- Written by Manish Singhvi
- Posted on September 11, 2025
- Updated on September 16, 2025
- 1396 Views
802.1X dynamic interface configuration allows for dynamic interface configuration on the 802.1X authenticator based on device profiling performed by a Network Access Controller (NAC). Traditionally, 802.1X authenticators require static interface configuration. This enhancement extends dynamic capabilities beyond existing features like dynamic VLAN assignment and ACL programming, enabling any type of interface configuration to be applied dynamically via the CLI.
- Written by Tarun Jaswanth LNU
- Posted on August 24, 2020
- Updated on November 10, 2025
- 36694 Views
802.1X is an IEEE standard protocol that prevents unauthorized devices from gaining access to the network.
- Written by Chris Pearson
- Posted on August 22, 2025
- Updated on August 22, 2025
- 1325 Views
This feature gives AVT/DPS tunnels the ability to transport IPv6 overlay traffic. Formerly, such tunnels could only transport IPv4 overlay traffic.
- Written by Himanshu Singh
- Posted on April 25, 2025
- Updated on September 11, 2025
- 3188 Views
Automatic certificate management provides support for retrieving signed x509v3 certificates from a server under the Enrollment over Secure Transport (EST) protocol, described in RFC 7030. The feature provides only EST client capabilities.
- Written by Anil Rao
- Posted on August 8, 2025
- Updated on December 12, 2025
- 1520 Views
BFD telemetry streaming via OpenConfig implements the gNMI path /bfd/interfaces/interface/peers such that users can get real time telemetry data on BFD sessions configured on the device.
- Written by Trevor Mendez
- Posted on December 20, 2021
- Updated on January 16, 2026
- 13534 Views
ACL based traffic management often requires matching packets’ destination addresses against one or more sets of IP prefixes. This can become difficult to manage when the prefix sets need to be consistently maintained on several devices and either change too frequently or are very large. When the prefixes for the prefix sets are learned by BGP, this feature provides an alternative to maintaining unwieldy sets of statically configured IP prefixes. Instead the prefix sets are populated by BGP based on the BGP communities that are assigned to learned prefixes. BGP can manage IP prefix field sets for use with Traffic Policies.
- Written by Yaonan Liang
- Posted on April 30, 2025
- Updated on September 12, 2025
- 3380 Views
Peer Tagging Route Filtering feature discards BGP route advertisements by the peers which the routes are received from. The feature lets users assign a peer-tag to a peer or a group of peers in inbound direction and discard routes advertisements by the peer-tag in outbound direction. One use case of the feature is to discard AS loop routes in outbound direction in data center deployments.
- Written by Keon Vafai
- Posted on June 22, 2020
- Updated on November 5, 2025
- 21009 Views
This feature adds support for BGP UCMP in the multi agent routing protocol model. The TOI for BGP UCMP in the ribd
- Written by Tanushree Bansal
- Posted on August 8, 2025
- Updated on January 8, 2026
- 1567 Views
Class Based Forwarding (CBF) is a means for steering IP traffic into specific tunnels based on either the ingress DSCP values or based on “classes”, which are derived from fields in the ingress packet headers and policies provisioned on the router. CBF may be used with SR-TE Policy or RSVP-TE colored tunnels. 4.35.1F adds support for CBF with flex-algo colored tunnels.
- Written by Ashwini Kumar
- Posted on September 4, 2025
- Updated on January 16, 2026
- 1581 Views
Arista’s CCS-710XP series of ethernet switches consist of CCS-710XP-12TH-2S SKU. CCS-710XP-12TH-2S is a 12 port 1000BASE-T PoE & 2-port SFP+ fanless switch device rich with networking features suited for campus deployments.
- Written by Ming Han
- Posted on September 4, 2025
- Updated on October 21, 2025
- 1393 Views
This document describes the configuration and behavior of physical interfaces on the CCS-710XP series switch
- Written by Dylan Cho
- Posted on April 30, 2025
- Updated on October 22, 2025
- 2748 Views
This feature implements the ability to configure any tx serdes parameters via the CLI. This is useful to work around any L1 issues that customers may encounter due to suboptimal networks/links/transceivers.
- Written by Vivek Subbarao
- Posted on January 3, 2023
- Updated on September 2, 2025
- 9251 Views
Network Address Translation (NAT) is a feature used to obfuscate private internal addresses to the external world. The feature makes sure that private internal addresses are translated into a publicly visible address which is used by all external hosts and it also does the reverse translation of the public address to the private internal address.
- Written by Tom Emmons
- Posted on October 22, 2024
- Updated on November 4, 2025
- 7350 Views
Cluster Load Balancing is a feature designed to ensure optimal load balancing of flows used as part of GPU based cluster communication. When this feature is enabled, a TOR router monitors RoCE traffic flowing between the GPU servers and spine uplinks and ensures optimal load balancing in the network.
- Written by Rajesh Semwal
- Posted on August 19, 2025
- Updated on January 13, 2026
- 1531 Views
Cluster Load Balancing for Spine is a feature designed to ensure optimal load balancing of flows used as part of GPU based cluster communication in a network that uses multiple links to connect a TOR router to a Spine router.. When this feature is enabled on a Spine, it monitors RoCE traffic coming from a TOR and applies optimal load balancing when forwarding the traffic to the next TOR router hosting the destination GPU server.
- Written by Muralidhar
- Posted on August 11, 2025
- Updated on October 21, 2025
- 1437 Views
Traditional policers treat all packets equally without considering the color of the incoming packet, potentially leading to transmission of excess packets that have already been marked with lower priority. Color aware flag in a policer configuration addresses this by providing the ability to consider the incoming packets’s drop precedence (DP) value while taking the policing decision on a given interface.
- Written by Rajat Jain
- Posted on August 8, 2025
- Updated on August 13, 2025
- 1437 Views
This feature allows the user to define a custom COS To Traffic-Class (TC) and Drop-Precedence (DP) map and apply it to an interface.
- Written by Mohammad Umar
- Posted on November 13, 2024
- Updated on September 11, 2025
- 3980 Views
This feature allows the user to define a custom DSCP-To-TC map and apply it to an interface.
- Written by Deepak Sebastian
- Posted on August 18, 2022
- Updated on September 15, 2025
- 11876 Views
Arista’s DCS-7130LBR series of switches are powerful network devices designed for ultra latency applications along with a wealth of networking features.
- Written by Augusto Wong
- Posted on February 17, 2021
- Updated on January 16, 2026
- 16700 Views
The DHCP relay feature, forwards DHCP packets between a client and the DHCP server when the server is not in the same broadcast domain as the client. The DHCP relay should be configured on the gateway interface (SVI/ L3 interface) for the clients.
- Written by Gabor
- Posted on August 12, 2025
- Updated on September 18, 2025
- 2114 Views
Egress filtered mirroring enables the selective mirroring of packets exiting a port, offering more precise control compared to mirroring all egress traffic. It is possible to selectively mirror egress packets based on the permit statements in the configured ACLs.
- Written by Can Sun
- Posted on August 12, 2025
- Updated on August 13, 2025
- 1418 Views
Measured boot is an anti-tamper mechanism. It calculates the cryptographic signatures for software system components and extends the signatures into the Trusted Platform Module (TPM) security chip. Upon startup, with the feature turned on, the Aboot bootloader and EOS calculate the hash of various system components and extend the hashes into the Platform Configuration Registers (PCRs), which is one of the resources of the Trusted Platform Module (TPM) security chip. The calculation and extension event is called the measured boot event, which is associated with a revision number to help the user identify changes to the event.
- Written by Denis Evoy
- Posted on August 8, 2025
- Updated on August 8, 2025
- 1430 Views
The FIB contains mappings between a prefix (identifying a destination network) and its associated Forwarding Equivalence Class (FEC), with the FEC containing one or more resolved Vias defining how traffic should be forwarded towards that destination network.
- Written by Dylan Walsh
- Posted on October 20, 2022
- Updated on August 7, 2025
- 11843 Views
EosSdkRpc is an agent built on top of the Arista EOS SDK. It uses gRPC as a mechanism to provide remote access to the EOS SDK. The gRPC interface that EosSdkRpc supports closely matches the interface provided by EOS SDK, and the intent is that the .proto interface can be publicly supported. EosSdkRpc allows for remote access and using protobuf to specify the interface isolates user code from the Linux ABI issues that come with building C++ applications on different compiler, libc, and kernel versions. EosSdkRpc is built using C++ but supports clients written in any of the languages currently supported by the gRPC framework.
- Written by Ajay Kini
- Posted on September 16, 2025
- Updated on September 16, 2025
- 1106 Views
This feature allows configuring backup entries for static MPLS LFIB routes via EOS SDK RPC to be activated if its corresponding primary entries are unable to forward traffic due to next hops being unresolved or its corresponding interface being down. Any backup entries will not be activated to forward traffic until all primary entries are unviable. Thereby, backup entries configured for the Static MPLS routes are a mechanism to achieve fast failover when the primary path fails.
- Written by Vamsi Anne
- Posted on December 29, 2021
- Updated on August 19, 2025
- 15438 Views
As Ethernet technologies made their way into the Metropolitan Area Networks (MAN) and the Wide Area Networks (WAN), from the conventional enterprise level usage, they are now widely being used by service providers to provide end-to-end connectivity to customers. Such service provider networks are typically spread across large geographical areas. Additionally, the service providers themselves may be relying on certain internet backbone providers, referred to as “operators”, to provide connectivity in case the geographical area to be covered is too huge. This mode of operation makes the task of Operations, Administration and Maintenance (OAM) of such networks to be far more challenging, and the ability of service providers to respond to such network faults swiftly directly impacts their competitiveness.
- Written by Christopher Yamashita
- Posted on January 3, 2025
- Updated on September 16, 2025
- 4003 Views
As Ethernet technologies made their way into the Metropolitan Area Networks (MAN) and the Wide Area Networks (WAN) from the conventional enterprise level usage, they are now widely being used by service providers to provide end-to-end connectivity to customers. Such service provider networks are typically spread across large geographical areas. Additionally, the service providers themselves may be relying on certain internet backbone providers, referred to as “operators”, to provide connectivity in case the geographical area to be covered is too huge. This mode of operation makes the task of Operations, Administration and Maintenance (OAM) of such networks far more challenging, and the ability of service providers to respond to frame loss in such networks directly impacts their competitiveness.
- Written by Alton Lo
- Posted on March 18, 2020
- Updated on January 16, 2026
- 25576 Views
In the Centralized Anycast Gateway configuration, the Spines are configured with EVPN-IRB and are used as the IP Default Gateway(DWG), whereas the Top of rack switches perform L2 EVPN Routing.
- Written by Lavanya Conjeevaram
- Posted on December 22, 2017
- Updated on September 5, 2025
- 14260 Views
In the traditional data center design, inter-subnet forwarding is provided by a centralized router, where traffic traverses across the network to a centralized routing node and back again to its final destination. In a large multi-tenant data center environment this operational model can lead to inefficient use of bandwidth and sub-optimal forwarding.
- Written by Jeff Wen
- Posted on January 21, 2019
- Updated on September 12, 2025
- 14961 Views
In the traditional data center design, inter-subnet forwarding is provided by a centralized router, where traffic traverses across the network to a centralized routing node and back again to its final destination. In a large multi-tenant data center environment this operational model can lead to inefficient use of bandwidth and sub-optimal forwarding.
- Written by Omar Jamil
- Posted on August 19, 2025
- Updated on August 19, 2025
- 1460 Views
The EVPN Gateway Data Center Interconnect (DCI) feature supports multihoming redundancy. This deployment model leverages a virtual Interconnect Ethernet Segment Identifier (I-ESI) to form an overlay ECMP across the EVPN DCI gateways. Recently, EOS added new features for managing the I-ES that improve traffic handling and convergence in certain failure scenarios:
- Written by Pavan Narasimhaprasad
- Posted on August 19, 2025
- Updated on October 31, 2025
- 1693 Views
Smart System Upgrade (SSU) provides the ability to upgrade the EOS image with minimal traffic disruption.
- Written by Sunil Bojanapally
- Posted on September 2, 2025
- Updated on September 2, 2025
- 1293 Views
Receive Side Scaling (RSS) which is also known as multi queue receive, distributes network receive flows across NIC card multiple hardware queues.
- Written by James Shephard
- Posted on August 25, 2019
- Updated on November 5, 2025
- 15955 Views
Forwarding destination prediction enables visibility into how a packet is forwarded through the switch, allowing you to determine which interfaces a packet would egress out of. Typical use cases include, but are not limited to, determining egress members for Port-Channels and ECMPs.
- Written by Dylan Walsh
- Posted on August 18, 2025
- Updated on January 7, 2026
- 1488 Views
gNPSI is an OpenConfig protocol designed to act as a proxy between the sFlow agent and interested gRPC clients. The gNPSI server receives datagrams from sFlow, repackages the datagrams in the protobuf message format and forwards these messages onto any subscribed gRPC clients. The protobuf used for this feature is available at the link above.
- Written by Pratik Mangalore
- Posted on December 14, 2020
- Updated on November 5, 2025
- 19399 Views
IP Locking is an EOS feature configured on an Ethernet Layer 2 port. When enabled, it ensures that a port will only permit IP and ARP packets with IP source addresses that have been authorized. As of EOS-4.25.0F release update, IP Locking can run in two modes - IPv4 Locking (which will be referred to as IP Locking) and IPv6 Locking, which can be configured using the commands mentioned in the below sections. IP Locking prevents another host on a different interface from claiming ownership of an IP address through either IP or ARP spoofing.
- Written by Sarah Chen
- Posted on January 12, 2022
- Updated on August 22, 2025
- 16223 Views
IS-IS flexible algorithm (FlexAlgo) provides a lightweight, simplified mechanism for performing basic traffic engineering functions within a single IS-IS area. FlexAlgo requires the cooperation of all nodes within the IS-IS area but does not require an external controller. Paths are computed by each node within the area, resulting in an MPLS switched forwarding path to nodes that are advertising a node Segment Identifier (SID) for the algorithm. The results of the path computation are placed in the colored tunnel RIB or system tunnel RIB, which simplifies route resolution.
- Written by Navneet Sinha
- Posted on June 29, 2016
- Updated on September 9, 2025
- 20943 Views
Segment Routing provides mechanism to define end-to-end paths within a topology by encoding paths as sequences of sub-paths or instructions. These sub-paths or instructions are referred to as “segments”. IS-IS Segment Routing (henceforth referred to as IS-IS SR) provides means to advertise such segments through IS-IS protocol.
- Written by Zeyad Tamimi
- Posted on March 3, 2023
- Updated on November 4, 2025
- 13987 Views
At a high level, L1 profiles are a set of configurations which allow EOS users to change the numbering scheme and default L1 configurations of all front panel interfaces across their network switch. On Arista network switches, front panel transceiver cages are exposed as ports which are numbered sequentially: 1, 2, 3, 4, etc. These identifiers are usually marked on the front panel to allow for easier identification.
- Written by Jeff Hornsberger
- Posted on August 19, 2020
- Updated on August 19, 2025
- 12262 Views
LDP End of LIB is a signaling enhancement defined in RFC 5919 to allow an LDP speaker to notify a neighbor when it has
- Written by Shyam Kota
- Posted on June 5, 2020
- Updated on August 20, 2025
- 11393 Views
This feature implements RFC 3478. It allows devices to preserve the MPLS LDP LFIB entries in the forwarding plane if the TCP connection is lost or LDP agent restarts.
- Written by Pavan Narasimhaprasad
- Posted on June 27, 2024
- Updated on September 4, 2025
- 5319 Views
Leaf Smart System Upgrade (SSU) provides the ability to upgrade the EOS image with minimal traffic disruption.Note: It is possible that SSU shutdown and bootup are not supported in the same image. If a product has shutdown support in image A and bootup support in a later image B, then SSU upgrade cannot be performed from image A to any images earlier than image B, including image A itself. However, upgrading from image A to image B onwards is allowed.
- Written by Shyam Kota
- Posted on November 6, 2019
- Updated on August 22, 2025
- 13285 Views
This feature allows setting the desired maximum VOQ latency. Drop probabilities are adjusted in hardware to meet this limit.
- Written by David Mirabito
- Posted on December 30, 2021
- Updated on January 2, 2026
- 27402 Views
MetaWatch is an FPGA-based feature available for Arista 7130 Series platforms. It provides precise timestamping of packets, aggregation and deep buffering for Ethernet links. Timestamp information and other metadata such as device and port identifiers are appended to the end of the packet as a trailer.
- Written by Abdul Haseeb Jehangir
- Posted on March 12, 2020
- Updated on August 28, 2025
- 17257 Views
Mirror on drop is a network visibility feature which allows monitoring of MPLS or IP flow drops occurring in the ingress pipeline. When such a drop is detected, it is sent to the control plane where it is processed and then sent to configured collectors. Additionally, CLI show commands provide general and detailed statistics and status.
- Written by Prakhar Rastogi
- Posted on April 23, 2018
- Updated on September 5, 2025
- 12961 Views
MLAG Smart System Upgrade (SSU) provides the ability to upgrade the EOS image of an MLAG switch with minimal traffic disruption.
- Written by Weichen Zhao
- Posted on May 12, 2022
- Updated on August 12, 2025
- 11753 Views
Generic UDP Encapsulation (GUE) is a general method for encapsulating packets of arbitrary IP protocols within a UDP tunnel. GUE provides an extensible header format with optional data. In this release, the ability to encapsulate MPLS over GUE packets of variant 1 header format has been added.
- Written by Vincent Lam
- Posted on January 18, 2019
- Updated on August 28, 2025
- 20007 Views
In conventional VXLAN deployments, each MLAG pair of switches are represented as a common logical VTEP. VXLAN traffic can be decapsulated on either switch. In some networks, there are hosts that are singly connected to one of the MLAG pair. VXLAN packets destined for the singly connected host could land on the other MLAG peer and subsequently be forwarded over the MLAG peer-link to reach the destination host. This path is undesirable since it would use up some bandwidth on the peer-link.
- Written by Diego Asturias
- Posted on January 30, 2024
- Updated on November 17, 2025
- 9244 Views
MultiAccess is an FPGA-based feature available on certain Arista 7130 platforms. It performs low-latency Ethernet multiplexing with optional packet contention queuing, storm control, VLAN tunneling, and packet access control. The interface to interface latency is a function of the selected MultiAccess profile, front panel interfaces, MultiAccess interfaces, configuration settings, and platform being used.
- Written by Saurabh Singhal
- Posted on August 19, 2025
- Updated on August 19, 2025
- 1408 Views
NIM-1QC is a single port OCP 3.0 standard NIM card manufactured by Intel. The AWE-7230R-4TX-4S-F, AWE-5310-F, and AWE-7250R-16S-F, AWE-5510-F devices have 2 and 4 NIM (Network Interface Module) slots respectively. These devices now support NIM-1QC cards.
