- Written by Harish Pradyot
- Posted on February 27, 2025
- Updated on February 27, 2025
- 4506 Views
This feature enables users to configure MPLS EXP rewrite behavior on the egress interface based upon the global TC-to-EXP mapping. Starting from software version 4.33.2F, the CLI configuration to enable or disable EXP rewrite on the egress interface introduces a clear distinction in the behavior of MPLS EXP processing during POP and SWAP operations.
- Written by Gabor
- Posted on August 12, 2025
- Updated on September 18, 2025
- 3847 Views
Egress filtered mirroring enables the selective mirroring of packets exiting a port, offering more precise control compared to mirroring all egress traffic. It is possible to selectively mirror egress packets based on the permit statements in the configured ACLs.
- Written by Mouli Baskaran
- Posted on May 1, 2015
- Updated on March 19, 2016
- 10818 Views
IPv4/IPv6 over MPLS packets are now eligible for ACLs at egress stage by default. The feature is applicable only to
- Written by Sridhar Nagarajan
- Posted on January 8, 2026
- Updated on January 8, 2026
- 1373 Views
EOS-4.35.1F adds support for egress IPv4/IPv6/MAC PACL. So, by default, egress IPv4/IPv6 ACL enabled on default profile and for MAC ACL to enable, it is required to add its support directly to the current tcam profile or create a new tcam profile based on the default profile and disable egress IPv4 and IPv6 ACL features.
- Written by Denis Evoy
- Posted on October 24, 2024
- Updated on October 24, 2024
- 5421 Views
Normally, an ingress router has no control over an autonomous system border router’s (ASBR) selection of inter-AS links. In the example below, Peer 2 and Peer 3 both advertise reachability to some remote network to ASBR 1 (e.g. service route 172.16.1.0/24). ASBR 1 would then use normal bestpath selection rules to select a preferred egress path (for traffic flowing to that service route). However, this means that the ingress router has no control over which egress path is chosen.
- Written by Ganesh Priyatham Palivela
- Posted on October 10, 2025
- Updated on October 10, 2025
- 2375 Views
Egress Priority Tagging is a feature that allows a switch to send out priority tagged ethernet frames in place of untagged frames. Priority tagged frames are sent with the VLAN ID set to zero allowing downstream devices to read the 802.1p priority bits set in the VLAN header.
- Written by Tanuj Kumar Jhamb
- Posted on February 7, 2024
- Updated on September 16, 2025
- 7965 Views
sFlow is a sampling technique which monitors incoming traffic on all interfaces without affecting network performance. Egress sFlow is a feature which samples the packets in the egress pipeline for analytical purposes. Currently egress sFlow is only software based on Arista switches.
- Written by AKSHAYA Sridharan
- Posted on December 17, 2020
- Updated on October 22, 2025
- 13805 Views
Egress traffic-policing can be applied on L3 Ethernet subinterfaces for outbound traffic.
- Written by Anupama Srivastava
- Posted on September 30, 2015
- Updated on February 8, 2022
- 10797 Views
This feature optimizes the utilization of hardware resources by sharing tcam entries for a group of SVIs on which an
- Written by Dhruba Jyoti Pokhrel
- Posted on July 7, 2023
- Updated on July 7, 2023
- 8770 Views
RadSec or RADIUS over TLS is a protocol for secure communication between a client and the RADIUS server. RadSec uses TCP and TLS protocols to form a secure tunnel between the client and the server.
- Written by Akshay Gattani
- Posted on February 8, 2017
- Updated on February 9, 2017
- 10887 Views
The BGP implementation now provides the ability to display the age of paths received for a given prefix using the
- Written by Jacob Sword
- Posted on February 16, 2022
- Updated on April 1, 2026
- 16338 Views
Multiple dynamic counter features may be enabled simultaneously, primarily configured using the ‘[no] hardware counter feature [feature]’ CLI commands. Compatibility of these features has been enhanced to allow for greater flexibility in simultaneously enabled counter features. Changes in counter feature compatibility across EOS releases is detailed below.
- Written by Kenneth Cheung
- Posted on November 22, 2017
- Updated on July 21, 2023
- 13307 Views
EOS 4.20.1F introduces expanded VRRP, VARP and MLAG Peer Gateway virtual MAC capabilities on the 7500R, 7280R,
- Written by Mihyar Baroudi
- Posted on December 8, 2015
- Updated on February 7, 2022
- 11095 Views
IP in IP decapsulation was first introduced for the supported platforms(below) in EOS version 4.15.0F (IP in IP
- Written by Lavanya Conjeevaram
- Posted on April 1, 2015
- Updated on August 2, 2022
- 1466 Views
DANZ provides a set of features and tools to enhance instrumentation and network/ application performance monitoring with the following key functional areas.
- Written by Can Sun
- Posted on December 20, 2024
- Updated on December 20, 2024
- 4847 Views
Measured boot is an anti-tamper mechanism. It calculates the cryptographic signatures for software system components and extends the signatures into the Trusted Platform Module (TPM) security chip. Upon startup, with the feature turned on, the Aboot bootloader and EOS calculate the hash of various system components and extend the hashes into the Platform Configuration Registers (PCRs), which is one of the resources of the Trusted Platform Module (TPM) security chip. The calculation and extension event is called the measured boot event, which is associated with a revision number to help the user identify changes to the event.
- Written by Can Sun
- Posted on June 23, 2026
- Updated on June 23, 2026
- 315 Views
Measured boot is an anti-tamper mechanism. It calculates the cryptographic signatures for software system components and extends the signatures into the Trusted Platform Module (TPM) security chip. Upon startup, with the feature turned on, the Aboot bootloader and EOS calculate the hash of various system components and extend the hashes into the Platform Configuration Registers (PCRs), which is one of the resources of the Trusted Platform Module (TPM) security chip. The calculation and extension event is called the measured boot event, which is associated with a revision number to help the user identify changes to the event.
- Written by Denis Evoy
- Posted on August 8, 2025
- Updated on August 8, 2025
- 2611 Views
The FIB contains mappings between a prefix (identifying a destination network) and its associated Forwarding Equivalence Class (FEC), with the FEC containing one or more resolved Vias defining how traffic should be forwarded towards that destination network.
- Written by Reji Thomas
- Posted on October 16, 2024
- Updated on March 13, 2026
- 5740 Views
RFC 5837 describes extensions to the Internet Control Message Protocol (ICMP) that enable network devices to identify incoming and outgoing interfaces and next-hop addresses via extensions to specific ICMP error messages. These extensions are particularly useful for network diagnostics and troubleshooting applications.
- Written by Dylan Walsh
- Posted on October 20, 2022
- Updated on August 7, 2025
- 13219 Views
EosSdkRpc is an agent built on top of the Arista EOS SDK. It uses gRPC as a mechanism to provide remote access to the EOS SDK. The gRPC interface that EosSdkRpc supports closely matches the interface provided by EOS SDK, and the intent is that the .proto interface can be publicly supported. EosSdkRpc allows for remote access and using protobuf to specify the interface isolates user code from the Linux ABI issues that come with building C++ applications on different compiler, libc, and kernel versions. EosSdkRpc is built using C++ but supports clients written in any of the languages currently supported by the gRPC framework.
- Written by Ajay Kini
- Posted on September 16, 2025
- Updated on September 16, 2025
- 2262 Views
This feature allows configuring backup entries for static MPLS LFIB routes via EOS SDK RPC to be activated if its corresponding primary entries are unable to forward traffic due to next hops being unresolved or its corresponding interface being down. Any backup entries will not be activated to forward traffic until all primary entries are unviable. Thereby, backup entries configured for the Static MPLS routes are a mechanism to achieve fast failover when the primary path fails.
- Written by Srilekha Nune
- Posted on April 24, 2025
- Updated on April 24, 2025
- 3733 Views
This feature prevents policy churn by automatically placing switch interfaces with frequent flapping into an error-disabled state, effectively performing an automatic administrative shutdown. The feature also allows for automatically recovering these interfaces after a specified time. This feature reduces the risk of lost packets caused by continuous recomputation of DANZ Monitoring Fabric (DMF) policies due to flapping interfaces.
- Written by Steve Ulrich
- Posted on June 5, 2023
- Updated on July 22, 2025
- 9156 Views
Traffic policies applied to interfaces are used to match traffic based on packet header fields or their summarized counterparts and take configured actions against them. The match rules configured in these policies are usually installed in a prioritized hardware table (i.e., TCAM) where the action of the first-hit filter is taken. The summarized fields are also installed in various hardware tables. The hardware utilization of traffic policies is very much dependent not only in the number of configured match rules but also in how the set of values are distributed for each field.
- Written by Abhishek Raghuveer
- Posted on July 9, 2025
- Updated on July 10, 2025
- 3494 Views
This feature is an extension of ZTX monitor mode functionality to virtual machines where a virtual machine running on a hypervisor(ESXi/KVM) will facilitate the generation of MSS policies by exporting flow telemetry to CloudVision Portal. vZTX will primarily focus on the use cases where the data traffic in the customer sites are limited(<10Gbps). This will help the customer to reduce the capital expenditure costs by avoiding the need of purchasing a dedicated hardware box. So, this product can cater to the needs of small to medium size enterprise customers.
- Written by Vamsi Anne
- Posted on December 29, 2021
- Updated on June 15, 2026
- 17290 Views
As Ethernet technologies made their way into the Metropolitan Area Networks (MAN) and the Wide Area Networks (WAN), from the conventional enterprise level usage, they are now widely being used by service providers to provide end-to-end connectivity to customers. Such service provider networks are typically spread across large geographical areas. Additionally, the service providers themselves may be relying on certain internet backbone providers, referred to as “operators”, to provide connectivity in case the geographical area to be covered is too huge. This mode of operation makes the task of Operations, Administration and Maintenance (OAM) of such networks to be far more challenging, and the ability of service providers to respond to such network faults swiftly directly impacts their competitiveness.
- Written by Vamsi Anne
- Posted on October 20, 2022
- Updated on December 30, 2024
- 13513 Views
As Ethernet technologies made their way into the Metropolitan Area Networks (MAN) and the Wide Area Networks (WAN) from the conventional enterprise level usage, they are now widely being used by service providers to provide end-to-end connectivity to customers. Such service provider networks are typically spread across large geographical areas. Additionally, the service providers themselves may be relying on certain internet backbone providers, referred to as “operators”, to provide connectivity in case the geographical area to be covered is too huge.
- Written by Christopher Yamashita
- Posted on January 3, 2025
- Updated on July 16, 2026
- 5548 Views
As Ethernet technologies made their way into the Metropolitan Area Networks (MAN) and the Wide Area Networks (WAN) from the conventional enterprise level usage, they are now widely being used by service providers to provide end-to-end connectivity to customers. Such service provider networks are typically spread across large geographical areas. Additionally, the service providers themselves may be relying on certain internet backbone providers, referred to as “operators”, to provide connectivity in case the geographical area to be covered is too huge.
- Written by Shourya Agrawal
- Posted on April 25, 2025
- Updated on April 25, 2025
- 3450 Views
This feature adds support for using the management port on AWE-7220RP-5TH-2S alternately as Ethernet8 port.
- Written by Mihyar Baroudi
- Posted on September 11, 2017
- Updated on October 31, 2019
- 13140 Views
The EOS Event Manager feature provides the ability to specify a condition and an action to be carried out when that
- Written by Mihyar Baroudi
- Posted on October 24, 2024
- Updated on October 24, 2024
- 5731 Views
The EOS Event Manager feature provides the ability to specify a condition and an action to be carried out when that condition is detected. It is a flexible and configurable way to automate the reaction to conditions without the need for a system operator to observe and apply the desired actions manually.
- Written by Mihyar Baroudi
- Posted on September 11, 2017
- Updated on May 7, 2024
- 14359 Views
The EOS Event Manager feature, introduced in 4.17.0F, provides the ability to specify a condition and an action
- Written by Mihyar Baroudi
- Posted on September 11, 2017
- Updated on February 8, 2022
- 13997 Views
The EOS Event Manager feature provides the ability to specify a condition and an action to be carried out when that
- Written by Peter Friend
- Posted on March 12, 2026
- Updated on March 13, 2026
- 831 Views
This feature stores events describing changes to IS-IS IP routes into a SQL. These events are intended to be used to debug convergence issues and understand the impact changes elsewhere in the network have on an EOS device. When an IS-IS IP route changes due to an IS-IS SPF calculation and this feature is enabled, the feature tracks the time the route change is reflected at various "layers" of the route processing pipeline.
- Written by Abhiram Kalluru
- Posted on March 4, 2025
- Updated on March 4, 2025
- 4201 Views
Event monitor is extended to support new event types that continuously synchronize their contents with the sqlite database (in contrast with event monitor’s current behavior of synchronizing event state only when cli commands are run.)
- Written by Julie Powell
- Posted on November 4, 2024
- Updated on November 4, 2024
- 4848 Views
CloudVision allows you to generate event notifications so that you can stay up to date on your network's status and performance. Notification configuration involves formatting notifications, configuring notification platforms, assigning notification receivers, and configuring notification rules.
- Written by Manuel Lai
- Posted on June 9, 2017
- Updated on August 2, 2022
- 2811 Views
The ability to monitor and react to Syslog messages provides a powerful and flexible tool that can be used to apply self
- Written by Julie Powell
- Posted on July 25, 2024
- Updated on July 25, 2024
- 5875 Views
In order to minimize the volume of change control events, CloudVision has introduced a new event, Change Control Events. Change Control Events is generated when 2 or more of the following events are triggered for the same change control:
- Written by Julie Powell
- Posted on October 22, 2024
- Updated on October 22, 2024
- 4960 Views
CloudVision will generate a Disk Utilization on CloudVision Node Breached Threshold event when disk utilization for a CloudVision node has either exceeded the default threshold or breached the user-configured threshold set in event rules.
- Written by Alton Lo
- Posted on November 6, 2023
- Updated on March 5, 2025
- 10603 Views
RFC7432 defines the MAC/IP advertisement NLRI (route type 2) for exchanging EVPN overlay end-hosts’ MAC and IP address reachability information. When an EVPN MAC/IP route contains more than one path to the same destination, the EVPN MAC/IP best-path selection algorithm determines which of these paths should be considered as the best path.
- Written by Alton Lo
- Posted on March 18, 2020
- Updated on May 26, 2026
- 28229 Views
In the Centralized Anycast Gateway configuration, the Spines are configured with EVPN-IRB and are used as the IP Default Gateway(DWG), whereas the Top of rack switches perform L2 EVPN Routing.
- Written by Mason Alexander Flowers
- Posted on January 3, 2023
- Updated on April 27, 2026
- 10852 Views
This feature introduces the show bgp evpn sanity ( brief | detail )command. This command displays which EVPN configuration attributes are inconsistent as well as potential errors in the EVPN operational state.
- Written by Alton Lo
- Posted on May 14, 2024
- Updated on July 10, 2025
- 10012 Views
This new feature explains the use of the BGP Domain PATH (D-PATH) attribute that can be used to identify the EVPN domain(s) through which the EVPN MAC-IP routes have passed. EOS DCI Gateway provides new mechanisms for users to specify the EVPN Domain Identifier for its local and remote domains. DCI Gateways sharing the same redundancy group should share the same local domain identifier and same remote domain identifier.
- Written by Mason Rumuly
- Posted on March 3, 2023
- Updated on July 21, 2026
- 13787 Views
Multihoming in EVPN allows a single customer edge (CE) to connect to multiple provider edges (PE or tunnel endpoint). In any multihoming EVPN instance (EVI), for each ethernet segment a designated forwarder is elected using EVPN type 4 Ethernet Segment (ES) routes sent through BGP. In single-active mode, the designated forwarder (DF) is responsible for sending and receiving all traffic. In all-active mode, the DF is only used to determine whether broadcast, unknown unicast or multicast packets should be egressed in order to avoid sending multiple copies of the same packet to a CE.
- Written by Aaron Bamberger
- Posted on April 23, 2020
- Updated on June 18, 2026
- 16304 Views
E-Tree is an L2 EVPN service (defined in RFC8317) in which each attachment circuit (AC) is assigned the role of Root or Leaf. Root ACs can communicate with leaf ACs and other root ACs. Leaf ACs can only communicate with root ACs. Leaf AC to leaf AC traffic is blocked. In this implementation, ACs are configured at the VLAN level, and the forwarding rules are enforced using a combination of local configuration of leaf VLANs (for local hosts), and asymmetric route targets (for remote hosts).
- Written by Lavanya Conjeevaram
- Posted on March 31, 2017
- Updated on July 23, 2025
- 21075 Views
Ethernet VPN (EVPN) is an extension of the BGP protocol introducing a new address family: L2VPN (address family number 25) / EVPN (subsequent address family number 70). It is used to exchange overlay MAC and IP address reachability information between BGP peers within a tunnel
- Written by Lavanya Conjeevaram
- Posted on December 22, 2017
- Updated on September 5, 2025
- 16202 Views
In the traditional data center design, inter-subnet forwarding is provided by a centralized router, where traffic traverses across the network to a centralized routing node and back again to its final destination. In a large multi-tenant data center environment this operational model can lead to inefficient use of bandwidth and sub-optimal forwarding.
- Written by Jeff Wen
- Posted on January 21, 2019
- Updated on September 12, 2025
- 16696 Views
In the traditional data center design, inter-subnet forwarding is provided by a centralized router, where traffic traverses across the network to a centralized routing node and back again to its final destination. In a large multi-tenant data center environment this operational model can lead to inefficient use of bandwidth and sub-optimal forwarding.
- Written by Jeffrey Nelson
- Posted on October 28, 2020
- Updated on August 5, 2026
- 30903 Views
This feature adds control plane support for inter-subnet forwarding between EVPN networks. This support is achieved by advertising received EVPN IP Prefix routes (Type-5) with next-hop self. VXLAN and MPLS encapsulation are supported, and the encapsulation type used for advertised routes is dependent on the encapsulation type configured for EVPN peering. The following diagram shows an example topology where an EVPN VXLAN network exchanges Type-5 routes with an EVPN MPLS network.
- Written by May Young
- Posted on June 24, 2021
- Updated on March 9, 2026
- 18319 Views
This feature is available when configuring Layer2 EVPN or EVPN IRB.As described in RFC7432 section 15 [1], “MAC Mobility” or “MAC move” occurs when a Customer Edge (CE) moves from one Ethernet segment to another, resulting in two EVPN MAC/IP (Type 2) routes being advertised -- one route with the previous Ethernet segment ID (ESI) and the other with the new Ethernet segment ID. MAC mobility also happens when a CE moves from a single-homed provider edge (PE) to a different PE.
- Written by Alton Lo
- Posted on January 23, 2019
- Updated on February 18, 2026
- 22587 Views
“MLAG Domain Shared Router MAC” is a new mechanism to introduce a new router MAC to be used for MLAG TOR Leaf pairs. The user can either explicitly configure the MAC address of their choice or use the system-generated MLAG system-id for this purpose.
