14.3 Creating a Low-Level Design

Key Takeaways

  • A low-level design (LLD) turns the HLD into device-level detail: hardware and optics, port maps, VLAN and IP tables, protocol parameters, wireless profiles, and management settings.

  • Port maps record every interface's purpose, VLAN mode, PoE priority, and authentication settings so configuration and documentation come from the same source.

  • AOS-CX values belong in the LLD in AOS-CX form: spanning tree priority as a 0-15 multiplier, rate limits in pps or percent, and LAG hash l3-src-dst unless a different hash is required.

  • Wireless LLD entries map each SSID to security, forwarding mode, VLAN or gateway cluster, and role, plus RF guidance such as 20 MHz channels in 2.4 GHz.

  • Central templates use variables such as hostnames and management IP addresses, with one variable-file row per device, so the LLD's tables can feed provisioning directly.

Last updated: October 2026

14.3 Creating a Low-Level Design

Quick Summary: A low-level design (LLD) is the implementation blueprint. Where the HLD says "each floor gets a VSF stack," the LLD says which models, which ports form VSF links, which ports uplink to which core ports, which VLAN each access port uses, what the management IP of each stack is, and which SSIDs use which security and forwarding mode. HPE6-A85 lists "create a low-level design" as a Plan objective, so expect questions about what belongs in an LLD and how its values are expressed on AOS-CX.


What the LLD Contains

1. Hardware Bill of Materials

  • Switch models per closet, sized from the environment analysis: port count, PoE budget and class (Section 2.2), Smart Rate ports for multi-gigabit APs, and uplink speeds.
  • Stacking: CX 6300 stacks of up to 10 members or CX 6200F stacks of up to 8 (Section 3.1).
  • Optics and cables: transceivers matched to fiber type and distance (Section 2.1), DACs for short in-rack links, and spares.
  • Access points per area: model chosen from coverage and capacity needs, form factor (indoor, external-antenna, outdoor, hospitality), and power class (Section 6.3).
  • Power: power supplies and redundancy for each switch.

2. Physical Layout and Port Maps

A port map assigns every interface a purpose:

SwitchPortConnected deviceModeVLAN(s)PoE priorityAccess control
FL2-STACK1/1/1-1/1/40Desks (phone + PC)Trunk, native data10 untagged, 20 voicehigh802.1X + MAC-Auth
FL2-STACK1/1/41-1/1/46APsTrunk100 AP mgmt (native), 500 guestcriticalMAC-Auth for APs
FL2-STACK1/1/49-1/1/50VSF link 1/2VSFn/an/an/a
FL2-STACK1/1/52, 2/1/52Core VSX pairLAG 1 (LACP)10,20,30,100,500,999 (native 999)n/aTrusted (DHCP snooping, ARP inspection)

Using the same port map for configuration and documentation prevents the classic mismatch where the drawing says one thing and the switch does another.

3. VLAN and IP Tables

VLANNameSubnetGateway (active-gateway VIP)DHCP helperNotes
10USERS10.10.0.0/2210.10.0.110.1.100.50DHCP snooping, ARP inspection
20VOICE10.20.0.0/2310.20.0.110.1.100.50voice VLAN, DSCP trusted from phones
30IOT10.30.0.0/2310.30.0.110.1.100.50MAC-Auth or MPSK
100AP-MGMT10.100.0.0/2410.100.0.110.1.100.50AP management
500GUEST172.16.0.0/22firewallfirewallBridged guest SSID
999NATIVE-UNUSEDnonenonenoneTrunk native VLAN only

Also record management addresses per device, loopbacks and OSPF router IDs, point-to-point link subnets (/30 or /31), and the management VRF and gateway.

4. Protocol Parameters in AOS-CX Terms

  • Spanning tree: region name, revision, VLAN-to-instance mapping, and root priorities expressed as AOS-CX multipliers (spanning-tree priority 0 for the primary root, 1 for the secondary; Section 5.2).
  • LAGs: LACP active on both ends, member ports on different stack members, and hash (l3-src-dst is the default).
  • VSF/VSX: secondary member, split-detection cabling, ISL ports, keepalive addresses, and active-gateway virtual MACs.
  • OSPF: areas, router IDs, point-to-point network type on routed uplinks, and passive SVIs.
  • Security: which ports are trusted for DHCP snooping and ARP inspection; port-security client limits; protection features such as BPDU guard and loop protection on edge ports.
  • QoS: trust mode per port type and any queue or schedule profiles.

5. Wireless Design Details

SSIDSecurityForwardingVLAN / destinationRoleBands
CORPWPA3-Enterprise (802.1X via ClearPass)TunnelGateway cluster VLAN 40Employee5 GHz, 6 GHz
VOICEWPA3-Enterprise, 802.11r enabledTunnelGateway cluster VLAN 41Voice5 GHz
IOTMPSKBridgeVLAN 30Per-device role2.4 GHz, 5 GHz
GUESTEnhanced Open (OWE) or captive portalBridgeVLAN 500Guest2.4, 5, 6 GHz (OWE required in 6 GHz)

Add RF guidance consistent with Section 6.2: 20 MHz channels in 2.4 GHz, 20 or 40 MHz in dense 5 GHz areas, and wider channels only where the 6 GHz channel pool allows. AirMatch will tune channels and power, but the LLD should state constraints and AP placement.

6. Management and Provisioning

  • Central structure: Classic Central groups and sites, or new Central scopes (site collections, sites, device groups), plus which device lands where (Section 11.1).
  • Templates and variables: a Classic Central template group uses variables such as hostname and management IP, filled in from a variable file with one row per device. LLD tables are the natural source for that file.
  • Firmware target: the AOS-CX and AOS 10 versions to run, from the release notes.
  • Naming conventions: for example building-floor-role-number, used consistently for hostnames, LAG descriptions, and labels.

Quality Checks Before Sign-Off

  1. Every HLD requirement maps to at least one LLD entry.
  2. Every port in the port map has a VLAN mode and an access-control decision.
  3. Every VLAN has a gateway, DHCP behavior, and a reason to exist on each trunk that carries it.
  4. PoE totals per switch fit the budget with the chosen allocation method.
  5. Native VLANs are listed in the trunks' allowed lists where they are meant to carry traffic (an AOS-CX requirement).
  6. The architect has reviewed and approved the LLD.

Common Exam Traps

  • Writing generic values that AOS-CX will reject. For example, an STP priority of 4096 must be entered as the multiplier 1.
  • Leaving out the management plane. Management VLAN or VRF, gateways, NTP, DNS, and Central placement are part of the LLD.
  • Mixing up HLD and LLD. "Use VSX at the core" is HLD; "ISL is LAG 256 on ports 1/1/53-1/1/54" is LLD.
Test Your Knowledge

Which item belongs in a low-level design rather than a high-level design?

A

Wireless users will be segmented by role through ClearPass and gateway policy

B

The core will be a VSX pair that provides active-gateway for the user VLANs

C

The campus will use a two-tier collapsed-core topology with VSF access stacks

D

Port 1/1/52 on member 1 and port 2/1/52 on member 2 form LAG 1 to the core

Test Your Knowledge

An LLD specifies that the aggregation switch should be the spanning tree root with bridge priority 4096 for MST instance 1. How should this appear in the AOS-CX configuration section of the LLD?

A

spanning-tree instance 1 priority 1

B

spanning-tree instance 1 root primary

C

spanning-tree instance 1 priority 4096

D

spanning-tree priority 4096 instance 1

Test Your Knowledge

An implementer is preparing a Classic Central template group for 40 access stacks. Which LLD artifact most directly feeds the template's variable file?

A

The RF predictive survey report with AP placements for every floor

B

The vendor's general data sheet listing port counts for the switch model

C

A per-device table of hostnames, management IPs, and other unique values

D

The HLD topology diagram showing the core, access, and WAN layers

Sections you finish are checked off in the contents.