4.2 EtherChannel Bundling: Static, LACP, and PAgP Implementation and Verification
Key Takeaways
EtherChannel bundles up to 8 active physical links (and up to 8 standby links in LACP) into a single logical Port-channel interface, aggregating bandwidth and preventing Spanning Tree blocking.
Link Aggregation Control Protocol (LACP / IEEE 802.3ad / 802.1ax) uses Active and Passive negotiation modes, utilizing System Priority and Port Priority (default 32768, lower is preferred) to select active versus hot-standby links.
Port Aggregation Protocol (PAgP) is a proprietary negotiation protocol utilizing Desirable and Auto modes, requiring at least one side set to Desirable to establish an operational channel bundle.
Member interfaces must maintain strict configuration consistency—including matching speed, duplex, switchport mode, native VLAN, allowed VLANs, and STP path costs—to prevent bundle suspension or err-disabled states.
EtherChannel load balancing relies on mathematical hash algorithms (evaluating source/destination MAC, IP, or Layer 4 transport ports), where link bundle sizes equal to powers of 2 (2, 4, 8) achieve optimal frame distribution without polarization.
EtherChannel Bundling: Static, LACP, and PAgP Implementation and Verification
Redundant inter-switch links in enterprise campus topologies introduce forwarding loops if left unmanaged. While Spanning Tree Protocol (STP) prevents Layer 2 loops by placing redundant physical links into a blocking state, this mechanism leaves valuable link bandwidth idle. EtherChannel technology resolves this limitation by aggregating multiple physical Ethernet links into a single logical link, known as a Port-channel (Po). Link aggregation provides cumulative bandwidth, deterministic link redundancy, and sub-second failover without triggering STP topology recalculations.
Link Aggregation Principles and Spanning Tree Interaction
When multiple physical links connect two switches, Spanning Tree sees only the logical Port-channel interface. STP calculates path costs and forwarding states based on the aggregate capacity of the bundle rather than individual physical interfaces. For example, aggregating four 1 Gbps physical links creates a 4 Gbps logical Port-channel with a substantially reduced STP path cost:
Physical View Logical STP View
+-----------------+ +-----------------+
| Switch A | | Switch A |
+-----------------+ +-----------------+
| | | | ||
Gi0/1 Gi0/2 Gi0/3 Gi0/4 || Port-channel 1
| | | | (4 Gbps Aggregated)
+-----------------+ ||
| Switch B | +-----------------+
+-----------------+ | Switch B |
(Without EtherChannel: +-----------------+
3 links blocked by STP) (All links active / forwarding)
If an individual physical link within an active bundle experiences a hardware fault or fiber break, EtherChannel redistributes traffic across the surviving member links in milliseconds. Because the logical Port-channel interface remains in the UP/UP state, Spanning Tree generates no Topology Change Notifications (TCNs), preventing network-wide MAC address table flushes.
Negotiation Protocols: PAgP vs. LACP vs. Static Mode
Cisco switches support two dynamic negotiation protocols alongside static manual bundling:
1. Port Aggregation Protocol (PAgP)
PAgP is a Cisco-proprietary link aggregation protocol. PAgP packets are exchanged across member links using multicast MAC address 01-00-0C-CC-CC-CC with Subnetwork Access Protocol (SNAP) encapsulation.
auto: Places the interface into a passive listening state. Responds to incoming PAgP packets but never initiates negotiation.desirable: Actively initiates negotiation by transmitting PAgP packets to form a bundle.- Silent vs. Non-Silent: By default, PAgP operates in silent mode (
channel-group 1 mode desirable). Silent mode allows a switch to bundle ports connected to passive partners (such as network file servers or traffic analyzers) that do not transmit PAgP packets. Configuringnon-silentrequires the partner to actively exchange PAgP packets; if no packets are received, the link is suspended.
2. Link Aggregation Control Protocol (LACP)
LACP is an open industry-standard protocol defined originally in IEEE 802.3ad and subsequently incorporated into IEEE 802.1ax. LACP packets (LACPDUs) use destination multicast MAC 01-80-C2-00-00-02 with EtherType 0x8809.
passive: Listens passively for LACPDUs. Responds to received packets but does not initiate negotiation.active: Actively transmits LACPDUs at regular intervals to initiate and maintain bundle negotiation.- 16-Link Aggregation (Active vs. Standby): LACP supports bundling up to 16 physical links within a single channel group. However, a maximum of 8 links can actively forward traffic simultaneously; the remaining links (up to 8) operate in hot-standby state, immediately activating if an operational link fails.
- Master Switch and Port Priority Election:
- LACP System Priority: A 2-byte priority (0–65535, default 32768) concatenated with the switch's 6-byte base MAC address. The switch with the lowest numeric system priority becomes the master decision-maker for bundle membership.
- LACP Port Priority: A 2-byte priority (0–65535, default 32768) and 2-byte port number assigned to each interface. The master switch selects the 8 active links based on the lowest numerical port priority. Member ports with higher numeric priorities are placed into hot-standby (
Hflag in CLI).
- LACP Timers: LACP exchange frequency is determined by
lacp rate:lacp rate normal(default): Sends LACPDUs every 30 seconds with a 90-second timeout.lacp rate fast: Sends LACPDUs every 1 second with a 3-second timeout, accelerating link failure detection.
3. Static EtherChannel (mode on)
Configuring channel-group <id> mode on forces the physical interfaces into an unconditional channel bundle without running any negotiation protocol.
- Both endpoints must be statically configured with
mode on. - Operational Hazard: Because no negotiation frames are exchanged, the switch cannot verify link partner identity or cable continuity. If a cabling error occurs, or if the remote partner is misconfigured, a catastrophic Layer 2 loop or traffic black hole will occur.
Protocol Comparison
| Dimension | PAgP | LACP | Static Mode (on) |
|---|---|---|---|
| Standard | Cisco Proprietary | IEEE 802.3ad / 802.1ax | Non-standard / Manual |
| Negotiation Modes | Auto, Desirable | Passive, Active | On |
| Max Active Links | 8 links | 8 links | 8 links |
| Hot-Standby Links | Not supported | Up to 8 standby links | Not supported |
| Heartbeat Frequency | Periodic (30s) | Fast (1s) or Normal (30s) | None |
| Loop Risk on Miswire | Low (negotiation prevents) | Low (negotiation prevents) | High (no keepalives) |
EtherChannel Mode Compatibility Matrix
| Local Interface Mode | Remote: On | Remote: Desirable | Remote: Auto | Remote: Active | Remote: Passive |
|---|---|---|---|---|---|
| On | Channel | No Channel | No Channel | No Channel | No Channel |
| Desirable (PAgP) | No Channel | Channel | Channel | No Channel | No Channel |
| Auto (PAgP) | No Channel | Channel | No Channel | No Channel | No Channel |
| Active (LACP) | No Channel | No Channel | No Channel | Channel | Channel |
| Passive (LACP) | No Channel | No Channel | No Channel | Channel | No Channel |
Member Interface Consistency Requirements
To form and maintain an operational EtherChannel bundle, all member physical interfaces must maintain identical physical and logical configurations:
- Port Speed and Duplex: All ports must operate at the same transmission speed (e.g., all 1 Gbps or all 10 Gbps) and duplex setting (full duplex is required).
- Switchport Mode: All interfaces must match as either access ports or trunk ports.
- Access VLAN: For access bundles, all ports must be assigned to the identical access VLAN ID.
- Trunking Parameters: For trunk bundles, ports must share identical trunk encapsulation (802.1Q), identical native VLAN IDs, and identical permitted VLAN ranges (
switchport trunk allowed vlan). - Spanning Tree Configuration: Member ports must share identical STP path costs, port priorities, and interface-level STP guard settings.
- Hardware Parameters: Quality of Service (QoS) markings, MTU boundaries, and storm control thresholds must match across all member interfaces.
Configuration Best Practice: Always apply configuration commands directly to the logical Port-channel interface (e.g., interface Port-channel 1). The switch automatically propagates changes made at the Port-channel interface to all bundled physical member interfaces, preventing configuration discrepancies.
Load-Balancing Hash Algorithms and Polarization
EtherChannel does not distribute frames across member links using round-robin packet switching. Round-robin transmission would cause packets belonging to the same TCP stream to arrive out of order, forcing TCP window resets and degrading throughput.
Instead, EtherChannel implements deterministic hashing algorithms. The switch evaluates specific packet header fields through a mathematical hash function, generating an index number (0 to 7) mapped to a specific physical link. All frames belonging to a single conversation flow hash to the identical member link, preserving in-order packet delivery.
Hash Configuration Options
The load-balancing algorithm is configured globally:
Switch(config)# port-channel load-balance <method>
Supported hash parameters include:
src-mac: Hashes on source MAC address (ideal for access-to-distribution links where multiple clients communicate with few default gateways).dst-mac: Hashes on destination MAC address.src-dst-mac: Hashes on combined source and destination MAC.src-ip/dst-ip/src-dst-ip: Evaluates Layer 3 IPv4/IPv6 addresses.src-port/dst-port/src-dst-port: Evaluates Layer 4 TCP/UDP transport port numbers, providing the most granular load distribution across multi-user application servers.
Power-of-Two Distribution and EtherChannel Polarization
The hash mechanism divides traffic into 8 discrete forwarding buckets. Optimal distribution occurs when the number of active physical links in the bundle is a power of 2 (2, 4, or 8 links):
- 2 Links: Each link receives 4 buckets (50% / 50% split).
- 4 Links: Each link receives 2 buckets (25% / 25% / 25% / 25% split).
- 8 Links: Each link receives 1 bucket (12.5% each).
If a bundle contains non-power-of-two link counts (e.g., 3 links), hash buckets cannot divide evenly. With 3 links, the switch allocates buckets in a 3-3-2 ratio (37.5%, 37.5%, and 25%), creating unavoidable traffic skew.
EtherChannel Polarization: When consecutive multi-tier switches (e.g., Access to Distribution, and Distribution to Core) implement identical hashing algorithms and identical link counts, all frames that hashed to Link 1 at the access layer will hash again to Link 1 at the distribution layer. This starves secondary uplinks. Mitigate polarization by alternating hashing algorithms across tiers (e.g., src-dst-ip at access, src-dst-port at distribution).
CLI Verification and Troubleshooting Err-Disabled States
Comprehensive CLI Verification
Switch# show etherchannel summary
Flags: D - down P - bundled in port-channel
I - stand-alone s - suspended
H - Hot-standby (LACP only)
R - Layer3 S - Layer2
U - in use f - failed to allocate aggregator
Group Port-channel Protocol Ports
------+-------------+-----------+-----------------------------------------------
1 Po1(SU) LACP Gi0/1(P) Gi0/2(P) Gi0/3(P) Gi0/4(P)
2 Po2(SU) PAgP Gi0/5(P) Gi0/6(P)
3 Po3(SD) LACP Gi0/7(D) Gi0/8(s)
Key flag interpretations:
S(Layer 2) vs.R(Layer 3): Defines whether the Port-channel operates as a switched or routed interface.U(In use): Port-channel is operational and actively passing traffic.P(Bundled in port-channel): Physical port has successfully converged into the bundle.s(Suspended): Member port configuration conflicts with the Port-channel aggregator (e.g., speed, duplex, or VLAN mismatch).H(Hot-standby): Port is an operational LACP link exceeding the 8-link active limit, waiting in standby.I(Stand-alone): Port failed negotiation and operates as an independent interface.
Additional diagnostics:
show lacp neighbor: Displays partner system ID, operational port priority, and state flags.show lacp sys-id: Reports the local switch's 2-byte system priority and MAC address.
Channel Misconfiguration Guard
Cisco switches incorporate Spanning Tree EtherChannel Guard (spanning-tree etherchannel guard misconfig). If member interfaces receive BPDUs containing inconsistent bridge IDs or port IDs—indicating that remote physical interfaces do not connect to the same switch or port channel—the switch disables the affected ports, placing them into the err-disabled state to prevent bridging loops:
%PM-4-ERR_DISABLE: channel-misconfig error detected on Gi0/1, putting Gi0/1 in err-disable state
Recovery requires resolving the physical wiring or configuration mismatch, followed by shutdown and no shutdown on the affected ports, or automating recovery using errdisable recovery cause channel-misconfig.
In an LACP EtherChannel configured with 10 physical links across two switches, which mechanism determines which 8 links actively forward traffic and which 2 links remain in hot-standby?
The switch with the higher MAC address selects active links based on the lowest interface speed
The switch with the lowest LACP System Priority determines active links based on its lowest numerical LACP Port Priorities
Both switches execute a Spanning Tree root election to disable the links with the highest path cost
The link with the highest physical port number is placed into hot-standby first, followed by the next highest port number
An enterprise network topology deploys EtherChannel bundles across access, distribution, and core switching tiers. Network monitoring reveals that traffic is heavily concentrated on a single physical link within each bundle, while parallel member links remain virtually unused. What phenomenon is causing this behavior, and how is it resolved?
DTP negotiation deadlock between tiers; resolved by configuring switchport nonegotiate on all of the trunk bundles
Native VLAN mismatch between tiers; resolved by executing vlan dot1q tag native globally on every switch in the topology
Spanning Tree root port inconsistency; resolved by deploying Root Guard on access layer uplinks
EtherChannel polarization from identical hash algorithms on each tier; fix it by using different hash inputs per tier
When inspecting the output of show etherchannel summary, an engineer observes that interface GigabitEthernet0/2 displays the s flag and the Port-channel displays SD. What does this indicate?
The member port is suspended because its settings (speed, duplex, VLANs) do not match the port channel, which is down
The physical port is in hot-standby mode, waiting for an active link in the LACP bundle to fail before it starts forwarding
The port-channel is operating as a Layer 3 routed interface and is successfully passing user traffic across all members
The physical port is operating in stand-alone mode because dynamic negotiation timed out
Sections you finish are checked off in the contents.