Updated on July 1, 2026
- 213 Views
The Timing Regeneration Filter (TRF) is a part of the Clock and Data Recovery component of the CRT50216 external PHY from Credo. It has a parameter, known as the bandwidth, which adjusts how the CRT50216 adjusts to frequency changes in the incoming signal from the peer. This TOI documents the addition of a command to allow the user to manually adjust the TRF bandwidth per Ethernet lane.
- Written by Benjamin Ye
- Posted on June 26, 2026
- Updated on June 26, 2026
- 267 Views
The tone generation feature enables switches to produce tones for fiber optic identification. This can produce 270Hz tones that standard fiber optic identifier devices can detect. The feature generates tones using SFP transceivers by toggling transceiver transmit disable at a configurable frequency. When enabled, this feature will disrupt the link and traffic on the interface.
- Written by Przemyslaw Jacak
- Posted on January 3, 2022
- Updated on July 27, 2026
- 10954 Views
This document describes LLDP’s VLAN Name TLV. It is defined in IEEE 802.1Q standard (802.1Q - D.2.3) and contains a list of VLAN names that the port is assigned to. This TLV is optional and it is disabled by default in Arista switches.
- Written by Oren Moshe
- Posted on June 24, 2026
- Updated on June 24, 2026
- 309 Views
VLAN tagged MACsec refers to frames that have a VLAN tag between the MAC source address and the MACsec ethertype. This VLAN tag is unencrypted (in the clear) so that intermediate devices between the MACsec endpoints can forward the MACsec frames based on this unencrypted VLAN tag.
- Written by Alton Lo
- Posted on June 26, 2026
- Updated on June 26, 2026
- 276 Views
With a static configured import and export route-target for a given vlan-aware-bundle, all its VLAN members share the same route-target value. For example, EVPN uses the same route-target in the Type 2 EVPN route advertisements for hosts residing in two different VLAN of the same bundle.
