cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1086
Views
0
Helpful
2
Replies

ACE ethertype ACL & bpdu

Mel Popple
Level 1
Level 1

Hopefully an easy one to solve, I'm new to ACE appliances.

I have two ACE appliances in bridged mode and configured as redundant pairs, they are connected to two separate 6500 switches. What I am seeing in the switch logs is the following error:

%SPANTREE-SP-2-LOOPGUARD_BLOCK: Loop guard blocking port Port-channel1 on VLAN066

The bridged vlans are 66 & 76.

i have "access-list bpduallow ethertype permit any" in my config and it is assigned to both of the bridged vlans, on both ACE appliances, with "access-group input bpduallow"

Is this correct or do I need a specific "access-list bpduallow ethertype permit bpdu" entry in the ACL? I would have thought the "permit any" included it.

And if this is correct and allowing bpdu packets through why would I be getting the the error on the switch?

Thanks

Mel

2 Replies 2

Mel Popple
Level 1
Level 1

It's the switch IOS version that is at fault not the ACE

https://supportforums.cisco.com/message/614359

Are you sure ? To me the port goes into the loop inconsistent state because bpdus are dropped somewhere.

Review Cisco Networking for a $25 gift card