Skip to content

Ethernet

Ethernet interfaces provide the fundamental physical and logical connectivity for network devices, supporting various speeds from Fast Ethernet (100 Mbps) to multi-gigabit rates (1G, 2.5G, 5G, 10G, 25G, 40G, 100G) with comprehensive Layer 2 switching and Layer 3 routing capabilities. They offer extensive configuration options including switchport modes (access, trunk), VLAN assignments, spanning tree parameters, quality of service policies, security features, and advanced protocols such as OSPF, BFD, and IPv6. Ethernet interfaces serve as the backbone of modern networks, enabling both access layer connectivity for end devices and high-performance trunk links between network infrastructure components while supporting features like port channels, network access control, and comprehensive monitoring capabilities.

Diagram
NameTypeConstraintMandatoryDefault Value
ethernetsList[ethernets]No

ethernets (iosxe.devices.configuration.interfaces)

Section titled “ethernets (iosxe.devices.configuration.interfaces)”
NameTypeConstraintMandatoryDefault Value
typeChoiceGigabitEthernet, TwoGigabitEthernet, FastEthernet, Ethernet, Port-channel, FiveGigabitEthernet, TenGigabitEthernet, TwentyFiveGigE, FortyGigabitEthernet, FiftyGigabitEthernet, HundredGigE, TwoHundredGigE, FourHundredGigEYes
idStringYes
managedBooleantrue, falseNo
interface_groupsListStringNo
interface_group_policyChoicemerge, replaceNo
media_typeChoiceauto-select, rj45, sfpNo
bandwidthIntegermin: 1, max: 200000000No
mtuIntegermin: 64, max: 18000No
descriptionStringNo
shutdownBooleantrue, falseNo
vrf_forwardingStringNo
ipv4Class[ipv4]No
ipv6Class[ipv6]No
bfdClass[bfd]No
spanning_treeClass[spanning_tree]No
speedChoice100, 1000, 2500, 5000, 10000, 25000, 40000, 50000, 100000, autoNo
speed_nonegotiateBooleantrue, falseNo
port_channel_idIntegermin: 1, max: 512No
port_channel_modeChoiceactive, auto, desirable, on, passiveNo
source_templatesList[source_templates]No
arp_timeoutIntegermin: 0, max: 2147483No
negotiation_autoBooleantrue, falseNo
service_policy_inputStringNo
service_policy_outputStringNo
load_intervalIntegermin: 30, max: 600No
snmp_trap_link_statusBooleantrue, falseNo
logging_event_link_statusBooleantrue, falseNo
device_trackingBooleantrue, falseNo
device_tracking_attached_policiesListStringNo
encapsulation_dot1q_vlan_idIntegermin: 1, max: 4094No
nbar_protocol_discoveryBooleantrue, falseNo
mplsClass[mpls]No
ospfClass[ospf]No
ospfv3Class[ospfv3]No
isisClass[isis]No
pimClass[pim]No
igmpClass[igmp]No
switchportClass[switchport]No
network_access_controlClass[network_access_control]No
auto_qosClass[auto_qos]No
cdpBooleantrue, falseNo
cdp_tlv_appBooleantrue, falseNo
cdp_tlv_locationBooleantrue, falseNo
cdp_tlv_server_locationBooleantrue, falseNo
evpn_ethernet_segmentsList[evpn_ethernet_segments]No
carrier_delay_msecIntegermin: 0, max: 1000No
hold_queue_inIntegermin: 0, max: 240000No
hold_queue_outIntegermin: 0, max: 240000No
vrrp_v2List[vrrp_v2]No
zone_member_securityStringNo

ipv4 (iosxe.devices.configuration.interfaces.ethernets)

Section titled “ipv4 (iosxe.devices.configuration.interfaces.ethernets)”
NameTypeConstraintMandatoryDefault Value
addressIPNo
address_maskIPNo
proxy_arpBooleantrue, falseNo
arp_inspection_trustBooleantrue, falseNo
arp_inspection_limit_rateIntegermin: 0, max: 4294967295No
dhcp_snooping_trustBooleantrue, falseNo
dhcp_relay_source_interface_typeChoiceLoopback, Vlan, GigabitEthernet, TwoGigabitEthernet, FiveGigabitEthernet, TenGigabitEthernet, TwentyFiveGigabitEthernet, FortyGigabitEthernet, FiftyGigabitEthernet, HundredGigabitEthernet, PortChannelNo
dhcp_relay_source_interface_idAnyString or Integer[min: 0]No
dhcp_relay_information_option_vpn_idBooleantrue, falseNo
helper_addressesList[helper_addresses]No
access_group_inStringNo
access_group_outStringNo
flow_monitorsList[flow_monitors]No
redirectsBooleantrue, falseNo
unreachablesBooleantrue, falseNo
unnumbered_interface_typeChoiceLoopback, Vlan, GigabitEthernet, TwoGigabitEthernet, FiveGigabitEthernet, TenGigabitEthernet, TwentyFiveGigabitEthernet, FortyGigabitEthernet, FiftyGigabitEthernet, HundredGigabitEthernet, PortChannelNo
unnumbered_interface_idAnyString or Integer[min: 0]No
nat_insideBooleantrue, falseNo
nat_outsideBooleantrue, falseNo
address_dhcpBooleantrue, falseNo
verify_unicast_source_reachable_viaChoiceany, rxNo
verify_unicast_source_allow_self_pingBooleantrue, falseNo
verify_unicast_source_allow_defaultBooleantrue, falseNo

ipv6 (iosxe.devices.configuration.interfaces.ethernets)

Section titled “ipv6 (iosxe.devices.configuration.interfaces.ethernets)”
NameTypeConstraintMandatoryDefault Value
enableBooleantrue, falseNo
addressesList[addresses]No
link_local_addressesListIPNo
address_autoconfig_defaultBooleantrue, falseNo
address_dhcpBooleantrue, falseNo
mtuIntegermin: 1280, max: 9976No
nd_ra_suppress_allBooleantrue, falseNo
flow_monitorsList[flow_monitors]No
pimClass[pim]No

bfd (iosxe.devices.configuration.interfaces.ethernets)

Section titled “bfd (iosxe.devices.configuration.interfaces.ethernets)”
NameTypeConstraintMandatoryDefault Value
templateStringNo
enableBooleantrue, falseNo
local_addressIPNo
intervalIntegermin: 50, max: 9999No
interval_min_rxIntegermin: 50, max: 9999No
interval_multiplierIntegermin: 3, max: 50No
echoBooleantrue, falseNo

spanning_tree (iosxe.devices.configuration.interfaces.ethernets)

Section titled “spanning_tree (iosxe.devices.configuration.interfaces.ethernets)”
NameTypeConstraintMandatoryDefault Value
portfastBooleantrue, falseNo
portfast_disableBooleantrue, falseNo
bpduguardBooleantrue, falseNo
bpduguard_disableBooleantrue, falseNo
guardChoiceloop, none, rootNo
link_typeChoiceshared, point-to-pointNo
portfast_trunkBooleantrue, falseNo
portfast_edgeBooleantrue, falseNo

source_templates (iosxe.devices.configuration.interfaces.ethernets)

Section titled “source_templates (iosxe.devices.configuration.interfaces.ethernets)”
NameTypeConstraintMandatoryDefault Value
nameStringYes
mergeBooleantrue, falseNo

mpls (iosxe.devices.configuration.interfaces.ethernets)

Section titled “mpls (iosxe.devices.configuration.interfaces.ethernets)”
NameTypeConstraintMandatoryDefault Value
ipBooleantrue, falseNo
mtuIntegerNo

ospf (iosxe.devices.configuration.interfaces.ethernets)

Section titled “ospf (iosxe.devices.configuration.interfaces.ethernets)”
NameTypeConstraintMandatoryDefault Value
authentication_key_chainStringNo
authentication_message_digestBooleantrue, falseNo
authentication_nullBooleantrue, falseNo
costIntegermin: 1, max: 65535No
dead_intervalIntegermin: 1, max: 65535No
hello_intervalIntegermin: 1, max: 65535No
message_digest_keysList[message_digest_keys]No
mtu_ignoreBooleantrue, falseNo
multi_area_idsListAny[String or Integer[min: 0]]No
network_typeChoicebroadcast, non-broadcast, point-to-multipoint, point-to-pointNo
priorityIntegermin: 0, max: 255No
process_idsList[process_ids]No
ttl_security_hopsIntegermin: 1, max: 254No

ospfv3 (iosxe.devices.configuration.interfaces.ethernets)

Section titled “ospfv3 (iosxe.devices.configuration.interfaces.ethernets)”
NameTypeConstraintMandatoryDefault Value
bfdBooleantrue, falseNo
costIntegermin: 1, max: 65535No
dead_intervalIntegermin: 1, max: 65535No
hello_intervalIntegermin: 1, max: 65535No
mtu_ignoreBooleantrue, falseNo
network_typeChoicebroadcast, non-broadcast, point-to-multipoint, point-to-pointNo
priorityIntegermin: 0, max: 255No

isis (iosxe.devices.configuration.interfaces.ethernets)

Section titled “isis (iosxe.devices.configuration.interfaces.ethernets)”
NameTypeConstraintMandatoryDefault Value
area_tagStringNo
ipv4_metric_levelsList[ipv4_metric_levels]No
network_point_to_pointBooleantrue, falseNo

pim (iosxe.devices.configuration.interfaces.ethernets)

Section titled “pim (iosxe.devices.configuration.interfaces.ethernets)”
NameTypeConstraintMandatoryDefault Value
passiveBooleantrue, falseNo
dense_modeBooleantrue, falseNo
sparse_modeBooleantrue, falseNo
sparse_dense_modeBooleantrue, falseNo
bfdBooleantrue, falseNo
borderBooleantrue, falseNo
bsr_borderBooleantrue, falseNo
dr_priorityIntegermin: 0, max: 4294967294No

igmp (iosxe.devices.configuration.interfaces.ethernets)

Section titled “igmp (iosxe.devices.configuration.interfaces.ethernets)”
NameTypeConstraintMandatoryDefault Value
versionIntegermin: 1, max: 3No

switchport (iosxe.devices.configuration.interfaces.ethernets)

Section titled “switchport (iosxe.devices.configuration.interfaces.ethernets)”
NameTypeConstraintMandatoryDefault Value
enableBooleantrue, falseNo
modeChoiceaccess, dot1q-tunnel, private-vlan-trunk, private-vlan-host, private-vlan-promiscuous, trunkNo
nonegotiateBooleantrue, falseNo
access_vlanIntegermin: 1, max: 4094No
voice_vlanAnyInteger[min: 1, max: 4094] or Choice[dot1p, none, untagged] or String[Regex: ^.*[\$\%]\{.*$]No
trunk_allowed_vlansClass[trunk_allowed_vlans]No
trunk_allowed_vlans_legacyClass[trunk_allowed_vlans_legacy]No
trunk_native_vlan_tagBooleantrue, falseNo
trunk_native_vlan_idIntegermin: 1, max: 4094No
hostBooleantrue, falseNo

network_access_control (iosxe.devices.configuration.interfaces.ethernets)

Section titled “network_access_control (iosxe.devices.configuration.interfaces.ethernets)”
NameTypeConstraintMandatoryDefault Value
authentication_periodicBooleantrue, falseNo
authentication_timer_reauthenticateIntegermin: 1, max: 1073741823No
authentication_timer_reauthenticate_serverBooleantrue, falseNo
mabBooleantrue, falseNo
mab_eapBooleantrue, falseNo
dot1x_paeChoiceauthenticator, supplicant, bothNo
dot1x_timeout_auth_periodIntegermin: 1, max: 65535No
dot1x_timeout_held_periodIntegermin: 1, max: 65535No
dot1x_timeout_quiet_periodIntegermin: 1, max: 65535No
dot1x_timeout_ratelimit_periodIntegermin: 1, max: 65535No
dot1x_timeout_server_timeoutIntegermin: 1, max: 65535No
dot1x_timeout_start_periodIntegermin: 1, max: 65535No
dot1x_timeout_supp_timeoutIntegermin: 1, max: 65535No
dot1x_timeout_tx_periodIntegermin: 1, max: 65535No
dot1x_max_reqIntegermin: 1, max: 10No
dot1x_max_reauth_reqIntegermin: 1, max: 10No

auto_qos (iosxe.devices.configuration.interfaces.ethernets)

Section titled “auto_qos (iosxe.devices.configuration.interfaces.ethernets)”
NameTypeConstraintMandatoryDefault Value
classifyBooleantrue, falseNo
classify_policeBooleantrue, falseNo
trustBooleantrue, falseNo
trust_cosBooleantrue, falseNo
trust_dscpBooleantrue, falseNo
video_ctsBooleantrue, falseNo
video_ip_cameraBooleantrue, falseNo
video_media_playerBooleantrue, falseNo
voip_cisco_phoneBooleantrue, falseNo
voip_cisco_softphoneBooleantrue, falseNo
voip_trustBooleantrue, falseNo
trust_deviceChoicecisco-phone, cts, ip-camera, media-playerNo

evpn_ethernet_segments (iosxe.devices.configuration.interfaces.ethernets)

Section titled “evpn_ethernet_segments (iosxe.devices.configuration.interfaces.ethernets)”
NameTypeConstraintMandatoryDefault Value
es_valueIntegermin: 1, max: 65535Yes

vrrp_v2 (iosxe.devices.configuration.interfaces.ethernets)

Section titled “vrrp_v2 (iosxe.devices.configuration.interfaces.ethernets)”
NameTypeConstraintMandatoryDefault Value
group_idIntegermin: 1, max: 255Yes
ip_primary_addressIPNo
ip_secondary_addressesListIPNo
priorityIntegermin: 1, max: 254No
preemptBooleantrue, falseNo
preempt_delay_minimumIntegermin: 0, max: 3600No
timers_advertise_intervalIntegermin: 1, max: 255No
authentication_textStringNo
descriptionStringNo
tracksList[tracks]No
shutdownBooleantrue, falseNo

helper_addresses (iosxe.devices.configuration.interfaces.ethernets.ipv4)

Section titled “helper_addresses (iosxe.devices.configuration.interfaces.ethernets.ipv4)”
NameTypeConstraintMandatoryDefault Value
addressIPYes
globalBooleantrue, falseNo
vrfStringNo

flow_monitors (iosxe.devices.configuration.interfaces.ethernets.ipv4)

Section titled “flow_monitors (iosxe.devices.configuration.interfaces.ethernets.ipv4)”
NameTypeConstraintMandatoryDefault Value
nameStringYes
directionChoiceinput, outputYes

addresses (iosxe.devices.configuration.interfaces.ethernets.ipv6)

Section titled “addresses (iosxe.devices.configuration.interfaces.ethernets.ipv6)”
NameTypeConstraintMandatoryDefault Value
prefixIPYes
eui_64Booleantrue, falseNo

pim (iosxe.devices.configuration.interfaces.ethernets.ipv6)

Section titled “pim (iosxe.devices.configuration.interfaces.ethernets.ipv6)”
NameTypeConstraintMandatoryDefault Value
pimBooleantrue, falseNo
bfdBooleantrue, falseNo
bsr_borderBooleantrue, falseNo
dr_priorityIntegermin: 0, max: 4294967295No

message_digest_keys (iosxe.devices.configuration.interfaces.ethernets.ospf)

Section titled “message_digest_keys (iosxe.devices.configuration.interfaces.ethernets.ospf)”
NameTypeConstraintMandatoryDefault Value
idIntegermin: 1, max: 255Yes
md5_auth_keyStringNo
md5_auth_typeChoice0, 7No

process_ids (iosxe.devices.configuration.interfaces.ethernets.ospf)

Section titled “process_ids (iosxe.devices.configuration.interfaces.ethernets.ospf)”
NameTypeConstraintMandatoryDefault Value
idIntegermin: 1, max: 65535No
areasListAny[String or Integer[min: 0]]No

ipv4_metric_levels (iosxe.devices.configuration.interfaces.ethernets.isis)

Section titled “ipv4_metric_levels (iosxe.devices.configuration.interfaces.ethernets.isis)”
NameTypeConstraintMandatoryDefault Value
levelChoicelevel-1, level-2Yes
valueIntegermin: 1, max: 16777214Yes

trunk_allowed_vlans (iosxe.devices.configuration.interfaces.ethernets.switchport)

Section titled “trunk_allowed_vlans (iosxe.devices.configuration.interfaces.ethernets.switchport)”
NameTypeConstraintMandatoryDefault Value
allBooleantrue, falseNo
noneBooleantrue, falseNo
vlansClass[vlans]No
addClass[add]No
exceptClass[except]No
removeClass[remove]No

trunk_allowed_vlans_legacy (iosxe.devices.configuration.interfaces.ethernets.switchport)

Section titled “trunk_allowed_vlans_legacy (iosxe.devices.configuration.interfaces.ethernets.switchport)”
NameTypeConstraintMandatoryDefault Value
idsListInteger[min: 1, max: 4094]No
rangesList[ranges]No

tracks (iosxe.devices.configuration.interfaces.ethernets.vrrp_v2)

Section titled “tracks (iosxe.devices.configuration.interfaces.ethernets.vrrp_v2)”
NameTypeConstraintMandatoryDefault Value
object_idIntegermin: 1, max: 1000Yes
decrementIntegermin: 1, max: 255No

vlans (iosxe.devices.configuration.interfaces.ethernets.switchport.trunk_allowed_vlans)

Section titled “vlans (iosxe.devices.configuration.interfaces.ethernets.switchport.trunk_allowed_vlans)”
NameTypeConstraintMandatoryDefault Value
idsListInteger[min: 1, max: 4094]No
rangesList[ranges]No

add (iosxe.devices.configuration.interfaces.ethernets.switchport.trunk_allowed_vlans)

Section titled “add (iosxe.devices.configuration.interfaces.ethernets.switchport.trunk_allowed_vlans)”
NameTypeConstraintMandatoryDefault Value
idsListInteger[min: 1, max: 4094]No
rangesList[ranges]No

except (iosxe.devices.configuration.interfaces.ethernets.switchport.trunk_allowed_vlans)

Section titled “except (iosxe.devices.configuration.interfaces.ethernets.switchport.trunk_allowed_vlans)”
NameTypeConstraintMandatoryDefault Value
idsListInteger[min: 1, max: 4094]No
rangesList[ranges]No

remove (iosxe.devices.configuration.interfaces.ethernets.switchport.trunk_allowed_vlans)

Section titled “remove (iosxe.devices.configuration.interfaces.ethernets.switchport.trunk_allowed_vlans)”
NameTypeConstraintMandatoryDefault Value
idsListInteger[min: 1, max: 4094]No
rangesList[ranges]No

ranges (iosxe.devices.configuration.interfaces.ethernets.switchport.trunk_allowed_vlans_legacy)

Section titled “ranges (iosxe.devices.configuration.interfaces.ethernets.switchport.trunk_allowed_vlans_legacy)”
NameTypeConstraintMandatoryDefault Value
fromIntegermin: 1, max: 4094Yes
toIntegermin: 1, max: 4094Yes

  • managed attribute: Controls whether Terraform continuously manages the interface configuration. When set to false, Terraform will push the initial configuration but will not continuously read it, detect drift, or reconcile changes. This is useful for:

    • Interfaces whose configuration changes dynamically due to authorization policies
    • Interfaces modified by local scripts or automation
    • Interfaces where configuration drift should be allowed and not corrected
    • Default: true (Terraform fully manages the interface and reconciles drift)
  • Usage example:

    interfaces:
    ethernets:
    - id: 1/0/1
    type: GigabitEthernet
    description: Dynamic interface
    managed: false # Terraform pushes initial config but ignores subsequent changes
  • mtu attribute: Sets the Maximum Transmission Unit (MTU) for the interface, which defines the largest packet size that can be transmitted. The valid range is 64-18000 bytes depending on platform capabilities.

  • Catalyst Platform Requirement: On Catalyst switches, individual interface MTU values cannot exceed the global system MTU. The system MTU must be configured first using the system mtu <value> global configuration command (requires device reload). Interface MTU values can be set to any value up to and including the system MTU.

  • Default MTU: Standard Ethernet default is 1500 bytes. Higher values (jumbo frames) improve performance for large data transfers but require end-to-end support.

  • Example:

    interfaces:
    ethernets:
    - id: 1/0/1
    type: GigabitEthernet
    mtu: 1600
    description: Server uplink
  • Platform-specific notes:

    • Catalyst switches: System MTU limits individual interface MTU (check with show system mtu)
    • Routers: Interface MTU can be configured independently without system MTU constraints
  • spanning_tree_portfast_edge attribute limitation: The spanning_tree_portfast_edge attribute uses a deprecated YANG model path (spanning-tree/portfast/edge) that does not translate to valid CLI commands on Catalyst switch platforms. While the YANG model accepts this configuration for backward compatibility with routers or older platforms, modern Catalyst switches (including Catalyst 9000 series) do not support the spanning-tree portfast edge CLI command. Attempting to configure this attribute on Catalyst switches will result in device configuration rejection errors (“inconsistent value: Device refused one or more commands”).

  • Recommended alternatives for Catalyst switches:

    • For access ports: Use spanning_tree_portfast: true (translates to spanning-tree portfast)
    • For trunk ports: Use spanning_tree_portfast_trunk: true (translates to spanning-tree portfast trunk)
    • Both options provide the same portfast functionality and are fully supported on Catalyst platforms
  • Portfast and guard mutual exclusivity: The spanning-tree portfast variants (portfast, portfast_disable, portfast_trunk) and guard options (loop, root, none) serve different purposes:

    • Portfast enables immediate forwarding for edge ports connecting to end devices
    • Guard protects against topology loops (loop) or unauthorized root bridges (root)
    • These can be configured together on the same interface for comprehensive protection
  • BPDU guard configuration: BPDU guard (bpduguard: true or bpduguard_disable: true) can be configured alongside any portfast variant to protect against unauthorized switches. When global BPDU guard is enabled (spanning-tree portfast bpduguard default), use bpduguard_disable: true to selectively disable it on specific interfaces.

IP Address Reassignment Between Interfaces

Section titled “IP Address Reassignment Between Interfaces”

IOS-XE enforces IP address uniqueness within the same VRF — no two interfaces can hold the same IP address simultaneously. When swapping IP addresses between two interfaces (for example, moving 10.1.1.1 from GigabitEthernet1 to GigabitEthernet2 and vice versa), terraform apply will fail because Terraform updates both interfaces in parallel without awareness of the cross-resource conflict. The device rejects the new IP assignment with an “inconsistent value: Device refused one or more commands” error because the target IP still exists on the other interface.

To perform an IP swap, apply the change in two steps:

  1. Remove the IP addresses from both interfaces (delete the ipv4 block or assign temporary addresses) and run terraform apply.
  2. Set the new desired IP addresses and run terraform apply a second time.

Interface ranges allow defining multiple interfaces with identical configuration using a from/to range. Range entries are lightweight — they only specify identity fields (type, from, to) and interface_groups. All configuration must be defined in the referenced interface groups.

  • Only the last numeric segment of the interface ID varies within a range (e.g., 1/0/1 to 1/0/48)
  • Multiple ranges of the same interface type are supported
  • Overlapping ranges or ranges that overlap with individual interface entries will produce errors when terraform plan is executed

Example:

iosxe:
interface_groups:
- name: ACCESS_100
configuration:
switchport:
mode: access
access_vlan: 100
spanning_tree:
portfast: true
devices:
- name: Switch1
configuration:
interfaces:
ranges:
ethernets:
- type: GigabitEthernet
from: "1/0/1"
to: "1/0/48"
interface_groups: [ACCESS_100]
- type: TenGigabitEthernet
from: "1/1/1"
to: "1/1/4"
interface_groups: [UPLINK_TRUNK]

Basic L2 Access Port with Port Channel and Spanning Tree

Section titled “Basic L2 Access Port with Port Channel and Spanning Tree”

Cisco IOS-XE CLI Equivalent:

interface GigabitEthernet1/1
description Server 1 Interface
mtu 1600
speed 1000
channel-group 10 mode active
switchport mode access
switchport access vlan 100
switchport voice vlan 900
spanning-tree guard loop
interface GigabitEthernet1/2
description WAN Interface
ipv6 address dhcp
iosxe:
devices:
- name: Device1
configuration:
interfaces:
ethernets:
- id: 1/1
type: GigabitEthernet
description: Server 1 Interface
mtu: 1600
speed: 1000
port_channel_id: 10
port_channel_mode: active
carrier_delay_msec: 250
hold_queue_in: 50
hold_queue_out: 50
switchport:
mode: access
access_vlan: 100
voice_vlan: 900
spanning_tree:
guard: loop
- id: 1/2
type: GigabitEthernet
description: WAN Interface
ipv6:
enable: true
address_dhcp: true

Comprehensive L3 Routed Interface with OSPF, BFD, and IPv6

Section titled “Comprehensive L3 Routed Interface with OSPF, BFD, and IPv6”
interface GigabitEthernet1/0/2
description L3 interface
mtu 1600
vrf forwarding VRF-PROD
arp timeout 300
load-interval 90
no snmp trap link-status
no logging event link-status
ip arp inspection limit rate 40
ip arp inspection trust
ip address 192.168.100.1 255.255.255.0
ip proxy-arp
ip dhcp relay source-interface Gi1/0/1
ip helper-address 10.1.1.1
ip access-group ACL-IN in
ip access-group ACL-OUT out
no ip redirects
no ip unreachables
ip verify unicast source reachable-via rx allow-self-ping allow-default
ip flow monitor FLOW1 input
ip igmp version 2
ip pim sparse-mode
ip ospf message-digest-key 1 md5 0 cisco
ip ospf 1 area 0
ip ospf cost 10
ip ospf dead-interval 40
ip ospf hello-interval 11
ip ospf network point-to-point
ip ospf priority 1
ip ospf ttl-security hops 2
ipv6 address 2001::1/64 eui-64
ipv6 address fe80::1 link-local
ipv6 mtu 1450
ipv6 nd ra suppress all
ipv6 pim dr-priority 100
ipv6 ospf cost 10
ipv6 ospf network point-to-point
bfd enable
bfd local-address 172.16.1.1
bfd interval 100 min_rx 101 multiplier 3
no bfd echo
vrrp 1 ip 192.168.100.254
vrrp 1 ip 192.168.100.253 secondary
vrrp 1 priority 110
vrrp 1 preempt delay minimum 30
vrrp 1 timers advertise 3
vrrp 1 authentication text SECRET
vrrp 1 description VRRP-GROUP-1
vrrp 1 track 1 decrement 20
vrrp 1 shutdown
iosxe:
devices:
- name: Device1
configuration:
interfaces:
ethernets:
- type: GigabitEthernet
id: 1/0/2
description: L3 interface
vrf_forwarding: "VRF-PROD"
mtu: 1600
arp_timeout: 300
load_interval: 90
snmp_trap_link_status: false
logging_event_link_status: false
ipv4:
arp_inspection_limit_rate: 40
arp_inspection_trust: true
address: 192.168.100.1
address_mask: 255.255.255.0
address_dhcp: true
proxy_arp: true
dhcp_relay_source_interface_type: GigabitEthernet
dhcp_relay_source_interface_id: 1/0/1
helper_addresses:
- address: 10.1.1.1
access_group_in: ACL-IN
access_group_out: ACL-OUT
redirects: false
unreachables: false
verify_unicast_source_reachable_via: rx
verify_unicast_source_allow_self_ping: true
verify_unicast_source_allow_default: true
flow_monitors:
- name: FLOW1
direction: input
ipv6:
enable: true
addresses:
- prefix: 2001::1/64
eui_64: true
link_local_addresses:
- fe80::1
mtu: 1450
nd_ra_suppress_all: true
pim:
dr_priority: 100
bfd:
enable: true
local_address: 172.16.1.1
interval: 100
interval_multiplier: 3
interval_min_rx: 101
echo: false
ospf:
cost: 10
dead_interval: 40
hello_interval: 11
mtu_ignore: false
network_type: point-to-point
priority: 1
ttl_security_hops: 2
process_ids:
- id: 1
areas:
- "0"
message_digest_keys:
- id: 1
md5_auth_key: "cisco"
md5_auth_type: "0"
ospfv3:
cost: 10
network_type: point-to-point
bfd: true
dead_interval: 40
hello_interval: 10
mtu_ignore: true
priority: 100
igmp:
version: 2
pim:
sparse_mode: true
vrrp_v2:
- group_id: 1
ip_primary_address: 192.168.100.254
ip_secondary_addresses:
- 192.168.100.253
priority: 110
preempt: true
preempt_delay_minimum: 30
timers_advertise_interval: 3
authentication_text: SECRET
description: VRRP-GROUP-1
shutdown: true
tracks:
- object_id: 1
decrement: 20

Access Port with Portfast, BPDU Guard, and BFD Template

Section titled “Access Port with Portfast, BPDU Guard, and BFD Template”
bfd-template single-hop SH-TEMPLATE-2
interval min-tx 500 min-rx 500 multiplier 3
interface GigabitEthernet1/0/1
description Access port with portfast
spanning-tree portfast
spanning-tree bpduguard
spanning-tree guard root
switchport mode access
bfd template SH-TEMPLATE-2
iosxe:
devices:
- name: Device1
configuration:
bfd:
single_hop_templates:
- name: SH-TEMPLATE-2
echo: false
interval_milliseconds_min_tx: 500
interval_milliseconds_min_rx: 500
interval_milliseconds_multiplier: 3
interfaces:
ethernets:
- type: GigabitEthernet
id: 1/0/1
description: Access port with portfast
spanning_tree:
portfast: true
bpduguard: true
guard: root
switchport:
enable: true
mode: access
bfd:
enable: true
template: SH-TEMPLATE-2
interface GigabitEthernet1/0/2
description Trunk port with portfast
speed 2500
spanning-tree portfast trunk
spanning-tree bpduguard
spanning-tree link-type shared
switchport mode trunk
switchport trunk allowed vlan 10-20,30,32
switchport trunk native vlan 5
iosxe:
devices:
- name: Device1
configuration:
interfaces:
ethernets:
- type: GigabitEthernet
id: 1/0/2
description: Trunk port with portfast
speed: 2500
speed_nonegotiate: false
spanning_tree:
portfast_trunk: true
bpduguard: true
link_type: shared
switchport:
mode: trunk
trunk_allowed_vlans:
vlans:
ids: [30, 32]
ranges:
- from: 10
to: 20
trunk_native_vlan_id: 5
interface GigabitEthernet1/0/3
description Port with portfast and loop guard
spanning-tree portfast
spanning-tree guard loop
switchport mode access
iosxe:
devices:
- name: Device1
configuration:
interfaces:
ethernets:
- type: GigabitEthernet
id: 1/0/3
description: Port with portfast and loop guard
spanning_tree:
portfast: true
guard: loop
switchport:
enable: true
mode: access

Access Port with Portfast Explicitly Disabled

Section titled “Access Port with Portfast Explicitly Disabled”
interface GigabitEthernet1/0/4
description Port with portfast disabled
spanning-tree portfast disable
spanning-tree guard loop
switchport mode access
iosxe:
devices:
- name: Device1
configuration:
interfaces:
ethernets:
- type: GigabitEthernet
id: 1/0/4
description: Port with portfast disabled
spanning_tree:
portfast_disable: true
guard: loop
switchport:
enable: true
mode: access

Access Port with BPDU Guard Explicitly Disabled

Section titled “Access Port with BPDU Guard Explicitly Disabled”
interface GigabitEthernet1/0/5
description Port with bpduguard disabled
spanning-tree bpduguard disable
spanning-tree link-type point-to-point
switchport mode access
iosxe:
devices:
- name: Device1
configuration:
interfaces:
ethernets:
- type: GigabitEthernet
id: 1/0/5
description: Port with bpduguard disabled
spanning_tree:
bpduguard_disable: true
link_type: point-to-point
switchport:
enable: true
mode: access
interface GigabitEthernet1/0/7
description Auto QoS trust DSCP test interface
auto qos trust dscp
iosxe:
devices:
- name: Device1
configuration:
interfaces:
ethernets:
- type: GigabitEthernet
id: 1/0/7
description: Auto QoS trust DSCP test interface
auto_qos:
trust_dscp: true
iosxe:
devices:
- name: Device1
configuration:
interfaces:
ethernets:
- type: GigabitEthernet
id: 1/0/6
switchport:
mode: trunk
trunk_allowed_vlans:
all: true
Allow All VLANs Implicitly (Default Behavior)
Section titled “Allow All VLANs Implicitly (Default Behavior)”

By default, all VLANs are allowed on a trunk switchport if no VLANs are explicitly allowed, mimicking native Cisco IOS-XE behavior.

iosxe:
devices:
- name: Device1
configuration:
interfaces:
ethernets:
- type: GigabitEthernet
id: 1/0/7
switchport:
mode: trunk
iosxe:
devices:
- name: Device1
configuration:
interfaces:
ethernets:
- type: GigabitEthernet
id: 1/0/8
switchport:
mode: trunk
trunk_allowed_vlans:
none: true
iosxe:
devices:
- name: Device1
configuration:
interfaces:
ethernets:
- type: GigabitEthernet
id: 1/0/9
switchport:
mode: trunk
trunk_allowed_vlans:
vlans:
ranges:
- from: 100
to: 200
iosxe:
devices:
- name: Device1
configuration:
interfaces:
ethernets:
- type: GigabitEthernet
id: 1/0/10
switchport:
mode: trunk
trunk_allowed_vlans:
except:
ids:
- 999
iosxe:
devices:
- name: Device1
configuration:
interfaces:
ethernets:
- type: GigabitEthernet
id: 1/0/11
switchport:
mode: trunk
trunk_allowed_vlans:
vlans:
ids:
- 100
- 200
ranges:
- from: 300
to: 400

Configure trunk interface with native VLAN tagging enabled.

Cisco IOS-XE CLI Equivalent:

interface GigabitEthernet1/0/12
description Trunk port with native VLAN tagging
switchport mode trunk
switchport trunk native vlan 10
switchport trunk native vlan tag
iosxe:
devices:
- name: Device1
configuration:
interfaces:
ethernets:
- type: GigabitEthernet
id: 1/0/12
description: Trunk port with native VLAN tagging
switchport:
mode: trunk
trunk_native_vlan_id: 10
trunk_native_vlan_tag: true

Configure DHCP relay information option vpn-id on interface.

Cisco IOS-XE CLI Equivalent:

interface GigabitEthernet2
ip dhcp relay information option vpn-id
iosxe:
devices:
- name: router
configuration:
interfaces:
ethernets:
- type: GigabitEthernet
id: '2'
ipv4:
dhcp_relay_information_option_vpn_id: true
- type: GigabitEthernet
id: '3'
ipv4:
dhcp_relay_information_option_vpn_id: true

Network Access Control (802.1X) Configuration

Section titled “Network Access Control (802.1X) Configuration”

Configure 802.1X authentication parameters on interface including timeout values for rate limiting and server communication.

interface GigabitEthernet1/0/1
dot1x timeout ratelimit-period 60
dot1x timeout server-timeout 30
dot1x pae authenticator
authentication periodic
authentication timer reauthenticate server
iosxe:
devices:
- name: switch
configuration:
interfaces:
ethernets:
- type: GigabitEthernet
id: 1/0/1
description: NAC Enabled Port
network_access_control:
dot1x_timeout_ratelimit_period: 60
dot1x_timeout_server_timeout: 30
dot1x_pae: authenticator
authentication_periodic: true
authentication_timer_reauthenticate_server: true
interface GigabitEthernet1/0/1
cdp tlv server-location
iosxe:
devices:
- name: switch
configuration:
interfaces:
ethernets:
- type: GigabitEthernet
id: 1/0/1
cdp_tlv_server_location: true
interface GigabitEthernet1/0/6
description Service policy test interface
service-policy input INBOUND_QOS
service-policy output OUTBOUND_QOS
iosxe:
devices:
- name: Device1
configuration:
interfaces:
ethernets:
- type: GigabitEthernet
id: 1/0/6
description: Service policy test interface
service_policy_input: INBOUND_QOS
service_policy_output: OUTBOUND_QOS

IS-IS Point-to-Point with Interface Metrics

Section titled “IS-IS Point-to-Point with Interface Metrics”
interface GigabitEthernet2
ip address 10.1.1.1 255.255.255.252
ip router isis TEST
isis network point-to-point
isis metric 100 level-1
isis metric 200 level-2
iosxe:
devices:
- name: router1
configuration:
routing:
isis_processes:
- area_tag: TEST
nets:
- tag: 49.0001.1920.0000.2001.00
metric_style_wide: true
interfaces:
ethernets:
- type: GigabitEthernet
id: "2"
ipv4:
address: 10.1.1.1
address_mask: 255.255.255.252
isis:
area_tag: TEST
network_point_to_point: true
ipv4_metric_levels:
- level: level-1
value: 100
- level: level-2
value: 200

Ethernet interfaces provide the fundamental physical and logical connectivity for network devices, supporting various speeds from Fast Ethernet (100 Mbps) to multi-gigabit rates (1G, 2.5G, 5G, 10G, 25G, 40G, 100G) with comprehensive Layer 2 switching and Layer 3 routing capabilities. They offer extensive configuration options including switchport modes (access, trunk), VLAN assignments, spanning tree parameters, quality of service policies, security features, and advanced protocols such as OSPF, BFD, and IPv6. Ethernet interfaces serve as the backbone of modern networks, enabling both access layer connectivity for end devices and high-performance trunk links between network infrastructure components while supporting features like port channels, network access control, and comprehensive monitoring capabilities.

Diagram
NameTypeConstraintMandatoryDefault Value
ethernetsList[ethernets]No

ethernets (iosxe.devices.configuration.interfaces)

Section titled “ethernets (iosxe.devices.configuration.interfaces)”
NameTypeConstraintMandatoryDefault Value
typeChoiceGigabitEthernet, FastEthernet, Ethernet, Port-channel, FiveGigabitEthernet, TenGigabitEthernet, TwentyFiveGigE, FortyGigabitEthernet, HundredGigE, TwoHundredGigE, FourHundredGigEYes
idStringYes
managedBooleantrue, falseNotrue
interface_groupsListStringNo
media_typeChoiceauto-select, rj45, sfpNo
bandwidthIntegermin: 1, max: 200000000No
mtuIntegermin: 64, max: 18000No
descriptionStringNo
shutdownBooleantrue, falseNo
vrf_forwardingStringNo
ipv4Class[ipv4]No
ipv6Class[ipv6]No
bfdClass[bfd]No
spanning_treeClass[spanning_tree]No
speedChoice100, 1000, 2500, 5000, 10000, 25000, 40000, 100000, autoNo
speed_nonegotiateBooleantrue, falseNo
port_channel_idIntegermin: 1, max: 512No
port_channel_modeChoiceactive, auto, desirable, on, passiveNo
source_templatesList[source_templates]No
arp_timeoutIntegermin: 0, max: 2147483No
negotiation_autoBooleantrue, falseNo
service_policy_inputStringNo
service_policy_outputStringNo
load_intervalIntegermin: 30, max: 600No
snmp_trap_link_statusBooleantrue, falseNo
logging_event_link_statusBooleantrue, falseNo
device_trackingBooleantrue, falseNo
device_tracking_attached_policiesListStringNo
encapsulation_dot1q_vlan_idIntegermin: 1, max: 4094No
nbar_protocol_discoveryBooleantrue, falseNo
mplsClass[mpls]No
ospfClass[ospf]No
ospfv3Class[ospfv3]No
pimClass[pim]No
igmpClass[igmp]No
switchportClass[switchport]No
network_access_controlClass[network_access_control]No
auto_qosClass[auto_qos]No
cdpBooleantrue, falseNo
cdp_tlv_appBooleantrue, falseNo
cdp_tlv_locationBooleantrue, falseNo
cdp_tlv_server_locationBooleantrue, falseNo

ipv4 (iosxe.devices.configuration.interfaces.ethernets)

Section titled “ipv4 (iosxe.devices.configuration.interfaces.ethernets)”
NameTypeConstraintMandatoryDefault Value
addressIPNo
address_maskIPNo
proxy_arpBooleantrue, falseNo
arp_inspection_trustBooleantrue, falseNo
arp_inspection_limit_rateIntegermin: 0, max: 4294967295No
dhcp_snooping_trustBooleantrue, falseNo
dhcp_relay_source_interface_typeChoiceLoopback, Vlan, GigabitEthernet, FiveGigabitEthernet, TenGigabitEthernet, FortyGigabitEthernet, HundredGigabitEthernet, PortChannelNo
dhcp_relay_source_interface_idAnyString or Integer[min: 0]No
dhcp_relay_information_option_vpn_idBooleantrue, falseNo
helper_addressesList[helper_addresses]No
access_group_inStringNo
access_group_outStringNo
flow_monitorsList[flow_monitors]No
redirectsBooleantrue, falseNo
unreachablesBooleantrue, falseNo
unnumbered_interface_typeChoiceLoopback, Vlan, GigabitEthernet, FiveGigabitEthernet, TenGigabitEthernet, FortyGigabitEthernet, HundredGigabitEthernet, PortChannelNo
unnumbered_interface_idAnyString or Integer[min: 0]No
nat_insideBooleantrue, falseNo
nat_outsideBooleantrue, falseNo

ipv6 (iosxe.devices.configuration.interfaces.ethernets)

Section titled “ipv6 (iosxe.devices.configuration.interfaces.ethernets)”
NameTypeConstraintMandatoryDefault Value
enableBooleantrue, falseNo
addressesList[addresses]No
link_local_addressesListIPNo
address_autoconfig_defaultBooleantrue, falseNo
address_dhcpBooleantrue, falseNo
mtuIntegermin: 1280, max: 9976No
nd_ra_suppress_allBooleantrue, falseNo
flow_monitorsList[flow_monitors]No
pimClass[pim]No

bfd (iosxe.devices.configuration.interfaces.ethernets)

Section titled “bfd (iosxe.devices.configuration.interfaces.ethernets)”
NameTypeConstraintMandatoryDefault Value
templateStringNo
enableBooleantrue, falseNo
local_addressStringNo
intervalIntegermin: 50, max: 9999No
interval_min_rxIntegermin: 50, max: 9999No
interval_multiplierIntegermin: 3, max: 50No
echoBooleantrue, falseNo

spanning_tree (iosxe.devices.configuration.interfaces.ethernets)

Section titled “spanning_tree (iosxe.devices.configuration.interfaces.ethernets)”
NameTypeConstraintMandatoryDefault Value
portfastBooleantrue, falseNo
portfast_disableBooleantrue, falseNo
bpduguardBooleantrue, falseNo
bpduguard_disableBooleantrue, falseNo
guardChoiceloop, none, rootNo
link_typeChoiceshared, point-to-pointNo
portfast_trunkBooleantrue, falseNo
portfast_edgeBooleantrue, falseNo

source_templates (iosxe.devices.configuration.interfaces.ethernets)

Section titled “source_templates (iosxe.devices.configuration.interfaces.ethernets)”
NameTypeConstraintMandatoryDefault Value
nameStringYes
mergeBooleantrue, falseNo

mpls (iosxe.devices.configuration.interfaces.ethernets)

Section titled “mpls (iosxe.devices.configuration.interfaces.ethernets)”
NameTypeConstraintMandatoryDefault Value
ipBooleantrue, falseNo
mtuIntegerNo

ospf (iosxe.devices.configuration.interfaces.ethernets)

Section titled “ospf (iosxe.devices.configuration.interfaces.ethernets)”
NameTypeConstraintMandatoryDefault Value
costIntegermin: 1, max: 65535No
dead_intervalIntegermin: 1, max: 65535No
hello_intervalIntegermin: 1, max: 65535No
mtu_ignoreBooleantrue, falseNo
network_typeChoicebroadcast, non-broadcast, point-to-multipoint, point-to-pointNo
priorityIntegermin: 0, max: 255No
ttl_security_hopsIntegermin: 1, max: 254No
process_idsList[process_ids]No
message_digest_keysList[message_digest_keys]No

ospfv3 (iosxe.devices.configuration.interfaces.ethernets)

Section titled “ospfv3 (iosxe.devices.configuration.interfaces.ethernets)”
NameTypeConstraintMandatoryDefault Value
network_typeChoicebroadcast, non-broadcast, point-to-multipoint, point-to-pointNo
costIntegermin: 1, max: 65535No

pim (iosxe.devices.configuration.interfaces.ethernets)

Section titled “pim (iosxe.devices.configuration.interfaces.ethernets)”
NameTypeConstraintMandatoryDefault Value
passiveBooleantrue, falseNo
dense_modeBooleantrue, falseNo
sparse_modeBooleantrue, falseNo
sparse_dense_modeBooleantrue, falseNo
bfdBooleantrue, falseNo
borderBooleantrue, falseNo
bsr_borderBooleantrue, falseNo
dr_priorityIntegermin: 0, max: 4294967294No

igmp (iosxe.devices.configuration.interfaces.ethernets)

Section titled “igmp (iosxe.devices.configuration.interfaces.ethernets)”
NameTypeConstraintMandatoryDefault Value
versionIntegermin: 1, max: 3No

switchport (iosxe.devices.configuration.interfaces.ethernets)

Section titled “switchport (iosxe.devices.configuration.interfaces.ethernets)”
NameTypeConstraintMandatoryDefault Value
enableBooleantrue, falseNo
modeChoiceaccess, dot1q-tunnel, private-vlan-trunk, private-vlan-host, private-vlan-promiscuous, trunkNo
nonegotiateBooleantrue, falseNo
access_vlanIntegermin: 1, max: 4094No
trunk_allowed_vlansClass[trunk_allowed_vlans]No
trunk_allowed_vlans_legacyClass[trunk_allowed_vlans_legacy]No
trunk_native_vlan_tagBooleantrue, falseNo
trunk_native_vlan_idIntegermin: 1, max: 4094No
hostBooleantrue, falseNo

network_access_control (iosxe.devices.configuration.interfaces.ethernets)

Section titled “network_access_control (iosxe.devices.configuration.interfaces.ethernets)”
NameTypeConstraintMandatoryDefault Value
authentication_periodicBooleantrue, falseNo
authentication_timer_reauthenticateIntegermin: 1, max: 1073741823No
authentication_timer_reauthenticate_serverBooleantrue, falseNo
mabBooleantrue, falseNo
mab_eapBooleantrue, falseNo
dot1x_paeChoiceauthenticator, supplicant, bothNo
dot1x_timeout_auth_periodIntegermin: 1, max: 65535No
dot1x_timeout_held_periodIntegermin: 1, max: 65535No
dot1x_timeout_quiet_periodIntegermin: 1, max: 65535No
dot1x_timeout_ratelimit_periodIntegermin: 1, max: 65535No
dot1x_timeout_server_timeoutIntegermin: 1, max: 65535No
dot1x_timeout_start_periodIntegermin: 1, max: 65535No
dot1x_timeout_supp_timeoutIntegermin: 1, max: 65535No
dot1x_timeout_tx_periodIntegermin: 1, max: 65535No
dot1x_max_reqIntegermin: 1, max: 10No
dot1x_max_reauth_reqIntegermin: 1, max: 10No

auto_qos (iosxe.devices.configuration.interfaces.ethernets)

Section titled “auto_qos (iosxe.devices.configuration.interfaces.ethernets)”
NameTypeConstraintMandatoryDefault Value
classifyBooleantrue, falseNo
classify_policeBooleantrue, falseNo
trustBooleantrue, falseNo
trust_cosBooleantrue, falseNo
trust_dscpBooleantrue, falseNo
video_ctsBooleantrue, falseNo
video_ip_cameraBooleantrue, falseNo
video_media_playerBooleantrue, falseNo
voipBooleantrue, falseNo
voip_cisco_phoneBooleantrue, falseNo
voip_cisco_softphoneBooleantrue, falseNo
voip_trustBooleantrue, falseNo
trust_deviceChoicecisco-phone, cts, ip-camera, media-playerNo

helper_addresses (iosxe.devices.configuration.interfaces.ethernets.ipv4)

Section titled “helper_addresses (iosxe.devices.configuration.interfaces.ethernets.ipv4)”
NameTypeConstraintMandatoryDefault Value
addressIPYes
globalBooleantrue, falseNo
vrfStringNo

flow_monitors (iosxe.devices.configuration.interfaces.ethernets.ipv4)

Section titled “flow_monitors (iosxe.devices.configuration.interfaces.ethernets.ipv4)”
NameTypeConstraintMandatoryDefault Value
nameStringYes
directionChoiceinput, outputYes

addresses (iosxe.devices.configuration.interfaces.ethernets.ipv6)

Section titled “addresses (iosxe.devices.configuration.interfaces.ethernets.ipv6)”
NameTypeConstraintMandatoryDefault Value
prefixIPYes
eui_64Booleantrue, falseNo

pim (iosxe.devices.configuration.interfaces.ethernets.ipv6)

Section titled “pim (iosxe.devices.configuration.interfaces.ethernets.ipv6)”
NameTypeConstraintMandatoryDefault Value
pimBooleantrue, falseNo
bfdBooleantrue, falseNo
bsr_borderBooleantrue, falseNo
dr_priorityIntegermin: 0, max: 4294967295No

process_ids (iosxe.devices.configuration.interfaces.ethernets.ospf)

Section titled “process_ids (iosxe.devices.configuration.interfaces.ethernets.ospf)”
NameTypeConstraintMandatoryDefault Value
idIntegermin: 1, max: 65535No
areasListAny[String or Integer[min: 0]]No

message_digest_keys (iosxe.devices.configuration.interfaces.ethernets.ospf)

Section titled “message_digest_keys (iosxe.devices.configuration.interfaces.ethernets.ospf)”
NameTypeConstraintMandatoryDefault Value
idIntegermin: 1, max: 255Yes
md5_auth_keyStringNo
md5_auth_typeChoice0, 7No

trunk_allowed_vlans (iosxe.devices.configuration.interfaces.ethernets.switchport)

Section titled “trunk_allowed_vlans (iosxe.devices.configuration.interfaces.ethernets.switchport)”
NameTypeConstraintMandatoryDefault Value
allBooleantrue, falseNo
noneBooleantrue, falseNo
vlansClass[vlans]No
addClass[add]No
exceptClass[except]No
removeClass[remove]No

trunk_allowed_vlans_legacy (iosxe.devices.configuration.interfaces.ethernets.switchport)

Section titled “trunk_allowed_vlans_legacy (iosxe.devices.configuration.interfaces.ethernets.switchport)”
NameTypeConstraintMandatoryDefault Value
idsListInteger[min: 1, max: 4094]No
rangesList[ranges]No

vlans (iosxe.devices.configuration.interfaces.ethernets.switchport.trunk_allowed_vlans)

Section titled “vlans (iosxe.devices.configuration.interfaces.ethernets.switchport.trunk_allowed_vlans)”
NameTypeConstraintMandatoryDefault Value
idsListInteger[min: 1, max: 4094]No
rangesList[ranges]No

add (iosxe.devices.configuration.interfaces.ethernets.switchport.trunk_allowed_vlans)

Section titled “add (iosxe.devices.configuration.interfaces.ethernets.switchport.trunk_allowed_vlans)”
NameTypeConstraintMandatoryDefault Value
idsListInteger[min: 1, max: 4094]No
rangesList[ranges]No

except (iosxe.devices.configuration.interfaces.ethernets.switchport.trunk_allowed_vlans)

Section titled “except (iosxe.devices.configuration.interfaces.ethernets.switchport.trunk_allowed_vlans)”
NameTypeConstraintMandatoryDefault Value
idsListInteger[min: 1, max: 4094]No
rangesList[ranges]No

remove (iosxe.devices.configuration.interfaces.ethernets.switchport.trunk_allowed_vlans)

Section titled “remove (iosxe.devices.configuration.interfaces.ethernets.switchport.trunk_allowed_vlans)”
NameTypeConstraintMandatoryDefault Value
idsListInteger[min: 1, max: 4094]No
rangesList[ranges]No

ranges (iosxe.devices.configuration.interfaces.ethernets.switchport.trunk_allowed_vlans_legacy)

Section titled “ranges (iosxe.devices.configuration.interfaces.ethernets.switchport.trunk_allowed_vlans_legacy)”
NameTypeConstraintMandatoryDefault Value
fromIntegermin: 1, max: 4094Yes
toIntegermin: 1, max: 4094Yes

  • managed attribute: Controls whether Terraform continuously manages the interface configuration. When set to false, Terraform will push the initial configuration but will not continuously read it, detect drift, or reconcile changes. This is useful for:

    • Interfaces whose configuration changes dynamically due to authorization policies
    • Interfaces modified by local scripts or automation
    • Interfaces where configuration drift should be allowed and not corrected
    • Default: true (Terraform fully manages the interface and reconciles drift)
  • Usage example:

    interfaces:
    ethernets:
    - id: 1/0/1
    type: GigabitEthernet
    description: Dynamic interface
    managed: false # Terraform pushes initial config but ignores subsequent changes
  • spanning_tree_portfast_edge attribute limitation: The spanning_tree_portfast_edge attribute uses a deprecated YANG model path (spanning-tree/portfast/edge) that does not translate to valid CLI commands on Catalyst switch platforms. While the YANG model accepts this configuration for backward compatibility with routers or older platforms, modern Catalyst switches (including Catalyst 9000 series) do not support the spanning-tree portfast edge CLI command. Attempting to configure this attribute on Catalyst switches will result in device configuration rejection errors (“inconsistent value: Device refused one or more commands”).

  • Recommended alternatives for Catalyst switches:

    • For access ports: Use spanning_tree_portfast: true (translates to spanning-tree portfast)
    • For trunk ports: Use spanning_tree_portfast_trunk: true (translates to spanning-tree portfast trunk)
    • Both options provide the same portfast functionality and are fully supported on Catalyst platforms
  • Portfast and guard mutual exclusivity: The spanning-tree portfast variants (portfast, portfast_disable, portfast_trunk) and guard options (loop, root, none) serve different purposes:

    • Portfast enables immediate forwarding for edge ports connecting to end devices
    • Guard protects against topology loops (loop) or unauthorized root bridges (root)
    • These can be configured together on the same interface for comprehensive protection
  • BPDU guard configuration: BPDU guard (bpduguard: true or bpduguard_disable: true) can be configured alongside any portfast variant to protect against unauthorized switches. When global BPDU guard is enabled (spanning-tree portfast bpduguard default), use bpduguard_disable: true to selectively disable it on specific interfaces.

iosxe:
devices:
- name: Device1
configuration:
interfaces:
ethernets:
- id: 1/1
type: GigabitEthernet
description: Server 1 Interface
speed: 1000
port_channel_id: 10
port_channel_mode: active
switchport:
mode: access
access_vlan: 100
spanning_tree:
guard: loop
iosxe:
devices:
- name: Device1
configuration:
interfaces:
ethernets:
- type: GigabitEthernet
id: 1/0/2
description: L3 interface
vrf_forwarding: "VRF-PROD"
speed: 10000
arp_timeout: 300
load_interval: 90
snmp_trap_link_status: false
logging_event_link_status: false
ipv4:
arp_inspection_limit_rate: 40
arp_inspection_trust: true
address: 192.168.100.1
address_mask: 255.255.255.0
proxy_arp: true
dhcp_relay_source_interface: Gig1/0/1
helper_addresses:
- address: 10.1.1.1
access_group_in: ACL-IN
access_group_out: ACL-OUT
redirects: false
unreachables: false
flow_monitors:
- name: FLOW1
direction: input
ipv6:
enable: true
addresses:
- prefix: 2001::1
prefix_length: 64
eui64: true
link_local_addresses:
- fe80::1
mtu: 1450
nd_ra_suppress_all: true
bfd:
enable: true
local_address: 172.16.1.1
interval: 100
interval_multiplier: 3
interval_min_rx: 101
echo: false
ospf:
cost: 10
dead_interval: 40
hello_interval: 11
mtu_ignore: false
network_type: point-to-point
priority: 1
ttl_security_hops: 2
process_ids:
- id: 1
areas:
- "0"
message_digest_keys:
- id: 1
md5_auth_key: "cisco"
md5_auth_type: "0"
ospfv3:
cost: 10
network_type: point-to-point
igmp:
version: 2
# Example 1: Standard access port with portfast and bpduguard
iosxe:
devices:
- name: Device1
configuration:
interfaces:
ethernets:
- type: GigabitEthernet
id: 1/0/1
description: Access port with portfast
spanning_tree:
portfast: true
bpduguard: true
guard: root
switchport:
enable: true
mode: access
# Example 2: Trunk port with portfast_trunk
iosxe:
devices:
- name: Device1
configuration:
interfaces:
ethernets:
- type: GigabitEthernet
id: 1/0/2
description: Trunk port with portfast
speed: 2500
speed_nonegotiate: false
spanning_tree:
portfast_trunk: true
bpduguard: true
link_type: shared
switchport:
mode: trunk
trunk_allowed_vlans:
vlans:
ids: [30, 32]
ranges:
- from: 10
to: 20
trunk_native_vlan_id: 5
# Example 3: Port with portfast and loop guard
iosxe:
devices:
- name: Device1
configuration:
interfaces:
ethernets:
- type: GigabitEthernet
id: 1/0/3
description: Port with portfast and loop guard
spanning_tree:
portfast: true
guard: loop
switchport:
enable: true
mode: access
# Example 4: Explicitly disable portfast (useful when global portfast is enabled)
iosxe:
devices:
- name: Device1
configuration:
interfaces:
ethernets:
- type: GigabitEthernet
id: 1/0/4
description: Port with portfast disabled
spanning_tree:
portfast_disable: true
guard: loop
switchport:
enable: true
mode: access
# Example 5: Port with bpduguard_disable (useful when global bpduguard is enabled)
iosxe:
devices:
- name: Device1
configuration:
interfaces:
ethernets:
- type: GigabitEthernet
id: 1/0/5
description: Port with bpduguard disabled
spanning_tree:
bpduguard_disable: true
link_type: point-to-point
switchport:
enable: true
mode: access

You can configure a trunk switchport to explicitly allow all VLANs as shown below.

iosxe:
devices:
- name: Device1
configuration:
interfaces:
ethernets:
- type: GigabitEthernet
id: 1/0/6
switchport:
mode: trunk
trunk_allowed_vlans:
all: true

Additionally, by default, all VLANs are allowed on a trunk switchport if no VLANs are explicitly allowed, mimicking native Cisco IOS-XE behavior. An example is shown below.

iosxe:
devices:
- name: Device1
configuration:
interfaces:
ethernets:
- type: GigabitEthernet
id: 1/0/7
switchport:
mode: trunk

You can configure a trunk switchport to explicitly allow no VLANs as shown below.

iosxe:
devices:
- name: Device1
configuration:
interfaces:
ethernets:
- type: GigabitEthernet
id: 1/0/8
switchport:
mode: trunk
trunk_allowed_vlans:
none: true

You can configure a trunk switchport to allow a range of VLANs as shown below.

iosxe:
devices:
- name: Device1
configuration:
interfaces:
ethernets:
- type: GigabitEthernet
id: 1/0/9
switchport:
mode: trunk
trunk_allowed_vlans:
vlans:
ranges:
- from: 100
to: 200

You can configure a trunk switchport to allow all VLANs except for specific VLANs as shown below.

iosxe:
devices:
- name: Device1
configuration:
interfaces:
ethernets:
- type: GigabitEthernet
id: 1/0/10
switchport:
mode: trunk
trunk_allowed_vlans:
except:
ids:
- 999

You can configure a trunk switchport to allow specific VLANs alongside a range of VLANs as shown below.

iosxe:
devices:
- name: Device1
configuration:
interfaces:
ethernets:
- type: GigabitEthernet
id: 1/0/11
switchport:
mode: trunk
trunk_allowed_vlans:
vlans:
ids:
- 100
- 200
ranges:
- from: 300
to: 400

Example configuring DHCP Relay information option vpn-id.

Cisco IOS-XE CLI Equivalent:

interface GigabitEthernet2
ip dhcp relay information option vpn-id

NAC YAML Configuration:

iosxe:
devices:
- name: router
configuration:
interfaces:
ethernets:
- type: GigabitEthernet
id: '2'
ipv4:
dhcp_relay_information_option_vpn_id: true
- type: GigabitEthernet
id: '3'
ipv4:
dhcp_relay_information_option_vpn_id: true