Skip to content

Network Bonding and VLANs

Applies to CentOS Stream 9 & 10 / AlmaLinux 9.x & 10.x / Rocky Linux 9.x & 10.x

Bonding several physical NICs into one logical link keeps your network up when a card or cable fails, while VLANs let you carve multiple isolated Layer 2 networks out of a single interface. This page walks you through both of these common advanced networking tasks using nmcli.

  • The bond operating modes and which one to choose
  • How to create a bond, add ports, configure IP, and check status with nmcli
  • How to create VLAN interfaces on top of a physical NIC or a bond
  • What changes in EL 10’s configuration storage, and how to troubleshoot common failures
  • A system running EL 9.x or EL 10.x
  • sudo privileges
  • At least two physical NICs (for the bond demo, e.g. enp1s0 and enp2s0)
  • NetworkManager running (enabled by default on EL)

A bond combines several NICs into a single logical interface, bondX. Depending on the mode you pick, it can provide failover (high availability) or aggregate bandwidth (load balancing).

The modes differ significantly in their switch requirements and use cases, so review the table before you start:

ModeNameDescriptionSwitch Requirement
active-backupActive/backupOnly one NIC is active; traffic fails over to the backup NIC automatically. Most common and safest.None
802.3adLACP aggregationAll NICs work simultaneously, aggregating bandwidth and providing redundancy; standards-basedLACP (link aggregation group) must be configured on the switch
balance-xorXOR load balancingHashes by source/destination MAC; a given flow always uses the same NICUsually a static aggregation group
balance-rrRound-robinPackets are sent across NICs in turn, which can cause reorderingA static aggregation group

The example below uses the most common active-backup mode to bond enp1s0 and enp2s0 into bond0.

  1. Create the bond primary interface

    miimon=100 checks link status every 100 milliseconds, which is what makes failover trigger promptly.

    Create bond0 (active-backup mode)
    $ sudo nmcli con add type bond con-name bond0 ifname bond0 \
    bond.options "mode=active-backup,miimon=100"
  2. Add the first port

    Add the physical NIC enp1s0 as a port of bond0:

    Add the first port
    $ sudo nmcli con add type ethernet con-name bond0-port1 \
    ifname enp1s0 master bond0
  3. Add the second port

    Add the second port
    $ sudo nmcli con add type ethernet con-name bond0-port2 \
    ifname enp2s0 master bond0
  4. Configure a static IP on the bond

    The IP goes on bond0, not on the physical NICs:

    Configure IP, gateway, and DNS for bond0
    $ sudo nmcli con mod bond0 \
    ipv4.addresses 192.168.1.10/24 \
    ipv4.gateway 192.168.1.1 \
    ipv4.dns 1.1.1.1 \
    ipv4.method manual
  5. Activate the bond

    Bring up the bond, which activates its ports in the correct order:

    Bring up bond0
    $ sudo nmcli con up bond0

The kernel exports the bond’s live state to /proc, which is the authoritative source for confirming that failover works:

View bond0 status
$ cat /proc/net/bonding/bond0

The output shows the current mode, the currently active slave, and each NIC’s link status (MII Status: up):

Example output
Bonding Mode: fault-tolerance (active-backup)
Currently Active Slave: enp1s0
MII Status: up
Slave Interface: enp1s0
MII Status: up
Slave Interface: enp2s0
MII Status: up

You can also check the overall connection and device status with nmcli:

Check connection and device status
$ nmcli con show
$ nmcli dev status

A VLAN (virtual LAN) carves multiple isolated Layer 2 networks out of a single physical NIC, each identified by an ID from 1 to 4094. To use VLANs, the corresponding switch port must be configured as a trunk that allows the relevant VLAN IDs.

The following creates a VLAN interface with ID 100 on enp1s0 and configures an IP:

  1. Create the VLAN interface

    Naming the connection after the VLAN ID makes it easy to identify. The interface name is generated automatically as enp1s0.100.

    Create VLAN 100 on enp1s0
    $ sudo nmcli con add type vlan con-name vlan100 dev enp1s0 id 100
  2. Configure an IP for the VLAN interface

    Configure the IP for VLAN 100
    $ sudo nmcli con mod vlan100 \
    ipv4.addresses 192.168.100.10/24 \
    ipv4.method manual
  3. Activate the VLAN interface

    Bring up vlan100
    $ sudo nmcli con up vlan100

Bonds and VLANs can be stacked: build a redundant bond first, then carve multiple VLANs out of it. This combination is very common on production servers. Just point dev at bond0:

Create VLAN 200 on bond0
$ sudo nmcli con add type vlan con-name vlan200 dev bond0 id 200
Configure the IP and activate the VLAN
$ sudo nmcli con mod vlan200 \
ipv4.addresses 192.168.200.10/24 \
ipv4.method manual
$ sudo nmcli con up vlan200

The nmcli commands are identical on EL 9 and EL 10, and every command on this page works directly on both versions. The difference lies in how configuration files are stored:

NetworkManager uses the keyfile format by default, stored in /etc/NetworkManager/system-connections/. EL 9 still reads legacy ifcfg scripts for compatibility, but new configuration should use keyfiles directly.

View connection profiles
$ ls /etc/NetworkManager/system-connections/

First confirm that each physical NIC’s connection is active, then confirm the bond is active. The wrong activation order is the most common cause:

Check device status
$ nmcli dev status
$ cat /proc/net/bonding/bond0

If a NIC shows MII Status: down, check the physical cabling and the peer switch port. If a port connection is disconnected, activate it manually:

Activate a port manually
$ sudo nmcli con up bond0-port1

802.3ad (LACP) requires the corresponding link aggregation group (LACP / port-channel) to be configured on the switch as well. If you enable it only on the server side and the switch is not configured, the link cannot forward traffic properly. Ask your network administrator to configure LACP for those two ports on the switch, or temporarily switch to active-backup to verify the physical link itself is fine.

All bond ports, the bond itself, and any VLANs on top of it must use a consistent MTU (a VLAN tag adds 4 bytes, so plan ahead if you use jumbo frames). Set the MTU explicitly on the connection:

Set the MTU for bond0
$ sudo nmcli con mod bond0 802-3-ethernet.mtu 9000

Make sure you are activating bond0 and not a physical NIC, and confirm the port connections exist and their master points to the right bond:

Confirm the connection relationships
$ nmcli con show
$ nmcli -g connection.master con show bond0-port1

If a change has not taken effect, reactivate the connection:

Reactivate bond0
$ sudo nmcli con up bond0