RPKI serves as a security mechanism to mitigate specific instances of inadvertent route leaking and deliberate route hijacking.

This is an addendum to the “IP in IP decapsulation” document.The Decap Group counters feature allows the device to count packets and octets that are decapsulated at the termination of the Decap Group.

TOI EOS 4.21.3F EOS 4.36.2F

Support for DHCPv4 (RFC 2131) and DHCPv6 Server (RFC 8415) was added to EOS-4.22.1 and EOS-4.23.0 respectively. EOS DHCP server leverages ISC Kea as backend. The router with DHCP Server enabled acts as a server that allocates and delivers network addresses with desired configuration parameters to its hosts.

Virtual Router Redundancy Protocol (VRRP) provides high availability for the default gateway within a broadcast domain. Previously, in VRRP-based deployments with DHCP Relay, each participating router forwarded DHCP requests using its interface IP address, which resulted in duplicate relay requests, duplicate DHCP server ACKs, and increased control-plane noise. This feature solves these issues by making DHCP relay processing VRRP state-aware.

TOI EOS 4.36.2F

EOS adds support for egress IPv4/IPv6 RACL. By default, these are enabled on the default profile. Egress ACL has to be configured the same way as ingress ACL and is applied to an interface by using token “out” instead of “in”

ACL TOI EOS 4.36.2F

This feature enables support for applying egress QoS policy-maps on L3 Ethernet subinterfaces for outbound traffic. Policy-maps consist of class-maps defining match criteria and associated actions such as policing, dropping, or setting DSCP on matching traffic. Egress QoS Policy-map can be applied on L3 Ethernet subinterfaces for outbound traffic.

EVPN Integrated Routing and Bridging (IRB) is a component of BGP EVPN that allows EVPN tunnel endpoints to advertise host routes. IP mobility further extends this capability by providing a means to resolve conflicts in the event that a host IP address moves between physical MAC addresses. IP duplicate detection determines when a host is rapidly moving between two or more MAC addresses and signals the event with a log message, optionally preventing the misbehaving host IP address from being advertised by EVPN.

TOI EOS 4.36.2F

EOS-4.20.0F introduces expanded VRRP, VARP and MLAG Peer Gateway virtual MAC capabilities on the 7500R*/7280R*/7020R series because of improved hardware capabilities. Simultaneous support for VRRP, VARP and MLAG Peer Gateway. VARP and MLAG Peer Gateway take priority over VRRP.

This feature introduces a per-VRF table "FIB route count" for hardware FIB tables, and associated actions to. The "FIB route count" for a VRF table includes FIB routes from most protocol sources (e.g., BGP, IGP, static) in each VRF and address-family (IPv4 and IPv6). Once a VRF table's FIB route count reaches a configured limit, routes can be suppressed or evicted based on the configured action.

TOI EOS 4.34.1F EOS 4.36.2F

EOS supports the ability to match on a single VLAN tag (example: encapsulation dot1q vlan 10) or a VLAN tag pair (example: encapsulation dot1q vlan 10 inner 20) to map matching packets to an interface. In this case, the encapsulation string is considered consumed by the mapped interface before forwarding, which means that the tags are effectively removed from the incoming packet for the purposes of any downstream forwarding.

To address these challenges, AristaAppForSplunk is integrated directly into EOS. The application now ships with the SWI image and will automatically enable once the Splunk Universal Forwarder is installed on the switch. Not only does it reduce potential compatibility breakages to a large extent, but also eliminate the installation step of the AristaAppForSplunk extension.

TOI Telemetry EOS 4.36.2F Splunk

Protocol Independent Multicast (PIM) distributes multicast data using routes gathered by other protocols. PIM Sparse Mode (PIM-SM), defined in RFC 4601, is a multicast routing protocol intended for networks where multicast group recipients are sparsely distributed, including wide-area and inter-domain networks.

IS-IS multi-topology (MT) allows separate topologies for IPv4 and IPv6, enabling independent shortest path (SPF) computations for each address family. While MT provides flexibility, some deployments may seek to migrate from multi-topology to single-topology mode to reduce resource consumption from redundant SPF computations.

TOI IS-IS EOS 4.36.2F Multi Topology

Pseudowires can be used to connect geographically separated L2 networks by emulating an L2 point-to-point connection over a MPLS backbone. While each pseudowire can be configured manually, a L2VPN solution can be used to perform auto-discovery and signaling of the desired pseudowires. VPWS (Virtual Private Wire Service) can be used for auto-discovery and signaling of point-to-point pseudowires. The pseudowires in each VPWS instance can be signaled by LDP or BGP. When signaled using BGP, there are two VPWS sub-types:

This Cli command places the forwarding ASIC into a reduced clock-frequency ( low-power ) operating mode to allow energy savings in exchange of reduced throughput in supported platforms.

TOI Platform EOS 4.36.2F Low Power

Currently, EOS supports only a global configurable EAPoL destination MAC address under mac security mode. This feature extends the support to allow EAPoL packets to the physical MAC address of the port which is also referred to as burned in address with the standard EtherType for ingress direction and a configurable destination MAC address for egress direction.

The maintenance mode feature allows network administrators to perform switch servicing with minimal traffic disruption. When an interface enters maintenance, the rate monitoring stage waits for traffic to drain below a configured threshold before transitioning the interface into maintenance. However, if traffic does not drain — for example, due to insufficient network redundancy or routing constraints — the interface may remain in the "Entering Maintenance" state indefinitely, potentially blocking scheduled maintenance operations.

Container-based deployments make creating cloud portable applications extremely easy. An application can be written on normal build infrastructure, that in turn can be run on a EOS switch or any Linux device that runs docker runtime engine. So the same applications that are run on a server for microservices can be run on a switch with Arista EOS. Since Arista extensible operating system is simply linux (AlmaLinux 9.7 at this time – 2026) we are able to integrate a container runtime engine into the operating system.

TOI EOS 4.36.1F EOS 4.36.2F

MetaWatch is an FPGA-based feature available for Arista 7130 Series platforms. It provides precise timestamping of packets, aggregation and deep buffering for Ethernet links. Timestamp information and other metadata such as device and port identifiers are appended to the end of the packet as a trailer.

Arista switches provide several mirroring features. Filtered mirroring to CPU adds a special destination to the mirroring features that allows the mirrored traffic to be sent to the switch supervisor. The traffic can then be monitored and analyzed locally without the need of a remote port analyzer. Use case of this feature is for debugging and troubleshooting purposes.

On Arista 7130 devices, the transmit and receive paths of front panel Ethernet interfaces are inherently independent. An interface can have a fully operational transmit path while the receive is down, yet the existing show interfaces output only displays a single combined link status. This can cause confusion when the interface state shows "down" even though the TX path is actively passing traffic.

Policy-based routing (PBR) is a feature that is applied on routable ports, to preferentially route packets. Forwarding is based on a policy that is enforced at the ingress of the applied interface and overrides normal routing decisions. In addition to matches on regular ACLs, PBR policy-maps can also include “raw match” statements that look like a single entry of an ACL as a convenience for users.

This article provides a general introduction to Precision Time Protocol (PTP) supported within EOS. PTP is aimed at distributing time with sub-microsecond accuracy. PTP support is based on the IEEE-1588 specification for version 2 of the protocol.

RADIUS over DTLS (Datagram Transport Layer Security) provides secure, encrypted communication between RADIUS clients and servers while maintaining the UDP transport characteristics of traditional RADIUS. This implementation follows RFC 7360 and enhances RADIUS security without requiring migration to TCP-based transports.

Routing control functions (RCF) is a language that can be used to express route filtering and attribute modification logic in a powerful and programmatic fashion. This document serves as a reference guide for: Routing protocol attributes , Operators for comparing and modifying attributes

Routing control functions (RCF) is a language that can be used to express route filtering and attribute modification logic in a powerful and programmatic fashion. This document serves as a reference guide for Bgp agent points of application:

Routing control functions (RCF) is a language that can be used to express route filtering and attribute modification logic in a powerful and programmatic fashion. This document serves as a reference guide for IpRib agent points of application Configuration of RCF

RSVP-TE, the Resource Reservation Protocol (RSVP) for Traffic Engineering (TE), is used to distribute MPLS labels for steering traffic and reserving bandwidth. The Label Edge Router (LER) feature implements the headend functionality, i.e., RSVP-TE tunnels can originate at an LER which can steer traffic into the tunnel.

RSVP-TE applies the Resource Reservation Protocol (RSVP) for Traffic Engineering (TE), i.e., to distribute MPLS labels for steering traffic and reserving bandwidth.

The send support-bundle feature adds a new CLI command which creates a ZIP file containing a useful set of logs and command outputs, and then writes it to either a local or remote destination specified by a CLI URL. When sending to a remote destination, the ZIP file will be created and streamed to the destination on-the-fly, saving local disk space.

The statuses of the transceiver low-speed pins are not easily readable. This feature provides a way to expose these statuses through a CLI command.

TOI EOS 4.36.2F

In EVPN deployments, MAC address reachability is ascertained using both (i) MAC only routes, and (ii) MAC-IP routes. If all EVPN peers in the network are guaranteed to advertise a MAC-only route for MACs, then it is redundant to compute MAC reachability based on MAC-IP routes for the same MAC. With higher scale of the number of IPs mapped to the same MAC address, BGP best path work experiences a higher load.

TOI EVPN L2VPN EOS 4.36.2F

Segment Routing over IPv6 (SRv6) Micro Segment (uSID) is a high-efficiency architecture that drastically reduces packet header overhead by compressing and packing multiple routing instructions into a single 128-bit IPv6 address. To ensure robust operational visibility, this feature integrates native endpoint counters that track real-time packet and byte volumes for every endpoint operation (such as uN processing), providing network operators with granular telemetry for streamlined debuggability, path verification, and traffic analysis.

SRv6 is the segment routing using IPv6 Data plane. The segment ID is encoded as an IPv6 address. The Micro-Segment extension to SRv6 has representation of SIDs to enable compressing multiple of them into a single IPv6 address. 

In Segment Routing, Adjacency Segment (Adj-SID) directs a node to forward the packet over a specific link or a set of links to the remote node. This feature adds support for statically configured SRv6 Adj-SIDs using micro-SIDs, also referred to as uA. This feature builds on the base SRv6 support described in SRv6 uN Support TOI.

This TOI supplements the Ingress Traffic Policy applied on ingress port interfaces. Please refer to that document for a description of Traffic Policies and field-sets. This TOI explains the Traffic Policies as applied in the ingress direction on VLAN interfaces. For Traffic Policies on the egress direction of VLAN interfaces, see the Egress Traffic Policy TOI.

This feature enables support for applying policy maps to Switch Virtual Interfaces (SVI) in the egress direction. A policy map is a Quality of Service (QoS) feature comprising multiple class maps, each with defined match criteria and actions. Class maps evaluate traffic against these criteria, and configured actions are applied to matching traffic. While these policy maps can be applied to interfaces in both input and output directions to match ingress and egress traffic respectively, this feature specifically adds support for applying output policy maps to SVIs.

Synchronous Ethernet (SyncE) provides support for frequency synchronization over Ethernet between devices traceable to an external frequency reference, like a primary reference clock, as specified in ITU G.8261.

VLAN tagged MACsec refers to frames that have a VLAN tag between the MAC source address and the MACsec ethertype.  This VLAN tag is unencrypted (in the clear) so that intermediate devices between the MACsec endpoints can forward the MACsec frames based on this unencrypted VLAN tag.

Previously, when both “ipv6 nd proxy prefix connected” and VXLAN is configured for a VLAN interface, and the router received a Neighbor solicitation (NS) with an IPv6 address within the connected prefix of the router, the router replied with the interface physical (or virtual-router if VARP is configured) mac address as long as the NS is received on a local (front-panel) port. This feature extends the behavior to also include the NS received from the VXLAN tunnel.

This feature is used to add VXLAN support for local-proxy-arp, Previously, when both “ip local-proxy-arp” and VXLAN is configured for a VLAN interface, and the router received an ARP request with an IP address within the same subnet as the router, the router replied with the interface physical (or virtual-router if VARP is configured) mac address for requests that are received on a local (front-panel) port. This feature extends the behavior to include the VXLAN tunneled ARP requests.

BGP TOI BMP EOS 4.36.2F

Wildcard-AS route target import for MAC VRFs enables simplified route target configuration in EVPN VXLAN deployments. When importing routes into MAC VRFs (VLAN-based or VLAN-aware-bundle), the Autonomous System (AS) portion of the route target can be replaced with a wildcard, so that only the Local Administrator value is compared during route target matching.

BGP TOI EOS 4.36.2F

WRED ( Weighted Random Early Detection ) is one of the congestion management techniques. It works at queue level to drop packets randomly after crossing the given queue threshold even before the queue is full. Without WRED, all newly arriving packets get tail dropped once the queue is full, which creates TCP global synchronization issues. WRED helps to avoid TCP global synchronization.