What is Ethernet link aggregation, and what does bundling four 10G links into one logical port give that four separate links do not?
answer
- one logical port, many cables
- spanning tree sees a single port
- capacity summed across flows
- survives a member failure
- IEEE 802.1AX, once 802.3ad
basics
~20 sLink aggregation joins parallel Ethernet links into one logical link: spanning tree and routing see one port, every member forwards, and a failed member only costs capacity. Four 10G links give 40G in total, yet each flow rides one member.
solid answer
~50 sLink aggregation, standardised as IEEE 802.1AX (first published as 802.3ad), combines parallel full-duplex Ethernet links between the same two devices into one **link aggregation group** (LAG). Upper layers see a single interface: one MAC-level port for spanning tree, one interface for IP and routing. That buys three things four separate links cannot. First, **all four forward**: separate parallel links would form a loop, so spanning tree would block three of them, while a bundle counts as one port and nothing is blocked. Second, **capacity adds up**: the bundle offers 40G in aggregate, spread by hashing each flow onto one member. Third, **resilience**: if a member fails, its flows move to the survivors and the logical link stays up, with nothing to reconverge above it. The catch is that a single flow is never split, so it still tops out at one member's 10G.
go deeper
Recall that a bundle is one logical port made of several cables, that spanning tree sees it as one port, and that a single flow still tops out at one member's speed.
Explain why parallel unbundled links get blocked, how per-flow hashing spreads traffic, and why frames of one flow stay on one member to avoid reordering.
Show judgement about when the aggregate figure is real: few large flows, poor hash inputs and member failures all shrink usable capacity well below the sum of the members.
Weigh a bundle against routed parallel links: the bundle hides members from upper layers, which simplifies design but also hides partial failures from routing unless a minimum-links rule exposes them.
## The problem with parallel links Two Ethernet switches, or a server and a switch, often need more bandwidth or more resilience than one cable gives. The obvious move is to plug in more cables. On a switched Ethernet network that backfires: two parallel links between the same two switches form a **Layer 2 loop**, and a loop with no protection lets broadcast frames circulate forever. Spanning tree exists to stop that, and it does so by **blocking** all but one of the parallel links. The extra cables then sit idle as cold spares, and when the forwarding link fails, traffic waits for spanning tree to unblock another one. **Link aggregation** solves this by changing what the upper layers see. It is standardised by the IEEE as **802.1AX**, first published in 2000 as the **802.3ad** amendment to Ethernet; the standard's text is not an IETF document, but RFC 7130 restates its purpose: a link aggregation group "provides mechanisms to combine multiple physical links into a single logical link" with higher bandwidth and better resiliency. ## What the bundle looks like from above The parallel links, called **members**, are tied to one logical interface: - **Spanning tree** sees one port, not four, so it has no loop to break and blocks nothing on the bundle. - **IP and routing** see one interface with one address; RFC 7130 notes that a protocol such as OSPF has no insight into the members and treats the group as one bigger interface. - **MAC learning** points a learned address at the logical port, so a frame for that address may leave on any member. The members are normally point-to-point, full-duplex links of one speed, and all of them must end on the same partner device (or on two switches that pretend to be one, a multi-chassis design covered separately). ## The three things it buys | Property | Four separate links | One four-member bundle | |---|---|---| | Links forwarding | One; spanning tree blocks the rest | All four | | Aggregate capacity | 10G | 40G, shared across flows | | A member fails | Spanning tree reconverges onto another link | Survivors carry on; the logical link stays up | | Capacity for one flow | 10G | Still 10G | 1. **Every member forwards.** With nothing blocked, all paid-for capacity is in use all the time. 2. **Aggregate bandwidth.** The bundle offers the sum of its members, 4 x 10G = 40G in total. 3. **Faster, quieter failure handling.** When a member drops, the frames it carried are lost, its flows are moved to the remaining members, and nothing above the bundle has to recompute a tree or a route. ## The limit everyone forgets The bundle does not split a stream of frames across members frame by frame. Reordering would hurt: TCP treats several segments arriving ahead of a late one as a sign of loss and retransmits needlessly, a cost RFC 2991 describes for multipath forwarding in general. So the sender runs a **hash** over header fields such as MAC addresses, IP addresses and ports, and every frame of one flow goes to the same member. Two consequences follow: - One TCP connection never exceeds **one member's speed**: a backup job copying one large file over the 40G bundle still moves at most 10G. - The 40G figure is reached only when many flows hash fairly evenly; a handful of large flows may land on the same member while another sits idle. ## Static or negotiated A bundle can be built two ways. A **static bundle** simply declares the ports aggregated on both ends; one vendor calls its bundles EtherChannel and supports this unnegotiated form. The **Link Aggregation Control Protocol (LACP)**, part of 802.1AX, has the two ends exchange control frames so each member joins only when both sides agree, which catches a cable plugged into the wrong device. Most designs prefer LACP for that safety. ## Where it is used - **Server to top-of-rack switch**, for more bandwidth across many client connections and for surviving a cable or optic failure. - **Switch-to-switch uplinks**, where it keeps every uplink forwarding instead of blocked. - **Multi-chassis bundles**, where a server's members land on two switches so that losing a whole switch is survivable; that needs the two switches to coordinate, since the standard assumes one partner. The junior-level answer is the four-row table above: everything forwards, capacity adds up across flows, a member failure is absorbed, and a single flow is still capped at one member.
- Why can't you get the same result by running four parallel links with spanning tree and no bundle?Four parallel links between the same two switches form a loop, so spanning tree blocks three of them and only one forwards. You get 10G, not 40G, and a link failure waits for spanning tree to unblock a replacement. A bundle presents the four as one port, so spanning tree blocks nothing and a member failure is handled inside the bundle.
- A backup job copies one large file over a 4 x 10G bundle; what speed should you expect, and why?At most about 10G. The bundle hashes each flow onto one member to keep its frames in order, and one file copy over one TCP connection is one flow. The other three members carry other flows. To use more of the bundle, the job must open several connections whose hash inputs differ, typically their source ports.
A bundle is a motorway with four lanes instead of one: the road as a whole carries four times the traffic, but each car stays in its lane, so no single car goes faster than one lane allows.
saying these in an interview costs you the question
- A 4 x 10G bundle makes a single file transfer run at 40G
- Spanning tree still blocks three of the four bundle members
- The bundle splits each flow's frames round-robin across members
- Losing one member takes the whole logical link down
- Link aggregation members may land on any switch without coordination