ArubaOS-Switch VLAN Tagging and Trunk CLI Guide - 夜莺博客

ArubaOS-Switch VLAN Tagging and Trunk CLI Guide

ArubaOS-Switch — the ProCurve lineage that runs on the 2530, 2540, 2920, 2930F/M and 3810 series — does not use Cisco-style switchport mode access|trunk commands. Ports are members of VLANs with an explicit untagged or tagged status, and a port can be untagged in exactly one VLAN while being tagged in many. Engineers arriving from Cisco IOS or ArubaOS-CX find this confusing for the first hour and obvious afterwards. This guide covers the VLAN model, LACP trunk configuration, spanning-tree tuning, loop protection and verification commands on a 2930F running ArubaOS-Switch 16.x.

The tagging model in one paragraph

An untagged member of a VLAN receives and sends frames without an 802.1Q tag: it is where end devices live. A tagged member expects and sends tagged frames, which is how one uplink carries many VLANs to another switch. Because untagged frames carry no VLAN identity, a port may be untagged in only one VLAN — everything else must be tagged. Configure the VLAN, then attach ports, rather than configuring ports first.

Step 1: create VLANs and assign ports

switch# configure
switch(config)# vlan 10
switch(vlan-10)# name Users
switch(vlan-10)# untagged 1-20
switch(vlan-10)# tagged 25-26
switch(vlan-10)# exit

switch(config)# vlan 20
switch(vlan-20)# name Voice
switch(vlan-20)# tagged 1-20
switch(vlan-20)# tagged 25-26
switch(vlan-20)# exit

Here access ports 1-20 are untagged in VLAN 10 (data) and tagged in VLAN 20 (voice), which is the classic phone-plus-PC wiring pattern. Uplinks 25-26 carry both VLANs tagged. To change a port's VLAN membership later, remove it from the old VLAN first — otherwise the switch refuses to move it:

switch(config)# vlan 10
switch(vlan-10)# no untagged 18
switch(vlan-10)# exit
switch(config)# vlan 30
switch(vlan-30)# untagged 18

Step 2: management IP and default gateway

switch(config)# vlan 1
switch(vlan-1)# ip address 10.10.10.5 255.255.255.0
switch(vlan-1)# exit
switch(config)# ip default-gateway 10.10.10.1

For a routed uplink rather than a management-only address, configure the same VLAN with an IP address and enable ip routing in global configuration.

Step 3: trunks — static or LACP

ArubaOS-Switch calls a link aggregation a trunk and names it trk1, trk2 and so on. A dynamic LACP trunk is created by naming the trunk and adding the lacp keyword:

switch(config)# trunk 23-24 trk1 lacp
switch(config)# trunk 21-22 trk2 trunk

The first line builds a dynamic LACP bundle, the second a static trunk with no control protocol. Once the trunk exists, it is treated like any other port for VLAN membership:

switch(config)# vlan 10
switch(vlan-10)# tagged trk1
switch(vlan-10)# exit
switch(config)# show trunks
switch(config)# show lacp

Remember the platform limits: up to 8 ports per trunk, and each switch series supports a fixed number of trunk groups (the 2930F supports trk1-trk60). Members do not have to be consecutive ports, but keeping them in the same port bank avoids oversubscription surprises.

Step 4: spanning tree and edge ports

switch(config)# spanning-tree
switch(config)# spanning-tree 1-20 admin-edge-port
switch(config)# spanning-tree 1-20 bpdu-protection
switch(config)# spanning-tree priority 4
switch(config)# spanning-tree config-name CAMPUS
switch(config)# spanning-tree config-revision 1

admin-edge-port makes the ports come up immediately instead of waiting for the listening and learning timers, and bpdu-protection err-disables a port if a switch is plugged into an access outlet. Set the same config-name and revision on every switch in the MSTP region — mismatched values silently create separate regions and defeat the topology.

Step 5: loop protection on access ports

switch(config)# loop-protect 1-20
switch(config)# loop-protect action disable 1-20
switch(config)# loop-protect transmit-interval 5

Loop protect sends keepalives on a port and disables it if its own frame comes back, which catches wiring mistakes that spanning tree cannot see — for example a patch cable returning to a different access port in the same VLAN.

Verification

switch# show vlan
switch# show vlan 10
switch# show trunks
switch# show interfaces brief
switch# show spanning-tree
switch# show lldp info remote-device
switch# show running-config
switch# write memory

Expect show vlan 10 to list ports 1-20 as untagged and 25-26, trk1 as tagged, and show trunks to report the trunk as up with all members active. Always finish with write memory — ArubaOS-Switch keeps running and startup configurations separate, and an unsaved change disappears at the next reload.

ArubaOS-Switch versus ArubaOS-CX in practice

Task ArubaOS-Switch (AOS-S) ArubaOS-CX
Access port vlan 10 then untagged 1 interface 1/1/1, no routing, vlan access 10
Trunk port vlan 20 then tagged 25 vlan trunk allowed 20, vlan trunk native 1
Link aggregation trunk 23-24 trk1 lacp interface lag 1, lacp mode active
Committed config write memory Automatic (running config persists)

If you are migrating a site to CX hardware, the ArubaOS-CX access and trunk tagging reference maps each of these commands, and the AOS-CX access versus trunk comparison explains the native VLAN behaviour that replaces untagged membership. Existing AOS-S power supplies and firmware images remain supported, so run both generations side by side during a migration — note that a firmware stage such as the 2930F firmware upgrade procedure should be done before, not during, a VLAN restructure.

Troubleshooting checklist

  • A port refuses to move VLANs: it is still untagged in its previous VLAN. Remove it there first.
  • Some VLANs missing on the far switch: the uplink is tagged in one VLAN but untagged (or absent) in the other. Membership must match on both ends.
  • Nothing passes on a tag-only uplink: no VLAN is untagged on the port, so management traffic from that port is dropped. With a tagged-only design, keep an untagged management VLAN on a separate port.
  • Trunk never comes up: check that both ends use the same mode (LACP on both, or static on both) and that the member ports are not in different VLAN groupings with mismatched speed and duplex settings.

原文链接:https://arubanetworking.hpe.com/techdocs/AOS-Switch/16.11/Aruba 2930F/2930M Advanced Traffic Management Guide for AOS-S 16.11