Skip to content

Port Channel

Port Channel interfaces provide link aggregation capabilities that combine multiple physical Ethernet interfaces into a single logical interface, delivering increased bandwidth, redundancy, and load distribution across member interfaces using protocols such as LACP (Link Aggregation Control Protocol) or static configuration. They enable seamless failover when individual member links fail while maintaining session continuity, and support both Layer 2 switching with VLAN trunking and Layer 3 routing with comprehensive protocol support including OSPF, BGP, and spanning tree participation. Port Channels are fundamental for building resilient network infrastructures, enabling high-bandwidth connections between switches, servers, and storage systems while providing the flexibility to scale bandwidth incrementally and ensure network availability through redundant path management.

Diagram
NameTypeConstraintMandatoryDefault Value
port_channelsList[port_channels]No

port_channels (iosxe.devices.configuration.interfaces)

Section titled “port_channels (iosxe.devices.configuration.interfaces)”
NameTypeConstraintMandatoryDefault Value
idIntegerYes
interface_groupsListStringNo
interface_group_policyChoicemerge, replaceNo
descriptionStringNo
shutdownBooleantrue, falseNo
mtuIntegermin: 64, max: 18000No
vrf_forwardingStringNo
ipv4Class[ipv4]No
ipv6Class[ipv6]No
bfdClass[bfd]No
spanning_treeClass[spanning_tree]No
arp_timeoutIntegermin: 0, max: 2147483No
load_intervalIntegermin: 30, max: 600No
snmp_trap_link_statusBooleantrue, falseNo
logging_event_link_statusBooleantrue, falseNo
mplsClass[mpls]No
ospfClass[ospf]No
ospfv3Class[ospfv3]No
isisClass[isis]No
pimClass[pim]No
igmpClass[igmp]No
switchportClass[switchport]No
subinterfacesList[subinterfaces]No
auto_qosClass[auto_qos]No
negotiation_autoBooleantrue, falseNo
evpn_ethernet_segmentsList[evpn_ethernet_segments]No
evpn_ethernet_segments_legacyList[evpn_ethernet_segments_legacy]No
vrrp_v2List[vrrp_v2]No
zone_member_securityStringNo

ipv4 (iosxe.devices.configuration.interfaces.port_channels)

Section titled “ipv4 (iosxe.devices.configuration.interfaces.port_channels)”
NameTypeConstraintMandatoryDefault Value
addressIPNo
address_maskIPNo
proxy_arpBooleantrue, falseNo
arp_inspection_trustBooleantrue, falseNo
arp_inspection_limit_rateIntegermin: 0, max: 4294967295No
dhcp_snooping_trustBooleantrue, falseNo
dhcp_relay_source_interface_typeChoiceLoopback, Vlan, GigabitEthernet, TwoGigabitEthernet, FiveGigabitEthernet, TenGigabitEthernet, TwentyFiveGigabitEthernet, FortyGigabitEthernet, FiftyGigabitEthernet, HundredGigabitEthernet, PortChannelNo
dhcp_relay_source_interface_idAnyString or Integer[min: 0]No
dhcp_relay_information_option_vpn_idBooleantrue, falseNo
helper_addressesList[helper_addresses]No
access_group_inStringNo
access_group_outStringNo
flow_monitorsList[flow_monitors]No
redirectsBooleantrue, falseNo
unreachablesBooleantrue, falseNo
unnumbered_interface_typeChoiceLoopback, Vlan, GigabitEthernet, TwoGigabitEthernet, FiveGigabitEthernet, TenGigabitEthernet, TwentyFiveGigabitEthernet, FortyGigabitEthernet, FiftyGigabitEthernet, HundredGigabitEthernet, PortChannelNo
unnumbered_interface_idAnyString or Integer[min: 0]No
nat_insideBooleantrue, falseNo
nat_outsideBooleantrue, falseNo
address_dhcpBooleantrue, falseNo
verify_unicast_source_reachable_viaChoiceany, rxNo
verify_unicast_source_allow_self_pingBooleantrue, falseNo
verify_unicast_source_allow_defaultBooleantrue, falseNo

ipv6 (iosxe.devices.configuration.interfaces.port_channels)

Section titled “ipv6 (iosxe.devices.configuration.interfaces.port_channels)”
NameTypeConstraintMandatoryDefault Value
enableBooleantrue, falseNo
addressesList[addresses]No
link_local_addressesListIPNo
address_autoconfig_defaultBooleantrue, falseNo
address_dhcpBooleantrue, falseNo
mtuIntegermin: 1280, max: 9976No
nd_ra_suppress_allBooleantrue, falseNo
flow_monitorsList[flow_monitors]No
pimClass[pim]No

bfd (iosxe.devices.configuration.interfaces.port_channels)

Section titled “bfd (iosxe.devices.configuration.interfaces.port_channels)”
NameTypeConstraintMandatoryDefault Value
templateStringNo
enableBooleantrue, falseNo
local_addressIPNo
intervalIntegermin: 50, max: 9999No
interval_min_rxIntegermin: 50, max: 9999No
interval_multiplierIntegermin: 3, max: 50No
echoBooleantrue, falseNo

spanning_tree (iosxe.devices.configuration.interfaces.port_channels)

Section titled “spanning_tree (iosxe.devices.configuration.interfaces.port_channels)”
NameTypeConstraintMandatoryDefault Value
portfastBooleantrue, falseNo
portfast_disableBooleantrue, falseNo
bpduguardBooleantrue, falseNo
bpduguard_disableBooleantrue, falseNo
guardChoiceloop, none, rootNo
link_typeChoiceshared, point-to-pointNo
portfast_trunkBooleantrue, falseNo
portfast_edgeBooleantrue, falseNo

mpls (iosxe.devices.configuration.interfaces.port_channels)

Section titled “mpls (iosxe.devices.configuration.interfaces.port_channels)”
NameTypeConstraintMandatoryDefault Value
ipBooleantrue, falseNo
mtuIntegerNo

ospf (iosxe.devices.configuration.interfaces.port_channels)

Section titled “ospf (iosxe.devices.configuration.interfaces.port_channels)”
NameTypeConstraintMandatoryDefault Value
authentication_key_chainStringNo
authentication_message_digestBooleantrue, falseNo
authentication_nullBooleantrue, falseNo
costIntegermin: 1, max: 65535No
dead_intervalIntegermin: 1, max: 65535No
hello_intervalIntegermin: 1, max: 65535No
message_digest_keysList[message_digest_keys]No
mtu_ignoreBooleantrue, falseNo
multi_area_idsListAny[String or Integer[min: 0]]No
network_typeChoicebroadcast, non-broadcast, point-to-multipoint, point-to-pointNo
priorityIntegermin: 0, max: 255No
process_idsList[process_ids]No
ttl_security_hopsIntegermin: 1, max: 254No

ospfv3 (iosxe.devices.configuration.interfaces.port_channels)

Section titled “ospfv3 (iosxe.devices.configuration.interfaces.port_channels)”
NameTypeConstraintMandatoryDefault Value
bfdBooleantrue, falseNo
costIntegermin: 1, max: 65535No
dead_intervalIntegermin: 1, max: 65535No
hello_intervalIntegermin: 1, max: 65535No
mtu_ignoreBooleantrue, falseNo
network_typeChoicebroadcast, non-broadcast, point-to-multipoint, point-to-pointNo
priorityIntegermin: 0, max: 255No

isis (iosxe.devices.configuration.interfaces.port_channels)

Section titled “isis (iosxe.devices.configuration.interfaces.port_channels)”
NameTypeConstraintMandatoryDefault Value
area_tagStringNo
ipv4_metric_levelsList[ipv4_metric_levels]No
network_point_to_pointBooleantrue, falseNo

pim (iosxe.devices.configuration.interfaces.port_channels)

Section titled “pim (iosxe.devices.configuration.interfaces.port_channels)”
NameTypeConstraintMandatoryDefault Value
passiveBooleantrue, falseNo
dense_modeBooleantrue, falseNo
sparse_modeBooleantrue, falseNo
sparse_dense_modeBooleantrue, falseNo
bfdBooleantrue, falseNo
borderBooleantrue, falseNo
bsr_borderBooleantrue, falseNo
dr_priorityIntegermin: 0, max: 4294967294No

igmp (iosxe.devices.configuration.interfaces.port_channels)

Section titled “igmp (iosxe.devices.configuration.interfaces.port_channels)”
NameTypeConstraintMandatoryDefault Value
versionIntegermin: 1, max: 3No

switchport (iosxe.devices.configuration.interfaces.port_channels)

Section titled “switchport (iosxe.devices.configuration.interfaces.port_channels)”
NameTypeConstraintMandatoryDefault Value
enableBooleantrue, falseNo
modeChoiceaccess, dot1q-tunnel, private-vlan-trunk, private-vlan-host, private-vlan-promiscuous, trunkNo
nonegotiateBooleantrue, falseNo
access_vlanIntegermin: 1, max: 4094No
voice_vlanAnyInteger[min: 1, max: 4094] or Choice[dot1p, none, untagged] or String[Regex: ^.*[\$\%]\{.*$]No
trunk_allowed_vlansClass[trunk_allowed_vlans]No
trunk_allowed_vlans_legacyClass[trunk_allowed_vlans_legacy]No
trunk_native_vlan_tagBooleantrue, falseNo
trunk_native_vlan_idIntegermin: 1, max: 4094No
hostBooleantrue, falseNo

subinterfaces (iosxe.devices.configuration.interfaces.port_channels)

Section titled “subinterfaces (iosxe.devices.configuration.interfaces.port_channels)”
NameTypeConstraintMandatoryDefault Value
idStringYes
descriptionStringNo
shutdownBooleantrue, falseNo
vrf_forwardingStringNo
ip_mtuIntegermin: 68, max: 18000No
ipv4Class[ipv4]No
ipv6Class[ipv6]No
bfdClass[bfd]No
encapsulation_dot1q_vlan_idIntegermin: 1, max: 4094No
arp_timeoutIntegermin: 0, max: 2147483No
auto_qosClass[auto_qos]No
mplsClass[mpls]No
ospfClass[ospf]No
ospfv3Class[ospfv3]No
isisClass[isis]No
pimClass[pim]No
igmpClass[igmp]No
vrrp_v2List[vrrp_v2]No
zone_member_securityStringNo

auto_qos (iosxe.devices.configuration.interfaces.port_channels)

Section titled “auto_qos (iosxe.devices.configuration.interfaces.port_channels)”
NameTypeConstraintMandatoryDefault Value
classifyBooleantrue, falseNo
classify_policeBooleantrue, falseNo
trustBooleantrue, falseNo
trust_cosBooleantrue, falseNo
trust_dscpBooleantrue, falseNo
video_ctsBooleantrue, falseNo
video_ip_cameraBooleantrue, falseNo
video_media_playerBooleantrue, falseNo
voip_cisco_phoneBooleantrue, falseNo
voip_cisco_softphoneBooleantrue, falseNo
voip_trustBooleantrue, falseNo
trust_deviceChoicecisco-phone, cts, ip-camera, media-playerNo

evpn_ethernet_segments (iosxe.devices.configuration.interfaces.port_channels)

Section titled “evpn_ethernet_segments (iosxe.devices.configuration.interfaces.port_channels)”
NameTypeConstraintMandatoryDefault Value
es_valueIntegermin: 1, max: 65535Yes

evpn_ethernet_segments_legacy (iosxe.devices.configuration.interfaces.port_channels)

Section titled “evpn_ethernet_segments_legacy (iosxe.devices.configuration.interfaces.port_channels)”
NameTypeConstraintMandatoryDefault Value
es_valueIntegermin: 1, max: 65535Yes

vrrp_v2 (iosxe.devices.configuration.interfaces.port_channels)

Section titled “vrrp_v2 (iosxe.devices.configuration.interfaces.port_channels)”
NameTypeConstraintMandatoryDefault Value
group_idIntegermin: 1, max: 255Yes
ip_primary_addressIPNo
ip_secondary_addressesListIPNo
priorityIntegermin: 1, max: 254No
preemptBooleantrue, falseNo
preempt_delay_minimumIntegermin: 0, max: 3600No
timers_advertise_intervalIntegermin: 1, max: 255No
authentication_textStringNo
descriptionStringNo
tracksList[tracks]No
shutdownBooleantrue, falseNo

helper_addresses (iosxe.devices.configuration.interfaces.port_channels.ipv4)

Section titled “helper_addresses (iosxe.devices.configuration.interfaces.port_channels.ipv4)”
NameTypeConstraintMandatoryDefault Value
addressIPYes
globalBooleantrue, falseNo
vrfStringNo

flow_monitors (iosxe.devices.configuration.interfaces.port_channels.ipv4)

Section titled “flow_monitors (iosxe.devices.configuration.interfaces.port_channels.ipv4)”
NameTypeConstraintMandatoryDefault Value
nameStringYes
directionChoiceinput, outputYes

addresses (iosxe.devices.configuration.interfaces.port_channels.ipv6)

Section titled “addresses (iosxe.devices.configuration.interfaces.port_channels.ipv6)”
NameTypeConstraintMandatoryDefault Value
prefixIPYes
eui_64Booleantrue, falseNo

pim (iosxe.devices.configuration.interfaces.port_channels.ipv6)

Section titled “pim (iosxe.devices.configuration.interfaces.port_channels.ipv6)”
NameTypeConstraintMandatoryDefault Value
pimBooleantrue, falseNo
bfdBooleantrue, falseNo
bsr_borderBooleantrue, falseNo
dr_priorityIntegermin: 0, max: 4294967295No

message_digest_keys (iosxe.devices.configuration.interfaces.port_channels.ospf)

Section titled “message_digest_keys (iosxe.devices.configuration.interfaces.port_channels.ospf)”
NameTypeConstraintMandatoryDefault Value
idIntegermin: 1, max: 255Yes
md5_auth_keyStringNo
md5_auth_typeChoice0, 7No

process_ids (iosxe.devices.configuration.interfaces.port_channels.ospf)

Section titled “process_ids (iosxe.devices.configuration.interfaces.port_channels.ospf)”
NameTypeConstraintMandatoryDefault Value
idIntegermin: 1, max: 65535No
areasListAny[String or Integer[min: 0]]No

ipv4_metric_levels (iosxe.devices.configuration.interfaces.port_channels.isis)

Section titled “ipv4_metric_levels (iosxe.devices.configuration.interfaces.port_channels.isis)”
NameTypeConstraintMandatoryDefault Value
levelChoicelevel-1, level-2Yes
valueIntegermin: 1, max: 16777214Yes

trunk_allowed_vlans (iosxe.devices.configuration.interfaces.port_channels.switchport)

Section titled “trunk_allowed_vlans (iosxe.devices.configuration.interfaces.port_channels.switchport)”
NameTypeConstraintMandatoryDefault Value
allBooleantrue, falseNo
noneBooleantrue, falseNo
vlansClass[vlans]No
addClass[add]No
exceptClass[except]No
removeClass[remove]No

trunk_allowed_vlans_legacy (iosxe.devices.configuration.interfaces.port_channels.switchport)

Section titled “trunk_allowed_vlans_legacy (iosxe.devices.configuration.interfaces.port_channels.switchport)”
NameTypeConstraintMandatoryDefault Value
idsListInteger[min: 1, max: 4094]No
rangesList[ranges]No

tracks (iosxe.devices.configuration.interfaces.port_channels.vrrp_v2)

Section titled “tracks (iosxe.devices.configuration.interfaces.port_channels.vrrp_v2)”
NameTypeConstraintMandatoryDefault Value
object_idIntegermin: 1, max: 1000Yes
decrementIntegermin: 1, max: 255No

vlans (iosxe.devices.configuration.interfaces.port_channels.switchport.trunk_allowed_vlans)

Section titled “vlans (iosxe.devices.configuration.interfaces.port_channels.switchport.trunk_allowed_vlans)”
NameTypeConstraintMandatoryDefault Value
idsListInteger[min: 1, max: 4094]No
rangesList[ranges]No

add (iosxe.devices.configuration.interfaces.port_channels.switchport.trunk_allowed_vlans)

Section titled “add (iosxe.devices.configuration.interfaces.port_channels.switchport.trunk_allowed_vlans)”
NameTypeConstraintMandatoryDefault Value
idsListInteger[min: 1, max: 4094]No
rangesList[ranges]No

except (iosxe.devices.configuration.interfaces.port_channels.switchport.trunk_allowed_vlans)

Section titled “except (iosxe.devices.configuration.interfaces.port_channels.switchport.trunk_allowed_vlans)”
NameTypeConstraintMandatoryDefault Value
idsListInteger[min: 1, max: 4094]No
rangesList[ranges]No

remove (iosxe.devices.configuration.interfaces.port_channels.switchport.trunk_allowed_vlans)

Section titled “remove (iosxe.devices.configuration.interfaces.port_channels.switchport.trunk_allowed_vlans)”
NameTypeConstraintMandatoryDefault Value
idsListInteger[min: 1, max: 4094]No
rangesList[ranges]No

ranges (iosxe.devices.configuration.interfaces.port_channels.switchport.trunk_allowed_vlans_legacy)

Section titled “ranges (iosxe.devices.configuration.interfaces.port_channels.switchport.trunk_allowed_vlans_legacy)”
NameTypeConstraintMandatoryDefault Value
fromIntegermin: 1, max: 4094Yes
toIntegermin: 1, max: 4094Yes

IP Address Reassignment Between Interfaces

Section titled “IP Address Reassignment Between Interfaces”

IOS-XE enforces IP address uniqueness within the same VRF — no two interfaces can hold the same IP address simultaneously. When swapping IP addresses between two interfaces (for example, moving 10.1.1.1 from Port-channel1 to Port-channel2 and vice versa), terraform apply will fail because Terraform updates both interfaces in parallel without awareness of the cross-resource conflict. The device rejects the new IP assignment with an “inconsistent value: Device refused one or more commands” error because the target IP still exists on the other interface.

To perform an IP swap, apply the change in two steps:

  1. Remove the IP addresses from both interfaces (delete the ipv4 block or assign temporary addresses) and run terraform apply.
  2. Set the new desired IP addresses and run terraform apply a second time.

Port channel ranges allow defining multiple port channels with identical configuration using a from/to range. Range entries are lightweight — they only specify from, to, and interface_groups. All configuration must be defined in the referenced interface groups.

  • Port channel IDs are integers, so the range is a simple numeric sequence
  • Multiple ranges are supported
  • Overlapping ranges or ranges that overlap with individual port channel entries will produce errors when terraform plan is executed

Example:

iosxe:
interface_groups:
- name: L3_PORT_CHANNEL
configuration:
switchport:
enable: false
ipv4:
proxy_arp: false
devices:
- name: Switch1
configuration:
interfaces:
ranges:
port_channels:
- from: 1
to: 10
interface_groups: [L3_PORT_CHANNEL]
interface Port-channel1
description Layer 3 Port Channel to Core
no switchport
vrf forwarding PRODUCTION
ip address 192.168.10.1 255.255.255.252
no ip proxy-arp
no ip redirects
no ip unreachables
ip verify unicast source reachable-via any allow-default
ipv6 address 2001:db8:10::1/64
ipv6 enable
ipv6 address fe80::1 link-local
bfd enable
bfd interval 100 min_rx 100 multiplier 3
ip ospf cost 10
ip ospf network point-to-point
ip ospf 10 area 0
ip igmp version 2
vrrp 1 ip 192.168.10.254
vrrp 1 priority 110
vrrp 1 preempt delay minimum 30
vrrp 1 timers advertise 3
vrrp 1 authentication text SECRET
vrrp 1 description VRRP-PORTCHANNEL
vrrp 1 track 1 decrement 20
vrrp 1 shutdown
iosxe:
devices:
- name: Device1
configuration:
vrfs:
- name: PRODUCTION
address_family_ipv4:
enable: true
address_family_ipv6:
enable: true
routing:
ospf_processes:
- id: 10
vrf: PRODUCTION
interfaces:
port_channels:
- id: 1
description: Layer 3 Port Channel to Core
shutdown: false
mtu: 9000
switchport:
enable: false
vrf_forwarding: PRODUCTION
ipv4:
address: 192.168.10.1
address_mask: 255.255.255.252
address_dhcp: true
proxy_arp: false
redirects: false
unreachables: false
verify_unicast_source_reachable_via: any
verify_unicast_source_allow_default: true
ipv6:
enable: true
addresses:
- prefix: 2001:db8:10::1/64
link_local_addresses:
- fe80::1
pim:
dr_priority: 100
bfd:
enable: true
interval: 100
interval_multiplier: 3
interval_min_rx: 100
ospf:
cost: 10
network_type: point-to-point
process_ids:
- id: 10
areas:
- "0"
igmp:
version: 2
vrrp_v2:
- group_id: 1
ip_primary_address: 192.168.10.254
priority: 110
preempt: true
preempt_delay_minimum: 30
timers_advertise_interval: 3
authentication_text: SECRET
description: VRRP-PORTCHANNEL
shutdown: true
tracks:
- object_id: 1
decrement: 20
interface Port-channel10
description Layer 2 Trunk to Access Switch
switchport mode trunk
switchport trunk allowed vlan 10,20,30,100-200
switchport trunk native vlan 1
switchport nonegotiate
spanning-tree guard root
spanning-tree link-type point-to-point
load-interval 30
snmp trap link-status
iosxe:
devices:
- name: Device1
configuration:
interfaces:
port_channels:
- id: 10
description: Layer 2 Trunk to Access Switch
shutdown: false
switchport:
mode: trunk
trunk_allowed_vlans:
vlans:
ids: [10, 20, 30]
ranges:
- from: 100
to: 200
trunk_native_vlan_id: 1
nonegotiate: true
spanning_tree:
guard: root
link_type: point-to-point
load_interval: 30
snmp_trap_link_status: true

Layer 2 Access Port Channel with Voice VLAN

Section titled “Layer 2 Access Port Channel with Voice VLAN”
interface Port-channel15
description Access Port Channel to IP Phone
switchport mode access
switchport access vlan 100
switchport voice vlan 900
iosxe:
devices:
- name: Device1
configuration:
interfaces:
port_channels:
- id: 15
description: Access Port Channel to IP Phone
shutdown: false
switchport:
mode: access
access_vlan: 100
voice_vlan: 900

The voice_vlan attribute supports integer VLAN IDs (1-4094) and keywords (dot1p, none, untagged).

interface Port-channel20
description Channel
no switchport
ipv6 address dhcp
iosxe:
devices:
- name: Device1
configuration:
interfaces:
port_channels:
- id: 20
description: Channel
ipv6:
enable: true
address_dhcp: true
switchport:
enable: false

Example configuring a port channel using an interface group. The interface_groups attribute is a NAC abstraction that applies shared configuration from a named group at template render time. The resulting device CLI reflects the fully merged configuration - interface_groups does not appear as a CLI command.

interface Port-channel11
description Shared Configuration from Interface Group
iosxe:
interface_groups:
- name: PORT_CHANNEL_BASE
configuration:
description: Shared Configuration from Interface Group
devices:
- name: Device1
configuration:
interfaces:
port_channels:
- id: 11
interface_groups:
- PORT_CHANNEL_BASE
iosxe:
devices:
- name: Device1
configuration:
vrfs:
- name: GUEST
address_family_ipv4:
enable: true
interfaces:
port_channels:
- id: 10
description: Layer 2 Trunk with Subinterface
shutdown: false
switchport:
mode: trunk
trunk_allowed_vlans:
vlans:
ids: [10, 20, 30]
ranges:
- from: 100
to: 200
subinterfaces:
- id: "10.100"
description: VLAN 100 Subinterface
shutdown: false
vrf_forwarding: GUEST
encapsulation_dot1q_vlan_id: 100
ip_mtu: 1400
ipv4:
address: 10.100.1.1
address_mask: 255.255.255.0
address_dhcp: true
helper_addresses:
- address: 10.1.1.10

You can configure a trunk switchport to explicitly allow all VLANs as shown below.

iosxe:
devices:
- name: Device1
configuration:
interfaces:
port_channels:
- id: 10
switchport:
mode: trunk
trunk_allowed_vlans:
all: true

Additionally, by default, all VLANs are allowed on a trunk switchport if no VLANs are explicitly allowed, mimicking native Cisco IOS-XE behavior. An example is shown below.

iosxe:
devices:
- name: Device1
configuration:
interfaces:
port_channels:
- id: 10
switchport:
mode: trunk

You can configure a trunk switchport to explicitly allow no VLANs as shown below.

iosxe:
devices:
- name: Device1
configuration:
interfaces:
port_channels:
- id: 10
switchport:
mode: trunk
trunk_allowed_vlans:
none: true

You can configure a trunk switchport to allow a range of VLANs as shown below.

iosxe:
devices:
- name: Device1
configuration:
interfaces:
port_channels:
- id: 10
switchport:
mode: trunk
trunk_allowed_vlans:
vlans:
ranges:
- from: 100
to: 200

You can configure a trunk switchport to allow all VLANs except for specific VLANs as shown below.

iosxe:
devices:
- name: Device1
configuration:
interfaces:
port_channels:
- id: 10
switchport:
mode: trunk
trunk_allowed_vlans:
except:
ids:
- 999

You can configure a trunk switchport to allow specific VLANs alongside a range of VLANs as shown below.

iosxe:
devices:
- name: Device1
configuration:
interfaces:
port_channels:
- id: 10
switchport:
mode: trunk
trunk_allowed_vlans:
vlans:
ids:
- 100
- 200
ranges:
- from: 300
to: 400
l2vpn evpn ethernet-segment 1
redundancy single-active
identifier type 3 system-mac 0011.2233.4455
!
interface Port-channel10
evpn ethernet-segment 1
iosxe:
devices:
- name: Device1
configuration:
evpn:
ethernet_segments:
- es_value: 1
redundancy: single-active
identifier: 0011.2233.4455
interfaces:
port_channels:
- id: 10
evpn_ethernet_segments:
- es_value: 1

On IOS-XE 17.12, the YANG path for EVPN ethernet segments on port-channels uses a flat structure (evpn/ethernet-segment) rather than the 17.15+ choice-based structure (evpn/ethernet-segment-choice). Use the evpn_ethernet_segments_legacy attribute for 17.12 devices.

iosxe:
devices:
- name: Device1
configuration:
evpn:
ethernet_segments:
- es_value: 1
redundancy: single-active
identifier: 0011.2233.4455
interfaces:
port_channels:
- id: 10
evpn_ethernet_segments_legacy:
- es_value: 1
interface Port-channel30
description Port-channel with NetFlow
no switchport
ip address 10.30.0.1 255.255.255.0
ip flow monitor FLOW-MONITOR-IPV4 input
ipv6 enable
ipv6 flow monitor FLOW-MONITOR-IPV6 input
iosxe:
devices:
- name: Device1
configuration:
flow:
records:
- name: FLOW-RECORD-IPV4
match:
ipv4_source_address: true
ipv4_destination_address: true
collect:
interface_output: true
- name: FLOW-RECORD-IPV6
match:
ipv6_source_address: true
ipv6_destination_address: true
collect:
interface_output: true
monitors:
- name: FLOW-MONITOR-IPV4
record: FLOW-RECORD-IPV4
- name: FLOW-MONITOR-IPV6
record: FLOW-RECORD-IPV6
interfaces:
port_channels:
- id: 30
description: Port-channel with NetFlow
switchport:
enable: false
ipv4:
address: 10.30.0.1
address_mask: 255.255.255.0
flow_monitors:
- name: FLOW-MONITOR-IPV4
direction: input
ipv6:
enable: true
flow_monitors:
- name: FLOW-MONITOR-IPV6
direction: input

Port Channel Subinterface with Flow Monitors

Section titled “Port Channel Subinterface with Flow Monitors”
iosxe:
devices:
- name: Device1
configuration:
interfaces:
port_channels:
- id: 30
switchport:
enable: false
subinterfaces:
- id: "30.100"
description: Subinterface with NetFlow
encapsulation_dot1q_vlan_id: 100
ipv4:
address: 10.30.100.1
address_mask: 255.255.255.0
flow_monitors:
- name: FLOW-MONITOR-IPV4
direction: input
ipv6:
enable: true
flow_monitors:
- name: FLOW-MONITOR-IPV6
direction: input
interface Port-channel10
description Auto QoS Trust DSCP Test Port-Channel
auto qos trust dscp
iosxe:
devices:
- name: Device1
configuration:
interfaces:
port_channels:
- id: 10
description: Auto QoS Trust DSCP Test Port-Channel
auto_qos:
trust_dscp: true

Port Channel interfaces provide link aggregation capabilities that combine multiple physical Ethernet interfaces into a single logical interface, delivering increased bandwidth, redundancy, and load distribution across member interfaces using protocols such as LACP (Link Aggregation Control Protocol) or static configuration. They enable seamless failover when individual member links fail while maintaining session continuity, and support both Layer 2 switching with VLAN trunking and Layer 3 routing with comprehensive protocol support including OSPF, BGP, and spanning tree participation. Port Channels are fundamental for building resilient network infrastructures, enabling high-bandwidth connections between switches, servers, and storage systems while providing the flexibility to scale bandwidth incrementally and ensure network availability through redundant path management.

Diagram
NameTypeConstraintMandatoryDefault Value
port_channelsList[port_channels]No

port_channels (iosxe.devices.configuration.interfaces)

Section titled “port_channels (iosxe.devices.configuration.interfaces)”
NameTypeConstraintMandatoryDefault Value
idIntegerYes
interface_groupsListStringNo
descriptionStringNo
shutdownBooleantrue, falseNo
vrf_forwardingStringNo
ipv4Class[ipv4]No
ipv6Class[ipv6]No
bfdClass[bfd]No
spanning_treeClass[spanning_tree]No
arp_timeoutIntegermin: 0, max: 2147483No
load_intervalIntegermin: 30, max: 600No
snmp_trap_link_statusBooleantrue, falseNo
logging_event_link_statusBooleantrue, falseNo
mplsClass[mpls]No
ospfClass[ospf]No
ospfv3Class[ospfv3]No
pimClass[pim]No
igmpClass[igmp]No
switchportClass[switchport]No
subinterfacesList[subinterfaces]No
auto_qosClass[auto_qos]No
negotiation_autoBooleantrue, falseNo

ipv4 (iosxe.devices.configuration.interfaces.port_channels)

Section titled “ipv4 (iosxe.devices.configuration.interfaces.port_channels)”
NameTypeConstraintMandatoryDefault Value
addressIPNo
address_maskIPNo
proxy_arpBooleantrue, falseNo
arp_inspection_trustBooleantrue, falseNo
arp_inspection_limit_rateIntegermin: 0, max: 4294967295No
dhcp_snooping_trustBooleantrue, falseNo
dhcp_relay_source_interface_typeChoiceLoopback, Vlan, GigabitEthernet, FiveGigabitEthernet, TenGigabitEthernet, FortyGigabitEthernet, HundredGigabitEthernet, PortChannelNo
dhcp_relay_source_interface_idAnyString or Integer[min: 0]No
dhcp_relay_information_option_vpn_idBooleantrue, falseNo
helper_addressesList[helper_addresses]No
access_group_inStringNo
access_group_outStringNo
flow_monitorsList[flow_monitors]No
redirectsBooleantrue, falseNo
unreachablesBooleantrue, falseNo
unnumbered_interface_typeChoiceLoopback, Vlan, GigabitEthernet, FiveGigabitEthernet, TenGigabitEthernet, FortyGigabitEthernet, HundredGigabitEthernet, PortChannelNo
unnumbered_interface_idAnyString or Integer[min: 0]No
nat_insideBooleantrue, falseNo
nat_outsideBooleantrue, falseNo

ipv6 (iosxe.devices.configuration.interfaces.port_channels)

Section titled “ipv6 (iosxe.devices.configuration.interfaces.port_channels)”
NameTypeConstraintMandatoryDefault Value
enableBooleantrue, falseNo
addressesList[addresses]No
link_local_addressesListIPNo
address_autoconfig_defaultBooleantrue, falseNo
address_dhcpBooleantrue, falseNo
mtuIntegermin: 1280, max: 9976No
nd_ra_suppress_allBooleantrue, falseNo
flow_monitorsList[flow_monitors]No
pimClass[pim]No

bfd (iosxe.devices.configuration.interfaces.port_channels)

Section titled “bfd (iosxe.devices.configuration.interfaces.port_channels)”
NameTypeConstraintMandatoryDefault Value
templateStringNo
enableBooleantrue, falseNo
local_addressStringNo
intervalIntegermin: 50, max: 9999No
interval_min_rxIntegermin: 50, max: 9999No
interval_multiplierIntegermin: 3, max: 50No
echoBooleantrue, falseNo

spanning_tree (iosxe.devices.configuration.interfaces.port_channels)

Section titled “spanning_tree (iosxe.devices.configuration.interfaces.port_channels)”
NameTypeConstraintMandatoryDefault Value
portfastBooleantrue, falseNo
portfast_disableBooleantrue, falseNo
bpduguardBooleantrue, falseNo
bpduguard_disableBooleantrue, falseNo
guardChoiceloop, none, rootNo
link_typeChoiceshared, point-to-pointNo
portfast_trunkBooleantrue, falseNo
portfast_edgeBooleantrue, falseNo

mpls (iosxe.devices.configuration.interfaces.port_channels)

Section titled “mpls (iosxe.devices.configuration.interfaces.port_channels)”
NameTypeConstraintMandatoryDefault Value
ipBooleantrue, falseNo
mtuIntegerNo

ospf (iosxe.devices.configuration.interfaces.port_channels)

Section titled “ospf (iosxe.devices.configuration.interfaces.port_channels)”
NameTypeConstraintMandatoryDefault Value
costIntegermin: 1, max: 65535No
dead_intervalIntegermin: 1, max: 65535No
hello_intervalIntegermin: 1, max: 65535No
mtu_ignoreBooleantrue, falseNo
network_typeChoicebroadcast, non-broadcast, point-to-multipoint, point-to-pointNo
priorityIntegermin: 0, max: 255No
ttl_security_hopsIntegermin: 1, max: 254No
process_idsList[process_ids]No
message_digest_keysList[message_digest_keys]No

ospfv3 (iosxe.devices.configuration.interfaces.port_channels)

Section titled “ospfv3 (iosxe.devices.configuration.interfaces.port_channels)”
NameTypeConstraintMandatoryDefault Value
network_typeChoicebroadcast, non-broadcast, point-to-multipoint, point-to-pointNo
costIntegermin: 1, max: 65535No

pim (iosxe.devices.configuration.interfaces.port_channels)

Section titled “pim (iosxe.devices.configuration.interfaces.port_channels)”
NameTypeConstraintMandatoryDefault Value
passiveBooleantrue, falseNo
dense_modeBooleantrue, falseNo
sparse_modeBooleantrue, falseNo
sparse_dense_modeBooleantrue, falseNo
bfdBooleantrue, falseNo
borderBooleantrue, falseNo
bsr_borderBooleantrue, falseNo
dr_priorityIntegermin: 0, max: 4294967294No

igmp (iosxe.devices.configuration.interfaces.port_channels)

Section titled “igmp (iosxe.devices.configuration.interfaces.port_channels)”
NameTypeConstraintMandatoryDefault Value
versionIntegermin: 1, max: 3No

switchport (iosxe.devices.configuration.interfaces.port_channels)

Section titled “switchport (iosxe.devices.configuration.interfaces.port_channels)”
NameTypeConstraintMandatoryDefault Value
enableBooleantrue, falseNo
modeChoiceaccess, dot1q-tunnel, private-vlan-trunk, private-vlan-host, private-vlan-promiscuous, trunkNo
nonegotiateBooleantrue, falseNo
access_vlanIntegermin: 1, max: 4094No
trunk_allowed_vlansClass[trunk_allowed_vlans]No
trunk_allowed_vlans_legacyClass[trunk_allowed_vlans_legacy]No
trunk_native_vlan_tagBooleantrue, falseNo
trunk_native_vlan_idIntegermin: 1, max: 4094No
hostBooleantrue, falseNo

subinterfaces (iosxe.devices.configuration.interfaces.port_channels)

Section titled “subinterfaces (iosxe.devices.configuration.interfaces.port_channels)”
NameTypeConstraintMandatoryDefault Value
idStringYes
descriptionStringNo
shutdownBooleantrue, falseNo
vrf_forwardingStringNo
ipv4Class[ipv4]No
ipv6Class[ipv6]No
bfdClass[bfd]No
encapsulation_dot1q_vlan_idIntegermin: 1, max: 4094No
arp_timeoutIntegermin: 0, max: 2147483No
auto_qosClass[auto_qos]No
mplsClass[mpls]No
ospfClass[ospf]No
ospfv3Class[ospfv3]No
pimClass[pim]No
igmpClass[igmp]No

auto_qos (iosxe.devices.configuration.interfaces.port_channels)

Section titled “auto_qos (iosxe.devices.configuration.interfaces.port_channels)”
NameTypeConstraintMandatoryDefault Value
classifyBooleantrue, falseNo
classify_policeBooleantrue, falseNo
trustBooleantrue, falseNo
trust_cosBooleantrue, falseNo
trust_dscpBooleantrue, falseNo
video_ctsBooleantrue, falseNo
video_ip_cameraBooleantrue, falseNo
video_media_playerBooleantrue, falseNo
voipBooleantrue, falseNo
voip_cisco_phoneBooleantrue, falseNo
voip_cisco_softphoneBooleantrue, falseNo
voip_trustBooleantrue, falseNo
trust_deviceChoicecisco-phone, cts, ip-camera, media-playerNo

helper_addresses (iosxe.devices.configuration.interfaces.port_channels.ipv4)

Section titled “helper_addresses (iosxe.devices.configuration.interfaces.port_channels.ipv4)”
NameTypeConstraintMandatoryDefault Value
addressIPYes
globalBooleantrue, falseNo
vrfStringNo

flow_monitors (iosxe.devices.configuration.interfaces.port_channels.ipv4)

Section titled “flow_monitors (iosxe.devices.configuration.interfaces.port_channels.ipv4)”
NameTypeConstraintMandatoryDefault Value
nameStringYes
directionChoiceinput, outputYes

addresses (iosxe.devices.configuration.interfaces.port_channels.ipv6)

Section titled “addresses (iosxe.devices.configuration.interfaces.port_channels.ipv6)”
NameTypeConstraintMandatoryDefault Value
prefixIPYes
eui_64Booleantrue, falseNo

pim (iosxe.devices.configuration.interfaces.port_channels.ipv6)

Section titled “pim (iosxe.devices.configuration.interfaces.port_channels.ipv6)”
NameTypeConstraintMandatoryDefault Value
pimBooleantrue, falseNo
bfdBooleantrue, falseNo
bsr_borderBooleantrue, falseNo
dr_priorityIntegermin: 0, max: 4294967295No

process_ids (iosxe.devices.configuration.interfaces.port_channels.ospf)

Section titled “process_ids (iosxe.devices.configuration.interfaces.port_channels.ospf)”
NameTypeConstraintMandatoryDefault Value
idIntegermin: 1, max: 65535No
areasListAny[String or Integer[min: 0]]No

message_digest_keys (iosxe.devices.configuration.interfaces.port_channels.ospf)

Section titled “message_digest_keys (iosxe.devices.configuration.interfaces.port_channels.ospf)”
NameTypeConstraintMandatoryDefault Value
idIntegermin: 1, max: 255Yes
md5_auth_keyStringNo
md5_auth_typeChoice0, 7No

trunk_allowed_vlans (iosxe.devices.configuration.interfaces.port_channels.switchport)

Section titled “trunk_allowed_vlans (iosxe.devices.configuration.interfaces.port_channels.switchport)”
NameTypeConstraintMandatoryDefault Value
allBooleantrue, falseNo
noneBooleantrue, falseNo
vlansClass[vlans]No
addClass[add]No
exceptClass[except]No
removeClass[remove]No

trunk_allowed_vlans_legacy (iosxe.devices.configuration.interfaces.port_channels.switchport)

Section titled “trunk_allowed_vlans_legacy (iosxe.devices.configuration.interfaces.port_channels.switchport)”
NameTypeConstraintMandatoryDefault Value
idsListInteger[min: 1, max: 4094]No
rangesList[ranges]No

vlans (iosxe.devices.configuration.interfaces.port_channels.switchport.trunk_allowed_vlans)

Section titled “vlans (iosxe.devices.configuration.interfaces.port_channels.switchport.trunk_allowed_vlans)”
NameTypeConstraintMandatoryDefault Value
idsListInteger[min: 1, max: 4094]No
rangesList[ranges]No

add (iosxe.devices.configuration.interfaces.port_channels.switchport.trunk_allowed_vlans)

Section titled “add (iosxe.devices.configuration.interfaces.port_channels.switchport.trunk_allowed_vlans)”
NameTypeConstraintMandatoryDefault Value
idsListInteger[min: 1, max: 4094]No
rangesList[ranges]No

except (iosxe.devices.configuration.interfaces.port_channels.switchport.trunk_allowed_vlans)

Section titled “except (iosxe.devices.configuration.interfaces.port_channels.switchport.trunk_allowed_vlans)”
NameTypeConstraintMandatoryDefault Value
idsListInteger[min: 1, max: 4094]No
rangesList[ranges]No

remove (iosxe.devices.configuration.interfaces.port_channels.switchport.trunk_allowed_vlans)

Section titled “remove (iosxe.devices.configuration.interfaces.port_channels.switchport.trunk_allowed_vlans)”
NameTypeConstraintMandatoryDefault Value
idsListInteger[min: 1, max: 4094]No
rangesList[ranges]No

ranges (iosxe.devices.configuration.interfaces.port_channels.switchport.trunk_allowed_vlans_legacy)

Section titled “ranges (iosxe.devices.configuration.interfaces.port_channels.switchport.trunk_allowed_vlans_legacy)”
NameTypeConstraintMandatoryDefault Value
fromIntegermin: 1, max: 4094Yes
toIntegermin: 1, max: 4094Yes

iosxe:
devices:
- name: Device1
configuration:
interfaces:
port_channels:
- id: 1
description: Layer 3 Port Channel to Core
shutdown: false
vrf_forwarding: PRODUCTION
ipv4:
address: 192.168.10.1
address_mask: 255.255.255.252
proxy_arp: false
redirects: false
unreachables: false
ipv6:
enable: true
addresses:
- prefix: 2001:db8:10::1/64
link_local_addresses:
- fe80::1
bfd:
enable: true
interval: 100
interval_multiplier: 3
interval_min_rx: 100
ospf:
cost: 10
network_type: point-to-point
process_ids:
- id: 1
areas:
- "0"
igmp:
version: 2
- id: 10
description: Layer 2 Trunk to Access Switch
shutdown: false
switchport:
mode: trunk
trunk_allowed_vlans:
vlans:
ids: [10, 20, 30]
ranges:
- from: 100
to: 200
trunk_native_vlan_id: 1
nonegotiate: true
spanning_tree:
guard: root
link_type: point-to-point
load_interval: 30
snmp_trap_link_status: true
subinterfaces:
- id: "10.100"
description: VLAN 100 Subinterface
shutdown: false
vrf_forwarding: GUEST
encapsulation_dot1q_vlan_id: 100
ipv4:
address: 10.100.1.1
address_mask: 255.255.255.0
helper_addresses:
- address: 10.1.1.10

You can configure a trunk switchport to explicitly allow all VLANs as shown below.

iosxe:
devices:
- name: Device1
configuration:
interfaces:
port_channels:
- id: 10
switchport:
mode: trunk
trunk_allowed_vlans:
all: true

Additionally, by default, all VLANs are allowed on a trunk switchport if no VLANs are explicitly allowed, mimicking native Cisco IOS-XE behavior. An example is shown below.

iosxe:
devices:
- name: Device1
configuration:
interfaces:
port_channels:
- id: 10
switchport:
mode: trunk

You can configure a trunk switchport to explicitly allow no VLANs as shown below.

iosxe:
devices:
- name: Device1
configuration:
interfaces:
port_channels:
- id: 10
switchport:
mode: trunk
trunk_allowed_vlans:
none: true

You can configure a trunk switchport to allow a range of VLANs as shown below.

iosxe:
devices:
- name: Device1
configuration:
interfaces:
port_channels:
- id: 10
switchport:
mode: trunk
trunk_allowed_vlans:
vlans:
ranges:
- from: 100
to: 200

You can configure a trunk switchport to allow all VLANs except for specific VLANs as shown below.

iosxe:
devices:
- name: Device1
configuration:
interfaces:
port_channels:
- id: 10
switchport:
mode: trunk
trunk_allowed_vlans:
except:
ids:
- 999

You can configure a trunk switchport to allow specific VLANs alongside a range of VLANs as shown below.

iosxe:
devices:
- name: Device1
configuration:
interfaces:
port_channels:
- id: 10
switchport:
mode: trunk
trunk_allowed_vlans:
vlans:
ids:
- 100
- 200
ranges:
- from: 300
to: 400