Solved

Recommendation on selecting Root switch

Posted on 2016-09-12
12
35 Views
Last Modified: 2016-09-13
TopologyHi
I am about to change all our switches and have pre configured spanning-tree and bpdu protection on all the switches.
I have simplified the drawing by removing a lot of switches, however all switches will connect back to switch 1 with a single crossover cable.
Spanning-tree with Portfast / Admin Edge Port and BPDU protection is configured on all ports with the exception of the uplinks.
I have a question about setting the root switch. I plan to set the bridge priority of switch 1 to have a value of 16384, all other switches are set to default. Would this be the recommended switch to set this on?
Do I also need to set a value of 16384 on the Cisco switch 5 for interface vlan 2?
Kind regards
Rick
0
Comment
Question by:Rick_Penney
  • 5
  • 5
  • 2
12 Comments
 
LVL 16

Expert Comment

by:Michael Ortega (Internetwerx, Inc.)
Comment Utility
If Switch one is going to be your main agg switch then it should be your root bridge. If it's also going to traverse vlan 2 traffic then it should also be the root for that segment as well.

For Cisco switches the default value for the bridge priority is 32k+. I would think it was a general standard default amongst other switch vendors as well.

MO
0
 

Author Comment

by:Rick_Penney
Comment Utility
Hi Michael, many thanks for your reply.
My primary and secondary (backup) routers do both connect to the same switch 1, so all traffic does go through that switch.
I don't however have any config on the switch 1 relating to vlan2. Traffic knows to get to vlan2 via a static route on the router to tell it to go through switch 5.
So, for me to make switch 1 the root for vlan 2 as well, will I just need to add a vlan 2 interface to the HP switch 1 and tag both vlans to the port on switch 1 that connects to switch 5?
Many thanks
Rick
0
 
LVL 16

Expert Comment

by:Michael Ortega (Internetwerx, Inc.)
Comment Utility
I'm confused. In your diagram, it shows that Switch 5 trunks to Switch 1. I'm assuming it sends the VLAN2 segment through the same link before it hits your Router(s)? Or do you have a separate link on Switch 5 that connects directly to your Router?

MO
0
 

Author Comment

by:Rick_Penney
Comment Utility
Hi, sorry I was trying to condense our network in the drawing I embedded.
There is actually a switch in between 1 and 5 .
The port that goes from this other switch to switch 5 is set up as a trunk for both vlans.
The port that goes from this other switch to switch 1 isn't set up as a trunk port.
switch-config2.JPG
0
 
LVL 16

Expert Comment

by:Michael Ortega (Internetwerx, Inc.)
Comment Utility
Ok, so switches 5 & 6 carry both VLAN1 & 2 over to the intermediate switch. The intermediate switch connects to Switch 1. You specify that it's not trunked to Switch 1, but you are passing VLAN1 traffic from the intermediate to Switch one via the link illustrated, right? You're just not passing VLAN2 traffic? If not, where does VLAN2 traffic go beyond the intermediate switch? Anywhere?

MO
0
 
LVL 26

Expert Comment

by:Predrag Jovic
Comment Utility
Cisco and HP run incompatible versions of STP. You should use MSTP in mixed environment.
ProCurve & Cisco Spanning Tree Interoperability
And missing switches in drawing for STP are not good idea. Don't forget that max diameter of STP is 7 "hops" (end-to-end anywhere should not be more than 7 switches) and with that said from Cisco switch 1 to Cisco switch 6 is 4 "hops". Diameter actually can be more than 7 hops, however it is not recommended.
0
Find Ransomware Secrets With All-Source Analysis

Ransomware has become a major concern for organizations; its prevalence has grown due to past successes achieved by threat actors. While each ransomware variant is different, we’ve seen some common tactics and trends used among the authors of the malware.

 

Author Comment

by:Rick_Penney
Comment Utility
Hi Michael
The intermediate switch does connect to switch 1 from its port 1.
There is no config on port 1, however traffic from both subnets from vlan 1 and 2 on the other two switches are able to pass through to Switch 1.
!
interface GigabitEthernet0/1
!
Every switch on our network is able to ping every device on switches 5 & 6

Hi Predrag Jovic
Many thanks for your comments and link. I will print this out tomorrow and have a read through.
The only reason that its configured like that is switch 1 is currently an old cisco 2950 24 port. The intermediate switch is a 2960 and connects to switch 5 via a fibre link as its in a different comms room. I appreciate the guidance though.
0
 
LVL 16

Expert Comment

by:Michael Ortega (Internetwerx, Inc.)
Comment Utility
Rick,

What that means is that the connection between the intermediate switch and Switch 1 is automatically trunking and the default behavior is to allow all VLAN traffic through.

MO
0
 

Author Comment

by:Rick_Penney
Comment Utility
Thanks Michael, I'm very grateful for your time and knowledge.
Just to go back to your comment ref the root switch for vlan2, shall I make it the intermediate switch or switch 1?.
I will be leaving 6 cisco switches in place as they are quite new Gigabit switches. The rest will be replaced with HP, so it looks like I've got of extra learning to do on the Cisco / HP compatibility front :-)
regards
Rick
0
 
LVL 16

Assisted Solution

by:Michael Ortega (Internetwerx, Inc.)
Michael Ortega (Internetwerx, Inc.) earned 250 total points
Comment Utility
The STP settings are fairly easy to modify. Shouldn't be a big deal at all.

Definitely want to make Switch 1 root for VLAN 1. For VLAN 2, it's really a toss-up. The worry is always about convergence time. In a setting like yours, I don't think it would be much of a problem making Switch 1 the root VLAN 2 as well, but it could also be on the intermediate switch and not be a problem. Do you lose convergence time from the one hop difference? Perhaps, but not anything noticeable, but it might be easier from an administrative level that 1 switch is the root for both VLANs.

MO
0
 
LVL 26

Accepted Solution

by:
Predrag Jovic earned 250 total points
Comment Utility
Hint:
If you don't have redundant links and also have bpdu protection on all non trunk ports basically you don't need STP except as prevention method if redundant link is introduced to your network. You should use it , but basically, you don't need it. In your topology it is needed just be security mechanism so you can use STP's bpdu protection.
HP switches do not understand BPDUs for VLAN 2 (and still HP switches will receive those packets), that's  why you need MSTP - both vendor support it and it is compatible between vendors. For STP or RSTP HP sends BPDU in native VLAN.
For your topology there is no difference where root bridge is located, although typically best place for sure would be on distribution switch (switch where interface VLANs are created - typically those are on the same switch (I guess your switch 1 or switch 5)), but there would be no difference if it is placed anywhere else in your topology.
0
 

Author Closing Comment

by:Rick_Penney
Comment Utility
Many thanks to you both for your help with this.
My reason for the "Best Solution" was for the HP side of things, although I'm aware Michael posted a lot of helpful replies so a massive thank you to you too.
Regards
Rick
0

Featured Post

What Is Threat Intelligence?

Threat intelligence is often discussed, but rarely understood. Starting with a precise definition, along with clear business goals, is essential.

Join & Write a Comment

The worst thing when starting a new job is when the previous Network Administrator left behind no documentation. How do you get into the devices? If you've been in this situation or just accidently mistyped your password, this article will hopefully…
This tutorial will go through the steps required to write a script that will back up the configuration settings of a HP-ProCurve switch. You will need to get the following things to follow this tutorial: Telnet Scripting Tool e.g. TST10.exe …
Internet Business Fax to Email Made Easy - With eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, fr…
Illustrator's Shape Builder tool will let you combine shapes visually and interactively. This video shows the Mac version, but the tool works the same way in Windows. To follow along with this video, you can draw your own shapes or download the file…

772 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now