14.3 Creating a Low-Level Design
Key Takeaways
A low-level design (LLD) turns the HLD into device-level detail: hardware and optics, port maps, VLAN and IP tables, protocol parameters, wireless profiles, and management settings.
Port maps record every interface's purpose, VLAN mode, PoE priority, and authentication settings so configuration and documentation come from the same source.
AOS-CX values belong in the LLD in AOS-CX form: spanning tree priority as a 0-15 multiplier, rate limits in pps or percent, and LAG hash l3-src-dst unless a different hash is required.
Wireless LLD entries map each SSID to security, forwarding mode, VLAN or gateway cluster, and role, plus RF guidance such as 20 MHz channels in 2.4 GHz.
Central templates use variables such as hostnames and management IP addresses, with one variable-file row per device, so the LLD's tables can feed provisioning directly.
14.3 Creating a Low-Level Design
Quick Summary: A low-level design (LLD) is the implementation blueprint. Where the HLD says "each floor gets a VSF stack," the LLD says which models, which ports form VSF links, which ports uplink to which core ports, which VLAN each access port uses, what the management IP of each stack is, and which SSIDs use which security and forwarding mode. HPE6-A85 lists "create a low-level design" as a Plan objective, so expect questions about what belongs in an LLD and how its values are expressed on AOS-CX.
What the LLD Contains
1. Hardware Bill of Materials
- Switch models per closet, sized from the environment analysis: port count, PoE budget and class (Section 2.2), Smart Rate ports for multi-gigabit APs, and uplink speeds.
- Stacking: CX 6300 stacks of up to 10 members or CX 6200F stacks of up to 8 (Section 3.1).
- Optics and cables: transceivers matched to fiber type and distance (Section 2.1), DACs for short in-rack links, and spares.
- Access points per area: model chosen from coverage and capacity needs, form factor (indoor, external-antenna, outdoor, hospitality), and power class (Section 6.3).
- Power: power supplies and redundancy for each switch.
2. Physical Layout and Port Maps
A port map assigns every interface a purpose:
| Switch | Port | Connected device | Mode | VLAN(s) | PoE priority | Access control |
|---|---|---|---|---|---|---|
| FL2-STACK | 1/1/1-1/1/40 | Desks (phone + PC) | Trunk, native data | 10 untagged, 20 voice | high | 802.1X + MAC-Auth |
| FL2-STACK | 1/1/41-1/1/46 | APs | Trunk | 100 AP mgmt (native), 500 guest | critical | MAC-Auth for APs |
| FL2-STACK | 1/1/49-1/1/50 | VSF link 1/2 | VSF | n/a | n/a | n/a |
| FL2-STACK | 1/1/52, 2/1/52 | Core VSX pair | LAG 1 (LACP) | 10,20,30,100,500,999 (native 999) | n/a | Trusted (DHCP snooping, ARP inspection) |
Using the same port map for configuration and documentation prevents the classic mismatch where the drawing says one thing and the switch does another.
3. VLAN and IP Tables
| VLAN | Name | Subnet | Gateway (active-gateway VIP) | DHCP helper | Notes |
|---|---|---|---|---|---|
| 10 | USERS | 10.10.0.0/22 | 10.10.0.1 | 10.1.100.50 | DHCP snooping, ARP inspection |
| 20 | VOICE | 10.20.0.0/23 | 10.20.0.1 | 10.1.100.50 | voice VLAN, DSCP trusted from phones |
| 30 | IOT | 10.30.0.0/23 | 10.30.0.1 | 10.1.100.50 | MAC-Auth or MPSK |
| 100 | AP-MGMT | 10.100.0.0/24 | 10.100.0.1 | 10.1.100.50 | AP management |
| 500 | GUEST | 172.16.0.0/22 | firewall | firewall | Bridged guest SSID |
| 999 | NATIVE-UNUSED | none | none | none | Trunk native VLAN only |
Also record management addresses per device, loopbacks and OSPF router IDs, point-to-point link subnets (/30 or /31), and the management VRF and gateway.
4. Protocol Parameters in AOS-CX Terms
- Spanning tree: region name, revision, VLAN-to-instance mapping, and root priorities expressed as AOS-CX multipliers (
spanning-tree priority 0for the primary root,1for the secondary; Section 5.2). - LAGs: LACP active on both ends, member ports on different stack members, and hash (
l3-src-dstis the default). - VSF/VSX: secondary member, split-detection cabling, ISL ports, keepalive addresses, and active-gateway virtual MACs.
- OSPF: areas, router IDs, point-to-point network type on routed uplinks, and passive SVIs.
- Security: which ports are trusted for DHCP snooping and ARP inspection; port-security client limits; protection features such as BPDU guard and loop protection on edge ports.
- QoS: trust mode per port type and any queue or schedule profiles.
5. Wireless Design Details
| SSID | Security | Forwarding | VLAN / destination | Role | Bands |
|---|---|---|---|---|---|
| CORP | WPA3-Enterprise (802.1X via ClearPass) | Tunnel | Gateway cluster VLAN 40 | Employee | 5 GHz, 6 GHz |
| VOICE | WPA3-Enterprise, 802.11r enabled | Tunnel | Gateway cluster VLAN 41 | Voice | 5 GHz |
| IOT | MPSK | Bridge | VLAN 30 | Per-device role | 2.4 GHz, 5 GHz |
| GUEST | Enhanced Open (OWE) or captive portal | Bridge | VLAN 500 | Guest | 2.4, 5, 6 GHz (OWE required in 6 GHz) |
Add RF guidance consistent with Section 6.2: 20 MHz channels in 2.4 GHz, 20 or 40 MHz in dense 5 GHz areas, and wider channels only where the 6 GHz channel pool allows. AirMatch will tune channels and power, but the LLD should state constraints and AP placement.
6. Management and Provisioning
- Central structure: Classic Central groups and sites, or new Central scopes (site collections, sites, device groups), plus which device lands where (Section 11.1).
- Templates and variables: a Classic Central template group uses variables such as hostname and management IP, filled in from a variable file with one row per device. LLD tables are the natural source for that file.
- Firmware target: the AOS-CX and AOS 10 versions to run, from the release notes.
- Naming conventions: for example building-floor-role-number, used consistently for hostnames, LAG descriptions, and labels.
Quality Checks Before Sign-Off
- Every HLD requirement maps to at least one LLD entry.
- Every port in the port map has a VLAN mode and an access-control decision.
- Every VLAN has a gateway, DHCP behavior, and a reason to exist on each trunk that carries it.
- PoE totals per switch fit the budget with the chosen allocation method.
- Native VLANs are listed in the trunks' allowed lists where they are meant to carry traffic (an AOS-CX requirement).
- The architect has reviewed and approved the LLD.
Common Exam Traps
- Writing generic values that AOS-CX will reject. For example, an STP priority of 4096 must be entered as the multiplier
1. - Leaving out the management plane. Management VLAN or VRF, gateways, NTP, DNS, and Central placement are part of the LLD.
- Mixing up HLD and LLD. "Use VSX at the core" is HLD; "ISL is LAG 256 on ports 1/1/53-1/1/54" is LLD.
Which item belongs in a low-level design rather than a high-level design?
Wireless users will be segmented by role through ClearPass and gateway policy
The core will be a VSX pair that provides active-gateway for the user VLANs
The campus will use a two-tier collapsed-core topology with VSF access stacks
Port 1/1/52 on member 1 and port 2/1/52 on member 2 form LAG 1 to the core
An LLD specifies that the aggregation switch should be the spanning tree root with bridge priority 4096 for MST instance 1. How should this appear in the AOS-CX configuration section of the LLD?
spanning-tree instance 1 priority 1
spanning-tree instance 1 root primary
spanning-tree instance 1 priority 4096
spanning-tree priority 4096 instance 1
An implementer is preparing a Classic Central template group for 40 access stacks. Which LLD artifact most directly feeds the template's variable file?
The RF predictive survey report with AP placements for every floor
The vendor's general data sheet listing port counts for the switch model
A per-device table of hostnames, management IPs, and other unique values
The HLD topology diagram showing the core, access, and WAN layers
Sections you finish are checked off in the contents.