Cisco Switching/Routing :: 3750 BPDU Guard And Bridge Loops

May 22, 2013

We have an environment where users create a lot of bridge loops.  We have tried to send E-mails about it and educate the users but it is almost a lost cause at this point.  The loops are created when users don’t pay attention and they plug a patch cable coming off of an access port up to ANOTHER access port by mistake.
 
All of our access ports are from 3750 stacked switches.  The way we tried to deal with this in the beginning was with BPDUGuard and ERRDiable (BPDUGuard) auto recovery.  We turned BPDUGuard on globally and left BPDUGuard auto recovery at the default value (I believe it was 30 seconds). so a loop would be detected and after 30 seconds, the switch would try to enable the port and if the loop still existed, close the port for 30 more seconds.  Then we started having problems with printers getting "fried".  Their NICs would die out and the control board would need to be replaced.  After a lot of troubleshooting and testing, it was determined that allowing the ports to come out of ERRDisabled state would flood the network and the packets would generate in the millions per second range and fry the NIC of these printer.
 
The fix for this and saving the printers was terrible.  We removed ERRDisable auto recovery and just let the ports that are looped stay in an ERRRDisabled state.  We wait for the user to figure out the loop and try to use the port and then put in a work order.  Then we physically visit the site and verify the port was shut (ERRDisabled) from a loop and we bounce the port (shut/no shut) and everything is resolved. I did lab tests with a switch looped and a printer on the switch and watched it fry.  We have had no printers fry after we removed the auto recovery protocol at every location.  Only the locations where loops existed and auto recovery protocol running were printers going bad.  What I found during my lab tests was that each time the port was auto-recovered (yes, for that millisecond while it checks if a loop still exists), more packets were re-generated and eventually enough was re-broadcastthat printers would go down.  We never had a problem with computer NICs.  I guess the cheaper printer NICs couldn’t handle the broadcast storms created by this.  I tried playing with the auto recovery timers and even the highest setting would eventually re-create these storms.
 
 So my question is what best practices are others using?  Should we get rid of BPDUGuard and just try to let spanning-tree handle these bridge loops?  Is there something else I can try?  I’m not CCNA by any means, just trying to do what I can in my environment.  Manually visiting sites when loops occur is becoming more and more my job, though and I have plenty of other things to be doing.

View 9 Replies


ADVERTISEMENT

Cisco Infrastructure :: 3550 Doesn't Send Traps When Bpdu-guard Sets A Port In Err-disable State

Mar 24, 2003

Currently it seems as our 3550's doesn't send traps when bpdu-guard sets a port in err-disable state. Or DFM doesnt recognize it.Is there a way to get a DFM alert when a 3550-port gets into err-disable state?

View 2 Replies View Related

Cisco Switching/Routing :: 3750 As A Port Channel Bridge?

Dec 7, 2011

I have 3750 core/distribution switches with routing enabled in two offices connected with copper link and L3 port channel interfaces. NewOffice#2 has moved about 5 miles farther away from office#1 and I have to deploy new core/distribution switch connect it to old core#2 via F.O and move all access switches with it. Old core will stay in old #2 offices as a bridge between office#1 and new office#2 Office#1core<->copper (Ethernet) <->oldoffice#2core<->f.o. <->new office#2core How I should configure port channels ports on oldoffice#2 core to act as bridge between office#1 core/dist and newoffice#2 core/dist without changing anything else (ip, etc) on whole network

View 1 Replies View Related

Cisco Switching/Routing :: VLAN Bridge With Catalyst 3750

Nov 8, 2012

I have 3 VLANs here that need to be on the same network segment.  They are going to be used by our Wi-Fi network (with Aironet APs), bound to 3 different SSIDs (as Aironet APs doesnt allow multiple SSID per VLAN), each one with a different authentication method and server.Is there a way to bridge those VLANs together with a Catalyst 3750 switch?  I tryed configuring an IP address on one of the VLAN interfaces, then configuring a bridge with the vlan-bridge protocol (Catalyst 3750 doesnt have the "ieee" bridge protocol type) and put all 3 VLAN interfaces on the same bridge-group, but it didnt work (even with "bridge x route ip").I also tryed configuring IRB bridging, with the 3 VLAN interfaces on the same bridge-group and an IP address on the BVI interface (the way I used to do with old 2600 routers).  Same result.(actually, I didint test to see if the interfaces are actually being "bridged", but I see neither of them can reach the router)

View 1 Replies View Related

Cisco Switching/Routing :: 3560G Does VTP Depends On BPDU

Aug 13, 2012

We currently have two 5548UP and  two 2232PP switches running on  5.1(3)N2(1a)  and the plan is to connect our old 3560G switches to 2232 PP using enhanced Vpc.
 
I enabled spanning tree bpdufilter on the 2232 PP ports so that we can connect switches to them but VTP is not working on those ports. Is there anything that needs to be done on the HIFs for VTP to work.Does VTP depends on BPDUs? Does enabling Bpdufilter affects VTP?

View 2 Replies View Related

Cisco Switching/Routing :: 3750 STP Vlan 21 And 22 Root Bridge On 2 Switches

Feb 16, 2013

I config vlans 21-23 on 3750 A and B switches.I config B  switch to be Root Bridge for all vlansspanning-tree vlan 1,21-23, priority 4096 sh span tree on B  switch 3750B#  sh spanning-tree.

View 18 Replies View Related

Cisco Switching/Routing :: Received SSTP BPDU With Bad TLV On Nexus 7000?

Jan 11, 2012

I obtain this message on Nexus 7000:2011 Dec 22 03:37:53 NNN %STP-2-RECV_BAD_TLV: Received SSTP BPDU with bad TLV on port-channel1 VLAN0020 and following with err-disabled port ?[URL]

View 3 Replies View Related

Cisco Switching/Routing :: BPDU Filter With 3560 Model Switch?

May 28, 2013

I am testing BPDU filter with 3560 model switch so I've looped 2 interfaces in that switch by configuring STP BPDU filter on interface levels and also connected one desktop in other interface on same vlan of looped interfaces with bpdufilter config. I am facing is both the looped interfaces are having heavy traffic due to this my switch CPU utilization also reached high. How to sort out this issue like why my switch interfaces traffic & CPU utilization went high even when I am using BPDU filter at interface level? As well as correct my BPDU configuration If I configured wrong. I thought it is a good practice and enabled this conf in some of my working environment but due to some loop my entire network went down?

View 6 Replies View Related

Cisco WAN :: Unexpected BPDU Received Port Has Been Disabled 3750

Dec 7, 2010

One of our Cisco 3750G switches keeps showing this warning:

Description: Gi4/0/43: Unexpected BPDU received. Port has been Disabled.

Recommendation: Check Configuration of the switch, also make sure devices connected to the switch. Enable this port again.

However, there is no thing connecting to the port Gi4/0/43 as shown this link: [URL]. Why do you get this warning?

View 17 Replies View Related

Cisco Switching/Routing :: 3560 / STP Loop Guard Blocking Vlans?

Mar 24, 2013

I have a strange issue where spanning-tree is blocking vlans through a mesh network.Here is my set up.

2-Cisco  3560's that have two trunk ports set with do1q and a native vlan of 2.  I'm allowing a client vlan (2) and a voice vlan (103) to come over the  trunk. They have a native vlan of 2 so the mesh APs can get an address  through DHCP. Spanning-tree loop guard is also enabled.
 
When connected to the mesh network, the voice vlan is being blocked by spanning-tree. I get the following erros:
 
000129: *Feb 28 19:24:58.289 EST: %SPANTREE-2-LOOPGUARD_BLOCK: Loop guard blocking port FastEthernet0/1 on VLAN0103.000130: *Feb 28 19:24:58.448 EST: %SPANTREE-2-LOOPGUARD_UNBLOCK: Loop guard unblocking port FastEthernet0/1 on VLAN0103.
 
Eventually  the loop is cleared and the port is set back to a forwarding state from  a blocking state. I don't want to disabled spanning-tree loopguard since I don't want to create a loop. The mesh network is supposed to act as a P2P connection between two switches. As  a test I disconnected the APs from their trunk ports. I then used a  cross over cable to connect the switches and no spanning tree loops  occured. The mesh doesn't have STP enabled on it and should just be acting as an over-the-air connection from one switch to another.

View 1 Replies View Related

Cisco Switching/Routing :: 3550 - Two MST Instances Enabling Root Guard

Jan 12, 2012

I have 2 3550 12G switches that I use as core fiber switches.  Switch 1 is the primary for 1/2 the V LANs and Switch 2 is the primary for the others using MST with 2 instances (I am not including the default 0 instance).  I am using HSRP to provide redundancy.  So far so good. 

Recently a tenant in my building would like to use their own switch for data but still needs access to a V LAN on mine for voice.  Again not a problem as I can configure a trunk port and give them what they need.  My concern is that if they try to configure STP on their switch can they take down mine.  Are there some preventions that I can put into place, such as root guard, that work with MST?  What happens if they too set up MST can they kill mine?
 
Switch 1 is the root for 1/2 the v lans and Switch 2 is the backup root.  The scenario is flipped for the other 1/2.

View 3 Replies View Related

Cisco Switching/Routing :: 6509 - Spanning Tree Root Guard Command

Dec 15, 2012

in my LAN the all access layer switchs/stacks are connected directly to core backbone switch (cisco 6509) via sfp fiber-optic, i want to protect my spanning tree setup with the "root guard" command.
 
1. where would i set this ? on uplink ports on access layer switches ? or on core backbone ports to which the access layer swithes  connect to?.
2. can this be set on active (production) ports without downtime?

View 5 Replies View Related

Cisco Switching/Routing :: SG500 - Roaming WiFi Machines In Conjunction With IP Source Guard?

Sep 29, 2012

I've just set up DHCP Snooping and IP Source Guard on our SG500 series switches.  It seems to work quite well, except when a wireless host roams from one AP to another (on a different switch port), all traffic from that host gets blocked. 

I can understand why this is occuring, but I don't know what I can do to work around this problem.had success with roaming WiFi machines in conjunction with IP Source Guard?

View 6 Replies View Related

Cisco Switching/Routing :: Nexus 5000 - What Cause Loops On Ports

Dec 14, 2011

Any opinion on what could cause loops on nexus 5000 ports that are connected to esx hosts ?

View 3 Replies View Related

Cisco Switching/Routing :: 2950 - Bridging Loops / STP Protection

Jan 20, 2012

I have a network where if an end user attaches an hub to the network, or rather one of those cheap unmanaged 8-port mini-switches and then plugs the two ends of the same cable into two ports of that mini-switch, all the network goes down. Loops are generated and many uplinks are shut down in err-disable state due to the loopback reason.
 
I know I could discourage the use of those mini-switches using port security. I even have NAC (cisco) deployed on the network, but there are cases where that mini-switches are allowed by the managment.In those cases, is not possible to exactly know wich hosts (mac addresses), and even how many of them will attach the network concurrently.As I know, they could even chain many mini-switch one to another. Of course, when even a single mini-switch is allowed on the network, it raises as a security hole.
 
Is there a way to allow the use of those devices without the risk of network outages? Some STP protection method? The best would be to have the Cisco access switch to get aware of the loop on its affected switchport (where the mini-switch is attached), immediately shutting down that port (to avoid loops on the network) and maybe sending an SNMP trap or a syslog message.
 
We are using Cisco Catalyst 2950 and 2960 for our access layer.

View 5 Replies View Related

Cisco Switching/Routing :: STP Stops Loops But R-PVST Goes Flapping 2960

Feb 22, 2012

Stange problem which I encountered today, I have a Cisco 2960 which is connected to a netgear. The switch started showing itself in CDP and was running STP. I checked the cables physically today and noted 3 uplinks to the netgear, all port on the Cisco active and forwarding and green lights.
 
The Cisco was running STP, I changed it to R-PVST and the lights on the Cisco went crazy and I got the message port flapping on the switch but the switch did not block any ports (all ports on same vlan).
 
There after I changed it back to stp and the switch blocked the other up links apart from one.
 
Sure R-PVST is far superior than STP?

View 5 Replies View Related

Cisco Switching/Routing :: Perform STFTP On 3750 Or 3750-X?

Jun 30, 2012

Do I need the Universal image to perform stftp on a 3750 or 3750-X?

View 8 Replies View Related

Cisco Switching/Routing :: Stacking 3750-X With Universal Image With 3750-G Running BIN Image?

Oct 10, 2011

I'm looking at adding a Cisco 3750-X switch running c3750e-universalk9-mz.122-55.SE1 (IP base license) into a stack of 3750-G switches running c3750-ipbasek9-mz.122-55.SE1.bin Given that the version and feature sets are the same I don't forsee any compatibility issues. Would there be any reason why a universal image wouldn't stack correctly with other switches running the single .bin file?

View 9 Replies View Related

Cisco Switching/Routing :: Replacing 3750 24 Port With 3750 48 Port?

May 21, 2012

We have a stack of switches that is at the max number of members allowed in the stack. Problem is we are running out of port density and need to add more ports. So instead of adding a whole new stack I would rather replace 2 of the 24-port swicthes with 48-port switches.
 
If the two 24-port swicthes we are removing are stack members and neither of them are the stack master, I should be able to replace the 24-port switches with the 48-port switches without bringing the master offline? If the new 48-port switches are running the same IOS version as the current 24-port swicthes, they should add themselves to the stack?Would I have to tell the new 48-port swicthes what switch numbers they are replacing in order for them to be added to the stack since we are at the max number of members?Also since the 48-port swicthes are replacing 24-port switches will the master give the 48-port switches the configuration for only the 24-ports?

View 11 Replies View Related

Cisco Switching/Routing :: Can Use 857W As Simple Bridge?

Dec 1, 2012

I need to replace an ADSL modem and have a spare 857W. Can I use this to act as a simple bridge between the ADSL PPPoA connection and the FW WAN port?
 
[  CISCO 857W  ]         
ISP - PPPoA - BRIDGE - FW WAN
 
I have a block of Public IP's so the PPPoA Dialer 0 connection would get x.x.x.185/29 I would like to bridge this directly to the FW WAN port and set that to x.x.x.185/29 with a gateway of x.x.x.186/32.Currently I am using it in router mode with no NAT or FW and am losing a Public IP as I need to set the FW WAN as x.x.x.186 with a GW of x.x.x.185 I am setting BVI 1 as x.x.x.185/29 and Dialer0 as IP Unnumbered BVI 1.

View 1 Replies View Related

Cisco Switching/Routing :: L2 Bridge On 1921 Interface?

Nov 20, 2012

I need to set up a L2 llink between my LAN and this 1921 router. I though IRB would do it but its not working yet. Here is the topology- I dont want to see another hop on this 1921 rtr so I hope I can just trunk it or something with IRB. Not working.

View 6 Replies View Related

Cisco Switching/Routing :: Setup WET200 As Wired Bridge?

Oct 8, 2012

I have two separate offices in the same building that I'm trying to  connect.  They are physically far apart so I cannot connect them  wirelessly.  I have had an ethernet cable run from the main office to  the second office and physically connected it to a WET200.  I can see the  WET200 on my router in the main office.  In the second office, I want  clients to be able to come in and connect wirelessly to the WET200 which  will then connect them to my router and internet connection.  The  WET200 is the correct device for this?

View 2 Replies View Related

Cisco Switching/Routing :: N55K - ISSU And Bridge Assurance

Jan 14, 2012

In preparing for an upcoming upgrade of our serverswitches (N7K and N55K), I've run into a wellknown issue with ISSU and Bridge Assurance, where ISSU is not supported when, among other, BA is enabled.
 
My topology is quite simple (see attatched jpg). A pair of N7K's as distributionlayer switches running in vPC mode with BA between them. The N55K's are dualhomed across the two N7K's through vPC, but each N55K operate indvidually, that is vPC is not running between them. The jpg shows a simplified topology, but I have several N55K's attached.
 
During the deployment of this network, we enabled BA downstream towards the N55K. In hindsight, maybe I could have excluded this option, but currently it's in operation and is also hindering me in doing ISSU on my N55K's. Now, the easy solution would be to simply revert to normal span-type mode and since the N55K is running LaCP upstream towards the N7K's, we've managed to stay clear of STP's shortcomings, so I believe I'm good even without BA.
 
Unfortunately, I don't have sufficient equipment at my disposal to set up a lab and test the impact of disabling BA between the N7Ks and N55Ks in a running enviroment. And since our server/application enviroment is somewhat fragile (that's putting it mildly), I'm trying to come up with an educated guess as to what impact to expect, if I concurrently (or as close as a manual intervention can get) re-configure the two ends of the channel to use span-type normal. I would expect the upstream port on the N55K (channel-port) to temporarily be suspended and having to go through the usual rstp cycle on both ends before coming operational again.

View 2 Replies View Related

Cisco Switching/Routing :: 6513 Brought Down By Bridge Mode On NIC

Mar 29, 2012

We have a 6513 with about 8 switches in it. I installed a Intel Pro PT NIC in a Dell PE2850 and setup the Team setting which created a bridge in the network connections.
 
10 minutes later, every server connected on that 'blade' went down and rebooted.
 
This happened once before to another tech here (I didn't know at the time it would do this but after he saw it he pointed it out)

View 2 Replies View Related

Cisco Switching/Routing :: 877w - Works As Wireless Client & Bridge?

Nov 25, 2011

We have dlink dir320 router and cisco 877W.
 
The goal is to make a 877W to work as a wireless client of dlink dir320 and brigde the LAN&WLAN so than the LAN clients of 877W could take DHCP from Dlink 320 directly.
 
Here's the config of 877w:
 
!
bridge irb
!
dot11 ssid DLINK_SSID

[Code].....

View 1 Replies View Related

Cisco Switching/Routing :: 8192 / STP Root Bridge Is Pointing At FWSM?

Feb 11, 2013

I have two 6509s both with single FWSMs running in transparent mode with bridged Inside and Outside VLANs.I have my Core A set to STP priority of 8192 and Core B set to 16,384 to make Core A the root for all VLANs.Problem I have is when I look at spanning-tree on Core A for Inside VLAN 324 it states to get to the Root go via PO100 (Cost of 9) and that the Root also has a Priority of 8192, but as the designated Root has a lower MAC address it's pointing to the etherchannel. PO100 is L2 Etherchannel between the Cores.Moving accross PO100 to Core B and running the show spanning-tree command I can see that to get to the Root Bridge I need to go via PO272.  PO272 is the internal Etherchannel to get to the FWSM on the Core B Switch.  This shows a cost of 6 to get to the Root and a mac address of the Root Bridge which resides on Core A (Outside VLAN 124)To give some perspectibe,theoutside VLAN of the pair has it's STP ROOT on the Core A switch as intended?

View 1 Replies View Related

Cisco Switching/Routing :: 2950 Root Bridge ID / Avoid Loop

Jan 18, 2012

I have an Extremely Old switch that I need to connect to my network.  Because it is so old I don't want it to become the Root Switch.
 
what is the command to change the priority. (Honestly I don't remember if it has to be a lower number 1 or a higher number ). Always get that mixed up. I've read about root guard, but I would like to prevent it manually. (It is a small network after all)It is a Cisco 2950.

View 3 Replies View Related

Cisco Switching/Routing :: 3750 - L2 Trunking Versus L3 Switching

Dec 9, 2011

some of our switches have the switchport mode trunk command configured between the 3750 switches but other 3750 switches connected to our 6509 core switch do not have the switchport mode trunk command to permit Vlans from going across the swtiches instead it has an ip address and says no switchport what is the difference between does two. Is trunking used only for Layer 2 and L3 is used to route  interface vlans?

View 2 Replies View Related

Cisco Switching/Routing :: Multiple VLAN Routing Tables For 3750 Catalyst

Oct 24, 2012

I have a network with a Catalyst 3750 as the main switch and then some Catalyst 2960 switches that are plugged in to that. I have a server running windows server 2008 with a couple of virtual machines running in Hyper-V. I created 4 VLANS listed below and gave the 3750 the following IP Address.I would like the 3750 to only be configurable from VLAN 40 but currently every VLAN can connect to it, I noticed in the standard web page settings there was a setting for "Management VLAN" but it was set to 1 and would not let me change it, I kinda assumed that was for the management port in the back.-Now the tricky part, I was trying to set up routing between the VLANs and so far I have only been able to get a sort of "all or nothing" routing to work. I can turn IP routing on and add two or more VLANs to the routing and it works fine. But what I was hoping to do is create a couple of "junction vlans" that would only route to one or two other vlans. For instance, I wanted to create a VLAN 100 that routed to VLAN 20 and 30 but nothing else. I also want to route VLAN 1 just to VLAN 30, and so on. I am able to do each one of the cases but only one, it seems like the switch only supports one "routing table" am I missing something or is this just a limitation of the switch?

View 2 Replies View Related

Cisco Switching/Routing :: Is 3750 SW Capable Of Handling Full Routing Tables

Oct 8, 2012

Is a 3750 sw capable of handling full routing tables and what can you recommend in a small mutihomed BGP router or switch capable of handling full routing tables?

View 2 Replies View Related

Cisco Switching/Routing :: Catalyst 3750 Multi-cast VLAN Routing

Oct 28, 2012

I have a network with several catalyst 2960 switches and one catalyst 3750. I have created two VLAN and set up the proper routing and everything is working fine there. I have a client/server application that used multicast in the initial start up for the client to determine available servers, the issue is one of my clients is on a different VLAN then the server. I am able to route the multicast using MVR as long as both the server and the client are plugged into the 3750 by creating a static route, making the server a source port and the client a receive port. Unfortunately I need the client and the server plugged in to different 2960s. My question is how do I establish multicast routing between the two and perferably do it dynamically (always route multicast traffic from one VLAN to another).

View 2 Replies View Related

Cisco Switching/Routing :: Inter-VLan Routing On Catalyst 3750 Switch

Dec 17, 2011

I have been looking into this for a while and I can't seem to figure out why my 2nd vlan is not able to connect properly to the net.
 
My switch has 12 ports where my devices connects directly, they are all on Vlan 1 and they all work perfectly. on Port 12 I have a dlink router that is connected to a cable modem. the dlink router has an Ip address of 192.168.0.20
 
I created a second vlan (vlan2) and enabled dhcp relay on it. then I assigned port 9 on the switch to  (vlan2)my laptop which is connected to port 9 seems to get an ip address fine and able to ping only some devices on my network (vlan1) and is not able to go out to the internet.  I think it has to do with the routes. [code]

View 4 Replies View Related

Cisco Switching/Routing :: 3825 / Replacing Routing Function With 3750 Switch?

Jul 27, 2012

I have the task of replicating the router config on a 3825 router on a 3750 switch. Reason is we are taking out the router and replacing it with the switch to make use of the router for other functions.
 
Below is main part of the router config:
 
!
ip source-route
ip cef
!
!
multilink bundle-name authenticated
!
license udi pid CISCO3825 sn FCZxxxxxxx
!
vlan internal allocation policy ascending

[code].....
 
The 3750 switch I have runs C3750E-UNIVERSALK9-M, Version 12.2(55)SE3 on a LAN BASE license.
 
The first thing I have done is to order for a license upgrade to IP BASE which would give the support for OSPF routing.I do not see much of an issue with the Interface configs, however, I am not too sure about replicating the routing config on the switch.
 
My question is can I run the commands as shown for the OSPF routing on the switch? If not, can I get suggestions on how best to set this up on the switch?

View 4 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved