- Written by Lavanya Conjeevaram
- Posted on 3月 31, 2017
- Updated on 7月 23, 2025
- 21259 Views
Ethernet VPN (EVPN) is an extension of the BGP protocol introducing a new address family: L2VPN (address family number 25) / EVPN (subsequent address family number 70). It is used to exchange overlay MAC and IP address reachability information between BGP peers within a tunnel
- Written by Lavanya Conjeevaram
- Posted on 12月 22, 2017
- Updated on 9月 5, 2025
- 16409 Views
In the traditional data center design, inter-subnet forwarding is provided by a centralized router, where traffic traverses across the network to a centralized routing node and back again to its final destination. In a large multi-tenant data center environment this operational model can lead to inefficient use of bandwidth and sub-optimal forwarding.
- Written by Chris Hydon
- Posted on 9月 24, 2026
- Updated on 9月 24, 2026
- 177 Views
EVPN Integrated Routing and Bridging (IRB) is a component of BGP EVPN that allows EVPN tunnel endpoints to advertise host routes. IP mobility further extends this capability by providing a means to resolve conflicts in the event that a host IP address moves between physical MAC addresses. IP duplicate detection determines when a host is rapidly moving between two or more MAC addresses and signals the event with a log message, optionally preventing the misbehaving host IP address from being advertised by EVPN.
- Written by Jeff Wen
- Posted on 1月 21, 2019
- Updated on 9月 12, 2025
- 16845 Views
In the traditional data center design, inter-subnet forwarding is provided by a centralized router, where traffic traverses across the network to a centralized routing node and back again to its final destination. In a large multi-tenant data center environment this operational model can lead to inefficient use of bandwidth and sub-optimal forwarding.
- Written by Jeffrey Nelson
- Posted on 10月 28, 2020
- Updated on 8月 5, 2026
- 31223 Views
This feature adds control plane support for inter-subnet forwarding between EVPN networks. This support is achieved by advertising received EVPN IP Prefix routes (Type-5) with next-hop self. VXLAN and MPLS encapsulation are supported, and the encapsulation type used for advertised routes is dependent on the encapsulation type configured for EVPN peering. The following diagram shows an example topology where an EVPN VXLAN network exchanges Type-5 routes with an EVPN MPLS network.
- Written by May Young
- Posted on 6月 24, 2021
- Updated on 3月 9, 2026
- 18522 Views
This feature is available when configuring Layer2 EVPN or EVPN IRB.As described in RFC7432 section 15 [1], “MAC Mobility” or “MAC move” occurs when a Customer Edge (CE) moves from one Ethernet segment to another, resulting in two EVPN MAC/IP (Type 2) routes being advertised -- one route with the previous Ethernet segment ID (ESI) and the other with the new Ethernet segment ID. MAC mobility also happens when a CE moves from a single-homed provider edge (PE) to a different PE.
- Written by Alton Lo
- Posted on 1月 23, 2019
- Updated on 2月 18, 2026
- 22739 Views
“MLAG Domain Shared Router MAC” is a new mechanism to introduce a new router MAC to be used for MLAG TOR Leaf pairs. The user can either explicitly configure the MAC address of their choice or use the system-generated MLAG system-id for this purpose.
- Written by Wade Carpenter
- Posted on 4月 24, 2020
- Updated on 3月 19, 2025
- 26373 Views
EVPN MPLS VPWS (RFC 8214) provides the ability to forward customer traffic to / from a given attachment circuit (AC) without any MAC lookup / learning. The basic advantage of VPWS over an L2 EVPN is the reduced control plane signalling due to not exchanging MAC address information. In contrast to LDP pseudowires, EVPN MPLS VPWS uses BGP for signalling. Port based and VLAN based services are supported.
- Written by Ayush
- Posted on 1月 31, 2024
- Updated on 4月 1, 2026
- 9979 Views
In network deployments, where the border leaf or Superspine act as PEG and it is in the transit path to other multicast VTEPs, the multicast stream will not pass since the border leaf will decapsulate the packet even if it doesn't have a receiver. This transit node is called the Bud Node. The device should be able to send decapsulated packets to any local receivers as well as send the encapsulated packets to other VTEPs
- Written by Alton Lo
- Posted on 12月 24, 2024
- Updated on 12月 24, 2024
- 6853 Views
Multihoming in EVPN allows a single customer edge (CE) to connect to multiple provider edges (PE or tunnel endpoint). These PE devices are all connected to the same Ethernet-Segment (ES). Multihoming is activated by assigning a unique Ethernet Segment Identifier (ESI) and ES-Import Route Target (RT) which enables all the PEs connected to the same multihomed site to import the Type 4 ES routes
- Written by Chris Hydon
- Posted on 10月 20, 2022
- Updated on 1月 30, 2026
- 14553 Views
In EVPN, an overlay index is a field in type-5 IP Prefix routes that indicates that they should resolve indirectly rather than using resolution information contained in the type-5 route itself. Depending on the type of overlay index, this resolution information may come from type-1 auto discovery or type-2 MAC+IP routes. For this feature the gateway IP address field of the type-5 NLRI is used as the overlay index, which matches the target IPv4 / IPv6 address in the type-2 NLRI. Other types of overlay index are described in RFC9136, but these are currently unsupported.
- Written by Xuan Qi
- Posted on 3月 13, 2020
- Updated on 3月 13, 2020
- 16790 Views
In EOS 4.22.0F, EVPN VXLAN all active multi homing L2 support is available. A customer edge (CE) device can connect to
- Written by Chris Hydon
- Posted on 6月 17, 2019
- Updated on 4月 27, 2026
- 33605 Views
Ethernet VPN (EVPN) networks normally require some measure of redundancy to reduce or eliminate the impact of outages and maintenance. RFC7432 describes four types of route to be exchanged through EVPN, with a built-in multihoming mechanism for redundancy. Prior to EOS 4.22.0F, MLAG was available as a redundancy option for EVPN with VXLAN, but not multihoming. EVPN multihoming is a multi-vendor standards-based redundancy solution that does not require a dedicated peer link and allows for more flexible configurations than MLAG, supporting peering on a per interface level rather than a per device level. It also supports a mass withdrawal mechanism to minimize traffic loss when a link goes down.
- Written by Xuan Qi
- Posted on 10月 20, 2022
- Updated on 7月 23, 2026
- 17497 Views
EVPN gateway support for all-active (A-A) multihoming adds a new redundancy model to our multi-domain EVPN solution. This deployment model introduces the concept of a WAN Interconnect Ethernet Segment identifier (WAN I-ESI).
- Written by Omar Jamil
- Posted on 8月 19, 2025
- Updated on 8月 19, 2025
- 2738 Views
The EVPN Gateway Data Center Interconnect (DCI) feature supports multihoming redundancy. This deployment model leverages a virtual Interconnect Ethernet Segment Identifier (I-ESI) to form an overlay ECMP across the EVPN DCI gateways. Recently, EOS added new features for managing the I-ES that improve traffic handling and convergence in certain failure scenarios:
- Written by Gokhan Tanisik
- Posted on 4月 25, 2025
- Updated on 4月 25, 2025
- 6088 Views
This feature adds the ability for an L3 default gateway TEP in a Centralized Gateway topology to advertise its SVI virtual IP addresses to VARP MAC bindings and primary addresses to System MAC bindings using EVPN type-2 routes for EVPN VXLAN overlays. Two new commands, redistribute router-mac virtual-ip[next-hop vtep primary] and redistribute router-mac system ip are introduced to enable the redistributions. This would help the L2 TEP on the network to learn the default gateway IP without flooding an ARP request for the gateway IP. This feature is only intended for Centralized Gateway Topologies.
- Written by Pavan Narasimhaprasad
- Posted on 8月 19, 2025
- Updated on 7月 7, 2026
- 3599 Views
Smart System Upgrade (SSU) provides the ability to upgrade the EOS image with minimal traffic disruption. SSU is supported on a standalone L2 only VTEP with EVPN-VXLAN configuration with the following scale is supported as of EOS 4.32.0F with the following scale numbers
- Written by Mitchell Jameson
- Posted on 8月 24, 2020
- Updated on 6月 30, 2026
- 14835 Views
Typical WiFi networks utilize a single, central Wireless LAN Controller (WLC) to act as a gateway between the wireless APs and the wired network. Arista differentiates itself by allowing the wireless network to utilize a distributed set of aggregation switches to connect APs to the wired network. This feature allows a decentralized and distributed set of aggregation switches to bridge wireless traffic on behalf of the set of APs configured to VXLAN tunnel all traffic to those aggregation switches, or their “local” APs.
- Written by Srilekha Nune
- Posted on 9月 22, 2025
- Updated on 9月 22, 2025
- 2226 Views
If any two policies use the same filter interface and the same priority, then an additional dynamic policy will be created to ensure the delivery of packets matching both of the original policies. There is a limit on how many overlap policies can be created and it is configurable with a range between 0 to 10 with a default value of 4. Currently, we exclude policies configured as inactive in the overlap policy limit calculation. With this new feature, we exclude policies that have an expired duration from the overlap policies limit calculation.
- Written by Kenneth Cheung
- Posted on 11月 22, 2017
- Updated on 9月 24, 2026
- 13477 Views
EOS-4.20.0F introduces expanded VRRP, VARP and MLAG Peer Gateway virtual MAC capabilities on the 7500R*/7280R*/7020R series because of improved hardware capabilities. Simultaneous support for VRRP, VARP and MLAG Peer Gateway. VARP and MLAG Peer Gateway take priority over VRRP.
- Written by Deva Pandian
- Posted on 2月 8, 2017
- Updated on 2月 5, 2022
- 11945 Views
This enhancement is to display the number of packets that were ECN (Explicit Congestion Notification) marked by the
- Written by Pauric Ward
- Posted on 3月 13, 2024
- Updated on 3月 10, 2025
- 8675 Views
Administrative Groups (AG) provide a way to associate certain attributes or policies with links, enabling network administrators to control the routing decisions based on specific criteria. Extended Administrative Groups (EAG) are an extension of AG which allow a larger range of admin groups to be utilized for various Traffic Engineering (TE) purposes within a network. EAGs are defined in a new sub-TLV for IS-IS link attributes, separate to AGs, however they are considered as one within EOS. The EAG feature in EOS allows the range of administrative color to be increased from 0-31 to 0-127.
- Written by Julie Powell
- Posted on 7月 25, 2024
- Updated on 7月 25, 2024
- 6280 Views
Use an External Certification Authority (ECA) to ensure secure communication and authentication with CloudVision..By default, Streaming Agent and other applications communicate with CloudVision using mutual-TLS certificates signed by a local certificate authority (CA). You now have the option to integrate CloudVision with Venafi, an external CA, to sign and verify these certificates.
- Written by Venkatesh Janakiraman
- Posted on 4月 10, 2015
- Updated on 2月 5, 2022
- 11126 Views
Starting EOS 4.15.0F, EOS can monitor (for long durations) low error rate errors on all fabric links. It
- Written by Anoop Dawani
- Posted on 9月 30, 2015
- Updated on 9月 30, 2015
- 11424 Views
The 7250X and 7300 series use an optimized internal CLOS design with multiple port ASICs interconnected via Fabric
- Written by Dhruba Jyoti Pokhrel
- Posted on 12月 16, 2024
- Updated on 12月 16, 2024
- 4551 Views
With the 18.0 release, Access Points (AP) can also use LAN2 as the Uplink Port. If both the LAN Ports are available as Uplink, the AP monitors both ports equally. Only on the first AP boot will AP consider LAN1 as the default Uplink, and LAN2 will be the failover. If LAN1 and LAN2 are connected and LAN1 fails to receive any packets, the AP can fail over to LAN2 as the Uplink Port and will continue to operate on the same uplink even if LAN1 is active again.
- Written by Dhruba Jyoti Pokhrel
- Posted on 5月 12, 2025
- Updated on 5月 14, 2025
- 3239 Views
With the 19.0 release, Access Points (AP) can seamlessly switch between LAN 1 and LAN 2 as the Uplink Port without disturbing the client connectivity and without any reboot. For the list of enhancements done for the same feature in the previous release, see the 18.0 TOI.
- Written by Shyam Kota
- Posted on 6月 13, 2019
- Updated on 3月 25, 2026
- 15075 Views
Fair Adaptive Dynamic thresholds (FADT) provides efficient allocation of shared packet buffer resources amongst various virtual output queues. FADT is useful when queues are getting congested and buffer resources should be allocated in a way tdat prioritizes certain queues while avoiding starvation of lower priority queues. the scheme works on each incoming packet by calculating instantaneous queue threshold based on available free resources. Queue buffer threshold is calculated as:
- Written by Muhammad Yousuf
- Posted on 4月 18, 2015
- Updated on 2月 5, 2022
- 11686 Views
The 7280E and 7500E series are Virtual Output Queues (VOQs) based multi chip systems where there is a VOQ for all the
- Written by Prasanth Sasidharan
- Posted on 9月 30, 2015
- Updated on 2月 8, 2022
- 11080 Views
Fallback PBR policy enables an alternate policy to be active when PBR policy attached to an interface is being
- Written by Rick Porter
- Posted on 6月 29, 2020
- Updated on 8月 8, 2025
- 13177 Views
Fast poll counters allow for rapid collection of a basic set of MAC counters on supported platforms at a very high frequency.
- Written by Ishwar Govind
- Posted on 7月 2, 2025
- Updated on 8月 25, 2025
- 3284 Views
This feature is to permit rapid restoration of outbound traffic on ECMP groups that have a mix of ports from Supervisor1(Linecard1) and Supervisor2(Linecard2) cards. In the context of the supported platforms, these are referred to as Uplink ports and have names starting with Eth1/ or Ethernet1/ (Linecard1) and Eth2 or Ethernet2/ (Linecard2).
- Written by Deepjyoti Kakati
- Posted on 7月 15, 2025
- Updated on 7月 17, 2025
- 2966 Views
This feature is to permit rapid restoration of outbound traffic on LAG (port-channel) groups that have a mix of ports from Supervisor1(Linecard1) and Supervisor2(Linecard2) cards. In the context of the supported platforms, these are referred to as Uplink ports and have names starting with Eth1/ or Ethernet1/ (Linecard1) and Eth2 or Ethernet2/ (Linecard2).
- Written by Jack Zhou
- Posted on 9月 29, 2026
- Updated on 9月 29, 2026
- 104 Views
This feature provides the functionality to bypass error indication to the PCS layer when Forward Error Correction (FEC) is in operation for an interface. Depending on the PHY implementation, there can be one or multiple FEC decoders when an error correction encoding is in use. Upon receiving a codeword, FEC decoders will attempt to test and see if the codeword can be decoded. If there were errors in the codeword
- Written by Sujit Kumar Sah
- Posted on 2月 6, 2024
- Updated on 3月 23, 2026
- 8772 Views
This document describes the Fec Dampening feature. When hardware FEC / ECMP resources usage go above the platform limit, Ale (HW Abstraction layer ) deletes some routes in the anticipation of freeing up some more hardware FEC resources to allow newly created FEC to get programmed. The above logic of deleting/unprogramming the route may lead to unnecessary traffic drop in the following cases of transient FEC resources overflow.
- Written by Evelyn Wang
- Posted on 3月 5, 2020
- Updated on 10月 16, 2025
- 16197 Views
The FEC (Forward Error Correction) traffic analyzer is designed to estimate the performance of the FEC layer, identify error statistics, and the source of correlated errors on physical interfaces.
- Written by Prachi Modi
- Posted on 7月 16, 2024
- Updated on 7月 16, 2024
- 5743 Views
In the 17.0 release, CV-CUE introduces FEED. FEED is a network dashboard that presents a timeline view of all the detected anomalies in the network. CV-CUE curates the FEED by continuously monitoring and proactively detecting anomalies in the network. It also analyzes the cause of the anomaly and provides dynamic suggestions to mitigate the issue. The administrator can analyze the issue, the AI-based recommended action, and then decide on the best approach to mitigate the issue. Feed also lets administrators go back in time and understand anomalies that occurred in the past.
- Written by Gaofeng Yue
- Posted on 1月 23, 2019
- Updated on 3月 26, 2025
- 15447 Views
FIB compression allows us to program routes into the hardware more efficiently. Routes are programmed in the route
- Written by Forhad Ahmed
- Posted on 7月 15, 2025
- Updated on 9月 11, 2026
- 3045 Views
This feature introduces a per-VRF table "FIB route count" for hardware FIB tables, and associated actions to. The "FIB route count" for a VRF table includes FIB routes from most protocol sources (e.g., BGP, IGP, static) in each VRF and address-family (IPv4 and IPv6). Once a VRF table's FIB route count reaches a configured limit, routes can be suppressed or evicted based on the configured action.
- Written by Monisha Chinta
- Posted on 3月 13, 2026
- Updated on 3月 17, 2026
- 825 Views
The Filter managed service action filters packets on the Service Node (SN) interface and supports optional VLAN tagging. Utilizing ACL rules, the system forwards or drops matched traffic. Traffic tagged with a VLAN exits the interface (Tx) after processing through the action chain. VLAN tagging specifically facilitates traffic steering in Switch-less SN deployments, where the forwarding plane relies on VLANs. This configuration produces no functional impact when the SN connects directly to a DMF switch within the fabric.
- Written by Stefan Kheraj
- Posted on 4月 18, 2024
- Updated on 5月 29, 2026
- 12049 Views
Filtered mirroring allows certain packets to be selected for mirroring, rather than all packets ingressing or egressing a mirror source port.
- Written by Lavanya Conjeevaram
- Posted on 6月 6, 2017
- Updated on 12月 22, 2017
- 12729 Views
MPLSoGRE Filtered Mirroring is a specialized version of Mirroring to GRE Tunnel and Filtered Mirroring in which
- Written by Sushmitha Guruprasad
- Posted on 6月 19, 2022
- Updated on 7月 28, 2025
- 11930 Views
Directed broadcast ACL allows inbound broadcast IP packets with source IP address as one of the permitted hosts and denies the rest of the directed broadcast traffic. Destination broadcast address of the IP packet should be the broadcast address of an interface with directed broadcast enabled. This feature gives a global command to configure sets of the permitted hosts via field-set.
- Written by Prachi Modi
- Posted on 5月 8, 2025
- Updated on 5月 8, 2025
- 3133 Views
With the 19.0 release, you can apply filters to report data before generating or scheduling a report. Previously, you manually filtered out the relevant data from the generated report. Applying filters before generating a report helps streamline the data, speeds up report generation, and improves its readability. With filters, you can create a customized report based on your specific needs.
- Written by Dhruba Jyoti Pokhrel
- Posted on 7月 16, 2024
- Updated on 7月 16, 2024
- 5783 Views
Organizations may have multiple access points (APs) of different models operating with various firmware versions. As an organization, you may want to designate a specific version as a compliant firmware version for a certain model. Assigning a compliant firmware version helps network administrators identify non-compliant AP models by generating notification alerts.
- Written by Baptiste Covolato
- Posted on 4月 1, 2026
- Updated on 4月 1, 2026
- 999 Views
Systems with support for Arista secure boot protect against tampering of the BIOS firmware & Aboot by write-protecting the BIOS SPI flash before EOS is loaded (refer to the “Security model” section in the secure boot TOI for details). While effective at protecting against unauthorized changes made from EOS, such a mechanism has limitations. For example, it is ineffective at protecting against physical reprogramming of the contents of the BIOS SPI flash, tampering through privileged serial console access, undiscovered security vulnerabilities in BIOS upgrade mechanism, etc.
- Written by Mattar Amith Kini
- Posted on 12月 27, 2024
- Updated on 12月 27, 2024
- 4894 Views
This document describes the CLI introduced to reallocate ECMP FEC banks on different levels in a hierarchical FEC configuration. Users may run out of entries on a certain level with other levels having little to no usage, and this CLI reconfigures the ECMP FEC entries to meet the requirements of the user.
- Written by Karthikeyan Kathiresan
- Posted on 4月 19, 2021
- Updated on 8月 5, 2025
- 9114 Views
Disabling the flooding of broadcast, multicast, and unknown unicast traffic into the VXLAN fabric can significantly reduce bandwidth consumption in the VXLAN underlay. This is particularly beneficial in use cases where such traffic is unnecessary. This feature, exclusively supported with EVPN, allows for the selective flooding of ARP and/or ND traffic, offering further control over bandwidth usage.
- Written by Prachi Modi
- Posted on 1月 17, 2024
- Updated on 1月 17, 2024
- 7660 Views
With the 16.0 release, CloudVision Cognitive Unified Edge (CV-CUE) introduces the following enhancements to Floor Plans:
- Written by Manvendra Pratap Singh
- Posted on 6月 26, 2026
- Updated on 6月 26, 2026
- 596 Views
Control Plane Policing (CoPP) classifies control plane traffic into different classes (e.g., IGMP, LLDP, PTP, OSPF) and applies rate limiting per class using queues shaping. However, when multiple flows within the same CoPP class share a single queue, a single high-rate flow can consume the entire allocated bandwidth for that class, starving other legitimate flows.
