Enough fabric capacity is needed to sustain line rate traffic of front panel ports of each switch element (FAP).

Security MAC ACLs can be used to permit and/or deny ethernet packets on the egress port by matching on the following

This feature enables the tunnel interfaces on the SAND platforms to perform filtering based on all options provided by DMF. 

The document describes an extension of the decap group feature, that allows IPv6 addresses to be configured and used as part of a group. IP-in-IP packets with v6 destination matching a configured decap group IP will be decapsulated and forwarded based on the inner header. That will allow any IP-to-IP packet type to be decapsulated, i.e. IPv4 in IPv4, IPv4 in IPv6, IPv6 in IPv4 and IPv6 in IPv6.

Verbatim qualifier This feature enhances two basic policy actions, redirect and offload, for Macro Segmentation

This article describes some enhanced mirroring configurations in addition to the ones described in

Two rate three color marker (TrTCM) meters an incoming packet stream and marks the packets based on two rates, PIR

The Wildcard tunneling feature allows the DANZ Monitoring Fabric (DMF) to decapsulate L2GRE-based tunneled traffic from any remote source. This feature, supported on SwitchLightOS (SWL) based DMF switches in prior releases, now allows wildcard tunnels on Arista EOS-based DMF switches. Please refer to the DMF User Guide for more information on configuring the feature.