Broadband aggregation switching

Platform: Arista EOS 4.29 · Role: access aggregation switch · Last reviewed 2026-09-22

Role in the network

This switch sits between the access network — optical network terminals, digital subscriber line access multiplexers, fixed wireless radios — and the broadband network gateway that authenticates subscribers and applies their service profile. It is a Layer 2 device by design: it must carry subscriber traffic to the gateway without routing it, without learning more addresses than it has table space for, and without letting one subscriber's traffic reach another subscriber directly.

VLAN allocation plan

A documented plan is the difference between a network you can grow and one you cannot.
RangePurpose
1Unused. Never carried on any trunk.
100–199Residential broadband subscriber aggregation, one VLAN per access node.
200–299Business Ethernet services handed to the service edge.
300–399Wholesale and carrier interconnect.
900Access node element management.
999Parking VLAN for disabled or unprovisioned ports.

Configuration

! ---------------------------------------------------------------------------
! Baseline. Management traffic is confined to its own VRF so that a routing
! fault in the data path cannot cost you access to the device.
! ---------------------------------------------------------------------------
hostname agg-sw-01
!
vrf instance MGMT
!
interface Management1
 description Out of band management
 vrf MGMT
 ip address 192.0.2.201/24
!
ip route vrf MGMT 0.0.0.0/0 192.0.2.254
!
! ---------------------------------------------------------------------------
! VLANs actually in use on this node. Anything not listed here does not exist
! on this switch, which keeps trunk allow-lists short and auditable.
! ---------------------------------------------------------------------------
vlan 101
 name RES-BB-ACCESS-NODE-01
!
vlan 102
 name RES-BB-ACCESS-NODE-02
!
vlan 201
 name BIZ-ETH-SERVICES
!
vlan 900
 name ACCESS-NODE-MGMT
!
vlan 999
 name PARKING-UNPROVISIONED
!
! ---------------------------------------------------------------------------
! Spanning tree. Access ports are edge ports and must never elect a root;
! a subscriber-side device claiming to be root is either a misconfiguration
! or an attack, and either way the port should shut down.
! ---------------------------------------------------------------------------
spanning-tree mode rapid-pvst
spanning-tree edge port bpduguard default
spanning-tree loopguard default
!
! ---------------------------------------------------------------------------
! Access node facing ports. Subscriber isolation is enforced by protected
! ports: two protected ports on the same switch cannot exchange frames
! directly, so subscriber-to-subscriber traffic must traverse the gateway
! where policy is applied.
! ---------------------------------------------------------------------------
interface Ethernet1
 description Access node 01 - OLT uplink
 switchport mode trunk
 switchport trunk allowed vlan 101,900
 switchport trunk native vlan none
 switchport port-security
 switchport port-security maximum 2048
 switchport port-security violation protect
 switchport protected
 spanning-tree portfast
 spanning-tree bpduguard enable
 storm-control broadcast level 1
 storm-control multicast level 2
 storm-control unknown-unicast level 1
!
interface Ethernet2
 description Access node 02 - DSLAM uplink
 switchport mode trunk
 switchport trunk allowed vlan 102,900
 switchport trunk native vlan none
 switchport port-security
 switchport port-security maximum 1024
 switchport port-security violation protect
 switchport protected
 spanning-tree portfast
 spanning-tree bpduguard enable
 storm-control broadcast level 1
 storm-control multicast level 2
 storm-control unknown-unicast level 1
!
! ---------------------------------------------------------------------------
! Unprovisioned ports are parked, shut and out of the way. An unused port
! left in the default VLAN and administratively up is how a network grows
! connections nobody planned.
! ---------------------------------------------------------------------------
interface Ethernet3-46
 description UNPROVISIONED
 switchport access vlan 999
 shutdown
!
! ---------------------------------------------------------------------------
! Uplink to the broadband network gateway. Dual-homed, active/active over a
! multi-chassis link aggregation group so a single gateway maintenance window
! is not a subscriber outage.
! ---------------------------------------------------------------------------
interface Port-Channel1
 description Uplink to BNG pair
 switchport mode trunk
 switchport trunk allowed vlan 101,102,201,900
 switchport trunk native vlan none
 mlag 1
!
interface Ethernet47
 description Uplink to BNG-01
 channel-group 1 mode active
!
interface Ethernet48
 description Uplink to BNG-02
 channel-group 1 mode active
!
! ---------------------------------------------------------------------------
! Suppress the noise that has no business on a subscriber-facing switch.
! ---------------------------------------------------------------------------
no lldp run
ip igmp snooping
ip igmp snooping vlan 101 querier address 192.0.2.201
!
! Explicit DHCP relay trust boundary: subscriber-facing ports are untrusted,
! only the gateway uplink may source DHCP server traffic.
ip dhcp snooping
ip dhcp snooping vlan 101,102
ip dhcp snooping information option
!
interface Port-Channel1
 ip dhcp snooping trust
!
! ---------------------------------------------------------------------------
! Logging and time. Correlating a subscriber complaint with a switch event
! requires both to agree on the clock.
! ---------------------------------------------------------------------------
logging vrf MGMT host 192.0.2.210
logging level spanning-tree informational
ntp server vrf MGMT 192.0.2.211 prefer
clock timezone UTC

Verification

CommandExpected result
show vlan Only the five planned VLANs present; VLAN 1 carries no active ports.
show interfaces trunk Allowed VLAN list on each trunk matches the plan exactly; native VLAN none on every trunk.
show spanning-tree detail | grep -A2 bpduguard BPDU guard active on every access port. Test by injecting a BPDU: the port must move to errdisable.
show port-security Learned address count per port well below the configured maximum under normal load.
show ip dhcp snooping Snooping enabled on subscriber VLANs, uplink port-channel listed as trusted.
show mlag detail State active, negotiation status connected, both peer links up.

Operational notes

Standards

Back to the configuration library