09-30-2011 12:03 AM - edited 03-07-2019 02:32 AM
Hello Community!
My company wants to create a split site for one of our applications. The approach to doing this is QinQ. In reallity we want to connect two switches over MetroEthernet, and bridge the two sites (5 vlans in total). For security reasons I was thinking of configuring both switches in VTP mode transparent and only creating the appropriate VLANs, but I got stuck when thinking about which switch should be the STP root... Does it matter??? Should I leave STP to do its job without any manual interference?
The other thing is that we are going to use two different providers for the metro ethernet, so we want to utilize both links (load balance traffic), so some vlans should prefer LinkA and the others LinkB. My approach to this would be to set vlan port-priority. I don't think that cost would have the same effect!
If we go with vlan port-priority should it be configured on both switches, or just on the root?
Finally is using udld and loop-guard a good idea for STP loop protection, or since our switches will connect to metroethernet switches from the provider, it won't make any difference?
To summarize, my questions are the following:
Any ideas, thoughts, comments would be really helpful!
Thank you in advance,
Katerina
Solved! Go to Solution.
09-30-2011 02:29 AM
Hi Katerina,
Definately if you want vlan as local vlan only and not to be propagated to other switch, then let it be transparent.
Not too sure on the port priority, but it should work if you set it only on root.
(And in the case if it doesn't you can always go and set on all trunk interfaces )
Regards,
Smitesh
09-30-2011 01:54 AM
Hi Katerina,
Since here you are planning for Q in Q, below are my suggestions:
1. VTP mode Transparent ??
- Why you would want VTP in transparent mode, when you can have single VTP domain if you don't go for transparent mode. My suggestion will be make one of your switch server and others as client.
2. Manually Configure STP root ?
- Definately a good idea.
3. Use vlan port-security and if yes configure all (4 trunks) ports ?
- depends on your company policy.
4. Use udld and loop-gaurd for loop prevention.
- udld will be good to use, if you want to disable the link ( in the event of link failure) and want to have alternate STP path.
-loop-gaurd always help in switched network and esp. when you have manual configure root and haven't given any considerations to other switches. It will also protect you from introduction of new switch ( of older hardware) accidentally becoming root.
HTH,
Smitesh
09-30-2011 02:19 AM
Thank you for your reply Smitesh!
Thanks in advnace,
Katerina
09-30-2011 02:29 AM
Hi Katerina,
Definately if you want vlan as local vlan only and not to be propagated to other switch, then let it be transparent.
Not too sure on the port priority, but it should work if you set it only on root.
(And in the case if it doesn't you can always go and set on all trunk interfaces )
Regards,
Smitesh
09-30-2011 03:22 AM
Thank you Smitesh!
I think I will start with the root trunks and see how that goes!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide