Interface groups provide a powerful mechanism for applying consistent configurations to multiple interfaces across one or more devices. They enable you to define reusable interface configuration templates that can be applied to interfaces with similar roles or requirements, promoting standardization and reducing configuration complexity.
Interface groups are particularly valuable for:
Role-based interface configuration : Standardizing configurations for server ports, uplinks, access ports, etc.
Service deployment : Applying consistent security policies, QoS settings, or VLAN configurations
Operational consistency : Ensuring uniform interface behaviors across your network infrastructure
Configuration maintenance : Centralizing interface policies for easier updates and troubleshooting
Interface groups work by:
Defining a named configuration template with interface-specific settings
Referencing the interface group from individual interfaces via the interface_groups attribute
Supporting variables for dynamic configuration based on device or group context
Allowing multiple interface groups to be applied to a single interface (configurations are merged)
This approach separates interface policy definition from individual interface declarations, making your network configurations more modular and maintainable.
When interface groups are applied at both the device_group and device levels for the same interface, the interface_group_policy attribute controls how they interact:
merge (default): Interface groups from device_groups and devices are combined. All referenced groups are applied, with device-level interface attributes taking final precedence over any group configuration.
replace : Device-level interface groups completely replace any interface groups inherited from device_groups. Only the groups explicitly listed at the device level are applied.
The policy can be set at two levels:
Device level (devices[].interface_group_policy): Applies as the default for all interfaces on the device.
Per-interface level (ethernets[].interface_group_policy, etc.): Overrides the device-level policy for a specific interface.
Precedence: per-interface policy > device-level policy > default (merge).
If interface_group_policy: replace is set but an interface is only defined in a device_group (not redefined at the device level), the inherited groups are still applied since there is nothing to replace them with.
Name Type Constraint Mandatory Default Value interface_groups List [interface_groups]No
Name Type Constraint Mandatory Default Value name String Yes variables Map No configuration Class [configuration]No
Name Type Constraint Mandatory Default Value media_type Choice auto-select, rj45, sfpNo bandwidth Integer min: 1, max: 200000000 No mtu Integer min: 64, max: 18000 No description String No shutdown Boolean true, falseNo vrf_forwarding String No ipv4 Class [ipv4]No ipv6 Class [ipv6]No bfd Class [bfd]No spanning_tree Class [spanning_tree]No speed Choice 100, 1000, 2500, 5000, 10000, 25000, 40000, 50000, 100000, autoNo speed_nonegotiate Boolean true, falseNo port_channel_id Integer min: 1, max: 512 No port_channel_mode Choice active, auto, desirable, on, passiveNo source_templates List [source_templates]No arp_timeout Integer min: 0, max: 2147483 No negotiation_auto Boolean true, falseNo service_policy_input String No service_policy_output String No load_interval Integer min: 30, max: 600 No snmp_trap_link_status Boolean true, falseNo logging_event_link_status Boolean true, falseNo device_tracking Boolean true, falseNo device_tracking_attached_policies List String No encapsulation_dot1q_vlan_id Integer min: 1, max: 4094 No nbar_protocol_discovery Boolean true, falseNo mpls Class [mpls]No ospf Class [ospf]No ospfv3 Class [ospfv3]No isis Class [isis]No pim Class [pim]No igmp Class [igmp]No switchport Class [switchport]No network_access_control Class [network_access_control]No auto_qos Class [auto_qos]No cdp Boolean true, falseNo cdp_tlv_app Boolean true, falseNo cdp_tlv_location Boolean true, falseNo cdp_tlv_server_location Boolean true, falseNo carrier_delay_msec Integer min: 0, max: 1000 No hold_queue_in Integer min: 0, max: 240000 No hold_queue_out Integer min: 0, max: 240000 No autostate Boolean true, falseNo
Name Type Constraint Mandatory Default Value address IP No address_mask IP No proxy_arp Boolean true, falseNo arp_inspection_trust Boolean true, falseNo arp_inspection_limit_rate Integer min: 0, max: 4294967295 No dhcp_snooping_trust Boolean true, falseNo dhcp_relay_source_interface_type Choice Loopback, Vlan, GigabitEthernet, TwoGigabitEthernet, FiveGigabitEthernet, TenGigabitEthernet, TwentyFiveGigabitEthernet, FortyGigabitEthernet, FiftyGigabitEthernet, HundredGigabitEthernet, PortChannelNo dhcp_relay_source_interface_id Any String or Integer[min: 0] No dhcp_relay_information_option_vpn_id Boolean true, falseNo helper_addresses List [helper_addresses]No access_group_in String No access_group_out String No flow_monitors List [flow_monitors]No redirects Boolean true, falseNo unreachables Boolean true, falseNo unnumbered_interface_type Choice Loopback, Vlan, GigabitEthernet, TwoGigabitEthernet, FiveGigabitEthernet, TenGigabitEthernet, TwentyFiveGigabitEthernet, FortyGigabitEthernet, FiftyGigabitEthernet, HundredGigabitEthernet, PortChannelNo unnumbered_interface_id Any String or Integer[min: 0] No nat_inside Boolean true, falseNo nat_outside Boolean true, falseNo address_dhcp Boolean true, falseNo verify_unicast_source_reachable_via Choice any, rxNo verify_unicast_source_allow_self_ping Boolean true, falseNo verify_unicast_source_allow_default Boolean true, falseNo
Name Type Constraint Mandatory Default Value enable Boolean true, falseNo addresses List [addresses]No link_local_addresses List IP No address_autoconfig_default Boolean true, falseNo address_dhcp Boolean true, falseNo mtu Integer min: 1280, max: 9976 No nd_ra_suppress_all Boolean true, falseNo flow_monitors List [flow_monitors]No pim Class [pim]No
Name Type Constraint Mandatory Default Value template String No enable Boolean true, falseNo local_address IP No interval Integer min: 50, max: 9999 No interval_min_rx Integer min: 50, max: 9999 No interval_multiplier Integer min: 3, max: 50 No echo Boolean true, falseNo
Name Type Constraint Mandatory Default Value portfast Boolean true, falseNo portfast_disable Boolean true, falseNo bpduguard Boolean true, falseNo bpduguard_disable Boolean true, falseNo guard Choice loop, none, rootNo link_type Choice shared, point-to-pointNo portfast_trunk Boolean true, falseNo portfast_edge Boolean true, falseNo
Name Type Constraint Mandatory Default Value name String Yes merge Boolean true, falseNo
Name Type Constraint Mandatory Default Value ip Boolean true, falseNo mtu Integer No
Name Type Constraint Mandatory Default Value authentication_key_chain String No authentication_message_digest Boolean true, falseNo authentication_null Boolean true, falseNo cost Integer min: 1, max: 65535 No dead_interval Integer min: 1, max: 65535 No hello_interval Integer min: 1, max: 65535 No message_digest_keys List [message_digest_keys]No mtu_ignore Boolean true, falseNo multi_area_ids List Any[String or Integer[min: 0]] No network_type Choice broadcast, non-broadcast, point-to-multipoint, point-to-pointNo priority Integer min: 0, max: 255 No process_ids List [process_ids]No ttl_security_hops Integer min: 1, max: 254 No
Name Type Constraint Mandatory Default Value bfd Boolean true, falseNo cost Integer min: 1, max: 65535 No dead_interval Integer min: 1, max: 65535 No hello_interval Integer min: 1, max: 65535 No mtu_ignore Boolean true, falseNo network_type Choice broadcast, non-broadcast, point-to-multipoint, point-to-pointNo priority Integer min: 0, max: 255 No
Name Type Constraint Mandatory Default Value area_tag String No ipv4_metric_levels List [ipv4_metric_levels]No network_point_to_point Boolean true, falseNo
Name Type Constraint Mandatory Default Value passive Boolean true, falseNo dense_mode Boolean true, falseNo sparse_mode Boolean true, falseNo sparse_dense_mode Boolean true, falseNo bfd Boolean true, falseNo border Boolean true, falseNo bsr_border Boolean true, falseNo dr_priority Integer min: 0, max: 4294967294 No
Name Type Constraint Mandatory Default Value version Integer min: 1, max: 3 No
Name Type Constraint Mandatory Default Value enable Boolean true, falseNo mode Choice access, dot1q-tunnel, private-vlan-trunk, private-vlan-host, private-vlan-promiscuous, trunkNo nonegotiate Boolean true, falseNo access_vlan Integer min: 1, max: 4094 No voice_vlan Any Integer[min: 1, max: 4094] or Choice[dot1p, none, untagged] or String[Regex: ^.*[\$\%]\{.*$] No trunk_allowed_vlans Class [trunk_allowed_vlans]No trunk_allowed_vlans_legacy Class [trunk_allowed_vlans_legacy]No trunk_native_vlan_tag Boolean true, falseNo trunk_native_vlan_id Integer min: 1, max: 4094 No host Boolean true, falseNo
Name Type Constraint Mandatory Default Value authentication_periodic Boolean true, falseNo authentication_timer_reauthenticate Integer min: 1, max: 1073741823 No authentication_timer_reauthenticate_server Boolean true, falseNo mab Boolean true, falseNo mab_eap Boolean true, falseNo dot1x_pae Choice authenticator, supplicant, bothNo dot1x_timeout_auth_period Integer min: 1, max: 65535 No dot1x_timeout_held_period Integer min: 1, max: 65535 No dot1x_timeout_quiet_period Integer min: 1, max: 65535 No dot1x_timeout_ratelimit_period Integer min: 1, max: 65535 No dot1x_timeout_server_timeout Integer min: 1, max: 65535 No dot1x_timeout_start_period Integer min: 1, max: 65535 No dot1x_timeout_supp_timeout Integer min: 1, max: 65535 No dot1x_timeout_tx_period Integer min: 1, max: 65535 No dot1x_max_req Integer min: 1, max: 10 No dot1x_max_reauth_req Integer min: 1, max: 10 No
Name Type Constraint Mandatory Default Value classify Boolean true, falseNo classify_police Boolean true, falseNo trust Boolean true, falseNo trust_cos Boolean true, falseNo trust_dscp Boolean true, falseNo video_cts Boolean true, falseNo video_ip_camera Boolean true, falseNo video_media_player Boolean true, falseNo voip_cisco_phone Boolean true, falseNo voip_cisco_softphone Boolean true, falseNo voip_trust Boolean true, falseNo trust_device Choice cisco-phone, cts, ip-camera, media-playerNo
Name Type Constraint Mandatory Default Value address IP Yes global Boolean true, falseNo vrf String No
Name Type Constraint Mandatory Default Value name String Yes direction Choice input, outputYes
Name Type Constraint Mandatory Default Value prefix IP Yes eui_64 Boolean true, falseNo
Name Type Constraint Mandatory Default Value pim Boolean true, falseNo bfd Boolean true, falseNo bsr_border Boolean true, falseNo dr_priority Integer min: 0, max: 4294967295 No
Name Type Constraint Mandatory Default Value id Integer min: 1, max: 255 Yes md5_auth_key String No md5_auth_type Choice 0, 7No
Name Type Constraint Mandatory Default Value id Integer min: 1, max: 65535 No areas List Any[String or Integer[min: 0]] No
Name Type Constraint Mandatory Default Value level Choice level-1, level-2Yes value Integer min: 1, max: 16777214 Yes
Name Type Constraint Mandatory Default Value all Boolean true, falseNo none Boolean true, falseNo vlans Class [vlans]No add Class [add]No except Class [except]No remove Class [remove]No
Name Type Constraint Mandatory Default Value ids List Integer[min: 1, max: 4094] No ranges List [ranges]No
Name Type Constraint Mandatory Default Value ids List Integer[min: 1, max: 4094] No ranges List [ranges]No
Name Type Constraint Mandatory Default Value ids List Integer[min: 1, max: 4094] No ranges List [ranges]No
Name Type Constraint Mandatory Default Value ids List Integer[min: 1, max: 4094] No ranges List [ranges]No
Name Type Constraint Mandatory Default Value ids List Integer[min: 1, max: 4094] No ranges List [ranges]No
Name Type Constraint Mandatory Default Value from Integer min: 1, max: 4094 Yes to Integer min: 1, max: 4094 Yes
# Server access port configuration
- name : SERVER_ACCESS_PORT
description : " Server Access Port "
port_security_maximum_ranges :
# Trunk uplink configuration
description : " Trunk Uplink to ${uplink_device} "
trunk_allowed_vlans : " 1-200,300-400 "
link_type : point-to-point
# Access port with dynamic VLAN
- name : DYNAMIC_ACCESS_PORT
access_vlan : ${port_vlan}
access_session_port_control : auto
# Management interface configuration
description : " Management Interface "
address_mask : " 255.255.255.0 "
snmp_trap_link_status : true
# CDP, IGMP, and queue tuning via interface group
- name : MULTICAST_CDP_TUNED
cdp_tlv_server_location : true
# VLAN interface configuration with autostate
description : " VLAN with Autostate Control "
address_mask : " 255.255.255.0 "
# Apply interface groups to devices
uplink_device : " Core-SW-01 "
# Server ports using SERVER_ACCESS_PORT group
interface_groups : [ SERVER_ACCESS_PORT ]
interface_groups : [ SERVER_ACCESS_PORT ]
# Uplink using TRUNK_UPLINK group
interface_groups : [ TRUNK_UPLINK ]
# User ports with dynamic access and multiple groups
interface_groups : [ DYNAMIC_ACCESS_PORT ]
# Management VLAN using MGMT_INTERFACE group
interface_groups : [ MGMT_INTERFACE ]
# VLAN with autostate control via interface group
interface_groups : [ VLAN_CONFIG_AUTO ]
description : " Z;FREE_PORT "
interface_groups : [ IFG_FREE_PORT ]
interface_groups : [ IFG_FREE_PORT ]
interface_groups : [ IFG_FREE_PORT ]
device_groups : [ PLATFORM_C9300 ]
interface_group_policy : replace
# Gi1/0/3 gets ONLY IFG_TRUNK_PORT (replace policy, device redefines this interface)
interface_groups : [ IFG_TRUNK_PORT ]
# Gi1/0/1 still gets IFG_FREE_PORT (not redefined at device level, so inherited groups apply)
Example configuring VLAN autostate control using an interface group. When autostate: false is set, the VLAN interface remains up even if no physical ports are active in that VLAN. The interface_groups attribute is a NAC abstraction - the group configuration is merged and rendered to device CLI at template time.
Cisco IOS-XE CLI Equivalent:
description VLAN with Autostate for Interface Groups Documentation
ip address 192.168.200.1 255.255.255.0
NAC YAML Configuration:
description : " VLAN with Autostate Control "
address_mask : " 255.255.255.0 "
interface_groups : [ VLAN_CONFIG_AUTO ]
Interface groups provide a powerful mechanism for applying consistent configurations to multiple interfaces across one or more devices. They enable you to define reusable interface configuration templates that can be applied to interfaces with similar roles or requirements, promoting standardization and reducing configuration complexity.
Interface groups are particularly valuable for:
Role-based interface configuration : Standardizing configurations for server ports, uplinks, access ports, etc.
Service deployment : Applying consistent security policies, QoS settings, or VLAN configurations
Operational consistency : Ensuring uniform interface behaviors across your network infrastructure
Configuration maintenance : Centralizing interface policies for easier updates and troubleshooting
Interface groups work by:
Defining a named configuration template with interface-specific settings
Referencing the interface group from individual interfaces via the interface_groups attribute
Supporting variables for dynamic configuration based on device or group context
Allowing multiple interface groups to be applied to a single interface (configurations are merged)
This approach separates interface policy definition from individual interface declarations, making your network configurations more modular and maintainable.
Name Type Constraint Mandatory Default Value interface_groups List [interface_groups]No
Name Type Constraint Mandatory Default Value name String Yes variables Map No configuration Class [configuration]No
Name Type Constraint Mandatory Default Value media_type Choice auto-select, rj45, sfpNo bandwidth Integer min: 1, max: 200000000 No mtu Integer min: 64, max: 18000 No description String No shutdown Boolean true, falseNo vrf_forwarding String No ipv4 Class [ipv4]No ipv6 Class [ipv6]No bfd Class [bfd]No spanning_tree Class [spanning_tree]No speed Choice 100, 1000, 2500, 5000, 10000, 25000, 40000, 100000, autoNo speed_nonegotiate Boolean true, falseNo port_channel_id Integer min: 1, max: 512 No port_channel_mode Choice active, auto, desirable, on, passiveNo source_templates List [source_templates]No arp_timeout Integer min: 0, max: 2147483 No negotiation_auto Boolean true, falseNo service_policy_input String No service_policy_output String No load_interval Integer min: 30, max: 600 No snmp_trap_link_status Boolean true, falseNo logging_event_link_status Boolean true, falseNo device_tracking Boolean true, falseNo device_tracking_attached_policies List String No encapsulation_dot1q_vlan_id Integer min: 1, max: 4094 No nbar_protocol_discovery Boolean true, falseNo mpls Class [mpls]No ospf Class [ospf]No ospfv3 Class [ospfv3]No pim Class [pim]No switchport Class [switchport]No network_access_control Class [network_access_control]No auto_qos Class [auto_qos]No autostate Boolean true, falseNo
Name Type Constraint Mandatory Default Value address IP No address_mask IP No proxy_arp Boolean true, falseNo arp_inspection_trust Boolean true, falseNo arp_inspection_limit_rate Integer min: 0, max: 4294967295 No dhcp_snooping_trust Boolean true, falseNo dhcp_relay_source_interface_type Choice Loopback, Vlan, GigabitEthernet, FiveGigabitEthernet, TenGigabitEthernet, FortyGigabitEthernet, HundredGigabitEthernet, PortChannelNo dhcp_relay_source_interface_id Any String or Integer[min: 0] No dhcp_relay_information_option_vpn_id Boolean true, falseNo helper_addresses List [helper_addresses]No access_group_in String No access_group_out String No flow_monitors List [flow_monitors]No redirects Boolean true, falseNo unreachables Boolean true, falseNo unnumbered_interface_type Choice Loopback, Vlan, GigabitEthernet, FiveGigabitEthernet, TenGigabitEthernet, FortyGigabitEthernet, HundredGigabitEthernet, PortChannelNo unnumbered_interface_id Any String or Integer[min: 0] No nat_inside Boolean true, falseNo nat_outside Boolean true, falseNo
Name Type Constraint Mandatory Default Value enable Boolean true, falseNo addresses List [addresses]No link_local_addresses List IP No address_autoconfig_default Boolean true, falseNo address_dhcp Boolean true, falseNo mtu Integer min: 1280, max: 9976 No nd_ra_suppress_all Boolean true, falseNo flow_monitors List [flow_monitors]No pim Class [pim]No
Name Type Constraint Mandatory Default Value template String No enable Boolean true, falseNo local_address String No interval Integer min: 50, max: 9999 No interval_min_rx Integer min: 50, max: 9999 No interval_multiplier Integer min: 3, max: 50 No echo Boolean true, falseNo
Name Type Constraint Mandatory Default Value portfast Boolean true, falseNo portfast_disable Boolean true, falseNo bpduguard Boolean true, falseNo bpduguard_disable Boolean true, falseNo guard Choice loop, none, rootNo link_type Choice shared, point-to-pointNo portfast_trunk Boolean true, falseNo portfast_edge Boolean true, falseNo
Name Type Constraint Mandatory Default Value name String Yes merge Boolean true, falseNo
Name Type Constraint Mandatory Default Value ip Boolean true, falseNo mtu Integer No
Name Type Constraint Mandatory Default Value cost Integer min: 1, max: 65535 No dead_interval Integer min: 1, max: 65535 No hello_interval Integer min: 1, max: 65535 No mtu_ignore Boolean true, falseNo network_type Choice broadcast, non-broadcast, point-to-multipoint, point-to-pointNo priority Integer min: 0, max: 255 No ttl_security_hops Integer min: 1, max: 254 No process_ids List [process_ids]No message_digest_keys List [message_digest_keys]No
Name Type Constraint Mandatory Default Value network_type Choice broadcast, non-broadcast, point-to-multipoint, point-to-pointNo cost Integer min: 1, max: 65535 No
Name Type Constraint Mandatory Default Value passive Boolean true, falseNo dense_mode Boolean true, falseNo sparse_mode Boolean true, falseNo sparse_dense_mode Boolean true, falseNo bfd Boolean true, falseNo border Boolean true, falseNo bsr_border Boolean true, falseNo dr_priority Integer min: 0, max: 4294967294 No
Name Type Constraint Mandatory Default Value enable Boolean true, falseNo mode Choice access, dot1q-tunnel, private-vlan-trunk, private-vlan-host, private-vlan-promiscuous, trunkNo nonegotiate Boolean true, falseNo access_vlan Integer min: 1, max: 4094 No trunk_allowed_vlans Class [trunk_allowed_vlans]No trunk_allowed_vlans_legacy Class [trunk_allowed_vlans_legacy]No trunk_native_vlan_tag Boolean true, falseNo trunk_native_vlan_id Integer min: 1, max: 4094 No host Boolean true, falseNo
Name Type Constraint Mandatory Default Value authentication_periodic Boolean true, falseNo authentication_timer_reauthenticate Integer min: 1, max: 1073741823 No authentication_timer_reauthenticate_server Boolean true, falseNo mab Boolean true, falseNo mab_eap Boolean true, falseNo dot1x_pae Choice authenticator, supplicant, bothNo dot1x_timeout_auth_period Integer min: 1, max: 65535 No dot1x_timeout_held_period Integer min: 1, max: 65535 No dot1x_timeout_quiet_period Integer min: 1, max: 65535 No dot1x_timeout_ratelimit_period Integer min: 1, max: 65535 No dot1x_timeout_server_timeout Integer min: 1, max: 65535 No dot1x_timeout_start_period Integer min: 1, max: 65535 No dot1x_timeout_supp_timeout Integer min: 1, max: 65535 No dot1x_timeout_tx_period Integer min: 1, max: 65535 No dot1x_max_req Integer min: 1, max: 10 No dot1x_max_reauth_req Integer min: 1, max: 10 No
Name Type Constraint Mandatory Default Value classify Boolean true, falseNo classify_police Boolean true, falseNo trust Boolean true, falseNo trust_cos Boolean true, falseNo trust_dscp Boolean true, falseNo video_cts Boolean true, falseNo video_ip_camera Boolean true, falseNo video_media_player Boolean true, falseNo voip Boolean true, falseNo voip_cisco_phone Boolean true, falseNo voip_cisco_softphone Boolean true, falseNo voip_trust Boolean true, falseNo trust_device Choice cisco-phone, cts, ip-camera, media-playerNo
Name Type Constraint Mandatory Default Value address IP Yes global Boolean true, falseNo vrf String No
Name Type Constraint Mandatory Default Value name String Yes direction Choice input, outputYes
Name Type Constraint Mandatory Default Value prefix IP Yes eui_64 Boolean true, falseNo
Name Type Constraint Mandatory Default Value pim Boolean true, falseNo bfd Boolean true, falseNo bsr_border Boolean true, falseNo dr_priority Integer min: 0, max: 4294967295 No
Name Type Constraint Mandatory Default Value id Integer min: 1, max: 65535 No areas List Any[String or Integer[min: 0]] No
Name Type Constraint Mandatory Default Value id Integer min: 1, max: 255 Yes md5_auth_key String No md5_auth_type Choice 0, 7No
Name Type Constraint Mandatory Default Value all Boolean true, falseNo none Boolean true, falseNo vlans Class [vlans]No add Class [add]No except Class [except]No remove Class [remove]No
Name Type Constraint Mandatory Default Value ids List Integer[min: 1, max: 4094] No ranges List [ranges]No
Name Type Constraint Mandatory Default Value ids List Integer[min: 1, max: 4094] No ranges List [ranges]No
Name Type Constraint Mandatory Default Value ids List Integer[min: 1, max: 4094] No ranges List [ranges]No
Name Type Constraint Mandatory Default Value ids List Integer[min: 1, max: 4094] No ranges List [ranges]No
Name Type Constraint Mandatory Default Value ids List Integer[min: 1, max: 4094] No ranges List [ranges]No
Name Type Constraint Mandatory Default Value from Integer min: 1, max: 4094 Yes to Integer min: 1, max: 4094 Yes
# Server access port configuration
- name : SERVER_ACCESS_PORT
description : " Server Access Port "
port_security_maximum_ranges :
# Trunk uplink configuration
description : " Trunk Uplink to ${uplink_device} "
trunk_allowed_vlans : " 1-200,300-400 "
link_type : point-to-point
# Access port with dynamic VLAN
- name : DYNAMIC_ACCESS_PORT
access_vlan : ${port_vlan}
access_session_port_control : auto
# Management interface configuration
description : " Management Interface "
address_mask : " 255.255.255.0 "
snmp_trap_link_status : true
# Apply interface groups to devices
uplink_device : " Core-SW-01 "
# Server ports using SERVER_ACCESS_PORT group
interface_groups : [ SERVER_ACCESS_PORT ]
interface_groups : [ SERVER_ACCESS_PORT ]
# Uplink using TRUNK_UPLINK group
interface_groups : [ TRUNK_UPLINK ]
# User ports with dynamic access and multiple groups
interface_groups : [ DYNAMIC_ACCESS_PORT ]
# Management VLAN using MGMT_INTERFACE group
interface_groups : [ MGMT_INTERFACE ]