Course menu

Course 5: LAN SwitchingLesson 1.3 (3 of 8 in this course)26 of 122 in the CCNA series

Lab: EtherChannel with LACP

Bundle two uplinks with LACP, make the port-channel a trunk, verify it, and fix stand-alone and suspended members.

Intermediate · 20 min read

What you will learn

After this lesson, you can bundle two uplinks with LACP, make the bundle a trunk, verify it with show etherchannel summary, and fix members that won't join.

  • LACP
  • Port-channel trunk
  • show etherchannel summary

EtherChannel bundles several parallel physical links between two switches into one logical port-channel. Spanning Tree sees a single link, so none of the members is blocked, and traffic is shared across them by a hash of addresses.

In simple terms: Two cables between the same two switches behave like one thicker cable: both carry traffic, and if one breaks the other keeps going.

The situation

The access switch AS1 has two gigabit uplinks to the distribution switch DS1. Today Spanning Tree blocks one of them, so users share 1 Gbps and the second cable sits idle. Bundle the two links into Port-channel 1 with LACP, carry VLANs 10 and 20 over it as a trunk, and prove that both members forward.

Gi1/0/1Gi1/0/23Gi1/0/2Gi1/0/24DS1distributionAS1access, VLANs 10 and 20PC10VLAN 10PC20VLAN 20
  1. 1. Goal: Gi1/0/1–2 on DS1 and Gi1/0/23–24 on AS1 become Port-channel 1, an 802.1Q trunk for VLANs 10 and 20.
  2. 2. Traffic: Each flow is hashed onto one member; different flows can use different members.

Task 1: plan it

Decide the protocol and mode on each side, the channel number, and where the trunk settings go.

Show the plan
SettingChoiceWhy
ProtocolLACP (802.3ad)Open standard, and it checks the far end before bundling, unlike mode on.
Modesactive on bothactive/active and active/passive both bundle; passive/passive never does.
Channel number1 on bothOnly locally significant, but matching numbers keep it readable.
Trunk settingsOn interface Port-channel 1Settings on the port-channel are copied to the members, which keeps them consistent.
Members must matchSpeed, duplex, mode (trunk), allowed VLANs, native VLANA member that differs is suspended.

Task 2: configure both switches

Show the configuration
! DS1 interface range GigabitEthernet1/0/1 - 2 channel-group 1 mode active ! interface Port-channel1 switchport mode trunk switchport trunk allowed vlan 10,20

channel-group creates Port-channel 1 automatically. The trunk settings are then applied to the port-channel.

! AS1 interface range GigabitEthernet1/0/23 - 24 channel-group 1 mode active ! interface Port-channel1 switchport mode trunk switchport trunk allowed vlan 10,20

The same on the access switch. On some older switches you also need switchport trunk encapsulation dot1q before switchport mode trunk.

port-channel load-balance src-dst-ip

Optional, global configuration: hash on source and destination IP so traffic between many hosts spreads more evenly than with the default MAC-based hash on some platforms.

Task 3: verify

Example output · based on Cisco documentation; exact format varies by platform and software version
AS1#show etherchannel summary
Flags:  D - down        P - bundled in port-channel
        I - stand-alone s - suspended
        H - Hot-standby (LACP only)
        R - Layer3      S - Layer2
        U - in use      f - failed to allocate aggregator

Number of channel-groups in use: 1
Number of aggregators:           1

Group  Port-channel  Protocol    Ports
------+-------------+-----------+-----------------------------------------------
1      Po1(SU)         LACP      Gi1/0/23(P) Gi1/0/24(P)
Po1(SU): a Layer 2 port-channel in use. Both members show (P), bundled. This is the line to check first whenever a bundle misbehaves.
Example output · based on Cisco documentation; exact format varies by platform and software version
AS1#show interfaces trunk
Port        Mode             Encapsulation  Status        Native vlan
Po1         on               802.1q         trunking      1

Port        Vlans allowed on trunk
Po1         10,20
The trunk is the port-channel, not the individual members.
Question: what does Spanning Tree show for VLAN 10 now?

One port, Po1, forwarding. Spanning Tree treats the bundle as a single link, so there is nothing left to block between DS1 and AS1. Check with show spanning-tree vlan 10.

Task 4: break it and fix it

Each output below comes from a slightly different mistake. Work out the cause before opening the answer.

Fault A

Example output · based on Cisco documentation; exact format varies by platform and software version
AS1#show etherchannel summary | begin Group
Group  Port-channel  Protocol    Ports
------+-------------+-----------+-----------------------------------------------
1      Po1(SD)         LACP      Gi1/0/23(I) Gi1/0/24(I)
Show diagnosis

Both members are (I) stand-alone and the channel is down: LACP found no partner. Someone configured channel-group 1 mode passive on both switches. Passive only answers; two passive ends never start the negotiation. Fix: make at least one side active.

Fault B

Example output · based on Cisco documentation; exact format varies by platform and software version
AS1#show etherchannel summary | begin Group
Group  Port-channel  Protocol    Ports
------+-------------+-----------+-----------------------------------------------
1      Po1(SU)         LACP      Gi1/0/23(P) Gi1/0/24(s)
Show diagnosis

Gi1/0/24 is (s) suspended: its settings don't match the bundle. Typically someone configured the member directly, for example switchport trunk allowed vlan 10 on Gi1/0/24 only. Fix: remove the member-specific settings (default interface is quickest, then re-add channel-group 1 mode active) and configure trunk settings on Port-channel 1 only.

Fault C

DS1 uses channel-group 1 mode on, AS1 uses mode active. What do you expect?

Show diagnosis

No bundle. on sends no LACP at all, so AS1's active ports never hear a partner and stay stand-alone, while DS1 forces a channel. That mismatch can also cause Spanning Tree to err-disable ports (EtherChannel misconfiguration guard). Fix: use LACP on both ends, or on on both ends, never a mix.

Task 5: check yourself

Predict · scenario 1

DS1 is LACP active and AS1 is LACP passive. Does the bundle form?

Predict · scenario 2

One member of a two-link bundle fails. What happens to traffic?

Predict · scenario 3

Where should switchport trunk allowed vlan 10,20 be configured?