Jump to content

Recommended Posts

Posted

As title really, new Core switches due soon. Do you guys have STP/MSTP enabled on just your access edge layer or both core/edge.

 

The core will have dual AGG links to each edge switch.

 

Sure i've seen somewhere that having it on the core is a no no if you have agg links.......

 

just thought i'd ask here to see what everybody else does.

 

core-switch-and-edge-switch.jpg

 

Cheers

Posted (edited)

Sure i've seen somewhere that having it on the core is a no no if you have agg links.......

 

A true core switch in the enterprise campus design (a design consisting of edge, distribution and core switches) is Layer 3 only so Spanning Tree isn’t a thing on these switches (as this is a layer 2 technology). But those designs are used in large sites.

 

Your core switches (this topology is often referred to a collapsed core) do have layer 2 links. In this situation you would have spanning tree enabled on all your switches including the core.

Edited by FN-GM
  • Thanks 2
  • 1 year later...
Posted (edited)

Apologies for Necro but i've got a question/small issue with STP (I believe - not an expert at switch config).

 

Core switch is a HP 5406 ZL - STP is not enabled on the core.

 

Edge switches are a mix of Mikrotik CRS354 48 Port / Netgear S3300-52X ProSAFE 48-Port / a couple of HP ProCurve 2626 (on the list to change)

 

All edge switches are connected to the core via x1 SFP uplink. RSTP is enabled on all switches besides the HP ProCurve 2626's & the Core switch.

Issue : On random occasions 1 / 2 switches will go down (almost always 1 / 2 of the Netgear's) I'm guessing due to the uplink port being disabled by STP. I have had no luck in finding a loop anywhere so far. We had an issue a month or so ago with DHCP & since then this issue has been occurring sproadically. If I'm in front of a switch & look at the activity lights, they seem to be all blinking at the same time, which to me indicates that there is a loop somewhere..

 

I believe my setup is similar to OP - would you recommend enabling STP on the core also?

 

Best practices of finding a loop - I was thinking of staying late one night & unplugging each edge from the core, one at a time to see if things steady?

 

*edit - Core is L2, all routing is done by the firewall

Edited by Olliedawg
Posted (edited)

Are you able to log onto the switch and view logs to config when the switches go down its due to STP?

 

FYI i now have RSTP enabled on our edge switches and not on our core.

 

However we have Core/Aggregation/Access switch layers with the Core and Aggregation Switches being L3 capable. So we just have RSTP enabled on our L2 edge switches.

 

If you're running a collapsed core (as per the diagram above) and as @FN-GM says, you can run STP on both as the "core".

 

*EDIT if you feel its STP from one of the edges, unplugging it from the core would help identify the problematic edge. Then disconnect each port on the edge until issues goes away...... if you don't have access to logs or have the luxury of the brief down time that is

 

*EDIT2:

 

do you disable/unpatch unused network sockets that are user facing?

Edited by Jaan
Posted (edited)
Are you able to log onto the switch and view logs to config when the switches go down its due to STP?

 

FYI i now have RSTP enabled on our edge switches and not on our core.

 

However we have Core/Aggregation/Access switch layers with the Core and Aggregation Switches being L3 capable. So we just have RSTP enabled on our L2 edge switches.

 

If you're running a collapsed core (as per the diagram above) and as @FN-GM says, you can run STP on both as the "core".

 

*EDIT if you feel its STP from one of the edges, unplugging it from the core would help identify the problematic edge. Then disconnect each port on the edge until issues goes away...... if you don't have access to logs or have the luxury of the brief down time that is

 

*EDIT2:

 

do you disable/unpatch unused network sockets that are user facing?

 

I've been looking at the RSTP config all morning on our switches. The bridge priorities were all over the place so i've tidied that up.

 

Yes our setup is pretty similar to OP

 

 

*EDIT if you feel its STP from one of the edges, unplugging it from the core would help identify the problematic edge. Then disconnect each port on the edge until issues goes away...... if you don't have access to logs or have the luxury of the brief down time that is

 

 

I'm thinking this is the easiest way.

 

 

do you disable/unpatch unused network sockets that are user facing?

 

 

I'll be honest, no. I did do a few last half term when I was replacing a few switches, tidied up the cabs at the same time & identified ports not in use & unpatched these.. however i'm sure there are plenty around site which are patched in, which don't need to be.

 

I've been monitoring the logs on the core switch all morning, nothing out of the ordinary so far

 

*edit* When I came in this morning, two of the Netgears were down. I checked them & the uplink port was disabled, so it must be STP..

Edited by Olliedawg
Posted

I would recommend that you disabled or unpatched any unused access ports/sockets. Students like to sick pens in and give them a wiggle and bent contacts which would cause an issue. found a square block of chocolate in one once!

 

We had a old network card (bromcom chip iirc) causing issues due to a incorrect manually installed driver.

 

found it via switch logs, mac addresses and a mixture of DHCP/DNS auditing. unplugged suspect pc and the issue went any, swap tested a usb NIC worked fine, updated driver via official sources on the onboard nic, worked fine after that issue resolved.

 

can all be a real pain, also once found a very small chunk out of a network cable under the leg of a teacher's desk which caused the same issue. Until you find where the issue is originating from, it can be stressful!

Posted
I would recommend that you disabled or unpatched any unused access ports/sockets. Students like to sick pens in and give them a wiggle and bent contacts which would cause an issue. found a square block of chocolate in one once!

 

We had a old network card (bromcom chip iirc) causing issues due to a incorrect manually installed driver.

 

found it via switch logs, mac addresses and a mixture of DHCP/DNS auditing. unplugged suspect pc and the issue went any, swap tested a usb NIC worked fine, updated driver via official sources on the onboard nic, worked fine after that issue resolved.

 

can all be a real pain, also once found a very small chunk out of a network cable under the leg of a teacher's desk which caused the same issue. Until you find where the issue is originating from, it can be stressful!

 

Thanks for the suggestions & yea I really do need to get them unpatched. Will be pain as I'm on my own!

Posted
Can you see anything in the log files/web interface on the core switch? If it's the same two netgear switches going down repeatedly it could literally be a problem with the switches - or the cabling? Only real way to find out would be to fit a HP switch and see if it stays up? You ca get the really old stuff like 2626 cheap as chips nowadays - grab one and test is my advice!
Posted
Can you see anything in the log files/web interface on the core switch? If it's the same two netgear switches going down repeatedly it could literally be a problem with the switches - or the cabling? Only real way to find out would be to fit a HP switch and see if it stays up? You ca get the really old stuff like 2626 cheap as chips nowadays - grab one and test is my advice!

 

I do have some spares (both HP and Netgear). When I get chance I i'll try one.

 

It doesn't seem to be causing any other network issues at all - everything is normal (or seems to be). I might try disconnect both net gears at once and see what happens then

Posted
I'm confused. Why in a hub and spoke arrangement would you not have spanning tree on the core? The middle of the network should be the arbiter of the topology, otherwise you are going to have a 'random' edge device being the root, and any connectivity failure there and you might end up with a full spanning tree recalculation happening or things going weirdly split-brain?
Posted
I'm confused. Why in a hub and spoke arrangement would you not have spanning tree on the core? The middle of the network should be the arbiter of the topology, otherwise you are going to have a 'random' edge device being the root, and any connectivity failure there and you might end up with a full spanning tree recalculation happening or things going weirdly split-brain?

 

Good question - this is what I've inherited so I can't answer that one. Will have to wait until summer to have a look at it as i'm not overly confident with network stuff like this. Core only supports MSTP & RPVST & all of the edge switches are configured to RSTP. I believe you can mix MSTP & RSTP however not advisable?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...