MetaWatch is an FPGA-based feature available for Arista 7130 Series platforms. It provides precise timestamping of packets, aggregation and deep buffering for Ethernet links. Timestamp information and other metadata such as device and port identifiers are appended to the end of the packet as a trailer.

Mirroring to a GRE tunnel allows mirrored packets to transit to a L3 network using GRE encapsulation.

The Egress Encapsulation Database (EEDB) is a hardware resource used to store encapsulation information for various networking features. As of EOS-4.36.1F, a new CLI command is available to display MPLS tunnel EEDB capacity usage on a per-forwarding engine basis. The command reports the number of in-use, free, and maximum entries for MPLS tunnels, grouped by label count.

TOI MPLS EOS 4.36.1F EEDB capacity

This feature provides the ability to interconnect EVPN VXLAN domains. Domains may or may not be within the same data center network, and the decision to stretch/interconnect a subnet between domains is configurable. The following diagram shows a multi-domain deployment using symmetric IRB. Note that two domains are shown for simplicity, but this solution supports any number of domains.

EOS now exposes ASIC integrated-circuit memory health metrics via gNMI, under the vendor-augmented OpenConfig component tree. Two categories of memory are reported per chip instance: DRAM Bulk Data Block (BDB) free counts and SRAM buffer free counts. Each category provides three views: current value, minimum observed since last reset, and minimum observed in the latest polling interval.

EOS 4.22.1F added support for multiple OSPFv2 instances to be configured in the default VRF. This feature provides isolation and allows for segregating/dividing the link state database based on interface.

The Per-MAC ACL feature provides the functionality to apply an IPv4/IPv6 ACL to a 802.1x supplicant instead of applying them on the port that the supplicant is behind. This allows for more flexible and specific traffic policies to be defined for supplicants trying to access certain resources on the network.

Similar to reconfiguring the traffic-class to transmit-queue map, the traffic-class to priority-group mapping can also be changed using the CLI. This enables configuration capability to the user who can adjust the mapping based on the nature of the traffic. This configuration change doesn’t inhibit the flow of traffic.

TOI EOS 4.21.3F EOS 4.36.1F

Routes covered by a resilient equal-cost multi-path (RECMP) prefix are types of routes that make use of hardware tables dedicated for equal-cost multi-path (ECMP) routing. Resilient ECMP deduping is a new feature wherein the switch will reactively attempt to reduce the number of ECMP hardware table entries allocated by forcing routes that share the same set of next hops but point to different hardware table entries to point to the same hardware table entry when hardware resource utilization is high. Forcing RECMP routes to change the hardware table entry that they point to may potentially cause a traffic flow disruption for any existing flows going over that route. The deduping process will attempt to minimize the amount of potential traffic loss caused.

RDMA over converged ethernet version 2 (RoCEv2) is a UDP protocol for transferring memory blocks between compute nodes. It is used for AI applications. RoCEv2 aware sampled flow tracking with IPFIX export is an enhancement that allows customers access to RoCEv2 flow information, for the purposes of analyzing and monitoring traffic associated with AI workloads.

Routing control functions (RCF) is a language that can be used to express route filtering and attribute modification logic in a powerful and programmatic fashion. This document serves as a reference guide for: Routing protocol attributes , Operators for comparing and modifying attributes

Routing control functions (RCF) is a language that can be used to express route filtering and attribute modification logic in a powerful and programmatic fashion. This document serves as a reference guide for: Routing protocol attributes , Operators for comparing and modifying attributes

Routing control functions (RCF) is a language that can be used to express route filtering and attribute modification logic in a powerful and programmatic fashion. This document serves as a reference guide for IpRib agent points of application Configuration of RCF

RSVP-TE, the Resource Reservation Protocol (RSVP) for Traffic Engineering (TE), is used to distribute MPLS labels for steering traffic and reserving bandwidth. The Label Edge Router (LER) feature implements the headend functionality, i.e., RSVP-TE tunnels can originate at an LER which can steer traffic into the tunnel.

RSVP-TE applies the Resource Reservation Protocol (RSVP) for Traffic Engineering (TE), i.e., to distribute MPLS labels for steering traffic and reserving bandwidth.The EOS implementation supports:

VXLAN UDP-ESP support allows the customer to encrypt traffic between two VXLAN VTEPs.

Segment Routing Traffic Engineering Policy (SR-TE) aka SR Policy makes use of Segment Routing (SR) to allow a headend to steer traffic along any path without maintaining per flow state in every node. A headend steers traffic into an “SR Policy”. EOS 4.21.0F adds support for SR Policy for the MPLS dataplane (SR-MPLS) for Type-1 SR Policy segments with BGP and locally configured policies as sources of SR Policies on Arista’s 7500, 7280 families of switches.

Segment Routing Traffic Engineering Policy (SR-TE) aka SR Policy makes use of Segment Routing (SR) to allow a headend to steer traffic along any path without maintaining per flow state in every node. A headend steers traffic into an “SR Policy”. EOS 4.21.0F adds support for SR Policy for the MPLS dataplane (SR-MPLS) for Type-1 SR Policy segments with BGP and locally configured policies as sources of SR Policies on Arista’s 7500, 7280 families of switches.

Subinterfaces divide a single ethernet or port channel interface into multiple logical L3 interfaces based on the 802.1q tag (VLAN ID) of incoming traffic. Subinterfaces are commonly used in the L2/L3 boundary device, but they can also be used to isolate traffic with 802.1q tags between L3 peers by assigning each subinterface to a different VRF

TOI EOS 4.36.1F

A mechanism to verify the authenticity and integrity of EOS Virtual Machine (VM) images is provided for supported virtual platforms. While EOS hardware images (EOS.swi) contain embedded signatures verified by Aboot during secure boot, VM platforms use bundled file formats. To ensure these images are genuine Arista product releases, a detached Cryptographic Message Syntax (CMS) signature is published alongside the VM image files.

TOI EOS 4.36.1F

Unicast Reverse Path Forwarding (uRPF) can help limit malicious IPv4/IPv6 traffic on a network. uRPF works by enabling the router to verify reachability (routing) of the source IP address (SIP) in the packet being forwarded. If the SIP is determined to be an invalid address, the packet is dropped.

"Micro segment" (SRv6 uSID or uSID for short) is an extension of SRv6 architecture, specifically designed to represent SRv6 SIDs in an extremely compact way. It addresses the overhead of using full 128-bit IPv6 SIDs for routing. Instead of using a 128-bit address for single SID, multiple uSIDs are packed into a single 128-bit address. Each 128-bit address comprises a block value representing the domain followed by multiple uSIDs, each of the same bit length. If there are bits left they are filled with trailing zeros. This allows for a complete SRv6 path to be represented by a 128-bit IPv6 address. Like a regular SID, each uSID is associated with a specific behavior on the SRv6 capable node. SRv6 uN refers to the End behavior with uSIDs.

The EOS-4.36.1 release introduces SSU support for SRv6 uN. This allows for SSU with SRv6 uN configuration, with negligible impact on active traffic flows.

TOI SSU SRv6 EOS 4.36.1F

Static NAT allows a switch to modify the source or destination IP address, and optionally the Layer 4 port, of packets traversing it. Each static NAT rule is explicitly defined by the user and specifies a one-to-one mapping between an original IP address and a translated IP address.

A traffic storm is a flood of packets entering a network, resulting in excessive traffic and degraded performance. Storm control prevents network disruptions by limiting traffic beyond specified thresholds on individual physical LAN interfaces. Storm control monitors inbound traffic levels over one-second intervals and compares the traffic level with a specified benchmark. The storm-control command configures and enables storm control on the configuration mode physical interface.

This feature adds support for CPU traffic policy capable of matching and acting on IP traffic which would otherwise hit the CPU. This policy is capable of permitting traffic from trusted sources, while rejecting untrusted traffic. It supports matching on a variety of IP packet header information such as DSCP, L4 port values, fragmentation bits, etc. as well as a number of actions such as permit, deny, and police. To prevent a malicious source from overloading the CPU, this traffic policy will take effect in the switching hardware, before the traffic is processed by the kernel. This feature provides a shorthand syntax for securing L3 protocol peers, in particular, BGP neighbors.

This feature adds support to configure the following decap group OpenConfig models via gNMI. GRE decap group for incoming traffic with IPv4 or IPv6 inner packets , UDP decap group for incoming traffic with IPv4 or IPv6 inner packets , UDP decap group for incoming traffic with MPLS inner packets

TOI OpenConfig Decap-group EOS 4.36.1F

Dynamic Twice NAT is a variant of the dynamic NAT feature where both the source and destination IP can be modified while forwarding a packet. One of the IP addresses will be dynamically assigned, while the other will be statically assigned.

In order to support PIM/IPv4 multicast routing on EOS switches with Broadcom Tomahawk5 ASICs, multicast support using ALPM tables is required. This works in both 3-level Algorithmic Longest Prefix Match (ALPM) capabilities and 2-level ALPM.

TOI Multicast IPv4 EOS 4.36.1F

In order to support PIM/IPv4 multicast routing on EOS switches with Broadcom Tomahawk4 ASICs, multicast support using ALPM is required. This works in both 3-level Algorithmic Longest Prefix Match (ALPM) capabilities and 2-level ALPM.

Private VLAN is a feature that segregates a regular VLAN broadcast domain while maintaining all ports in the same IP subnet. There are three types of VLAN within a private VLAN

Currently EOS supports redistribution into BGP at the global ( instance ) level. Also EOS supports redistribution in BGP at Address Family Identifier/Subsequent Address Family Identifier(AFI/SAFI) level to some extent. But the current redistribution mechanism is not flexible and does not provide full control at AFI/SAFI level ( some redistribution protocols are only supported at global level, or at some AFI/SAFI level ). This feature will support redistribution at AFI/SAFI level as well as at the global level. This will simplify the configuration requirements and supportability for complex and granular configurations when subsequent address family configurations co-exist. This will also give more control at AFI/SAFI level ( for example, route-map/rcf can be configured at AFI/SAFI level while they are not configured at global level ). This feature only works in multi-agent routing model.

SRv6 is the segment routing using IP v6 Data plane. The segment ID is encoded as an IPv6 address. The Micro-Segment extension to SRv6 has representation of SIDs to enable compressing multiple of them into a single IPv6 address.

TOI IS-IS SRv6 EOS 4.36.1F

In Segment Routing, Adjacency Segment (Adj-SID) directs a node to forward the packet over a specific link or a set of links to the remote node. This feature adds support for statically configured SRv6 Adj-SIDs using micro-SIDs, also referred to as uA. This feature builds on the base SRv6 support described in SRv6 uN Support TOI.

Access Control Lists (ACL) use packet classification to mark certain packets going through the packet processor pipeline and then take configured action against them. Rules are defined based on various fields of packets and usually TCAM is used to match packets to rules. For example, there can be a rule to match the packet source IP address against a list of IP addresses, and drop the packet if there is a match. This will be expressed in TCAM with multiple entries matching the list of IP addresses. The number of entries is reduced by masking off bits, if possible. TCAM is a limited resource, so with classifiers having a large number of rules and a big field list, TCAM runs out of resources.

This document describes the availability of VLAN ingress and egress counters on R Series platforms. VLAN counters provide the ability to count packets and bytes ingressing or egressing a bridge domain (VLAN).

This document describes the availability of VLAN interface ingress and egress counters on R Series platforms. VLAN interface counters provide the ability to count packets and bytes ingressing or egressing a VLAN interface.

This feature allows the export of IP FIB (Forwarding Information Base) through the OpenConfig AFT YANG models.

SwitchApp is an FPGA-based feature available on compatible Arista 7130 devices. It performs ultra low latency Ethernet packet switching. Its packet switching feature set, port count, and port to port latency are a function of the selected SwitchApp profile. 

This feature adds TLS support to TACACS+. With the new CLI commands, users can set an SSL profile and enable using TLS to communicate with TACACS+ servers. Once configured, all TACACS+ traffic is transmitted over TLS 1.3 connections with mutual certificate authentication, providing confidentiality, data integrity, and authenticity for AAA communications.

Security AAA TOI Tls TACACS EOS 4.36.1F

This article describes the Tap Aggregation MPLS Pop feature. The purpose of this feature is to support tools that do not parse MPLS labels and therefore need the switch to remove (pop) the MPLS header. This feature supports both IPv4 and IPv6 over MPLS.

The ‘redirect’ action used in TCAM profile has lower priority than system rules, if packets match both TCAM rule using ‘redirect’ action and system rules. Hence ‘redirect’ action does not take effect on these packets. This improvement allows ‘redirect’ action in TCAM profile to override system rules, so that the aforementioned packets will always be redirected even if they match system rules. 

  

The Timing Regeneration Filter (TRF) is a part of the Clock and Data Recovery component of the CRT50216 external PHY from Credo. It has a parameter, known as the bandwidth, which adjusts how the CRT50216 adjusts to frequency changes in the incoming signal from the peer.   This TOI documents the addition of a command to allow the user to manually adjust the TRF bandwidth per Ethernet lane.

The tone generation feature enables switches to produce tones for fiber optic identification. This can produce 270Hz tones that standard fiber optic identifier devices can detect. The feature generates tones using SFP transceivers by toggling transceiver transmit disable at a configurable frequency. When enabled, this feature will disrupt the link and traffic on the interface.

TOI L1 EOS 4.36.1F Tone Generation

This document describes LLDP’s VLAN Name TLV. It is defined in IEEE 802.1Q standard (802.1Q - D.2.3) and contains a list of VLAN names that the port is assigned to. This TLV is optional and it is disabled by default in Arista switches.

TOI EOS 4.26.1F EOS 4.36.1F

VLAN tagged MACsec refers to frames that have a VLAN tag between the MAC source address and the MACsec ethertype. This VLAN tag is unencrypted (in the clear) so that intermediate devices between the MACsec endpoints can forward the MACsec frames based on this unencrypted VLAN tag.

With a static configured import and export route-target for a given vlan-aware-bundle, all its VLAN members share the same route-target value. For example, EVPN uses the same route-target in the Type 2 EVPN route advertisements for hosts residing in two different VLAN of the same bundle.

TOI EOS 4.30.1F EOS 4.36.1F