VLAN interfaces, also known as Switched Virtual Interfaces (SVIs), provide Layer 3 gateway functionality for VLANs by creating routable interfaces associated with specific VLAN IDs, enabling inter-VLAN routing, network segmentation, and centralized gateway services for broadcast domains. They support comprehensive Layer 3 features including IPv4 and IPv6 addressing, routing protocol participation (OSPF, BGP), DHCP relay services, access control lists, and advanced capabilities such as BFD for fast convergence and HSRP/VRRP for high availability. VLAN interfaces are essential for network infrastructure design, serving as default gateways for VLANs, enabling communication between different network segments, and providing centralized routing and policy enforcement points in switched network environments.
Name Type Constraint Mandatory Default Value vlans List [vlans]No
Name Type Constraint Mandatory Default Value id Integer min: 1, max: 4094 Yes interface_groups List String No interface_group_policy Choice merge, replaceNo description String No shutdown Boolean true, falseNo ip_mtu Integer min: 68, max: 18000 No autostate Boolean true, falseNo vrf_forwarding String No ipv4 Class [ipv4]No ipv6 Class [ipv6]No bfd Class [bfd]No load_interval Integer min: 30, max: 600 No mpls Class [mpls]No ospf Class [ospf]No ospfv3 Class [ospfv3]No isis Class [isis]No pim Class [pim]No igmp Class [igmp]No mac_address MAC No vrrp_v2 List [vrrp_v2]No zone_member_security String No
Name Type Constraint Mandatory Default Value address IP No address_mask IP No proxy_arp Boolean true, falseNo local_proxy_arp Boolean true, falseNo arp_inspection_trust Boolean true, falseNo arp_inspection_limit_rate Integer min: 0, max: 4294967295 No dhcp_relay_source_interface_type Choice Loopback, Vlan, GigabitEthernet, TwoGigabitEthernet, FiveGigabitEthernet, TenGigabitEthernet, TwentyFiveGigabitEthernet, FortyGigabitEthernet, FiftyGigabitEthernet, HundredGigabitEthernet, PortChannelNo dhcp_relay_source_interface_id Any String or Integer[min: 0] No dhcp_relay_information_option_vpn_id Boolean true, falseNo helper_addresses List [helper_addresses]No access_group_in String No access_group_out String No redirects Boolean true, falseNo unreachables Boolean true, falseNo nat_inside Boolean true, falseNo nat_outside Boolean true, falseNo unnumbered_interface_type Choice Loopback, Vlan, GigabitEthernet, TwoGigabitEthernet, FiveGigabitEthernet, TenGigabitEthernet, TwentyFiveGigabitEthernet, FortyGigabitEthernet, FiftyGigabitEthernet, HundredGigabitEthernet, PortChannelNo unnumbered_interface_id Any String or Integer[min: 0] No address_dhcp Boolean true, falseNo
Name Type Constraint Mandatory Default Value enable Boolean true, falseNo addresses List [addresses]No link_local_addresses List IP No address_autoconfig_default Boolean true, falseNo address_dhcp Boolean true, falseNo mtu Integer min: 1280, max: 9976 No nd_ra_suppress_all Boolean true, falseNo flow_monitors List [flow_monitors]No pim Class [pim]No
Name Type Constraint Mandatory Default Value template String No enable Boolean true, falseNo local_address IP No interval Integer min: 50, max: 9999 No interval_min_rx Integer min: 50, max: 9999 No interval_multiplier Integer min: 3, max: 50 No echo Boolean true, falseNo
Name Type Constraint Mandatory Default Value ip Boolean true, falseNo mtu Integer No
Name Type Constraint Mandatory Default Value authentication_key_chain String No authentication_message_digest Boolean true, falseNo authentication_null Boolean true, falseNo cost Integer min: 1, max: 65535 No dead_interval Integer min: 1, max: 65535 No hello_interval Integer min: 1, max: 65535 No message_digest_keys List [message_digest_keys]No mtu_ignore Boolean true, falseNo multi_area_ids List Any[String or Integer[min: 0]] No network_type Choice broadcast, non-broadcast, point-to-multipoint, point-to-pointNo priority Integer min: 0, max: 255 No process_ids List [process_ids]No ttl_security_hops Integer min: 1, max: 254 No
Name Type Constraint Mandatory Default Value bfd Boolean true, falseNo cost Integer min: 1, max: 65535 No dead_interval Integer min: 1, max: 65535 No hello_interval Integer min: 1, max: 65535 No mtu_ignore Boolean true, falseNo network_type Choice broadcast, non-broadcast, point-to-multipoint, point-to-pointNo priority Integer min: 0, max: 255 No
Name Type Constraint Mandatory Default Value area_tag String No ipv4_metric_levels List [ipv4_metric_levels]No network_point_to_point Boolean true, falseNo
Name Type Constraint Mandatory Default Value passive Boolean true, falseNo dense_mode Boolean true, falseNo sparse_mode Boolean true, falseNo sparse_dense_mode Boolean true, falseNo bfd Boolean true, falseNo border Boolean true, falseNo bsr_border Boolean true, falseNo dr_priority Integer min: 0, max: 4294967294 No
Name Type Constraint Mandatory Default Value version Integer min: 1, max: 3 No
Name Type Constraint Mandatory Default Value group_id Integer min: 1, max: 255 Yes ip_primary_address IP No ip_secondary_addresses List IP No priority Integer min: 1, max: 254 No preempt Boolean true, falseNo preempt_delay_minimum Integer min: 0, max: 3600 No timers_advertise_interval Integer min: 1, max: 255 No authentication_text String No description String No tracks List [tracks]No shutdown Boolean true, falseNo
Name Type Constraint Mandatory Default Value address IP Yes global Boolean true, falseNo vrf String No
Name Type Constraint Mandatory Default Value prefix IP Yes eui_64 Boolean true, falseNo
Name Type Constraint Mandatory Default Value name String Yes direction Choice input, outputYes
Name Type Constraint Mandatory Default Value pim Boolean true, falseNo bfd Boolean true, falseNo bsr_border Boolean true, falseNo dr_priority Integer min: 0, max: 4294967295 No
Name Type Constraint Mandatory Default Value id Integer min: 1, max: 255 Yes md5_auth_key String No md5_auth_type Choice 0, 7No
Name Type Constraint Mandatory Default Value id Integer min: 1, max: 65535 No areas List Any[String or Integer[min: 0]] No
Name Type Constraint Mandatory Default Value level Choice level-1, level-2Yes value Integer min: 1, max: 16777214 Yes
Name Type Constraint Mandatory Default Value object_id Integer min: 1, max: 1000 Yes decrement Integer min: 1, max: 255 No
IOS-XE enforces IP address uniqueness within the same VRF — no two interfaces can hold the same IP address simultaneously. When swapping IP addresses between two interfaces (for example, moving 10.1.1.1 from Vlan100 to Vlan200 and vice versa), terraform apply will fail because Terraform updates both interfaces in parallel without awareness of the cross-resource conflict. The device rejects the new IP assignment with an “inconsistent value: Device refused one or more commands” error because the target IP still exists on the other interface.
To perform an IP swap, apply the change in two steps:
Remove the IP addresses from both interfaces (delete the ipv4 block or assign temporary addresses) and run terraform apply.
Set the new desired IP addresses and run terraform apply a second time.
ip address 10.100.100.1 255.255.255.0
description Production VLAN 100 Gateway
ip address 10.100.1.1 255.255.255.0
ip helper-address 10.1.1.10
ip verify unicast source reachable-via rx allow-self-ping allow-default
description Production VLAN 110 Gateway
ip unnumbered loopback 200
address_mask : 255.255.255.0
description : Production VLAN 100 Gateway
address_mask : 255.255.255.0
description : Production VLAN 110 Gateway
unnumbered_interface_type : Loopback
unnumbered_interface_id : 200
Full example:
mac_address : 0000.dead.beef
address_mask : 255.255.255.0
dhcp_relay_source_interface_type : GigabitEthernet
dhcp_relay_source_interface_id : " 1/0/1 "
access_group_out : ACL_OUT
verify_unicast_source_reachable_via : rx
verify_unicast_source_allow_self_ping : true
verify_unicast_source_allow_default : true
- prefix : 2001:db8:10::1/64
address_autoconfig_default : false
ip_primary_address : 172.16.10.254
preempt_delay_minimum : 30
timers_advertise_interval : 3
authentication_text : SECRET
description : VRRP-GROUP-1
Example configuring VRRPv2 on an SVI:
Cisco IOS-XE CLI Equivalent:
vrrp 1 ip 172.16.10.253 secondary
vrrp 1 preempt delay minimum 30
vrrp 1 timers advertise 3
vrrp 1 authentication text SECRET
vrrp 1 description VRRP-GROUP-1
vrrp 1 track 1 decrement 20
Example configuring DHCP Relay information option vpn-id.
Cisco IOS-XE CLI Equivalent:
ip dhcp relay information option vpn-id
NAC YAML Configuration:
url : https://10.81.239.58
dhcp_relay_information_option_vpn_id : true
Configure a VLAN interface as a NAT inside interface. This is commonly used when the SVI serves as the default gateway for an internal VLAN whose traffic should be translated by NAT.
Note: nat_inside and nat_outside are mutually exclusive on a single interface (only one can be configured at a time).
Cisco IOS-XE CLI Equivalent:
description Internal VLAN - NAT Inside
ip address 10.100.1.1 255.255.255.0
description : Internal VLAN - NAT Inside
address_mask : 255.255.255.0
Configure a VLAN interface as a NAT outside interface. This is used when the SVI faces an external or public-facing network segment.
Cisco IOS-XE CLI Equivalent:
description External VLAN - NAT Outside
ip address 203.0.113.1 255.255.255.0
description : External VLAN - NAT Outside
address_mask : 255.255.255.0
VLAN interfaces, also known as Switched Virtual Interfaces (SVIs), provide Layer 3 gateway functionality for VLANs by creating routable interfaces associated with specific VLAN IDs, enabling inter-VLAN routing, network segmentation, and centralized gateway services for broadcast domains. They support comprehensive Layer 3 features including IPv4 and IPv6 addressing, routing protocol participation (OSPF, BGP), DHCP relay services, access control lists, and advanced capabilities such as BFD for fast convergence and HSRP/VRRP for high availability. VLAN interfaces are essential for network infrastructure design, serving as default gateways for VLANs, enabling communication between different network segments, and providing centralized routing and policy enforcement points in switched network environments.
Name Type Constraint Mandatory Default Value vlans List [vlans]No
Name Type Constraint Mandatory Default Value id Integer min: 1, max: 4094 Yes interface_groups List String No description String No shutdown Boolean true, falseNo autostate Boolean true, falseNo vrf_forwarding String No ipv4 Class [ipv4]No ipv6 Class [ipv6]No bfd Class [bfd]No load_interval Integer min: 30, max: 600 No mpls Class [mpls]No ospf Class [ospf]No ospfv3 Class [ospfv3]No pim Class [pim]No igmp Class [igmp]No mac_address MAC No
Name Type Constraint Mandatory Default Value address IP No address_mask IP No proxy_arp Boolean true, falseNo arp_inspection_trust Boolean true, falseNo arp_inspection_limit_rate Integer min: 0, max: 4294967295 No dhcp_relay_source_interface_type Choice Loopback, Vlan, GigabitEthernet, FiveGigabitEthernet, TenGigabitEthernet, FortyGigabitEthernet, HundredGigabitEthernet, PortChannelNo dhcp_relay_source_interface_id Any String or Integer[min: 0] No dhcp_relay_information_option_vpn_id Boolean true, falseNo helper_addresses List [helper_addresses]No access_group_in String No access_group_out String No redirects Boolean true, falseNo unreachables Boolean true, falseNo unnumbered_interface_type Choice Loopback, Vlan, GigabitEthernet, FiveGigabitEthernet, TenGigabitEthernet, FortyGigabitEthernet, HundredGigabitEthernet, PortChannelNo unnumbered_interface_id Any String or Integer[min: 0] No
Name Type Constraint Mandatory Default Value enable Boolean true, falseNo addresses List [addresses]No link_local_addresses List IP No address_autoconfig_default Boolean true, falseNo address_dhcp Boolean true, falseNo mtu Integer min: 1280, max: 9976 No nd_ra_suppress_all Boolean true, falseNo flow_monitors List [flow_monitors]No pim Class [pim]No
Name Type Constraint Mandatory Default Value template String No enable Boolean true, falseNo local_address String No interval Integer min: 50, max: 9999 No interval_min_rx Integer min: 50, max: 9999 No interval_multiplier Integer min: 3, max: 50 No echo Boolean true, falseNo
Name Type Constraint Mandatory Default Value ip Boolean true, falseNo mtu Integer No
Name Type Constraint Mandatory Default Value cost Integer min: 1, max: 65535 No dead_interval Integer min: 1, max: 65535 No hello_interval Integer min: 1, max: 65535 No mtu_ignore Boolean true, falseNo network_type Choice broadcast, non-broadcast, point-to-multipoint, point-to-pointNo priority Integer min: 0, max: 255 No ttl_security_hops Integer min: 1, max: 254 No process_ids List [process_ids]No message_digest_keys List [message_digest_keys]No
Name Type Constraint Mandatory Default Value network_type Choice broadcast, non-broadcast, point-to-multipoint, point-to-pointNo cost Integer min: 1, max: 65535 No
Name Type Constraint Mandatory Default Value passive Boolean true, falseNo dense_mode Boolean true, falseNo sparse_mode Boolean true, falseNo sparse_dense_mode Boolean true, falseNo bfd Boolean true, falseNo border Boolean true, falseNo bsr_border Boolean true, falseNo dr_priority Integer min: 0, max: 4294967294 No
Name Type Constraint Mandatory Default Value version Integer min: 1, max: 3 No
Name Type Constraint Mandatory Default Value address IP Yes global Boolean true, falseNo vrf String No
Name Type Constraint Mandatory Default Value prefix IP Yes eui_64 Boolean true, falseNo
Name Type Constraint Mandatory Default Value name String Yes direction Choice input, outputYes
Name Type Constraint Mandatory Default Value pim Boolean true, falseNo bfd Boolean true, falseNo bsr_border Boolean true, falseNo dr_priority Integer min: 0, max: 4294967295 No
Name Type Constraint Mandatory Default Value id Integer min: 1, max: 65535 No areas List Any[String or Integer[min: 0]] No
Name Type Constraint Mandatory Default Value id Integer min: 1, max: 255 Yes md5_auth_key String No md5_auth_type Choice 0, 7No
description : Production VLAN 100 Gateway
address_mask : 255.255.255.0
Full example:
mac_address : 0000.dead.beef
address_mask : 255.255.255.0
dhcp_relay_source_interface_type : GigabitEthernet
dhcp_relay_source_interface_id : " 1/0/1 "
access_group_out : ACL_OUT
- prefix : 2001:db8:10::1/64
address_autoconfig_default : false
Example configuring DHCP Relay information option vpn-id.
Cisco IOS-XE CLI Equivalent:
ip dhcp relay information option vpn-id
NAC YAML Configuration:
url : https://10.81.239.58
dhcp_relay_information_option_vpn_id : true