Junos Aggregated Ethernet (AE) and LACP Configuration - 夜莺博客

Junos Aggregated Ethernet (AE) and LACP Configuration

Junos combines multiple physical Ethernet links into a single logical aggregated Ethernet (ae) interface - the Juniper equivalent of a port-channel or LAG - for more bandwidth and link redundancy between switches and routers. Unlike a plain static bundle, LACP negotiates membership and detects misconfigurations such as speed or MTU mismatches between the two ends. This guide walks through the complete Junos AE + LACP configuration flow with set commands: enabling the chassis device count, binding member interfaces with 802.3ad, turning on LACP, carrying VLANs, and verifying with show lacp interfaces.

What Aggregated Ethernet Buys You

A bundle of four 10G links gives you 40G of aggregate capacity in one direction and one logical interface to route or switch on. More importantly, it gives you graceful degradation: a single member failing costs 25% of the bandwidth rather than the whole link. Failover on a static bundle is fast because the remaining members simply keep forwarding, but a static bundle has a nasty failure mode — if only one side's cabling is wrong, or a member is mis-cabled into a different VLAN, the bundle can come up and black-hole traffic with no visible alarm.

LACP (IEEE 802.3ad) solves that by having both ends exchange control PDUs. A member only becomes active once both sides agree it belongs to the same bundle, which means a mis-cabled link never silently joins the LAG. LACP also carries the partner's system ID and port key, so a member connected to the wrong switch is rejected rather than absorbed.

Two terms are worth fixing in your head before configuring anything: a member link is a physical interface (ge-0/0/0) that has been bound to the bundle, and the ae interface (ae0) is the logical interface that carries the VLAN or IP configuration. Configuration always lands on the ae interface, never on the member.

Step 1: Define How Many AE Interfaces the Chassis Can Create

set chassis aggregated-devices ethernet device-count 8

This pre-allocates ae0 through ae7. If you already configured a high enough device count you can skip this step.

The device count is a chassis-wide allocation, not a per-port setting, and it must be present before the ae interfaces exist. If you try to commit set interfaces ae0 without it, the commit fails with an error explaining that the aggregated Ethernet device count is zero. The count is also a hard limit: with device-count 8 you can create ae0 to ae7, and adding ae8 later requires raising the count and committing, which momentarily affects the existing bundles on some platforms. Size it once, generously, for the whole box.

Step 2: Bind Member Interfaces into the Bundle

Member interfaces must not carry their own unit configuration - a logical unit on a member causes a commit error:

set interfaces ge-0/0/0 gigether-options 802.3ad ae0
set interfaces ge-0/0/1 gigether-options 802.3ad ae0

Two syntax variants exist depending on the platform. On older EX and MX platforms the command is ether-options 802.3ad ae0; on EX/QFX with newer Junos versions the family-specific gigether-options or mge-options form is used. The Junos CLI will reject the wrong one for the interface type, so if a commit fails with an unknown statement error, that is usually the reason.

A member interface cannot have units, addresses or VLANs of its own. Any leftover configuration from a previous life — a stray unit 0 family inet address, for example — will block the commit. Remove it explicitly:

delete interfaces ge-0/0/0 unit 0
set interfaces ge-0/0/0 gigether-options 802.3ad ae0

Step 3: Configure the AE Interface with LACP

Enable LACP in active mode (at least one side must be active) and, for a switch, set the trunk VLANs on the ae interface:

set interfaces ae0 description "LACP uplink to EX2"
set interfaces ae0 aggregated-ether-options lacp active
set interfaces ae0 aggregated-ether-options lacp periodic fast
set interfaces ae0 aggregated-ether-options minimum-links 1
set interfaces ae0 unit 0 family ethernet-switching port-mode trunk
set interfaces ae0 unit 0 family ethernet-switching vlan members [ 10 20 100 ]
commit

For a routed bundle, replace the family block with set interfaces ae0 unit 0 family inet address 192.168.0.1/24. Options worth knowing: link-speed 10g forces member speed, maximum-links puts excess members in standby, and minimum-links keeps the bundle down until enough members are up.

The LACP settings deserve a little more detail because they are where most production bundles are misconfigured:

  • Active vs passive. A bundle forms when at least one end is active. Active/active is preferred for switches because both sides transmit PDUs, which means failures are detected faster and either side can renegotiate. Active/passive works but relies entirely on the active peer's timers.
  • Periodic fast vs slow. fast sends a PDU every second; slow every 30 seconds. Use fast on links to servers and on any bundle carrying latency-sensitive traffic, so a failed member is removed within roughly three seconds instead of ninety.
  • minimum-links. Setting minimum-links 2 on a four-member bundle takes the whole ae interface down when only one member survives — a deliberate choice when a single 10G link would be too thin for the traffic, and a good way to fail over to a backup path instead of silently congesting. Setting it to 1 maximises availability.
  • link-speed. Pin the expected member speed (link-speed 10g) so a member that negotiates a different speed is rejected rather than silently joining a slower bundle.

Step 4: Configure the Peer (Passive Side)

The far end uses the same structure; it may run LACP in passive mode since the active side initiates:

set interfaces ge-0/0/0 gigether-options 802.3ad ae0
set interfaces ae0 aggregated-ether-options lacp passive
set interfaces ae0 unit 0 family ethernet-switching port-mode trunk
set interfaces ae0 unit 0 family ethernet-switching vlan members [ 10 20 100 ]
commit

Do not forget set chassis aggregated-devices ethernet device-count on the peer as well — it is a per-chassis requirement, and a peer that lacks it cannot create the ae interface at all.

VLAN Trunking Across the Bundle

When the bundle is a switch-to-switch uplink, the VLAN configuration lives on the ae interface's logical unit and nowhere else:

set interfaces ae0 unit 0 family ethernet-switching interface-mode trunk
set interfaces ae0 unit 0 family ethernet-switching vlan members 10
set interfaces ae0 unit 0 family ethernet-switching vlan members 20
set interfaces ae0 unit 0 family ethernet-switching vlan members 100
set interfaces ae0 unit 0 family ethernet-switching native-vlan-id 100

On Junos switch platforms, port-mode trunk and interface-mode trunk are the older and newer statement names for the same behaviour; recent releases accept interface-mode and warn on port-mode. Either way, the native VLAN is configured with native-vlan-id on the interface, not inside the VLAN list.

A member interface never sees the VLAN list. If you find yourself wondering which member carries VLAN 10, the answer is that all of them do — the bundle distributes frames across active members, and the configuration that matters is on ae0.

Routed Bundles, IRBs and Layer 3

set interfaces ae0 unit 0 family inet address 192.168.0.1/24
set interfaces ae0 unit 0 family inet6 address 2001:db8::1/64

For a router-to-router bundle, the member links carry the LAG and the ae unit carries the IP address. To route between VLANs while still switching them, use an IRB paired with the VLAN:

set vlans SERVERS vlan-id 100
set vlans SERVERS l3-interface irb.100
set interfaces irb unit 100 family inet address 10.0.100.1/24
set interfaces ae0 unit 0 family ethernet-switching interface-mode trunk
set interfaces ae0 unit 0 family ethernet-switching vlan members 100

The ae interface trunks VLAN 100, the VLAN binds to irb.100, and the IRB carries the gateway address. That combination is the Junos equivalent of an SVI on a switch and keeps Layer 2 and Layer 3 in one logical place.

Load Balancing and Hash Behaviour

Junos chooses a member for each flow with a hash, so a bundle does not give one flow more than one link's worth of bandwidth. Knowing which fields are hashed matters when you troubleshoot uneven utilisation:

show interfaces ae0 extensive | match "Link status|input bytes|output bytes"
show lacp interfaces ae0

If one member is saturated while the others idle, the traffic is almost certainly a small number of high-volume flows with identical hash inputs — a single backup job over NFS, for example. The remedy is a different hash policy or more flows, not a configuration error. On some platforms the Layer 3/Layer 4 hash fields can be tuned with set forwarding-options hash-key; on others the policy is fixed, and spreading the flows is the only lever.

Verification Commands

show interfaces ae0 terse
show lacp interfaces
show lacp statistics interfaces ge-0/0/0
show interfaces ae0 extensive

In show lacp interfaces, all Actor and Partner flags set to 1 means the bundle is fully operational; a Detached mux state means LACP frames are not being exchanged with the peer.

Read the output in this order:

  • Aggregated interface — the bundle name, ae0, together with the LACP mode and the periodic interval.
  • LACP state / mux state — Current means the member is forwarding; Detached means PDUs are not being received from the peer; Attached with no traffic suggests a network-side issue rather than LACP.
  • Actor and Partner flags — the seven flags (Activity, Timeout, Aggregation, Synchronization, Collecting, Distributing, Defaulted) describe the negotiation state. All ones is the healthy state; Defaulted set on the Partner side indicates the local switch is using default partner information because no PDUs arrive.
  • show interfaces ae0 extensive — confirms the members, the distribution of traffic across them and any output errors.

Troubleshooting Common LACP Failures

  • Member not in the bundle — a leftover unit configuration on the member, or a VLAN that is not a member of the bundle's allowed list. Delete the stray unit and re-commit.
  • Mux state Detached — LACP PDUs are not reaching the peer. Check the physical link, then the peer's configuration; a switch that has LACP disabled or is running a different periodic setting will not form a bundle with an active end.
  • Bundle up but traffic black-holed — one member is a member on the local side but its peer port is in a different VLAN or is not part of the bundle. Check both ends with show lacp interfaces on each switch.
  • Commit error about aggregated Ethernet — the chassis device count is missing or too small. Raise it and commit again.
  • Uneven member utilisation — hashing, not LACP. See the load-balancing section above.
  • Members flapping — a speed or MTU mismatch. Pin link-speed and verify the MTU matches on both switches, especially when jumbo frames are in use.

Config Groups, Commit and Rollback

On chassis switches that connect to a fixed set of peers, config groups keep AE definitions identical across the fabric and remove a whole class of typo-driven mismatches:

set groups LACP-UPLINK interfaces ge-0/0/0 gigether-options 802.3ad ae0
set groups LACP-UPLINK interfaces ge-0/0/1 gigether-options 802.3ad ae0
set groups LACP-UPLINK interfaces ae0 aggregated-ether-options lacp active
set apply-groups LACP-UPLINK

Before committing, always preview the diff and record a rollback point:

commit check
show | compare
commit comment "ae0 LACP uplink to EX2"
rollback 0

commit check validates the candidate configuration without applying it, which catches member-unit conflicts before they disrupt a live bundle. rollback 0 re-applies the current committed configuration and is the fastest way to undo a change made in the last minute; rollback 1 returns to the previous commit. Note that adding or removing members of a live bundle causes a brief traffic hit on the affected member's flows, so do it in a change window.

FAQ

Do both sides have to be active? No. LACP forms when at least one end is active. Active/active is still the better choice for fast failure detection.

Does an AE bundle give one flow 40G? No. A single flow is hashed onto one member. Aggregate bandwidth grows with the number of flows, not with a single socket.

Should member interfaces be shut down before joining a bundle? No. Junos handles the membership change itself; shutting members down first simply causes a longer outage.

What is the difference between a static bundle and LACP here? A static bundle omits the lacp statement entirely. It comes up faster but cannot detect a mis-cabled member, which is exactly the failure LACP prevents.

Link aggregation concepts apply everywhere: compare with Arista EOS port-channel and LACP, Linux bonding with LACP, Cisco EtherChannel: PAgP vs LACP and Linux Bonding 802.3ad: LACP Rate and Hash Policy for a cross-platform view.

原文链接:https://networkcuriosity.com/junos-aggregated-ethernet-example