3.2 VSF Split Detection, Failover, and Auto-Stacking

Key Takeaways

  • A VSF stack split leaves two fragments that can both try to forward with the same MAC and IP addresses, which is why chain topologies need split detection.

  • AOS-CX VSF split detection uses the management (OOBM) interfaces of the primary and secondary members, configured with vsf split-detect mgmt.

  • When fragments are discovered, the fragment containing the primary member (member 1) always wins, and the losing fragment brings down all its non-VSF interfaces.

  • The losing fragment's interfaces stay down until the stack is reconnected or the primary fragment goes down; the primary fragment's interfaces always stay up.

  • Auto-stacking lets factory-default switches join through the reserved VSF ports (for example ports 49 and 50 on 48-port models), receiving the lowest free member ID and rebooting into the stack.

Last updated: October 2026

3.2 VSF Split Detection, Failover, and Auto-Stacking

Virtual Switching Framework (VSF) makes several physical switches act as one, which is convenient until the stack loses the links that hold it together. This section covers the failure cases you are expected to recognize on HPE6-A85: what a stack split is, how AOS-CX split detection limits the damage, how the Conductor and Standby roles fail over, and how auto-stacking and VSF in-service software upgrade (ISSU) simplify operations. All behavior described here comes from the AOS-CX 10.14 VSF Guide for the 6200 and 6300 switch series.


Why a Split Is Dangerous

A VSF stack shares one configuration, one management IP address, and one set of system MAC addresses. In a chain topology there is only one path between any two members, so a single VSF link or member failure can divide the stack into two fragments.

Consider a four-member chain: member 1 (primary, Conductor), member 2 (secondary, Standby), members 3 and 4. If the VSF link between members 2 and 3 fails:

  1. Members 1 and 2 remain together. Member 1 is still the Conductor.
  2. Members 3 and 4 lose contact with both the Conductor and the Standby.
  3. If both fragments kept their front-panel ports active, the network would see the same router MAC, gateway IP addresses, and LACP system ID from two places. Upstream switches would see MAC moves, LAGs could mis-hash, and clients could receive conflicting ARP replies.

A ring topology avoids most of this: every member has two VSF links, so any single link or member failure leaves a path between the survivors and the ring simply operates as a chain. HPE strongly recommends rings whenever feasible. Split detection is the safety net for the failures a ring cannot absorb, and the main protection for chains.

Terminology note: Older documents and other vendors call this "split-brain" protection or "multi-active detection (MAD)". On AOS-CX VSF the command and the documentation use split detection.


How AOS-CX Split Detection Works

AOS-CX VSF supports split detection over the management interfaces of the primary and secondary members:

  • Connect the mgmt ports of the primary (member 1) and secondary members to the same Layer 2 network. They can also be cabled directly to each other.
  • Enable the method once for the stack:
switch(config)# vsf split-detect mgmt
  • Remove it with no vsf split-detect.

If a split occurs and the primary and secondary end up in different fragments, the secondary's fragment uses the management connection to learn that the primary fragment is still operational. The decision rule is fixed:

FragmentResult
Contains the primary member (member 1)Always wins. All interfaces stay operational.
Does not contain the primary (for example, the secondary's fragment)Brings down all front-plane non-VSF interfaces to avoid duplicate MAC and IP addresses.

The losing fragment's interfaces remain down until the stack is reconnected or the primary fragment goes down. Management access through the console and the management interface remains available so you can investigate.

Use show vsf to check the stack. The output includes the topology (Ring or Chain), the stack status (for example "No Split" or "Active Fragment"), and the configured split detection method ("None" or "mgmt").

switch# show vsf
 Force Autojoin             : Disabled
 Autojoin Eligibility Status: Not Eligible
 MAC Address                : 38:21:c7:5d:d0:c0
 Secondary                  : 2
 Topology                   : Ring
 Status                     : No Split
 Split Detection Method     : mgmt

Additional commands such as show vsf detail, show vsf link, and show vsf topology help you trace which link failed.


Conductor and Standby Failover

Failover depends on the role that was lost:

EventWhat happens
A member (not primary or secondary) failsIts ports go down; the rest of the stack keeps running. In a ring, the remaining members stay connected.
The Conductor fails or becomes unreachableThe Standby automatically assumes the Conductor role, because it already holds a synchronized copy of the configuration database.
The Standby failsThe Conductor keeps running; the stack has no control-plane backup until the secondary returns.
No secondary member is configuredLosing the Conductor stops the stack's control plane, which is why HPE recommends always configuring vsf secondary-member.

Design tips that follow from these rules:

  • Take uplinks from both the primary and the secondary member (for example a cross-stack LAG), so either one can carry traffic.
  • Connect both management ports to the management network so management access and split detection survive the loss of one member.
  • Prefer a ring so a single failure does not create fragments.

Auto-Stacking

Building a stack manually means logging in to each switch, configuring VSF links, and renumbering. Auto-stacking reduces this to cabling:

  1. A switch with a factory-default configuration is "auto-join eligible".
  2. Connect it to a VSF link port of an existing stack member. Most models reserve two ports for auto-stacking: ports 13 and 14 on 12-port models, 25 and 26 on 24-port models, and 49 and 50 on 48-port models.
  3. Peer discovery runs from the Conductor. The new switch replies with its eligibility, MAC address, and part number.
  4. The Conductor adds the member and link configuration automatically, assigns the lowest available member ID, and the new switch reboots and joins the stack.

A switch that is no longer at factory default is not auto-join eligible; you can configure its links and member number manually instead, or use the documented force auto-join option. The stack configuration is stored separately from the startup configuration, so erase startup-config does not break the stack; erase all zeroize returns all members to factory default.


Upgrading a VSF Stack

A standard upgrade reboots the stack. On the CX 6300, VSF ISSU (issu update-software) upgrades the Conductor, Standby, and members with minimal downtime by keeping the data plane forwarding while the control plane is upgraded. It applies to upgrades between minor releases, so always read the release notes before choosing the method.


Common Exam Traps

  • The primary always wins. Split resolution does not compare priorities or uptime; the fragment with member 1 keeps its ports up.
  • Only mgmt split detection. AOS-CX VSF split detection uses the management interfaces of the primary and secondary members; do not pick LLDP- or data-port-based answers for VSF.
  • Losing fragment = non-VSF ports down. The losing fragment does not reboot or erase its configuration; it disables its front-plane non-VSF interfaces until the stack is rejoined or the primary fragment goes away.
Loading diagram...
VSF Split Detection Decision Flow
Test Your Knowledge

A four-member AOS-CX VSF chain has split detection configured with vsf split-detect mgmt. A VSF link fails, leaving member 1 (primary) and member 3 in one fragment and member 2 (secondary) and member 4 in the other. What happens next?

A

Both fragments reboot and re-elect a single Conductor based on the lowest base MAC address

B

The member 1 fragment keeps its interfaces up; the other fragment disables its non-VSF interfaces

C

The fragment with the secondary member wins because it holds the most recently synchronized configuration

D

Both fragments compare uptime, and the fragment with the longest uptime keeps its ports active

Test Your Knowledge

Which configuration provides AOS-CX VSF split detection?

A

Put the primary and secondary members' management ports on one L2 network, then enter vsf split-detect mgmt

B

Configure a VSX keepalive between members 1 and 2 over UDP port 7678 using the management VRF

C

Enable LLDP on two front-panel ports of every member and enter vsf lldp-mad on both of them

D

Enable spanning tree root guard on the VSF link ports so a split blocks the losing fragment's ports

Test Your Knowledge

A technician cables a factory-default CX 6300 48-port switch to an existing VSF stack using port 49. What does auto-stacking do?

A

Makes the new switch the Conductor because it runs the newest firmware image of all the members

B

Copies the new switch's startup configuration to every existing member and then reboots the stack

C

Gives it the lowest free member ID, adds its VSF link configuration, and reboots it into the stack

D

Keeps the new switch standalone until an administrator assigns it a member priority of 255 in the stack

Sections you finish are checked off in the contents.