GRitchie Posted June 19, 2015 Posted June 19, 2015 So we've just had a problem, where a student had plugged one end of a LAN cable into patch panel on the wall, and the other into another panel. As you're probably aware, it causes a loop and crashes the switch. This then fed back through the fibre and crashed other switches. My question is, how do YOU stop this from happening? Can you configure standard HP switches to essential block a loop like this? Any ideas would be great!
Steve21 Posted June 19, 2015 Posted June 19, 2015 Depending on your models it's loop-protect option. Sends a "special" packet that if it detects on a port it'll disable it. (Obviously don't enable on uplinks ) Steve
RobD Posted June 19, 2015 Posted June 19, 2015 We configure Spanning Tree protocol on all our switches to stop this from happening. We did learn the hard way though....two days down until we found the culprit!! http://www.hp.com/rnd/support/manuals/pdf/release_06628_07110/Bk2_Ch5_STP.pdf
DMcCoy Posted June 19, 2015 Posted June 19, 2015 MSTP on the core, RSTP on the edge, with correctly configured roots and edge ports. 1
GRitchie Posted June 19, 2015 Author Posted June 19, 2015 We configure Spanning Tree protocol on all our switches to stop this from happening. We did learn the hard way though....two days down until we found the culprit!! http://www.hp.com/rnd/support/manuals/pdf/release_06628_07110/Bk2_Ch5_STP.pdf Can this/loop-protection be configured from the switch webpage? Or only via a console link
RobD Posted June 19, 2015 Posted June 19, 2015 Looking at the PDF (page 3) it seems as if you can although it may depend on the model of switch. You should be able to telnet to the switch otherwise.
SteveM555 Posted June 19, 2015 Posted June 19, 2015 We also use Spanning Tree Protocol on our switches to stop this.
Davit2005 Posted June 19, 2015 Posted June 19, 2015 Spanning tree here as well, actually one of only many stacks that did not have it setup, found when student done the same thing and sent switch into loop. As soon as I looked at the stack of 3 X 48 port switches going mad I could sense something was not right, thankfully we have many vLANS and the VLAN that was effected was only one area of MACS .
Steve21 Posted June 19, 2015 Posted June 19, 2015 Just remember spanning tree on it's own only protects managed devices and if you have unmanaged devices looping it can still take it out Would always suggest loop-protect too. HP - Loop Protection can be used independently of Spanning Tree Protocol and is targeted for use on ports to which unmanaged devices are connected. Unmanaged devices will typically drop Spanning Tree BPDUs Steve
Sagima Posted June 19, 2015 Posted June 19, 2015 We have just decided to do spanning tree here after a student looped the physics switch for the this time this year. Hasn't been an issue prior to this year
cpjitservices Posted June 19, 2015 Posted June 19, 2015 STP, if you have Cisco switches Spanning tree is on by default I believe.
Oaktech Posted June 19, 2015 Posted June 19, 2015 The new batch of HP 19xx switches I've just bought had STP on by default... STP FTW. Acronyms FTW!
Chris_ Posted June 19, 2015 Posted June 19, 2015 We enable STP on our HP switches, and as a more physical approach to preventing this happening we un-patch any spare ports in rooms so that there's less chance of somebody linking two ports together.
IanT Posted June 30, 2015 Posted June 30, 2015 You can enable loop-protect, bpdu protection and STP from the CLI.
Duke5A Posted July 21, 2015 Posted July 21, 2015 As already mentioned, if you have a dumb switch in a classroom and a kid loops that then all the Spanning Tree protection in the world won't do anything. You need to be monitoring your switch links in some kind of SNMP poller like MRTG or The Dude. The Dude saved my backside last year as we had a kid loop a 5-port switch in a classroom. Looking at the links between the switches you can see which way the broadcast traffic is flowing and trace it back to the offending switch and finally the port.
ITGURU Posted July 21, 2015 Posted July 21, 2015 We've had loopbacks happen on a few occasions over the year. Don't have Spanning Tree enabled as all edge switches go back to the core, and only 1 switch per cab. I have D-Link switches with Loopback detection enabled along with Syslog. As soon as a loopback occurs, the 2 switch ports are disabled, and it re-checks whether the loop still exists at the set interval (I have it set to 1 minute). This gives me time for the switch to SYSLOG report the loop back to the syslog server and then I get emailed the switch that the loop occurred at which then narrows it down to the location, which you can usually guarantee is one of the ICT suites. Then gives me time to run out and find the culprit with the usual response "it was like that when I came in the classroom" with the patch lead connected into 2 sockets! Doesn't take the whole network down.
ITGURU Posted July 21, 2015 Posted July 21, 2015 We enable STP on our HP switches, and as a more physical approach to preventing this happening we un-patch any spare ports in rooms so that there's less chance of somebody linking two ports together. I guess your patch leads aren't long enough to reach between 2 sockets then, for example where you have an ICT suite where multiple sockets would be live!
ColinP Posted October 1, 2015 Posted October 1, 2015 I guess your patch leads aren't long enough to reach between 2 sockets then, for example where you have an ICT suite where multiple sockets would be live! We also only patch in sockets that are required - if someone is going to be malicious and deliberately cause a loop to another working socket, they would have to take two pc's offline to achieve this and make it easy to find
Michael Posted October 1, 2015 Posted October 1, 2015 STP should be enabled on all switches. On some HP's it's on by default and on others it's disabled, but either way it's well worth enabling as it can save a great deal of trouble taking out the whole network and creating a broadcast storm. Wherever possible it should be enabled on all core and end switches. Just because you have it enabled on the core and not the end switch, still means it'll temporarily cause disruption on everyone connected to that switch.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now