12.2 AOS-CX Layer 2 and Interface Diagnostic Commands
Key Takeaways
On AOS-CX,
show interfacereports Admin state and Link state separately: admin down means the port is shut down, while admin up with link down points to cabling, the far end, optics, or a protection feature that disabled the port.Late collisions on an Ethernet interface are an unmistakable signature of a duplex mismatch (one end full-duplex, the other half-duplex) or an Ethernet cable exceeding the 100-meter distance limit.
show lldp neighbor-infoprovides rapid neighbor validation across physical links, confirming remote chassis IDs, port IDs, system names, and management addresses (show lldp neighbor-info <port>adds LLDP-MED details).LACP LAG formation fails and member ports become detached or blocked if both switch ends are set to passive mode or if interface parameters (speed, duplex, VLAN tagging) are mismatched across members.
MAC address flapping between two physical ports indicates a severe Layer 2 loop caused by Spanning Tree misconfiguration or an undetected bridge loop.
AOS-CX Layer 2 and Interface Diagnostic Commands
Quick Summary: In campus local area networks, Layer 1 physical faults and Layer 2 data link misconfigurations account for a substantial majority of connectivity failures. Aruba AOS-CX switches provide rich command-line interface (CLI) diagnostic utilities to evaluate physical transceivers, interface operational states, Link Layer Discovery Protocol (LLDP) neighbors, Link Aggregation Groups (LAG/LACP), dynamic MAC address learning tables, and Spanning Tree Protocol (STP) convergence. Mastering the interpretation of these commands allows network administrators to rapidly distinguish hardware failures from protocol-level misconfigurations.
Physical Layer and Interface Status Diagnostics
Troubleshooting begins by verifying physical port connectivity and interface hardware health using show interface <interface-id> and show interface brief. The output below is abbreviated for study purposes:
switch# show interface 1/1/1
Interface 1/1/1 is up
Admin state is up
Link state: up for 12 days, 4 hours
Link transitions: 2
Description: Uplink-to-Core-Switch
Type: 10G-BaseSR
IPv4 address: 10.1.1.2/30
Speed-duplex: 10000-full (auto)
Flow-control: off
Error-control: off
MTU: 1500
RX
142385923 packets 182394812301 bytes
0 input drops 0 CRC/FCS
0 runts 0 giants
TX
189234812 packets 293847192834 bytes
0 output drops 0 collisions
0 late collisions 0 deferred
Interpreting Administrative vs. Operational (Link) State
Every interface displays two distinct operational indicators: Admin state (administrative configuration) and Link state (physical/operational carrier state).
| Admin State | Link State | Diagnostic Interpretation and Remediation |
|---|---|---|
| up | up | Healthy Operation: Physical link is established, carrier signal detected, and Layer 2 framing is functional. |
| down | down | Administratively Disabled: The port is disabled by software. Enter interface configuration mode and issue no shutdown. |
| up | down | Physical Carrier Loss: The port is enabled, but no electrical/optical carrier signal is detected. Check cable connection, unplugged patch cord, remote device power, or faulty SFP optic. |
| up | down (disabled by a protection feature) | Security/Protection Shutdown: The port was disabled by an automated protection mechanism (e.g., BPDU Guard, a port-security shutdown action, or loop protection). Resolve the root cause and re-enable the port, or wait for that feature's recovery timer. |
| up | down / flapping | Marginal Physical Medium: Marginal optical light levels, damaged copper wire pairs, or incompatible transceiver optics. Inspect fiber patch with an optical power meter or swap transceivers. |
Speed and Duplex Auto-Negotiation Failures
Under the IEEE 802.3u standard, Ethernet devices use Fast Link Pulses (FLPs) to automatically negotiate the highest mutually supported transmission speed (10 Mbps, 100 Mbps, 1 Gbps, 10 Gbps) and duplex mode (Half vs. Full).
When auto-negotiation fails or is misconfigured, a duplex mismatch occurs:
- The Classic Duplex Mismatch Trap: If Switch A has its port hardcoded to
100-full(auto-negotiation off) while Switch B is left inauto, Switch B cannot learn the partner's duplex. It detects the speed by parallel detection but falls back to half-duplex. (1000BASE-T copper relies on auto-negotiation, which is why mismatches are mostly a 10/100 problem.) - Consequences: Switch A operates in Full Duplex (transmits and receives simultaneously; CSMA/CD disabled). Switch B operates in Half Duplex (uses CSMA/CD; aborts transmission if it senses Switch A transmitting). As traffic increases, Switch B experiences collisions, while Switch A experiences frame check sequence (FCS/CRC) errors and runt packets.
- Exam Diagnostic Rule: In modern Gigabit and 10-Gigabit Ethernet networks, both ends must be set to auto-negotiation, or both ends must be explicitly configured identically. Never configure one end manually and leave the other on auto!
Interface Error Counters and Fault Signatures
The counters in show interface reveal precise physical and data link fault signatures:
- CRC / FCS Errors (Cyclic Redundancy Check / Frame Check Sequence):
- Indicates frames received with mathematically corrupted data bits.
- Root Causes: Defective copper patch cable (damaged twisted pairs), cable running near high-voltage EMI sources (elevators, fluorescent lighting), contaminated fiber optic endfaces, excessive optical attenuation (exceeding optical decibel budget), or failing SFP transceivers.
- Collisions (Normal Collisions):
- Occurs when two half-duplex stations transmit simultaneously within the first 64 bytes (512 bit times) of a frame.
- Normal in half-duplex CSMA/CD hubs, but should never occur in a switched, full-duplex campus network.
- Late Collisions:
- A collision that occurs after the first 64 bytes (512 bits) of the frame pre-amble and header have been transmitted.
- Unmistakable Signature: Late collisions almost exclusively indicate a duplex mismatch or an Ethernet cable that exceeds the maximum physical length specification of 100 meters (328 feet).
- Runts:
- Packets received that are smaller than the IEEE 802.3 minimum Ethernet frame size of 64 bytes and fail the FCS integrity check.
- Root Causes: Collisions, duplex mismatches, or faulty network interface cards (NICs).
- Giants:
- Packets received that exceed the maximum transmission unit (standard 1518 bytes untagged / 1522 bytes 802.1Q tagged) without an authorized jumbo frame configuration.
- Root Causes: MTU mismatch between connected switches (e.g., host transmitting 9000-byte jumbo frames to a switch port configured with default 1500-byte MTU).
- Input Drops vs. Output Drops:
- Input Drops: The switch ASIC ingress queue or internal buffer is full, forcing the switch to discard incoming frames before processing. Indicates severe traffic bursts, CPU exhaustion, or ingress QoS rate-limiting.
- Output Drops (TX Drops): The egress port buffer is congested because traffic arrives faster than the port can transmit onto the physical medium. Typical when multiple 10 Gbps uplinks forward traffic toward a 1 Gbps access port (speed mismatch/oversubscription).
Link Layer Discovery Protocol (LLDP) Diagnostics
Link Layer Discovery Protocol (IEEE 802.1AB) is an open, vendor-neutral Layer 2 protocol used by network switches to advertise identity, capabilities, and configurations to adjacent neighbors. An abbreviated AOS-CX example:
switch# show lldp neighbor-info
LLDP Neighbor Information
=========================
LOCAL-PORT CHASSIS-ID PORT-ID PORT-DESC TTL SYS-NAME
------------------------------------------------------------------------
1/1/48 70:79:90:a1:b2:c0 1/1/48 1/1/48 120 Core-Switch-01
1/1/1 ac:3a:7a:12:34:56 eth0 eth0 120 AP-515-BuildingA
1/1/12 00:04:f2:98:76:54 00:04... LAN 120 Polycom-VVX-Phone
Diagnostic Value of LLDP
- Cabling and Topology Verification: Running
show lldp neighbor-infoinstantly verifies whether switch ports are physically patched to the expected upstream aggregation switches, core routers, or wireless Access Points (APs), eliminating the need to physically trace cables in data closets. - Detailed Neighbor Inspection (
show lldp neighbor-info <port>): Displays the neighbor's exact management IP address, switch firmware version, system capabilities (Bridge, Router, WLAN AP), enabled VLANs, and port description.
LLDP-MED (Media Endpoint Discovery)
LLDP-MED (ANSI/TIA-1057) extends LLDP for voice and endpoint devices (IP phones, video conferencing units, wireless APs):
- Voice VLAN Dynamic Discovery: Through the Network Policy Type-Length-Value (TLV), the switch advertises the Voice VLAN ID, 802.1p priority tag (CoS), and DSCP value to connected IP phones. If a phone fails to join the Voice VLAN, check
show lldp neighbor-info <port>and confirm that a voice VLAN is configured, because AOS-CX sends the Network Policy TLV only when a voice VLAN exists. - PoE Power Negotiation: Using LLDP power TLVs, high-power devices (such as tri-radio APs) negotiate exact wattages within their class limits (for example up to 30 W for 802.3at or 60 W for 802.3bt Type 3). If an AP boots with restricted functions, verify allocated and drawn power with
show power-over-ethernet <port>.
Link Aggregation (LAG) and LACP Diagnostics
Link Aggregation combines multiple physical Ethernet links into a single logical channel (LAG) to provide bandwidth aggregation and link-level redundancy. Aruba AOS-CX uses the Link Aggregation Control Protocol (LACP, IEEE 802.3ad / 802.1AX) to dynamically establish and monitor trunk groups.
switch# show lag 1
Aggregate-name : lag1
Aggregated-interfaces : 1/1/47 1/1/48
Aggregation-key : 1
Aggregate mode : active
Hash : l3-src-dst
Speed : 20000 Mb/s
Status : up
Up-ports : 1/1/47 1/1/48
Down-ports :
Blocked-ports :
switch# show lacp interfaces
Interface Actor Actor Partner Partner Port LACP Forwarding
Port Pri Port Pri Oper Mode State
----------------------------------------------------------------------
1/1/47 1/1/47 1 1/1/47 1 up act forwarding
1/1/48 1/1/48 1 1/1/48 1 up act forwarding
Active vs. Passive LACP Negotiation Modes
- Active Mode (
lacp mode active): The port actively transmits LACP packets at configured intervals (fast 1s or slow 30s) to initiate aggregation negotiation with the partner. - Passive Mode (
lacp mode passive): The port listens for incoming LACP packets from the partner and only transmits LACP packets in response. - Failure Condition: If both switches are configured in Passive mode, neither switch initiates LACP negotiation. The member interfaces remain unbundled, and the LAG remains down.
Common LAG Diagnostic Faults
- Out-of-Sync / Blocked Ports: If
show lagdisplays member ports in aBlockedorDetachedstate:- Speed / Duplex Mismatch: All member ports in a LAG must operate at identical speed and duplex. If port 1/1/47 negotiates 10G and port 1/1/48 negotiates 1G, the switch blocks the slower port.
- VLAN Membership Inconsistency: All member ports must inherit identical VLAN configurations (same native VLAN, same allowed trunk VLAN list).
- Cross-Cabling without Multi-Chassis Stacking: Connecting member port 1/1/47 to Switch Core-01 and member port 1/1/48 to Switch Core-02 will cause LACP failure unless Core-01 and Core-02 run Virtual Switching Framework (VSF) or Virtual Switching Extension (VSX) with a Multi-Chassis LAG (MC-LAG).
MAC Address Table Learning and Flapping Diagnostics
Layer 2 switches forward unicast frames by inspecting destination MAC addresses against the dynamic MAC address forwarding table (Filtering Database / CAM table).
switch# show mac-address-table
MAC Age-time : 300 seconds
Number of MAC Addresses : 4
MAC Address VLAN Type Port
------------------------------------------------
00:50:56:a1:b2:c3 10 dynamic 1/1/1
00:50:56:d4:e5:f6 10 dynamic 1/1/2
00:1a:1e:88:99:aa 20 dynamic lag1
Diagnosing MAC Address Flapping
A switch dynamically associates a source MAC address with the physical port on which the frame arrived. Under normal conditions, a client's MAC address remains anchored to its access port.
MAC Address Flapping occurs when the switch rapidly learns the identical MAC address on two different physical ports. Check show mac-address-table mac-move for the move count and history; the event log shows the same pattern in simplified form:
MAC 00:50:56:a1:b2:c3 moved from port 1/1/1 to port 1/1/2
MAC 00:50:56:a1:b2:c3 moved from port 1/1/2 to port 1/1/1
Root Causes:
- Layer 2 Bridging Loop (Most Common): An unmanaged switch or accidental loop cable connects two switch ports together without Spanning Tree active. Broadcast and unknown unicast frames circulate endlessly, hitting alternate ports and overwriting the MAC table continuously.
- Duplicate Hardware MAC Address: Two rogue NICs or improperly cloned virtual machines share the exact same physical MAC address on different switch ports.
- Virtual Machine Live Migration: Normal when a VM migrates from Host A to Host B (occurs once or twice, not continuously).
Spanning Tree Protocol (STP / MSTP) Diagnostics
Spanning Tree Protocol (IEEE 802.1D / 802.1w RSTP / 802.1s MSTP) prevents forwarding loops by placing redundant ports into a blocking/discarding state.
switch# show spanning-tree
Spanning tree status : Enabled Protocol: MSTP
MST0
Spanning tree status : Enabled
Root ID Priority : 4096
MAC-Address : 70:79:90:a1:b2:c0
This bridge is the root
Bridge ID Priority : 4096
MAC-Address : 70:79:90:a1:b2:c0
Hello time: 2s Forward delay: 15s Max-age: 20s
Topology change count: 34
Time since last topology change: 14s
Port Role State Cost Priority Type
--------------------------------------------------------------------
1/1/1 Designated Forwarding 2000 128 P2P
1/1/2 Designated Forwarding 2000 128 P2P
1/1/48 Root Forwarding 2000 128 P2P
1/1/47 Alternate Discarding 2000 128 P2P
Evaluating Spanning Tree Health
- Root Bridge Verification: Verify that the primary core switch is elected as Root Bridge. If an unexpected access switch becomes Root Bridge (due to default priority 32768 across all switches), traffic takes suboptimal paths.
- Port Roles and Forwarding States:
- Root Port (RP): The single port on a non-root switch with the lowest path cost to the root bridge (State:
Forwarding). - Designated Port (DP): The port on a segment that advertises the lowest cost BPDU (State:
Forwarding). - Alternate / Backup Port: Blocked redundant link preventing loops (State:
Discarding).
- Root Port (RP): The single port on a non-root switch with the lowest path cost to the root bridge (State:
- Topology Change Notifications (TCN):
- When an active switch port transitions up or down, the switch generates a Topology Change Notification.
- TCN Impact: All switches in the STP domain flush their dynamic MAC address aging timer down from default 300 seconds to the forward delay timer (15 seconds), triggering widespread unicast flooding across the campus.
- Exam Diagnostic Rule: If
Topology change countis continuously climbing andTime since last topology changeis perpetually low (under 60 seconds), an unstable access port or flapping link is destabilizing the entire Layer 2 campus. Configurespanning-tree port-type admin-edgeon all host-facing ports to prevent edge transitions from generating TCNs!
Spanning Tree Protection Features
- BPDU Guard (
spanning-tree bpdu-guard): Configured on edge ports. If an unexpected BPDU arrives (e.g., an unauthorized switch connected under an office desk), the switch immediately disables the port, protecting the topology. - Root Guard (
spanning-tree root-guard): Configured on designated downstream ports. If a switch connected to that port advertises a superior BPDU claiming to be the new Root Bridge, Root Guard places the port in a root-inconsistent (blocking) state until the rogue BPDUs stop.
Summary of AOS-CX Layer 2 CLI Diagnostic Commands
| Command | Operational Diagnostic Purpose |
|---|---|
show interface <port> | Displays link/admin state, duplex, MTU, and error counters (CRC, late collisions, drops). |
show interface brief | High-level summary of all physical ports, link states, speeds, and VLAN memberships. |
show lldp neighbor-info | Discovers neighbor chassis IDs, remote port IDs, device names, and management IPs. |
show lldp neighbor-info <port> | Deep inspection of neighbor TLVs including PoE power and Voice VLAN policy. |
diag cable-diagnostic test <port> | Runs a cable test (TDR) on supported copper ports; view results with diag cable-diagnostic show <port>. |
show lag <id> | Displays LAG operational status, member port states, hash mode, and aggregate speed. |
show lacp interfaces | Displays granular LACP actor/partner port priorities, operational states, and modes. |
show mac-address-table | Displays dynamic MAC address-to-port bindings and VLAN associations. |
show spanning-tree | Displays Root Bridge ID, bridge priority, topology change counts, and port roles/states. |
show spanning-tree inconsistent-ports | Displays ports blocked by Root Guard, Loop Guard, or BPDU protection. |
An administrator examines an AOS-CX switch uplink port (1/1/48) connected via a 10GBASE-SR fiber SFP+ transceiver. The command 'show interface 1/1/48' reveals a steadily climbing counter for CRC errors and input drops, while output drops remain zero. The link state is up/up, but users experience intermittent packet loss and degraded performance across the uplink. What is the most probable physical-layer cause?
A broadcast rate limit that is actively dropping excess ingress broadcast traffic on the port
An MTU mismatch that causes untagged frames to exceed the standard 1518-byte frame limit
A duplex mismatch in which one end is hard-coded to full duplex and the other to half duplex
A dirty fiber connector, damaged patch cable, or marginal SFP+ transceiver corrupting frames
An administrator binds two physical interfaces (1/1/1 and 1/1/2) into a Link Aggregation Group (lag 1) on Switch A and connects them to interfaces 1/1/1 and 1/1/2 on Switch B. However, running 'show lacp interfaces' on Switch A displays both member interfaces in a 'Detached' state, and the LAG fails to pass traffic. Switch A is configured with 'lacp mode passive', and Switch B is also configured with 'lacp mode passive'. What is the root cause of this failure?
AOS-CX switches support only static link aggregation; LACP is not supported
Both switches are in passive LACP mode, so neither side starts sending LACPDUs
LACP passive mode requires the member interfaces to operate at half duplex only
The member interfaces must be in different VLANs before LACP negotiation can start
An administrator observes repetitive syslog entries on an Aruba CX 6300 switch stating: 'MAC 00:50:56:a1:b2:c3 moved from port 1/1/1 to port 1/1/2'. Concurrently, overall network responsiveness plummets and switch CPU utilization rises. What network condition is occurring?
The ARP table aging timer has expired, forcing the switch to flood unicast frames out every interface
The switch has enabled dynamic 802.1X re-authentication and is re-verifying all client credentials
LLDP-MED has detected an IP phone that is renegotiating its PoE power budget with the switch
A Layer 2 loop is circulating broadcasts and relearning the MAC on alternating ports
Sections you finish are checked off in the contents.