12-20-2024 10:31 PM
Hello Cisco Community,
I am seeking your expertise regarding a potential Layer 2 loop in my network. Below is a summary of the situation:
Topology Overview:
Questions:
Additional Info:
12-20-2024 10:37 PM
What is STP mode in each SW
And sure you will face issue since you enable bpdufilter
MHM
12-20-2024 10:41 PM
UPS --> Rapid STP
SW177 and SW180 --> i don't have access
you can say that we have 2 networks network 1 edge UPS SW and network 2 edge SW177 and SW188
12-20-2024 10:49 PM
How you isolate two network??
since you connect UPS to two SW that also interconnect then sure there is loop.
Indeed we use bpdufilter to isolate two STP domain but that Work only if there is one link connect two domain' here as I mention it two so idea of isolated doamin can not apply.
Remove bpdufilter and share show spanning tree of UPS
MHM
12-20-2024 11:10 PM
we think the if we connect UPS sw to the other 2 switches with different access port [vlan177,vlan180] it may avoid loop
what is you opinion to connect UPS SW to one if the 2 other switches with trunk port and use trunk allow vlan 177 and 180 and enable stp and configure root bridge for vlan 177 and 180 in the network that contain 2 switches
12-20-2024 11:17 PM
Access port not solution.
You can connect UPS to one SW via trunk and allow both vlan
Here you will get one link and yoh can use bdpufilter.
MHM
12-20-2024 11:18 PM
ok i will apply and feedback you
12-20-2024 10:54 PM
If the requirement is Layer 2, you are expected to see the STP Loop that is expected according to your diagram.
in that case, the suggestion is as follows:
1. UPS_SW is your main switch then make sure that acts as always root bridge for all the VLAN
2. To avoid confusion, Only allow the required VLAN in the trunk rather than all 4K VLANs.
3. where is your Layer 3 SVI for that VLAN (I hope it's all in UPS_SW?) - then the root is the best place.
I've included the document below to help you understand how that works and what remediation is available for you to take action.
suggest Peter good explanation :
12-20-2024 11:11 PM
SVI for VLAN 177 and VLAN 180 at sw 177 so i want to make him as root bridge for that network and connect ups switch with sw177 only with trunk port just allow vlan 177 , 180
12-21-2024 04:41 AM
SW 177 - as root for STP and allow only VLAN required for the respected Trunk will not cause any Loops.
SW177 and SW180 --> i don't have access
challenge you need to ask owner to make changes what needed on the respective switches.
12-21-2024 01:06 AM
Hello
As those ports on the UPS sw to either 177 &180 sws-are currently in administrative mode of access and the fact you don’t have access to them I envisage in initially setting this up was done with the cooperation of the administrator of those switches for their ports to be access ports also?
Currently these access ports to either sw177-188 from UPS is fine, you should not see any stp loop between the 3 switches providing as I have said the other side of the ports connections are also in access mode , just remove the bpdu filtering from the UPS sw you will be okay.
12-21-2024 04:50 AM
i am trying to investigate configuration of SW177 and SW180 and there are 2 SVIs there and routing is done between to switches
BPDU filter is done on SW177 and SW180 not UPS SW
12-21-2024 06:04 AM - edited 12-21-2024 06:05 AM
Hello
now i’m confused you say you have no access to those switchs and ONLY the ups sw?
what investigation are you querying?
and what is it you want to do with that information?
Also note - BPDU-FILTER can be a dangerous feature to implement depending how it’s applied -globally or at interface level
12-21-2024 06:10 AM
I contact admin for SW177 and SW180 and know that there routing between 2 SVIs 177 and 180. I want to know full conf to decide that this topology that I mentioned above may lead to loop or not
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide