Arista EOS TAP Aggregation: Build a Packet Broker - 夜莺博客

Arista EOS TAP Aggregation: Build a Packet Broker

An Arista switch in TAP aggregation mode is a packet broker: mirrored copies from multiple links enter tap ports, get filtered, tagged or truncated, and leave on tool ports to analyzers. The mode is exclusive — a switch in TAP aggregation stops being a normal VLAN switch, so it belongs in a dedicated visibility rack, not in your production core. This guide builds a working broker from an EOS CLI.

Enable TAP Aggregation Mode

configure terminal
tap aggregation
   mode exclusive

mode exclusive puts every non-configured port into error-disabled state so an accidental cable cannot leak traffic into a top-of-rack network. To keep selected ports usable (for example a PTP reference or an out-of-band management link), exempt them explicitly:

tap aggregation
   mode exclusive
   mode exclusive no-errdisable Ethernet48

Before entering the mode, save the running-config and schedule a maintenance window — the transition resets interfaces.

Classify Ports: tap and tool

interface Ethernet1
   description TAP-from-DMZ-FW
   switchport mode tap
!
interface Ethernet2-3
   description Analyzer-A-Bond0
   switchport mode tool

tap ports are ingress-only mirrors; tool ports are egress-only toward the analyzers. Never mix the two roles on one port.

Organise Traffic with Groups

interface Ethernet1
   switchport mode tap
   switchport tap default group Development
   switchport tap default group Production
!
interface Ethernet2-3
   switchport mode tool
   switchport tool group Development

One tap port can feed several groups and one group can feed several tool ports, which is how you fan a single span out to two analyzers without duplicating the SPAN session upstream.

Trim the Traffic Before It Reaches the Analyzer

interface Ethernet1
   switchport tap truncation 128
!
interface Ethernet2
   switchport tool strip vlan
!
interface Ethernet2
   switchport tool truncation 96

truncation 128 keeps only the first 128 bytes of each frame — perfect for header analytics, and it multiplies the effective capacity of your tool ports. strip vlan removes the outer tag so an analyzer cannot accidentally bridge your production VLANs.

Filter Traffic with ACLs on Tap Ports

ip access-list TAP-ONLY-HTTP
   10 permit tcp any any eq 80
!
interface Ethernet1
   switchport mode tap
   ip access-group TAP-ONLY-HTTP in

Apply the ACL inbound on the tap port so only the traffic you paid for consumes analyzer CPU.

Feed Timestamps to the Analyzer with PTP

ptp mode boundary
ptp source ip 1.2.3.4
!
interface Ethernet48
   ptp enable

Boundary-clock PTP gives the capture accurate timestamps, which is the difference between correlating an incident and guessing at it.

Verification

show tap aggregation
show tap aggregation groups
show interfaces status
show interfaces counters rates

Watch for errdisabled ports after entering exclusive mode — any interface you did not explicitly configure stays down by design, and show tap aggregation tells you whether a group has tap input but no tool output, which is the signature of a missing group membership.

Practical Limits

  • TAP aggregation is a platform feature — confirm support on your SKU before the maintenance window.
  • Copying a 40G stream to a single 10G tool port silently drops; size the tool side for the worst-case burst, not the average.
  • Truncation happens after ACL evaluation, so a filter that matches on payload bytes beyond the truncation point will not work as expected.

Related Reading

Deeper dives on the same topics from our archive:

原文链接:https://arista.my.site.com/AristaCommunity/s/article/danz-tap-aggregation-configuration-getting-started