cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
668
Views
5
Helpful
4
Replies

Spanning Tree RPVST on C9200 on Primary and backup Site issue

Xx20GaryL21xX
Level 1
Level 1

Hi,

 

We used default of Spanning Tree RPVST on 2x C9200 in Primary Site and Backup Site and would like to use these more effectively to prevent the STP loop and single port loop.

 

We would like to set this followed STP Root Priorty Primary and Secondary.

 

 

As our Setting as below:

Primary Site  C9200 --> Etherchannel(Trunk) --> C9200 --> Temp (Trunk Lan) --> Backup site 

C9200 --> Etherchannel(Trunk) --> C9200

 

Layer 2 Vlan setting without IP

SW1,2,3,4

Vlan 101 

Vlan 102

Vlan 103

Vlan 104

 

As We only allow 101 -102 on etherchannel to other switch and trunk to backup Site,

 

Trunk to other backup Site

Trunk allowed Vlan 101 - 102 

Trunk Mode

 

Layer 2 Etherchannel 

Trunk allowed Vlan 101 - 102

Trunk Mode

SW1: PO1 Active 

SW2: PO2 Active

SW3: PO3 Active

SW4: PO4 Active

 

As RPSVT+/PSVT used Per Vlan Spanning Tree. We only allow 101 -102 on ether channel trunk to backup Site, 

Do we need to set as follow or just set 101 - 102 as root Primary and secondary? Other Vlan access ports are Portfast and Bpduguard enable. As I known, all vlan must set on Spanning Tree to Prevent the switch loop,

Would you have any suggestion?

 

 

Primary Site

SW1 101-102 Primary

        103 -104 secondary

 

SW2 103 -104 Primary

         101 - 102 secondary

Backup Site

SW1 101-102 Primary

        103 -104 secondary

 

SW2 103 -104 Primary

        101 - 102 secondary

 

4 Replies 4

follow

Deepak Kumar
VIP Alumni
VIP Alumni

If I am getting it properly, you are asking for design recommendations but the above-mentioned information is not enough for us. So I am looking for more information.

Regards,
Deepak Kumar,
Don't forget to vote and accept the solution if this comment will help you!

Hi Deepak,

 

We would like set the RPVST two switches 9200L on each site.

 

EVGN is our main site

CAVC is our Backup Site

 

All setting that we use an Layer 2 setting in Etherchannel, Vlan, Trunk (Metro E)  to other backup site.

All switches only management port have IP address, other than is Layer 2 setting without IP.

It used Esxi server to connect with other devices such as SIP, Internal, PBL server or PC. 

 

Vlan 101 Operations, Administration, and Maintenance P 1 -12

Vlan 102 Public P 19 - 24

Vlan 103 SIP 1  P 25 -  30

Vlan 104 SIP 2  P 31 -  47

Metro E (Trunk): P 45

EtherChannel (Active,Active): P45 -47

Metro E will change to Fiber P1

Remote PC: P48 (Vlan 101)

Management (Switch 9200 and 9300) : P13 -16  (Vlan 101)

 

Network design_modified.jpg

 

Current setting.

1. We set on Switch STP mode RPVST default and we did not set the STP Root priority of Vlan Primary and Secondary.

2. Vlan 101 -104 has set on Switches.

3. Etherchannel (active active )set trunk allowed Vlan 101 -102 and trunk mode on P 47 - 48 to connected Switch 2 9200L with same site.

4. Metro E Trunk allowed Vlan 101 - 102 and trunk mode  only set on P45 on Switch 1 and Switch 2 for internetwork to connect to backup set. 

 

STP Rapid PVST

 

P45 or later (Fiber P1) use for Metro E (CWDM) to connect to Backup site.

At same site, all esxi servers (SIP1, SIP2, PBL, INT) crossed to switch 1 and switch 2 at the same sites (Main site and Backup site)

 

  • We would like to use the ESXi server access ports for Root bridge or Root port. 
  • Vlan 101 -102 are only allowed to Metro E and Etherchannel.
  • Vlan 103 - 104 are SIP server only. We do not want P25 to be Root bridge or Root Port.
  • Trunk port (Etherchannel and Metro E) also do not want to be Root bridge or Root Port.
  • All other Access Ports to set on Spanning-tree BPDUGuard enable and Portfast Edge.

 

Do we also set on one of remote PC port for Port-Security, storm control to prevent the loop for STP or switchport itself if we use PC port for remote or Wireshark purpose?

 

 

As these Setting, As I known, it is not enough to prevent Loop issue and we know that we still got some setting that we did not add on switches.

 

Main Site

SW1 101-102 Primary

        103 -104 secondary

 

SW2 103 -104 Primary

         101 - 102 secondary

Backup Site

SW1 101-102 Primary

        103 -104 secondary

 

SW2 103 -104 Primary

        101 - 102 secondary

 

what are your recommendation on our setting?

 

Best Regards,

Gary

 

Hi Deepak,

 

We find out

Main site                                                                           Backup Site

 

Switch 1A                  -->  Trunk (allowed 101 - 102)   --> Switch 2A

/\                                                                                               /\                                                                                                               

||                                                                                               ||

Etherchannel 1(Trunk Allowed 101 -102)                           Etherchannel 2(Trunk Allowed 101 -102)                        

||                                                                                                ||

\/                                                                                                \/ 

Switch 1B                   --> Trunk (allowed 101 - 102)  -->  Switch 2B

 

This RPVST RTP formed the Trunk Loop on VLan 101 and Vlan 102, but it did not form a blocked state as Link.

 

We still need to fix on this issue.

 

Do you have any suggestion on that?

Review Cisco Networking for a $25 gift card