ArubaOS-CX vs AOS-S: VLAN and Trunk Command Mapping - 夜莺博客

ArubaOS-CX vs AOS-S: VLAN and Trunk Command Mapping

Moving from a ProVision (AOS-S) distribution to ArubaOS-CX access switches is mostly a mental-model change, not a feature change. AOS-S gives every VLAN a per-port membership state — untagged, tagged or excluded — while AOS-CX forces each interface into one of two modes: access (one untagged VLAN) or trunk (a native untagged VLAN plus an explicit allowed list). This article maps the commands one-for-one and shows the migration order that avoids locking yourself out of the uplink.

The two models side by side

Task AOS-S (ProVision) ArubaOS-CX
Create VLANs vlan 1-3 vlan 1-3 (same)
Access port in VLAN 2 vlan 2 then untagged a1 interface 1/1/1 then vlan access 2
Trunk port carrying 1-3 vlan 1 untagged a1, vlan 2 tagged a1, vlan 3 tagged a1 vlan trunk native 1 plus vlan trunk allowed 1-3
No VLAN on a port vlan 3 then no tagged a1 remove the ID from vlan trunk allowed, or use a different mode

HPE's own interoperability guidance documents exactly this translation: a switch-to-switch link built with vlan trunk native 1 and vlan trunk allowed 1-3 on the CX side corresponds to the untagged/tagged block on the AOS-S side.

Migration order that keeps the uplink alive

switch(config)# vlan 1-3
switch(config)# interface 1/1/2
switch(config-if)# no shutdown
switch(config-if)# no routing
switch(config-if)# vlan trunk native 1
switch(config-if)# vlan trunk allowed 1-3

Build the CX uplink first, verify it forwarding, and only then convert the AOS-S side. Configuring the native VLAN as tagged (vlan trunk native 1 tag) removes the untagged domain entirely and is the safer target state for inter-switch links, but it will not interoperate with an AOS-S port that still treats the VLAN as untagged.

What AOS-CX deliberately cannot do

AOS-S (like Comware hybrid ports) can carry one untagged VLAN and a tagged VLAN on the same edge port. AOS-CX cannot — a port is access or trunk. If a design depends on that behaviour, split it across two ports or move the tagged service onto the uplink. Accepting this constraint up front is cheaper than discovering it during cutover.

Verification

switch# show vlan
switch# show vlan port 1/1/2
switch# show interface 1/1/2 trunk
switch# show running-config interface 1/1/2

show vlan port flags each VLAN on the port as tagged or untagged — the fastest way to prove the mapping landed, and the fastest way to catch a native-VLAN mismatch after a partial migration.

Related reading: ArubaOS-CX access vs trunk comparison table, Cisco IOS to ArubaOS-CX command mapping, Native VLAN tagging on AOS-CX.

原文链接:https://airheads.hpe.com/HigherLogic/System/DownloadDocumentFile.ashx?DocumentFileKey=bd2bb0ec-51c1-4e89-a508-018ccf37dfdc