Professional Documents
Culture Documents
CHAPTER 2
Broadcast frames would travel around redundant paths forever quickly consuming available bandwidth without some form of loop prevention
SPANNING TREE
A mesh topology use Spanning Tree Kind of converts a mesh into a star Chooses what ports to block Maintains only ONE active path between LAN segments (Collision Domains) Stops LANs from having redundant links Stops Broadcast Loops Network meltdown Caused by broadcast storms How do you stop a loop in progress?
Avoids bridging loops by putting some interfaces into a blocking state based on their Bridge Port Data Unit (802.1d)
STP elects a root switch (or bridge) and puts all working interfaces on the switch into forwarding state Each non-root switch chooses the port with the lowest cost between itself and the root switch, called the root port (RP), and places it into forwarding state Many switches can attach to the same Ethernet segment and the switch with the lowest cost from itself to the root bridge, as compared with the other switches on the segment, is placed into forwarding state The lowest cost switch on each segment is called the designated bridge and that bridges interface attached to that segment is called the designated port (DP) All other interfaces are placed into blocking state
2.
3.
Root Bridge All interfaces on this bridge / switch are in Forwarding Non Root bridge has at least one of its ports to have the lowest cost back to the root bridge. This is called the Root Port and is in forwarding state. The Bridge with the lowest administrative cost between itself and the root bridge is called the Designated Bridge. The interface attached to this segment is called the Designated Port.
1. 2. 3.
Root Bridges ID The MAC Address plus the Priority of the Bridge. The Cost to Reach the Root Bridge The Bridge ID of the sender of the BPDU.
The Election process starts the lowest Bridge ID becomes the Root Bridge.
BPDU Starts with Priority, so lowest Priority wins. If tie goes to the lowest MAC Address
The
interface through which it has the least SPT cost to reach the root switch Most of the time you only have one connection
STP TIMERS
Dont mess with the defaults. Timers are set for a reason. They work!!!
Cisco has adopted 802.1d STP EtherChannel Combines multiple channels into one single channel on a switch. This way if one channel goes down another can take its place and no effect to STP
Must be same speed Must be same destination All trunks Eight interfaces max EtherChannel does combine the bandwidth of the channels
STP CONVERGENCE
PAGE 75
When STP converges a switch transitions interfaces from one state to another, however, a transition from blocking to forwarding cannot be done immediately because forwarding data could temporarily cause frames to loop
Listening State 15 seconds - Interfaces in this state do not forward frames but old MAC table entries are timed out because incorrect MAC entries could cause temporary loops Learning State 15 seconds - Interfaces in the state still do not forward frames but the switch begins to learn the MAC addresses of frames received on the interface
STP SECURITY
Switch interfaces that connect to end-user locations have some security exposures Attackers could connect a switch with a low STP priority and become the root switch The attacker could connect a LAN analyzer and copy large amounts of data sent through the LAN The Cisco BPDU Guard feature helps defeat these kinds of problems by disabling the port of BPDUs are received on the port This is normally used in conjunction with PortFast on an access port The Cisco Root Guard feature helps defeat the problem where a rogue switch tries to become the root switch If a port with Root Guard enabled received BPDU with superior root ID, the BPDU will be ignored and the interface will be disabled
with same parameters Elects root port on non root switches with same parameters Elects designated ports on each LAN segments with the same Rule Place forwarding and blocking state. (RSTP blocking is called Discarding)
RSTP IMPROVEMENTS
Can be deployed on switches along side of STP Convergence is a lot faster with RSTP
Typically
about 10 seconds compared to 50 seconds for STP Not designed to work with hubs But most networks dont use hubs Main advantage is speed!
Edge Type
End
node to switch
Backup Port When a switch has two links to the same segment. Knows it is a backup port when it receives the same BPDU it send out back.
Is
this a problem?
What happens when you add a switch? What happens when you remove a switch?
STP TROUBLESHOOTING
Very seldom have to mess with it! Step 1 Determine the root switch Step 2 For each non-root switch, determine the root port (RP) and cost to reach the root switch through that RP Step 3 For each segment, determine the designated port (DP) and the cost advertised by the DP onto that segment
Step 1 Pick a switch and find the switchs root BID and local BID using the show spanning-tree vlan vlan-id command Step 2 If the root BID and local BID are equal, then the local switch is the root switch Step 3 If the root BID and local BID are not equal then
Find the RP on the local switch with show spanningtree command Using CDP or other documentation determine which switch is on the other end of the RP Log onto the switch on the other end of the RP and repeat the process starting at step 1
Step 1 Determine all possible paths over which a frame can reach the root switch Step 2 For each path add the costs of all outgoing interfaces in the path Step 3 The lowest cost found is the RP Step 4 If the cost ties, use port priority, and if that ties use the lowest port number