14.2 Interpreting an Architect's High-Level Design

Key Takeaways

  • A high-level design (HLD) states the architecture: topology tiers, redundancy model, Layer 2/Layer 3 boundary, routing, segmentation, wireless forwarding model, security, and management approach.

  • VSF stacks (single control plane) typically sit at the access layer, while VSX pairs (two control planes) sit at aggregation or core and provide VSX-LAG uplinks and active-gateway.

  • Where the default gateways live defines the Layer 2/Layer 3 boundary: SVIs with active-gateway on a VSX pair mean user VLANs must be trunked from access to that pair.

  • A tunneled SSID needs only the AP management VLAN on the access port, while a bridged SSID needs its client VLAN tagged on the AP port and every trunk up to the gateway.

  • An associate translates the HLD into implementation tasks and asks the architect about gaps; design decisions are not changed without the architect's approval.

Last updated: October 2026

14.2 Interpreting an Architect's High-Level Design

Quick Summary: The high-level design (HLD) is the architect's description of the target network: which tiers exist, how they are made redundant, where routing starts, how users are segmented, how wireless traffic is forwarded, and how everything is managed. HPE6-A85 expects you to interpret an HLD: recognize what each statement means for the devices you will configure, notice what is missing, and turn the design into concrete tasks.


What an HLD Usually Contains

HLD elementTypical statementWhat you must understand
Topology"Two-tier collapsed core" or "three-tier access/aggregation/core"How many layers of switches and where each closet uplinks
Access redundancy"CX 6300 VSF stacks in a ring per closet"VSF links, primary/secondary members, split detection
Aggregation/core redundancy"CX 8360 VSX pair with active-gateway"ISL, keepalive, VSX-LAG downlinks, shared gateway
L2/L3 boundary"User SVIs on the core" or "routed access"Where VLANs end and which trunks carry them
Routing"OSPF area 0 between core and WAN edge"Which links run OSPF and which are passive
Segmentation"Roles via ClearPass; IoT tunneled with UBT"Which ports use 802.1X/MAC-Auth and which roles tunnel
Wireless"AOS 10; corporate SSID tunneled to a two-node gateway cluster; guest SSID bridged"What VLANs the AP ports need
Security"WPA3-Enterprise; DHCP snooping and ARP inspection on access"Trust settings on uplinks
Management"HPE Aruba Networking Central; out-of-band management network"Onboarding path and management VLAN/VRF
QoS"Trust DSCP from phones and APs; voice in strict priority"Trust and queue settings

An HLD is deliberately not a configuration. It may show one representative closet instead of all twenty, and it rarely lists port numbers. That detail belongs in the low-level design (Section 14.3).


Reading the Common Patterns

Two-tier versus three-tier

  • Two-tier (collapsed core): access switches uplink directly to a core pair that also performs aggregation. Common in single buildings and mid-size campuses.
  • Three-tier: access uplinks to aggregation per building or zone, and aggregation uplinks to a core. Common on large campuses where many buildings connect to the core.

VSF at the access layer

A statement such as "access closets use CX 6300 VSF stacks in a ring" tells you:

  • Each closet is one logical switch with one management IP address (Section 3.1).
  • You will configure VSF links on the designated ports, a secondary member for the Standby role, and vsf split-detect mgmt if the management ports are cabled (Section 3.2).
  • Uplinks should come from at least two members so the closet survives a member failure.

VSX at aggregation or core

"Aggregation is a CX 8360 VSX pair with active-gateway" tells you:

  • Two switches with independent control planes, an ISL LAG, and a keepalive (Section 3.3).
  • Each access closet connects with a VSX-LAG, one or more links to each peer, so no links are blocked by spanning tree.
  • User default gateways live on SVIs on both peers with active-gateway: the same virtual IP and virtual MAC on both peers (Section 3.4).

The Layer 2 / Layer 3 boundary

If gateways are on the VSX pair, every user VLAN must be created on the access stack, carried on the access uplink trunk, and allowed on the VSX-LAG. If the design says routed access, the access switch owns the gateways and the uplinks become routed links running OSPF, so VLANs stay inside the closet.

Wireless forwarding model

  • Tunneled SSID (AOS 10 with a gateway cluster): the access port to the AP needs only the AP management VLAN; client VLANs live on the gateway cluster (Section 7.2).
  • Bridged SSID: the client VLAN must be tagged on the AP port and on every trunk up to its default gateway.
  • Mixed: both rules apply, SSID by SSID.

A Worked Example

The HLD for a three-floor office says:

  1. "Each floor has a CX 6300 VSF ring. Uplinks: VSX-LAG to a CX 8360 VSX core pair."
  2. "User, voice, and IoT gateways: active-gateway on the core. OSPF area 0 from the core to the WAN edge."
  3. "AOS 10 APs. Corporate SSID: WPA3-Enterprise, tunneled to a two-gateway cluster. Guest SSID: bridged to VLAN 500, internet only."
  4. "802.1X with ClearPass on desk ports; MAC-Auth for printers; phones get the voice VLAN through LLDP-MED."
  5. "Managed by Central."

Implementation implications an associate should list:

  • VSF: ring links and a secondary member per floor; management ports connected for split detection.
  • Uplinks: an LACP LAG on each stack with members on two different stack members, terminating on a VSX-LAG on the core.
  • VLANs on access trunks: user, voice, IoT, AP management, and VLAN 500 (because guest is bridged). Corporate wireless VLANs are not needed on access trunks because that SSID is tunneled.
  • Core: SVIs with active-gateway for each user VLAN, an OSPF uplink to the WAN edge, and passive OSPF on user SVIs.
  • Access ports: 802.1X and MAC-Auth with ClearPass as the RADIUS server, a voice VLAN flagged with voice, and dynamic authorization for CoA.
  • Central: devices added to the GreenLake workspace, subscriptions assigned, and groups or scopes prepared.

Questions to Raise with the Architect

A good associate does not guess. Typical clarifying questions:

  • Which ports are reserved for VSF links and uplinks on each model?
  • What should happen if ClearPass is unreachable: is there a critical role?
  • Is the guest VLAN routed by the core or only by the firewall?
  • Which DSCP values must be trusted, and on which ports?
  • Is there an out-of-band management network, and which VRF should management use?

Changing a design decision, such as converting a tunneled SSID to bridged because it is "simpler," is not the implementer's call.


Common Exam Traps

  • Confusing VSF and VSX roles in a design. VSF is a single logical switch for access stacking; VSX is a two-switch pair with separate control planes for aggregation or core.
  • Forgetting bridged SSID VLANs. A bridged SSID's VLAN must reach the AP port; a tunneled SSID's VLAN does not.
  • Treating the HLD as complete. Missing details are expected; they are resolved in the low-level design with the architect's input.
Loading diagram...
Reading a Typical Two-Tier HLD
Test Your Knowledge

An HLD states that a corporate SSID is tunneled to an AOS 10 gateway cluster and a guest SSID is bridged to VLAN 500. Which VLANs must be allowed on the access switch ports that connect the APs?

A

Every VLAN defined on the gateway cluster

B

The AP management VLAN and guest VLAN 500

C

Only the corporate user VLANs

D

No VLANs, because all wireless traffic is tunneled

Test Your Knowledge

A design says that user default gateways use active-gateway on a CX 8360 VSX pair and access stacks uplink with VSX-LAGs. What does this tell the implementer about user VLANs?

A

User VLANs must exist on the access stacks and be allowed on the uplinks up to the VSX pair

B

User VLANs are replaced by VRFs on the access switches, one VRF for each user group

C

User VLANs end at the access stack, and the uplinks to the core are routed OSPF links

D

User VLANs are only needed on the VSX ISL, since active-gateway answers ARP for them

Test Your Knowledge

While reviewing an HLD, a deployment technician notices that it does not say what access ports should do when the RADIUS servers are unreachable. What is the appropriate action?

A

Disable 802.1X on the access ports until the design document has been finished

B

Ask the architect so the low-level design can define the behavior, such as a critical role

C

Configure open access on all ports so that users are never blocked during an outage

D

Copy the RADIUS-down setting from a different customer's design that worked well

Sections you finish are checked off in the contents.