Arista EOS Port-Specific VLAN Tagging: Access, Trunk, Native - 夜莺博客

Arista EOS Port-Specific VLAN Tagging: Access, Trunk, Native

“Port-specific tags” on Arista EOS is a fancy way of asking which VLAN a given port carries untagged and which VLANs it carries tagged. EOS answers that question with interface mode — access for exactly one untagged VLAN, trunk for a native untagged VLAN plus an explicit allowed list of tagged VLANs — and nothing about tagging works reliably until you verify it with the right show commands rather than by re-reading the config.

Access port: one untagged VLAN

switch# configure terminal
switch(config)# vlan 40
switch(config-vlan-40)# name ACCESS-SERVERS
switch(config)# interface Ethernet1
switch(config-if-Et1)# switchport mode access
switch(config-if-Et1)# switchport access vlan 40
switch(config-if-Et1)# no shutdown

Frames leave this port untagged; the VLAN is implied by the port configuration. Anything that arrives tagged is dropped unless it matches the access VLAN.

Trunk port: tagged VLANs plus a native VLAN

switch(config)# interface Ethernet2
switch(config-if-Et2)# switchport mode trunk
switch(config-if-Et2)# switchport trunk native vlan 999
switch(config-if-Et2)# switchport trunk allowed vlan 10,20,30,100

VLANs 10, 20, 30 and 100 cross the link tagged; untagged frames land in VLAN 999. Keep the allowed list explicit — the EOS default of “all” means a VLAN created for an unrelated purpose later rides this trunk without anyone deciding that it should.

Adding to an allowed list without blackholing traffic

switch(config-if-Et49)# switchport trunk allowed vlan add 50,60
switch(config-if-Et49)# switchport trunk allowed vlan remove 60

Omitting add replaces the entire list. That single missing keyword is one of the most common self-inflicted outages on EOS: every VLAN you did not retype stops forwarding at that instant.

Verification that actually proves tagging

switch# show interfaces Ethernet2 switchport
switch# show interfaces trunk
switch# show vlan brief
switch# show mac address-table vlan 20

show interfaces switchport reports administrative and operational mode, the access VLAN, the native VLAN and the allowed list. show interfaces trunk is authoritative when config looks correct but traffic does not flow — it lists VLANs allowed, VLANs active in spanning tree, and VLANs forwarding. Then prove data plane behaviour by MAC learning: if the expected MAC never appears in show mac address-table vlan 20, tagging is wrong no matter how clean the config looks.

Common tagging failures

  • Native VLAN mismatch between the two ends of a trunk — untagged traffic lands in different VLANs on each side.
  • Allowed list too restrictive — the trunk is up, the frames are silently dropped.
  • Far end expects access while the local port is trunk (or the reverse).
  • VLAN never created or left suspended — on EOS the VLAN database lives in running-config, so an unsaved VLAN disappears on reload.
  • Mirrored or breakout port configured instead of the intended interface.

Related reading: Arista EOS VLAN create, assign and verify, Arista EOS VLAN troubleshooting, Arista EOS private VLAN (PVLAN) configuration.

原文链接:https://techyorker.com/port-specific-tags-in-arista-3