核心:EtherChannel 将多根物理链路聚合成一根逻辑 Port-Channel,通过 Hash 将不同 Flow 分散到不同 Member,从而同时获得聚合带宽和链路冗余。


1. 为什么需要 EtherChannel

假设 SW1、SW2 之间有 4 条 10G 二层链路:

1
2
3
4
SW1 ================= SW2
=================
=================
=================

如果它们是 4 条独立的 L2 Trunk,STP 会把它们看成 4 条独立路径。为了防止二层环路,在简单场景下可能只有一条 Forwarding,其余 Blocking / Discarding。

EtherChannel 将它们聚合:

1
2
3
4
E0/0 ─┐
E0/1 ─┤
E0/2 ─┼──→ Po1
E0/3 ─┘

此时 STP 看到的是一个逻辑接口 Po1,而不是 4 条独立路径。

如果 Po1 为 Forwarding,所有正常加入 Bundle 的 Member 都可以承载业务流量。

EtherChannel = 多根物理链路 → 一根逻辑链路。


2. 聚合带宽与 Hash

假设:

1
Po1 = 4 × 10G

理论聚合容量约为:

1
40G Aggregate Bandwidth

但:

1
2
3
40G Aggregate Bandwidth
≠
Single Flow 可以跑 40G

EtherChannel 通常使用 Hash 选择 Member,而不是 Packet-by-Packet 轮询。

Hash 输入根据平台/配置可能包括:

1
2
3
Source / Destination MAC
Source / Destination IP
Source / Destination Port

例如:

1
2
3
4
Flow A → E0/0
Flow B → E0/2
Flow C → E0/1
Flow D → E0/3

同一 Flow 通常保持在同一个 Member 上,以减少报文乱序。

因此:

1
2
3
4 × 10G Po
→ Aggregate ≈ 40G
→ Single Flow 通常仍受单 Member 10G 限制

Flow

常见 Flow 可以用五元组区分:

1
SIP + DIP + Protocol + Sport + Dport

例如:

1
2
192.168.1.10:50001 → 10.1.1.10:443
192.168.1.10:50002 → 10.1.1.10:443

客户端 Source Port 不同,因此可能成为不同 Flow,并有机会 Hash 到不同 Member。

一个网站/应用也可能同时建立多个 TCP/UDP Flow,所以整个应用的总吞吐可以利用多根 Member。

一个应用 ≠ 一个 Flow。

Hash 也不保证流量绝对均匀,因为不同 Flow 的流量大小不同。


3. Member 故障

正常:

1
2
3
4
Flow A → E0/0
Flow B → E0/1
Flow C → E0/2
Flow D → E0/3

如果:

1
E0/2 DOWN

只要 Po1 仍满足工作条件:

1
2
Po1:40G → 30G
Po1:仍然 UP

原本映射到 E0/2 的流量会重新映射到剩余 Member。

具体重新映射范围取决于平台的 Hash / Resilient Hash 实现。

需要注意:

  • Member Failure ≠ Port-Channel Failure
  • 故障切换期间可能存在短暂丢包或乱序
  • Hash 不是实时寻找“最空闲”的 Member

4. LACP

LACP(Link Aggregation Control Protocol)负责:

1
2
3
哪些接口可以组成 Bundle?
对端是谁?
Member 是否属于正确的聚合关系?

它不是业务流量的 Hash 算法。

1
2
3
4
5
LACP
→ Control / Negotiation

Hash
→ Data Plane Member Selection

LACP 模式

1
2
3
active  + active   → √
active + passive → √
passive + passive → ×

核心:

LACP 至少需要一端 Active。

Static EtherChannel

1
channel-group 1 mode on

mode on 不运行 LACP/PAgP,属于静态聚合。

1
2
on + on → √
on + active → ×

PAgP:

1
2
3
desirable + desirable → √
desirable + auto → √
auto + auto → ×

不同聚合协议不能混用。


5. Member 一致性

因为多个 Member 对上层必须表现成“一根逻辑链路”,所以关键转发属性必须兼容。

重点检查:

1
2
3
4
5
6
7
8
L2 / L3 类型
Access / Trunk
Access VLAN
Allowed VLAN
Native VLAN
Speed / Duplex
Physical State
LACP Mode / Partner

例如:

1
2
3
4
E0/0 → Trunk VLAN 10,20
E0/1 → Trunk VLAN 10,20
E0/2 → Trunk VLAN 10,20
E0/3 → Access VLAN 30

E0/3 不应该正常加入这个 Bundle。

另外:

1
SW1 E0/0 ↔ SW2 E1/3

完全可以。

两端物理接口编号不需要相同。

Channel-Group Number 也是本地意义:

1
SW1 Po1 ↔ SW2 Po20

可以正常工作。

工程上通常保持编号一致,只是为了方便维护。


6. L2 与 L3 EtherChannel

L2 EtherChannel

1
2
3
4
5
6
7
Po1
↓
Switchport / Trunk
↓
VLAN / MAC
↓
参与 STP

例如:

1
2
3
interface Port-channel1
switchport mode trunk
switchport trunk allowed vlan 10,20

L3 EtherChannel

1
2
3
4
5
Po1
↓
Routed Port
↓
IP / Routing

例如:

1
2
3
interface Port-channel1
no switchport
ip address 10.0.12.1 255.255.255.252

IP 地址配置在 Po 上,而不是分别配置在各 Member 上。

L3 Po 不属于 VLAN 的二层交换拓扑,因此:

1
2
L2 Po → STP
L3 Po → 不依靠 STP,由 Routing Protocol 处理三层路径

TTL 只是防止 IP Packet 无限循环,并不是三层防环/收敛协议。


min-links 用来规定:

Port-Channel 至少需要多少个有效 Member 才能保持 UP。

例如:

1
2
Po1 = 4 × 10G
min-links = 2

则:

1
2
3
4
5
4 Member → UP
3 Member → UP
2 Member → UP
1 Member → DOWN
0 Member → DOWN

例如:

1
2
3
4
5
6
E0/0(P)
E0/1(P)
E0/2 DOWN
E0/3(I)

min-links = 3

有效 Member:

1
2 < 3

因此:

1
Po1 DOWN

即使 E0/0、E0/1 都是 (P),整个 Po 仍然可以 Down。

故障后的收敛:

1
2
3
4
5
6
7
L2 Po DOWN
→ STP / RSTP 收敛
→ 使用二层备用路径

L3 Po DOWN
→ OSPF / EIGRP 等重新收敛
→ 使用其他三层路径

8. 配置命令

L2 LACP EtherChannel

SW1:

1
2
3
4
5
6
interface range Ethernet0/0-3
channel-group 1 mode active

interface Port-channel1
switchport mode trunk
switchport trunk allowed vlan 10,20

SW2:

1
2
3
4
5
6
interface range Ethernet0/0-3
channel-group 1 mode passive

interface Port-channel1
switchport mode trunk
switchport trunk allowed vlan 10,20

原则:

Member 负责“加入哪个 Bundle”,Port-Channel 负责“这条逻辑链路做什么”。

L3 EtherChannel

1
2
3
4
5
6
7
interface range Ethernet0/0-3
no switchport
channel-group 1 mode active

interface Port-channel1
no switchport
ip address 10.0.12.1 255.255.255.252

具体命令和配置继承行为可能因平台而异。


9. 验证 / Show 命令

EtherChannel 总体状态

1
show etherchannel summary

例如:

1
Po1(SU)  LACP  Et0/0(P) Et0/1(P) Et0/2(P) Et0/3(P)

常见含义:

1
2
3
4
S = Layer 2
U = In Use
P = Bundled in Port-Channel
I = Stand-Alone

注意:

1
2
3
4
5
6
7
(P)
→ Member 成功 Bundle

(I)
→ 没有成功 Bundle
→ 不等于 Physical Down
→ 也不等于 STP Blocking

LACP

1
show lacp neighbor

Hash

1
show etherchannel load-balance

Port-Channel

1
show interfaces port-channel 1

Trunk / STP

1
2
3
show interfaces trunk
show spanning-tree vlan 10
show spanning-tree vlan 20

检查异常 Member

1
2
3
4
show interfaces Ethernet0/3
show interfaces Ethernet0/3 switchport
show running-config interface Ethernet0/3
show running-config interface Port-channel1

10. 故障排查与最终总结

看到:

1
2
3
4
5
6
Po1(SU)

E0/0(P)
E0/1(P)
E0/2(P)
E0/3(I)

首先问:

为什么只有 E0/3 和其他 Member 不一样?

排查顺序:

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
show etherchannel summary
↓
找到异常 Member
↓
Physical Interface 是否 UP?
↓
接线 / Partner 是否正确?
↓
show lacp neighbor
↓
对端是否加入正确 Channel?
↓
L2 / L3 是否一致?
↓
Access / Trunk / VLAN 是否一致?
↓
Speed / Duplex 等是否兼容?
↓
检查 min-links

最终核心逻辑

1
2
3
4
5
6
7
8
9
10
11
12
13
多根物理链路
↓
EtherChannel
↓
一个逻辑 Port-Channel
↓
LACP 负责协商 Member
↓
Hash 负责选择 Member
↓
不同 Flow 分散到不同 Member
↓
提高 Aggregate Bandwidth + 提供链路冗余

必须记住:

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
Aggregate Bandwidth ≠ Single-Flow Bandwidth

Member DOWN ≠ Po DOWN

(P) ≠ Po 一定 UP

(I) ≠ Physical Down

LACP ≠ Hash

L2 Po → STP

L3 Po → Routing Protocol

有效 Member < min-links → Po DOWN

一句话总结:EtherChannel 的本质不是把一条 Flow 拆到多根链路,而是把多根物理链路抽象成一根逻辑链路,再通过 Hash 将不同 Flow 分散到不同 Member,从而获得聚合带宽和链路冗余。