11-01-2018 10:34 PM
Curious what the consensus is on STP guard settings for ports on Meraki switches. We've turned on BPDU guard for all access ports. However, I was wondering under what circumstances Root or Loop guard would be used. We have a few 3rd party switches uplinked to some of our Meraki switches (trunk ports). Would Root or Loop guard be worthwhile to activate?
The same question goes for fiber uplinks - from Meraki switches to a core. Is there a best practice on what STP guard settings should be? Or is "disabled" the norm?
Thanks for your input. Happy to provide more topology details if need be.
Solved! Go to Solution.
11-02-2018 07:19 AM
- We use bpdu-guard for client ports to prevent spanning-tree problems f.e. when users connect switches to the ports.
- We use loop-guard on switches with multiple uplink-ports to prevent loops in case of spanning-tree or aggregation problems.
- We don´t use the root-guard option because our core-switch is the rootguard with the best bridge ID priority value. So it´s not neccessary.
https://documentation.meraki.com/MS/Port_and_VLAN_Configuration/RSTP_on_the_MS_Switch
https://documentation.meraki.com/MS/Port_and_VLAN_Configuration/Switch_Ports
https://www.cisco.com/c/en/us/support/docs/lan-switching/spanning-tree-protocol/10596-84.html
https://documentation.meraki.com/MS/Other_Topics/Switch_Settings
11-02-2018 07:19 AM
- We use bpdu-guard for client ports to prevent spanning-tree problems f.e. when users connect switches to the ports.
- We use loop-guard on switches with multiple uplink-ports to prevent loops in case of spanning-tree or aggregation problems.
- We don´t use the root-guard option because our core-switch is the rootguard with the best bridge ID priority value. So it´s not neccessary.
https://documentation.meraki.com/MS/Port_and_VLAN_Configuration/RSTP_on_the_MS_Switch
https://documentation.meraki.com/MS/Port_and_VLAN_Configuration/Switch_Ports
https://www.cisco.com/c/en/us/support/docs/lan-switching/spanning-tree-protocol/10596-84.html
https://documentation.meraki.com/MS/Other_Topics/Switch_Settings
11-02-2018 08:56 AM
Thanks for this redsector. A follow-up question, and to quote the Cisco STP article link you sent...
"The biggest issue with STP is that some hardware failures can cause it to fail"
With that said, is there any benefit (or drawback / issue) to enabling Loop guard on a single uplink port? I'm not certain on what type of hardware failure on a Meraki switch that would cause an overall STP failure. However, if Loop guard has inherent protections against something weird, it sounds like a good idea.
Thanks again for your input.
11-02-2018 10:39 AM
LoopGuard is to protect against uni-directional links. So yes, even if there's only one uplink it can be useful.
However, my personal preference is to use UDLD over LoopGuard.
12-20-2020 08:33 PM
Can we use loop guard and UDPD on same ports which is same port channel.
12-20-2020 09:07 PM
So long as the configurations of the two ports are the same you should be able to aggregate them. You can certainly use Loop Guard and UDLD together, and the Meraki documentation recommends it.
11-02-2018 12:11 PM
I don't ever use root guard. I have had it bite me in the past when various failures happened, and it made those failures more severe.
11-02-2018 12:14 PM
I'm not really a fan of loop guard unless there are redundant paths. Othewise if you have a single link and it triggers it'll take out the downstream network.
03-25-2019 09:22 AM
Follow normal recommendations for STP.
On out case, we are using MS devices as L2 only at the access layer.. Our core L3 devices are 4500 cisco.
we use the follwing settings that work perfect.
*Root guard: Configure at core on all ports to access switches and on access switches to APs
*BPDU guard: Configure in all access ports
*Loop guard: Configure in uplinks to core
*UDLD enforce on uplinks to core
09-16-2019 12:00 PM
On AP's do you mean Access Ports or Access Points?
09-16-2019 12:54 PM
I would think AP's meaning Wireless Access Points.
As a follow up, we now activate BPDU guard (with enforcement) on all access ports and any truck ports connected to a switch not under our control (a reality in a campus + residential environment). Has worked as advertised and saved our keisters on at least a dozen occasions since.
09-16-2019 12:58 PM
10-02-2019 03:01 PM
04-15-2020 08:06 AM
AP = Access Points indeed. Wireless Access Points
09-16-2019 11:35 PM
On AP's do you mean Access Ports or Access Points?
---------------------
Accesspoints.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide