11-22-2022 08:30 AM
I have a strange issue that I'm having a difficult time locating the source and solution.
I work for a county government. We have multiple locations but all communications go back to the Core Switch in the Admin building. The Core switch is currently set manually as the root bridge (with low priority number) for all vlans on the whole network.
Currently we are in the process of updating the network to be run on Meraki almost 100%. The Core switch is a Catalyst 9500 and was an upgrade a few months ago after the previous core switch died out. The switch with the multiple STP changes is a Meraki switch in another building (connected by fiber) and is 5 or 6 switches away from the core switch.
When the STP changes happen, I'm seeing two different devices that seem to "take over" as root bridge but it happens very quickly before the Core switch takes over again, and it will flip back and forth quite a few times for a few minutes before it goes back to normal. When I try to locate those two devices by their mac address (that I get from the wireshark captures), I can't locate them when the network is running smoothly. This makes me think there's a device that someone has and is using throughout the day just plugging in to the network at random times throughout the day. I'm trying to catch the STP changes happen realtime so maybe I can track down those devices, but it's hard to arrange that when I don't know when to expect it to happen, and with the fact that I'm a very busy person working on many other things simultaneously.
Does anyone have any suggestions on how to troubleshoot this? I've been working on this for a week now and it's driving me nuts with the constant outages it is causing for devices on that switch (phones, computers, printers, etc
Solved! Go to Solution.
05-04-2023 05:53 AM
Been a while, just wanted to update everyone on this in case anyone comes across something similar.
What I ended up doing was turning off RSTP on the Meraki Switches due to some possible "incompatibility" with Cisco Catalyst STP processes. This is just based off of some reading I've done, reading articles of other people's experiences. Something about having a mix of Catalyst and Meraki switches can apparently cause STP issues. So my plan at this point is to have all Meraki Switches not do any RSTP advertisements until we are done upgrading the whole network with Meraki switches. Since the main core switch is the root bridge for all Vlans at this point, this should not be an issue doing it this way.
Thanks again for everyone's suggestions.
11-22-2022 09:10 AM
- Can sometimes also happen , when it has physical connectivity problems towards the core and or becomes isolated from the root-bridge, check counters of uplink ports (e.g.)
M.
11-22-2022 09:17 AM
Can you please elaborate a little bit? I'm not following you completely.
Thanks
11-22-2022 09:21 AM
Can you make small diagram for us to understand.
make sure you elect right place for teh Root bridge for the VLAN with priority so that will give you control not to elect other switch as root bridge.
Meraki tend to elect as root bridge that what we observered
This just to get an to identify the problem
11-22-2022 09:43 AM
there is debug but I dont prefer use it.
anyway
https://www.cisco.com/c/en/us/support/docs/lan-switching/spanning-tree-protocol/28943-170.html
11-23-2022 01:34 AM
Hello,
you could configure BPDU Guard on all access ports of the 'problem' Meraki. When a BPDU is detected, the port in question will transition to 'disabled'. You will then need to go and find out what is connected to that port...
11-27-2022 10:20 PM
Hi,
I suggest to BPDU Gaurd on all access switches and disable the error recovery feature set for a while. Mostly, I will trace such issues with the "show spanning-tree details" command (in the small network only). You will find the source port of the issue. You might need to check multiple switches for it.
I faced the same issue as you a few months ago and we found that it was caused by one of the HOST Vswitch.
05-04-2023 05:53 AM
Been a while, just wanted to update everyone on this in case anyone comes across something similar.
What I ended up doing was turning off RSTP on the Meraki Switches due to some possible "incompatibility" with Cisco Catalyst STP processes. This is just based off of some reading I've done, reading articles of other people's experiences. Something about having a mix of Catalyst and Meraki switches can apparently cause STP issues. So my plan at this point is to have all Meraki Switches not do any RSTP advertisements until we are done upgrading the whole network with Meraki switches. Since the main core switch is the root bridge for all Vlans at this point, this should not be an issue doing it this way.
Thanks again for everyone's suggestions.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide