skip to content

How does LACP (IEEE 802.1AX) differ from a static link bundle, and how do its active and passive modes catch a mis-cabled member?

level: middleimportance: should knowfreq 30%

answer

  1. negotiated versus declared
  2. both ends must agree
  3. System ID and key in every LACPDU
  4. passive plus passive stays silent
  5. a timeout removes a silent member

basics

~20 s

A static bundle forwards on every member with link; LACP exchanges LACPDUs carrying each end's System ID and key, so a member joins only when both ends agree. A member cabled to the wrong device is left out rather than blackholing traffic.

solid answer

~50 s

A **static bundle** is declared on both ends with no protocol: any member with physical link carries its hash share of traffic, whatever it is plugged into. **LACP**, the Link Aggregation Control Protocol in IEEE 802.1AX, makes the ends exchange **LACPDUs** describing themselves (the *actor*) and what they hear (the *partner*): a System ID, a key naming the bundle, a port identifier and state bits. A port is aggregated only if its partner's System ID and key match the other members', and it carries traffic only once both ends reach the Collecting and Distributing states. So a cable landing on the wrong switch, or a member that stops hearing its partner, is held out of the bundle. In **active** mode a port sends LACPDUs on its own; in **passive** mode it only answers, so active-active and active-passive form a bundle while passive-passive never does.

go deeper

for a junior

Recall that LACP negotiates a bundle while a static bundle is only configured, and that two passive ends never start the conversation.

for a middle

Explain what an LACPDU carries, how matching System ID and key select members, and how the Collecting and Distributing states gate traffic.

for a senior

Show how LACP turns a mis-cable or a one-way failure into a member held out of the bundle, and size the fast or slow timeout for the failure you care about.

for a principal

Decide where a static bundle is still acceptable, such as a device without LACP, and what extra monitoring that choice requires to catch silent member faults.

## Two ways to build a bundle Link aggregation makes several parallel Ethernet links act as one logical port. How the two ends agree on which links belong to it is the difference between the two ways to build one. - A **static bundle** is pure configuration: both ends are told that these ports form a group, and every member whose physical link is up receives its share of hashed traffic. One vendor calls its bundles EtherChannel and offers this unnegotiated form alongside LACP. - **LACP**, the **Link Aggregation Control Protocol**, is defined by IEEE 802.1AX (first published as 802.3ad). Its text is not an IETF document, so the values below are the IEEE standard's. The two ends exchange **LACPDUs**, small control frames sent on each member. ## What an LACPDU carries Each LACPDU describes the sender, the **actor**, and echoes what it last heard from the other end, the **partner**: | Field | Meaning | |---|---| | System ID | A system priority plus a MAC address that names the device | | Key | A number naming which bundle this port may join | | Port ID | Port priority plus port number | | State bits | Activity, Timeout, Aggregation, Synchronization, Collecting, Distributing, Defaulted, Expired | The frames go to a reserved IEEE multicast address that bridges do not forward (`01-80-C2-00-00-02`, the IEEE's Slow Protocols address), so they stay on the one link. ## How a member joins 1. Each port learns its partner's System ID and key from the LACPDUs it receives. 2. Ports that share the same local key and lead to the same partner System ID and key are **selected** for the same aggregator. 3. Both ends signal **Synchronization** once they agree, then **Collecting** (accepting frames) and **Distributing** (sending frames). 4. Only a member in the Distributing state receives traffic from the hash. RFC 7130, which adds BFD to LAG members, confirms the model: its sessions exist only while a member is Distributing or Standby. An implementation may cap the number of active members and keep extras in **Standby**, ranked by port priority; the cap is an implementation choice. ## Active and passive modes The **Activity** bit decides who talks first. | Local mode | Remote mode | Result | |---|---|---| | Active | Active | Bundle forms | | Active | Passive | Bundle forms; the passive end answers | | Passive | Passive | Nothing forms; neither end starts | | Active | Static, no LACP | No partner heard, so those ports are not aggregated | Passive mode exists so a port can be ready to bundle without speaking first. Its trap is that two passive ends wait for each other forever. ## What LACP catches that a static bundle cannot The scenario: a server bundles four 10G ports, and one cable is patched into the wrong switch. - **Static bundle:** the stray member has link, so the server hashes about a quarter of its flows onto it. The wrong switch has no idea it is part of a bundle; those frames are dropped, flooded into the wrong VLAN or, between two switches, can create a loop. The failure is partial and intermittent, the worst kind to troubleshoot. - **LACP:** the stray member hears a partner System ID (or key) different from the other three, or hears nothing at all. It is not selected for the bundle and carries no traffic. The other three run normally, and the mismatch is visible in the member's state. LACP also catches **one-way failures**. If a member keeps physical link but stops delivering frames in one direction, the receiving end stops hearing LACPDUs and, after its timeout, marks the partner information expired and removes the member. The IEEE timers come in two pairs: - **Fast**: an LACPDU every 1 s, timeout after 3 s. - **Slow**: an LACPDU every 30 s, timeout after 90 s. The Timeout bit in each LACPDU asks the partner for the rate this end wants to receive; which rate an implementation uses by default is its choice. For detection faster than seconds, RFC 7130 runs BFD on each member, a separate subject. ## Choosing | Concern | Static bundle | LACP | |---|---|---| | Mis-cabled member | Carries traffic and blackholes it | Left out of the bundle | | One-way member failure | Undetected while link is up | Removed after the timeout | | Mismatched ends | Silent loss or loop | Bundle does not form | | Dependency | None | Both ends must speak LACP | A static bundle remains the fallback when a device cannot run LACP. Everywhere else, the negotiation is cheap insurance.

  • One end of a link bundle runs LACP in active mode and the other is configured as a static bundle; what happens?
    The LACP end never receives a partner LACPDU, so it does not aggregate those ports; whether it leaves them as individual ports or suspends them is an implementation choice. The static end, meanwhile, believes it has a bundle and hashes traffic across all members. The mismatch can cause loss or a loop, which is why both ends must use the same method.
  • Why might an operator choose LACP's fast timeout on a server bundle?
    With the slow pair, a member that fails in one direction but keeps link can blackhole its flows for up to 90 seconds before the 30-second LACPDUs time out. The fast pair, an LACPDU every second with a 3-second timeout, cuts that to about 3 seconds at the cost of more control frames. Faster still needs BFD on each member, as RFC 7130 defines.

saying these in an interview costs you the question

  • Two ports in LACP passive mode will still negotiate a bundle
  • A static bundle detects a member cabled to the wrong switch
  • LACP balances traffic by negotiating which flows use which member
  • LACPDUs are forwarded by bridges across the whole switched network
  • LACP's 1-second and 30-second timers are defined in an IETF RFC