Arista EOS VLAN Configuration Step by Step - 夜莺博客

Arista EOS VLAN Configuration Step by Step

Arista EOS follows a Cisco-like model for VLANs but differs in one detail that surprises nearly every engineer arriving from IOS: a VLAN interface (SVI) is not created by typing interface Vlan10, it is created with interface vlan 10 only after the VLAN exists, and on several platforms the SVI must be created explicitly before it will carry a routing address. This walkthrough builds a working VLAN from scratch - creation, port assignment, trunking, SVI, verification - on EOS 4.x syntax.

Step 1: create the VLANs

switch# configure terminal
switch(config)# vlan 10
switch(config-vlan-10)# name USERS
switch(config-vlan-10)# exit
switch(config)# vlan 20,30-32
switch(config-vlan-20,30-32)# name SERVERS
switch(config-vlan-20,30-32)# exit

EOS accepts comma-separated and ranged VLAN lists in a single vlan command, and an access port assignment also creates the VLAN implicitly:

switch(config)# interface Ethernet3
switch(config-if-Et3)# switchport access vlan 40

The implicit form is convenient but leaves the VLAN without a name and is easy to miss during an audit. Prefer explicit creation plus a show vlan check.

Step 2: assign access ports

switch(config)# interface Ethernet1-4
switch(config-if-Et1-4)# switchport mode access
switch(config-if-Et1-4)# switchport access vlan 10
switch(config-if-Et1-4)# spanning-tree portfast
switch(config-if-Et1-4)# exit

Note that switchport mode access is not strictly mandatory in EOS - setting an access VLAN is enough - but keeping the explicit mode makes the intent readable and prevents a later trunk configuration from being silently inherited.

Step 3: build the trunk to the distribution switch

switch(config)# interface Ethernet49-50
switch(config-if-Et49-50)# switchport mode trunk
switch(config-if-Et49-50)# switchport trunk native vlan 999
switch(config-if-Et49-50)# switchport trunk allowed vlan 10,20,30-32
switch(config-if-Et49-50)# exit

Two behaviours are worth calling out. First, a port in trunk mode allows all VLANs by default on EOS, so an allowed list is a restriction, not an extension - and using one flips the logic so that only the listed VLANs pass. Second, the native VLAN should match on both ends; the usual hardening choice is an unused VLAN ID (999 here) so that untagged frames never land in the user VLAN.

Port channels

switch(config)# interface Port-Channel1
switch(config-if-Po1)# switchport mode trunk
switch(config-if-Po1)# switchport trunk allowed vlan 10,20,30-32
switch(config-if-Po1)# exit
switch(config)# interface Ethernet49-50
switch(config-if-Et49-50)# channel-group 1 mode active

Configure the VLAN attributes on the port channel, never on the members: EOS propagates the port-channel configuration down and member-level VLAN statements are removed or ignored. LACP active mode with the VLAN settings on the bundle is the standard access-to-distribution pattern.

Step 4: create the SVI for inter-VLAN routing

switch(config)# interface vlan 10
switch(config-if-Vl10)# ip address 10.10.10.1/24
switch(config-if-Vl10)# no shutdown
switch(config-if-Vl10)# exit

The SVI is up as soon as the VLAN exists and at least one member port is up. To check that the interface was actually created rather than silently rejected, run:

switch# show interfaces vlan 10
switch# show ip interface brief

On platforms that require explicit creation of the interface, the sequence is interface vlan 10 in global configuration plus the VLAN's existence in the VLAN database; creating the VLAN first is the habit that avoids the problem entirely.

Enabling routing on the switch

switch(config)# ip routing

Inter-VLAN traffic through the SVI will not forward until ip routing is enabled. This is a global setting and is off by default on some EOS images and SKUs - worth checking first when SVIs are up but hosts cannot reach each other.

Step 5: verify

switch# show vlan
switch# show vlan 10
switch# show interfaces Ethernet1 status
switch# show interfaces Ethernet49 trunk
switch# show mac address-table vlan 10
switch# show ip route

Read the output in that order: VLAN membership first, then port state, then trunk parameters, then the MAC table to confirm hosts are being learned in the right VLAN, and finally the routing table to confirm the SVI subnet appears as a connected route. If the MAC table shows an address in the wrong VLAN, the port is either in the wrong access VLAN or the switchport mode is still default.

Adjacent material on this site includes the EOS VLAN native VLAN and trunk troubleshooting guide, the VLAN trunk and SVI port-channel runbook and the EOS MSTP configuration guide. A Chinese-language version is available as Arista EOS VLAN 配置.

原文链接:https://www.arista.com/en/um-eos/eos-virtual-lans-vlans