- Written by Jing Wu
- Posted on 4月 24, 2025
- Updated on 4月 29, 2025
- 3328 Views
This document describes managing certificates and private keys in DMF.
- Written by Preyas Hathi
- Posted on 6月 2, 2022
- Updated on 6月 2, 2022
- 10014 Views
A server cluster or a cluster is a group of Wireless Manager (WM) servers. A cluster comprises a parent WM server and one or more child WM servers. A cluster is created to manage multiple servers using a single server.
- Written by Anurag Chowdhary
- Posted on 3月 18, 2026
- Updated on 3月 18, 2026
- 617 Views
Beginning with DMF version 8.9, the action keyword is required to add or modify actions within a managed service. This keyword is a mandatory token across all managed service submodes, providing a consistent way to define service behaviors.
- Written by Harry Dhillon
- Posted on 3月 18, 2026
- Updated on 3月 18, 2026
- 611 Views
DMF 8.9 introduces a redesigned Managed Services dashboard, replacing the former interface.
- Written by Joseph Walsh
- Posted on 10月 24, 2024
- Updated on 10月 24, 2024
- 4861 Views
The Management Connectivity Studio is used to configure out-of-band (OOB) management interfaces. You’ll create a profile of configured attributes for management interfaces, which can be assigned to multiple devices at once using tags.
- Written by Siddarth Karki
- Posted on 7月 14, 2026
- Updated on 7月 14, 2026
- 207 Views
Container-based deployments make creating cloud portable applications extremely easy. An application can be written on normal build infrastructure, that in turn can be run on a EOS switch or any Linux device that runs docker run time engine. So the same applications that are run on a server for microservices can be run on a switch with Arista EOS. Since Arista extensible operating system is simply linux (AlmaLinux 9.7 at this time – 2026) we are able to integrate a container runtime engine into the operating system.
- Written by Eric Lanini
- Posted on 10月 29, 2025
- Updated on 11月 13, 2025
- 1999 Views
In general, EOS always configures the PHYs to have the correct polarity to match that of the standard, such that if a standard compliant transceiver is plugged in and the peer is standard compliant everything will work.
- Written by Navneet Sinha
- Posted on 6月 29, 2016
- Updated on 2月 8, 2022
- 11410 Views
MapReduce Tracer is an existing feature that monitors MapReduce nodes that are directly connected to Arista
- Written by Nishant Kumar
- Posted on 3月 13, 2026
- Updated on 3月 13, 2026
- 615 Views
The Mask Dual-tone Multi-Frequency (DTMF) in Real-time Transport Protocol (RTP) feature supports masking digits in voice data to hide sensitive information, such as credit card or social security numbers. Masking of sensitive data is a compliance issue that various agencies require to obfuscate information before storage.
- Written by Sunil Kumar
- Posted on 5月 5, 2025
- Updated on 5月 5, 2025
- 3237 Views
In DMF 8.7.0, the redesigned integration configuration now masks the password field and improves the configuration management. Use the Edit icon to Add, Modify, or Delete the Integration configuration.
- Written by Digvijay Gahlot
- Posted on 12月 22, 2017
- Updated on 12月 22, 2017
- 10902 Views
Classification of MPLS packets based on traffic class bits in MPLS header for QoS Policy Maps. DCS
- Written by Paul McDade
- Posted on 3月 13, 2026
- Updated on 6月 18, 2026
- 748 Views
As of DMF-8.9.0, when several IP addresses are used in a single policy (whether via an address group or individually across match rules with otherwise identical conditions), the controller groups the addresses together and programs them as a field set on supported switches. This field set has a label that can be directly referenced by TCAM, which allows that TCAM entry to match against packets with any of the IP prefixes in that field set. This optimization dramatically reduces the TCAM consumption for policies that reference many addresses, allowing significantly more policies or addresses to be programmed without exceeding switch TCAM capacity limits. For example, on a switch incapable of performing this optimization, a policy matching traffic from a 100-entry source address group to a 100-entry destination address group would require 100x100=10,000 individual entries. With this optimization, the controller programs two field sets and a single match rule that references both field sets, reducing TCAM consumption from 10,000 entries to just 1 entry for that policy.
- Written by Yashvir Singh
- Posted on 3月 2, 2021
- Updated on 5月 9, 2025
- 14920 Views
This feature allows classification of packets on QoS policy-maps based on the Class of Service (CoS), VLAN, Drop Eligible Indicator (DEI) in the 802.1q header of the packet. CoS (Class of Service) corresponds to the Priority code point (PCP) bits in the 802.1q header.
- Written by Shyam Kota
- Posted on 11月 6, 2019
- Updated on 1月 27, 2026
- 14828 Views
This feature allows setting the desired maximum VOQ latency. Drop probabilities are adjusted in hardware to meet this limit.
- Written by Navneet Sinha
- Posted on 6月 29, 2016
- Updated on 6月 29, 2016
- 11623 Views
Currently, the 'maximum routes' knob allows one to set an upper bound on the number of routes that can be received from a
- Written by Ioana Costea
- Posted on 11月 9, 2020
- Updated on 4月 11, 2025
- 11353 Views
Previously, the maximum valid port channel ID was equal to the maximum number of port channels configurable on the
- Written by Can Sun
- Posted on 8月 12, 2025
- Updated on 6月 23, 2026
- 2782 Views
Measured boot is a tamper-detection mechanism that records a system's boot process. It calculates cryptographic hashes of system components and configurations, which are then securely stored in the Platform Configuration Registers (PCRs) of a Trusted Platform Module (TPM) chip. This process creates a secure "hash chain" of the boot sequence. After the system starts, the TPM Quote operation, along with the PCR extension records, can be used to verify the PCR values, confirming that the system components are unchanged and the software is trusted.
- Written by Can Sun
- Posted on 12月 20, 2024
- Updated on 12月 20, 2024
- 4740 Views
Measured boot is an anti-tamper mechanism. It calculates the cryptographic signatures for software system components and extends the signatures into the Trusted Platform Module (TPM) security chip. Upon startup, with the feature turned on, the Aboot bootloader and EOS calculate the hash of various system components and extend the hashes into the Platform Configuration Registers (PCRs), which is one of the resources of the Trusted Platform Module (TPM) security chip. The calculation and extension event is called the measured boot event, and the event is associated with a revision number to help the user identify changes to the event.
- Written by Mihyar Baroudi
- Posted on 2月 1, 2016
- Updated on 3月 4, 2022
- 19937 Views
Media Access Control Security (MACSec) is an industry standard encryption mechanism to protect all traffic flowing
- Written by Alejandro Schwoykoski
- Posted on 12月 22, 2021
- Updated on 6月 1, 2026
- 21185 Views
MetaMux is an FPGA-based feature available on Arista’s 7130 platforms. It performs ultra-low latency Ethernet packet multiplexing with or without packet contention queuing. The port to port latency is a function of the selected MetaMux profile, front panel ingress port, front panel egress port, FPGA connector ingress port, and platform being used.
- Written by David Mirabito
- Posted on 12月 30, 2021
- Updated on 7月 1, 2026
- 32845 Views
MetaWatch is an FPGA-based feature available for Arista 7130 Series platforms. It provides precise timestamping of packets, aggregation and deep buffering for Ethernet links. Timestamp information and other metadata such as device and port identifiers are appended to the end of the packet as a trailer.
- Written by Julie Powell
- Posted on 11月 4, 2024
- Updated on 11月 4, 2024
- 5529 Views
CloudVision provides support for microperimeter segmentation and enforcement as part of Arista’s Multi-Domain Segmentation Service (MSS) for Zero Trust Networking (ZTN).
ZTN works to reduce lateral movement into increasingly smaller areas where workloads are granularly identified and only approved connections are permitted.
- Written by Abdul Haseeb Jehangir
- Posted on 3月 12, 2020
- Updated on 5月 5, 2026
- 19301 Views
Mirror on drop is a network visibility feature which allows monitoring of MPLS or IP flow drops occurring in the ingress pipeline. When such a drop is detected, it is sent to the control plane where it is processed and then sent to configured collectors. Additionally, CLI show commands provide general and detailed statistics and status.
- Written by Anurag Mishra
- Posted on 1月 22, 2019
- Updated on 12月 17, 2024
- 11136 Views
This feature allows a user to configure a mirror session with subinterface sources from the CLI. This feature is only available with ingress mirroring (rx direction)
- Written by Charlotte Fedderly
- Posted on 4月 22, 2024
- Updated on 5月 25, 2026
- 7939 Views
On supported devices, a port-channel can be configured as a mirroring destination for both ingress and egress source directions. Traffic mirrored to a port-channel is load-balanced based on the global port-channel load-balance configuration, which is the same for other port-channels.
- Written by Adrian Fettes
- Posted on 4月 22, 2024
- Updated on 5月 25, 2026
- 7589 Views
An interface may be a source for both a mirroring session and sFlow at the same time. For more information about mirroring and ingress and egress sFlow look in the Resources section below.
- Written by Sabah Khan
- Posted on 7月 25, 2024
- Updated on 7月 25, 2024
- 5750 Views
Port mirroring allows you to duplicate ethernet packets or frames on a source interface to send to a remote host, like DANZ Monitoring Fabric (DMF). The mirrored packets or frames can be sent via a SPAN interface dedicated for communication with the host or over an L2 Generic Routing Encapsulation (L2GRE) tunnel.
- Written by Kevin Amiraux
- Posted on 9月 30, 2015
- Updated on 5月 29, 2026
- 26080 Views
Arista switches provide several mirroring features. Filtered mirroring to CPU adds a special destination to the mirroring features that allows the mirrored traffic to be sent to the switch supervisor. The traffic can then be monitored and analyzed locally without the need of a remote port analyzer. Use case of this feature is for debugging and troubleshooting purposes.
- Written by Johnny Chen
- Posted on 9月 15, 2023
- Updated on 4月 13, 2026
- 10536 Views
For traffic mirroring, Arista switches support several types of mirroring destinations. This document describes a new type of mirroring destination in which mirrored traffic is tunneled over VXLAN as the inner packet to a remote VTEP. This feature is useful for when the traffic analyzer is a VTEP reachable over a VXLAN tunnel.
- Written by Dickson Chum
- Posted on 4月 18, 2024
- Updated on 5月 29, 2026
- 7786 Views
Mirrored packets may be configured to be truncated per mirroring session.
- Written by Robert Ling
- Posted on 5月 2, 2025
- Updated on 5月 2, 2025
- 3240 Views
DMF 8.7.0 introduces an updated dashboard for viewing sFlow drops. The DMF analytics Node (AN) displays reasons for dropped packets as a Mirror on Drop (MOD) drop Flow sFlow collector by analyzing overall drops and drops by flow.
- Written by Shamit Kapadia
- Posted on 9月 30, 2015
- Updated on 6月 10, 2026
- 16584 Views
In an MLAG setup, routing on a switch (MLAG peer) is possible using its own bridge/system MAC, VARP MAC or VRRP MAC. When a peer receives an IP packet with destination MAC set to one of the aforementioned MACs, the packet gets routed if the hardware has enough information to route the packet. Before introducing this feature, if the destination MAC is peer’s bridge MAC, the packet is L2 bridged on the peer-link and the routing takes place on the peer. This behavior to use the peer-link to bridge the L3 traffic to the peer is undesirable especially when the MLAG peers can route the packets themselves.
- Written by Som Neema
- Posted on 9月 30, 2015
- Updated on 9月 30, 2015
- 14199 Views
MLAG currently checks for basic MLAG configuration to be consistent (e.g. domain id) before formation with the peer.
- Written by Tarun Soin
- Posted on 2月 15, 2018
- Updated on 7月 11, 2019
- 14736 Views
When MLAG peer link goes down, the secondary peer assumes the primary peer is down/dead, and takes over the primary
- Written by Navneet Sinha
- Posted on 6月 29, 2016
- Updated on 11月 17, 2016
- 11634 Views
In an MLAG setup, periodic TCP/UDP heartbeats are sent over peer link to ensure IP connectivity between peers. Prior
- Written by Ryan Megathlin
- Posted on 9月 12, 2024
- Updated on 12月 20, 2024
- 5900 Views
This feature allows users to configure L2 subinterfaces on MLAG interfaces. L2 subinterfaces are not supported on the MLAG peer-link.
- Written by Shyam Kota
- Posted on 6月 13, 2019
- Updated on 8月 4, 2025
- 20016 Views
The objective of Maintenance Mode on MLAG is to gracefully drain away the traffic (L2 and BGP) flowing through a switch
- Written by Prakhar Rastogi
- Posted on 4月 23, 2018
- Updated on 8月 6, 2026
- 14756 Views
MLAG Smart System Upgrade (SSU) provides the ability to upgrade the EOS image of an MLAG switch with minimal traffic disruption.
- Written by Ravikumar Chandrasekaran
- Posted on 3月 21, 2025
- Updated on 3月 21, 2025
- 3824 Views
MLAG will support the following features Bridging, Routing, STP, VARP
- Written by Hemanth Murthy
- Posted on 2月 8, 2017
- Updated on 12月 17, 2020
- 13584 Views
If an MLAG flaps on one peer, then we may have to remap the MAC addresses learned, such that the reachability is via the
- Written by Kenneth Cheung
- Posted on 6月 4, 2020
- Updated on 6月 19, 2025
- 14267 Views
On a MLAG chassis, MAC addresses learned on individual peers are synced and appropriate interfaces are mapped to these MAC addresses. In case of unexpected events like reloading of one of the peers in the MLAG chassis or flapping of one or more MLAG interfaces, some loss of traffic may be observed.
- Written by Kartic Bhargav
- Posted on 11月 4, 2025
- Updated on 11月 4, 2025
- 6987 Views
For packets sent and received on the front-panel interfaces, this feature allows creation of a profile to configure buffer reservations in the MMU (MMU = Memory Management Unit which manages how the on-chip packet buffers are organized).
- Written by Sahil Midha
- Posted on 5月 14, 2015
- Updated on 7月 3, 2024
- 6898 Views
For packets sent and received on the front-panel interfaces, this feature allows creation of a profile to configure buffer reservations in the MMU (MMU = Memory Management Unit which manages how the on-chip packet buffers are organized). The profile can contain configurations for ingress and egress. On the ingress, configuration is supported at both a port level as well as a priority-group level.
- Written by Dhruba Jyoti Pokhrel
- Posted on 7月 21, 2026
- Updated on 7月 22, 2026
- 162 Views
Mobility Domain is a logical grouping of Access Points (AP) that allows APs to share clients' security credentials and operational keys with neighboring APs, enabling seamless, ultra-fast client roaming. In CV-CUE, you can create a mobility domain in the Inter AP Coordination section in the Network tab while configuring an SSID. CV-CUE assigns a mobility domain ID to each mobility domain name in its database.
- Written by Alphan Karacaer
- Posted on 2月 27, 2025
- Updated on 2月 27, 2025
- 3963 Views
The main objective of this feature is to prevent modular systems from being shut down due to insufficient power by powering off cards if there is not enough power in the system at card startup.
- Written by Travis Hammond
- Posted on 3月 6, 2020
- Updated on 5月 29, 2026
- 11400 Views
This feature allows the removal of a configurable number of leading bytes starting from the Ethernet layer of packets sent to a monitor session. A new per-monitor session CLI command is provided to configure this, up to a maximum of 90 bytes.
- Written by Prachi Modi
- Posted on 7月 16, 2024
- Updated on 7月 16, 2024
- 5599 Views
With the 17.0 release, you can view the Tunnel Status and Tunnel State of the standby VXLAN tunnel. Until now, you could only see the status of the tunnel being used. There was no way to know if your standby tunnel was reachable or not. With this release, you can view the Tunnel Status and the Tunnel State of your primary or secondary tunnel operating in the Standby Mode.
- Written by Siddarth Karki
- Posted on 3月 3, 2023
- Updated on 1月 16, 2026
- 11345 Views
From the 4.29.2F release of EOS, proactive probing of servers is supported. Using this feature Arista switches can continuously probe configured servers to check their liveliness and use the information obtained from these probes while sending out requests to the servers.
- Written by Lavanya Conjeevaram
- Posted on 11月 22, 2017
- Updated on 9月 4, 2019
- 12027 Views
The feature MP BGP Multicast provides a way to populate the MRIB (Multicast Routing Information Base). MRIB is an
- Written by Emil Maric
- Posted on 9月 18, 2024
- Updated on 9月 18, 2024
- 5293 Views
The intended purpose of this feature is to introduce a server streaming RPC. When a client subscribes to this RPC, they will receive a message anytime there is an update to the hardware programming state of an MPLS route or the Nexthop-Group to which it points to. Note that messages will only be streamed in this RPC callback for versioned MPLS routes that point to versioned nexthop-groups. Messages will not be streamed via this RPC for MPLS routes and Nexthop-Groups that don’t meet this criteria.
