Network Bonding and VLANs
Applies to CentOS Stream 9 & 10 / AlmaLinux 9.x & 10.x / Rocky Linux 9.x & 10.x
Bonding several physical NICs into one logical link keeps your network up when a card or cable fails, while VLANs let you carve multiple isolated Layer 2 networks out of a single interface. This page walks you through both of these common advanced networking tasks using nmcli.
What You Will Learn
Section titled “What You Will Learn”- The bond operating modes and which one to choose
- How to create a bond, add ports, configure IP, and check status with
nmcli - How to create VLAN interfaces on top of a physical NIC or a bond
- What changes in EL 10’s configuration storage, and how to troubleshoot common failures
Prerequisites
Section titled “Prerequisites”- A system running EL 9.x or EL 10.x
- sudo privileges
- At least two physical NICs (for the bond demo, e.g.
enp1s0andenp2s0) - NetworkManager running (enabled by default on EL)
Link Aggregation with Bonds
Section titled “Link Aggregation with Bonds”A bond combines several NICs into a single logical interface, bondX. Depending on the mode you pick, it can provide failover (high availability) or aggregate bandwidth (load balancing).
Choosing a Bond Mode
Section titled “Choosing a Bond Mode”The modes differ significantly in their switch requirements and use cases, so review the table before you start:
| Mode | Name | Description | Switch Requirement |
|---|---|---|---|
active-backup | Active/backup | Only one NIC is active; traffic fails over to the backup NIC automatically. Most common and safest. | None |
802.3ad | LACP aggregation | All NICs work simultaneously, aggregating bandwidth and providing redundancy; standards-based | LACP (link aggregation group) must be configured on the switch |
balance-xor | XOR load balancing | Hashes by source/destination MAC; a given flow always uses the same NIC | Usually a static aggregation group |
balance-rr | Round-robin | Packets are sent across NICs in turn, which can cause reordering | A static aggregation group |
Creating the Bond and Adding Ports
Section titled “Creating the Bond and Adding Ports”The example below uses the most common active-backup mode to bond enp1s0 and enp2s0 into bond0.
-
Create the bond primary interface
miimon=100checks link status every 100 milliseconds, which is what makes failover trigger promptly.Create bond0 (active-backup mode) $ sudo nmcli con add type bond con-name bond0 ifname bond0 \bond.options "mode=active-backup,miimon=100" -
Add the first port
Add the physical NIC
enp1s0as a port ofbond0:Add the first port $ sudo nmcli con add type ethernet con-name bond0-port1 \ifname enp1s0 master bond0 -
Add the second port
Add the second port $ sudo nmcli con add type ethernet con-name bond0-port2 \ifname enp2s0 master bond0 -
Configure a static IP on the bond
The IP goes on
bond0, not on the physical NICs:Configure IP, gateway, and DNS for bond0 $ sudo nmcli con mod bond0 \ipv4.addresses 192.168.1.10/24 \ipv4.gateway 192.168.1.1 \ipv4.dns 1.1.1.1 \ipv4.method manual -
Activate the bond
Bring up the bond, which activates its ports in the correct order:
Bring up bond0 $ sudo nmcli con up bond0
Checking Bond Status
Section titled “Checking Bond Status”The kernel exports the bond’s live state to /proc, which is the authoritative source for confirming that failover works:
$ cat /proc/net/bonding/bond0The output shows the current mode, the currently active slave, and each NIC’s link status (MII Status: up):
Bonding Mode: fault-tolerance (active-backup)Currently Active Slave: enp1s0MII Status: up
Slave Interface: enp1s0MII Status: up
Slave Interface: enp2s0MII Status: upYou can also check the overall connection and device status with nmcli:
$ nmcli con show$ nmcli dev statusA VLAN (virtual LAN) carves multiple isolated Layer 2 networks out of a single physical NIC, each identified by an ID from 1 to 4094. To use VLANs, the corresponding switch port must be configured as a trunk that allows the relevant VLAN IDs.
Creating a VLAN on a Physical NIC
Section titled “Creating a VLAN on a Physical NIC”The following creates a VLAN interface with ID 100 on enp1s0 and configures an IP:
-
Create the VLAN interface
Naming the connection after the VLAN ID makes it easy to identify. The interface name is generated automatically as
enp1s0.100.Create VLAN 100 on enp1s0 $ sudo nmcli con add type vlan con-name vlan100 dev enp1s0 id 100 -
Configure an IP for the VLAN interface
Configure the IP for VLAN 100 $ sudo nmcli con mod vlan100 \ipv4.addresses 192.168.100.10/24 \ipv4.method manual -
Activate the VLAN interface
Bring up vlan100 $ sudo nmcli con up vlan100
Creating a VLAN on Top of a Bond
Section titled “Creating a VLAN on Top of a Bond”Bonds and VLANs can be stacked: build a redundant bond first, then carve multiple VLANs out of it. This combination is very common on production servers. Just point dev at bond0:
$ sudo nmcli con add type vlan con-name vlan200 dev bond0 id 200$ sudo nmcli con mod vlan200 \ ipv4.addresses 192.168.200.10/24 \ ipv4.method manual$ sudo nmcli con up vlan200EL 10 Notes
Section titled “EL 10 Notes”The nmcli commands are identical on EL 9 and EL 10, and every command on this page works directly on both versions. The difference lies in how configuration files are stored:
NetworkManager uses the keyfile format by default, stored in /etc/NetworkManager/system-connections/. EL 9 still reads legacy ifcfg scripts for compatibility, but new configuration should use keyfiles directly.
$ ls /etc/NetworkManager/system-connections/EL 10 removes support for ifcfg scripts entirely; all connections are stored only as keyfiles in /etc/NetworkManager/system-connections/. Because you are using nmcli, this change is transparent to you — the commands are unchanged, and NetworkManager writes keyfiles automatically.
$ ls /etc/NetworkManager/system-connections/bond0.nmconnection bond0-port1.nmconnection vlan100.nmconnectionCommon Issues
Section titled “Common Issues”Ports (slaves) Do Not Come Up
Section titled “Ports (slaves) Do Not Come Up”First confirm that each physical NIC’s connection is active, then confirm the bond is active. The wrong activation order is the most common cause:
$ nmcli dev status$ cat /proc/net/bonding/bond0If a NIC shows MII Status: down, check the physical cabling and the peer switch port. If a port connection is disconnected, activate it manually:
$ sudo nmcli con up bond0-port1802.3ad Mode Has No Connectivity
Section titled “802.3ad Mode Has No Connectivity”802.3ad (LACP) requires the corresponding link aggregation group (LACP / port-channel) to be configured on the switch as well. If you enable it only on the server side and the switch is not configured, the link cannot forward traffic properly. Ask your network administrator to configure LACP for those two ports on the switch, or temporarily switch to active-backup to verify the physical link itself is fine.
MTU Mismatch Causing Packet Loss
Section titled “MTU Mismatch Causing Packet Loss”All bond ports, the bond itself, and any VLANs on top of it must use a consistent MTU (a VLAN tag adds 4 bytes, so plan ahead if you use jumbo frames). Set the MTU explicitly on the connection:
$ sudo nmcli con mod bond0 802-3-ethernet.mtu 9000Bond Configuration Has No Effect
Section titled “Bond Configuration Has No Effect”Make sure you are activating bond0 and not a physical NIC, and confirm the port connections exist and their master points to the right bond:
$ nmcli con show$ nmcli -g connection.master con show bond0-port1If a change has not taken effect, reactivate the connection:
$ sudo nmcli con up bond0Further Reading
Section titled “Further Reading”- NetworkManager Basics
- IP & Routing
- High Availability Practices
man nmcli/man nm-settings