Broadband aggregation switching
Platform: Arista EOS 4.29 · Role: access aggregation switch · Last reviewed 2026-09-22
Role in the network
This switch sits between the access network — optical network terminals, digital
subscriber line access multiplexers, fixed wireless radios — and the broadband
network gateway that authenticates subscribers and applies their service profile. It is
a Layer 2 device by design: it must carry subscriber traffic to the gateway without
routing it, without learning more addresses than it has table space for, and without
letting one subscriber's traffic reach another subscriber directly.
VLAN allocation plan
A documented plan is the difference between a network you can grow and one you cannot.
| Range | Purpose |
| 1 | Unused. Never carried on any trunk. |
| 100–199 | Residential broadband subscriber aggregation, one VLAN per access node. |
| 200–299 | Business Ethernet services handed to the service edge. |
| 300–399 | Wholesale and carrier interconnect. |
| 900 | Access node element management. |
| 999 | Parking VLAN for disabled or unprovisioned ports. |
Configuration
! ---------------------------------------------------------------------------
! Baseline. Management traffic is confined to its own VRF so that a routing
! fault in the data path cannot cost you access to the device.
! ---------------------------------------------------------------------------
hostname agg-sw-01
!
vrf instance MGMT
!
interface Management1
description Out of band management
vrf MGMT
ip address 192.0.2.201/24
!
ip route vrf MGMT 0.0.0.0/0 192.0.2.254
!
! ---------------------------------------------------------------------------
! VLANs actually in use on this node. Anything not listed here does not exist
! on this switch, which keeps trunk allow-lists short and auditable.
! ---------------------------------------------------------------------------
vlan 101
name RES-BB-ACCESS-NODE-01
!
vlan 102
name RES-BB-ACCESS-NODE-02
!
vlan 201
name BIZ-ETH-SERVICES
!
vlan 900
name ACCESS-NODE-MGMT
!
vlan 999
name PARKING-UNPROVISIONED
!
! ---------------------------------------------------------------------------
! Spanning tree. Access ports are edge ports and must never elect a root;
! a subscriber-side device claiming to be root is either a misconfiguration
! or an attack, and either way the port should shut down.
! ---------------------------------------------------------------------------
spanning-tree mode rapid-pvst
spanning-tree edge port bpduguard default
spanning-tree loopguard default
!
! ---------------------------------------------------------------------------
! Access node facing ports. Subscriber isolation is enforced by protected
! ports: two protected ports on the same switch cannot exchange frames
! directly, so subscriber-to-subscriber traffic must traverse the gateway
! where policy is applied.
! ---------------------------------------------------------------------------
interface Ethernet1
description Access node 01 - OLT uplink
switchport mode trunk
switchport trunk allowed vlan 101,900
switchport trunk native vlan none
switchport port-security
switchport port-security maximum 2048
switchport port-security violation protect
switchport protected
spanning-tree portfast
spanning-tree bpduguard enable
storm-control broadcast level 1
storm-control multicast level 2
storm-control unknown-unicast level 1
!
interface Ethernet2
description Access node 02 - DSLAM uplink
switchport mode trunk
switchport trunk allowed vlan 102,900
switchport trunk native vlan none
switchport port-security
switchport port-security maximum 1024
switchport port-security violation protect
switchport protected
spanning-tree portfast
spanning-tree bpduguard enable
storm-control broadcast level 1
storm-control multicast level 2
storm-control unknown-unicast level 1
!
! ---------------------------------------------------------------------------
! Unprovisioned ports are parked, shut and out of the way. An unused port
! left in the default VLAN and administratively up is how a network grows
! connections nobody planned.
! ---------------------------------------------------------------------------
interface Ethernet3-46
description UNPROVISIONED
switchport access vlan 999
shutdown
!
! ---------------------------------------------------------------------------
! Uplink to the broadband network gateway. Dual-homed, active/active over a
! multi-chassis link aggregation group so a single gateway maintenance window
! is not a subscriber outage.
! ---------------------------------------------------------------------------
interface Port-Channel1
description Uplink to BNG pair
switchport mode trunk
switchport trunk allowed vlan 101,102,201,900
switchport trunk native vlan none
mlag 1
!
interface Ethernet47
description Uplink to BNG-01
channel-group 1 mode active
!
interface Ethernet48
description Uplink to BNG-02
channel-group 1 mode active
!
! ---------------------------------------------------------------------------
! Suppress the noise that has no business on a subscriber-facing switch.
! ---------------------------------------------------------------------------
no lldp run
ip igmp snooping
ip igmp snooping vlan 101 querier address 192.0.2.201
!
! Explicit DHCP relay trust boundary: subscriber-facing ports are untrusted,
! only the gateway uplink may source DHCP server traffic.
ip dhcp snooping
ip dhcp snooping vlan 101,102
ip dhcp snooping information option
!
interface Port-Channel1
ip dhcp snooping trust
!
! ---------------------------------------------------------------------------
! Logging and time. Correlating a subscriber complaint with a switch event
! requires both to agree on the clock.
! ---------------------------------------------------------------------------
logging vrf MGMT host 192.0.2.210
logging level spanning-tree informational
ntp server vrf MGMT 192.0.2.211 prefer
clock timezone UTC
Verification
| Command | Expected result |
show vlan |
Only the five planned VLANs present; VLAN 1 carries no active ports. |
show interfaces trunk |
Allowed VLAN list on each trunk matches the plan exactly; native VLAN
none on every trunk. |
show spanning-tree detail | grep -A2 bpduguard |
BPDU guard active on every access port. Test by injecting a BPDU: the port must
move to errdisable. |
show port-security |
Learned address count per port well below the configured maximum under normal
load. |
show ip dhcp snooping |
Snooping enabled on subscriber VLANs, uplink port-channel listed as trusted. |
show mlag detail |
State active, negotiation status connected, both peer links up. |
Operational notes
- Native VLAN none. Setting the native VLAN to none on every trunk
means an untagged frame arriving on a trunk is dropped instead of landing in a VLAN
nobody intended. This removes a whole class of VLAN hopping problem.
- Port security maximum. Size it to the number of subscriber devices
the access node can present, not to a round number.
violation protect
drops the excess without disabling the port, which is the right trade-off on an
aggregation link serving thousands of subscribers.
- Protected ports are not a substitute for policy. They stop direct
subscriber-to-subscriber forwarding on this switch only. Isolation across access
nodes is the gateway's job.
- Storm control thresholds. One percent of a 10 Gbps link is still
100 Mbps of broadcast, which is far more than a healthy access VLAN ever
generates. Start here, then tighten using the measured baseline.
Standards
- IEEE 802.1Q — VLAN bridging.
- IEEE 802.1w and 802.1D — Rapid spanning tree and bridging.
- IEEE 802.3ad / 802.1AX — Link aggregation.
- RFC 3046 — DHCP relay agent information option, the basis of subscriber
line identification.
- RFC 4541 — IGMP and MLD snooping switch behaviour.
- ITU-T G.984 and G.9807 — GPON and XGS-PON access, for the optical
terminals feeding this switch.
Back to the configuration library