Jump to content

Recommended Posts

Posted

So we've just had a problem, where a student had plugged one end of a LAN cable into patch panel on the wall, and the other into another panel.

 

As you're probably aware, it causes a loop and crashes the switch. This then fed back through the fibre and crashed other switches.

 

My question is, how do YOU stop this from happening?

Can you configure standard HP switches to essential block a loop like this?

 

Any ideas would be great!

Posted

Depending on your models it's loop-protect option.

 

Sends a "special" packet that if it detects on a port it'll disable it. (Obviously don't enable on uplinks :D)

 

Steve

Posted
Looking at the PDF (page 3) it seems as if you can although it may depend on the model of switch. You should be able to telnet to the switch otherwise.
Posted

Spanning tree here as well, actually one of only many stacks that did not have it setup, found when student done the same thing and sent switch into loop.

 

As soon as I looked at the stack of 3 X 48 port switches going mad I could sense something was not right, thankfully we have many vLANS and the VLAN that was effected was only one area of MACS :hand: .

Posted

Just remember spanning tree on it's own only protects managed devices and if you have unmanaged devices looping it can still take it out :) Would always suggest loop-protect too.

 

HP - Loop Protection can be used independently of Spanning Tree Protocol and is targeted for use on ports to which unmanaged devices are connected. Unmanaged devices will typically drop Spanning Tree BPDUs

 

Steve

Posted
We have just decided to do spanning tree here after a student looped the physics switch for the this time this year. Hasn't been an issue prior to this year
Posted
We enable STP on our HP switches, and as a more physical approach to preventing this happening we un-patch any spare ports in rooms so that there's less chance of somebody linking two ports together.
  • 2 weeks later...
  • 3 weeks later...
Posted
As already mentioned, if you have a dumb switch in a classroom and a kid loops that then all the Spanning Tree protection in the world won't do anything. You need to be monitoring your switch links in some kind of SNMP poller like MRTG or The Dude. The Dude saved my backside last year as we had a kid loop a 5-port switch in a classroom. Looking at the links between the switches you can see which way the broadcast traffic is flowing and trace it back to the offending switch and finally the port.
Posted

We've had loopbacks happen on a few occasions over the year. Don't have Spanning Tree enabled as all edge switches go back to the core, and only 1 switch per cab.

I have D-Link switches with Loopback detection enabled along with Syslog.

As soon as a loopback occurs, the 2 switch ports are disabled, and it re-checks whether the loop still exists at the set interval (I have it set to 1 minute). This gives me time for the switch to SYSLOG report the loop back to the syslog server and then I get emailed the switch that the loop occurred at which then narrows it down to the location, which you can usually guarantee is one of the ICT suites.

 

Then gives me time to run out and find the culprit with the usual response "it was like that when I came in the classroom" with the patch lead connected into 2 sockets!

 

Doesn't take the whole network down.

Posted
We enable STP on our HP switches, and as a more physical approach to preventing this happening we un-patch any spare ports in rooms so that there's less chance of somebody linking two ports together.

 

I guess your patch leads aren't long enough to reach between 2 sockets then, for example where you have an ICT suite where multiple sockets would be live!

  • 2 months later...
Posted
I guess your patch leads aren't long enough to reach between 2 sockets then, for example where you have an ICT suite where multiple sockets would be live!

 

We also only patch in sockets that are required - if someone is going to be malicious and deliberately cause a loop to another working socket, they would have to take two pc's offline to achieve this and make it easy to find

Posted

STP should be enabled on all switches. On some HP's it's on by default and on others it's disabled, but either way it's well worth enabling as it can save a great deal of trouble taking out the whole network and creating a broadcast storm.

 

Wherever possible it should be enabled on all core and end switches. Just because you have it enabled on the core and not the end switch, still means it'll temporarily cause disruption on everyone connected to that switch.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...