BACK TO SUPPORT PORTAL
RUCKUS Technologies
Wired
Wireless
Cloud Services
Miscellaneous
RUCKUS Lennar Support
Lennar Knowledge Base
RUCKUS Lennar Support
Resources
Community
Technical
Register
RUCKUS Technologies
Home
RUCKUS Technologies and Products
ICX Switches
stp-bdpuguard and MSTP not working
unknown
Hi all,
I am doing a demo of an ICX 7150 and just configured it for MSTP. I set a port to stp-bpduguard and intentionally hooked up a cisco switch to that port, but bpduguard does not seem to trigger. Am I doing something wrong here?
Find more posts tagged with
Accepted answers
All comments
unknown
You are not doing anything wrong. Cisco's BPDUguard is proprietary and does not recognize ICX BPDUs just like CDP does not recognize FDP packets.
unknown
Hmm... The Cisco device immediately err-disabled the port. So does this mean there is no bpdu guard protection if a Cisco device is hooked up?
unknown
disregard. Got it working.
unknown
Here is probably what is going on. I am speaking from experience (a bad experience in 2017 resulting in 10 to 15 minutes downtime...) as I troubleshooted...
😉
If you have a Cisco device running BPDUguard on an interface, and it receives a recognized BPDU, it will put the port into an err-disabled state.
On a Cisco Device, that may look something like:
interface GigabitEthernet 1/0/48
spanning-tree bpduguard enable
!
That interface will go into err-disabled when it sees another "recognized" BPDU (i.e. a BPDU from another Cisco switch).
If, however, you connect an ICX switch to that G 1/0/48 port, the BPDU from the ICX will NOT shut-down the port because it is not a recognized BPDU by Cisco.
*****
Now here is where it gets fun...
Let's say you connect another, different Cisco device to that ICX device (within the same VLAN) as the ICX interface connecting to G 1/0/48 on the Cisco above.
Topology: Cisco Device => ICX Device => Cisco Device with BPDUguard
The ICX not recognizing the Cisco BPDU does exactly what it is designed to do and switches the Frame (Frame is the PDU for Layer-2, where the PDU for Layer-3 is the "packet"). Once the ICX device forwards a BPDU from one Cisco into the G 1/0/48 interface on another Cisco, the Cisco port that received the BPDUguard puts that interface into err-disabled.
*****
General rule of thumb:
Do NOT mix ICX and Cisco within the same Layer-2 when it can be avoided. It is MUCH better to separate these via Layer-3 because things like BPDUs and neighboring protocols do not work very well together.
For example, ICX uses FDP as its discovery protocol. A Cisco device does not know what to do with an FDP Frame, so it just forward the frame as if it were any other unknown frame. When they hit other ICX devices, you can no longer use FDP to meaningfully map your network.
Although these are minor issues, the most cost-effective solution to your ultimate problem is to build an ICX network. The ICX-7150 series are excellent workhorse switches. I would recommend getting the PoE+ variety to better future-proof your build. If you want a great Layer-3 switch for the connection of a bunch of ICX-7150 switches, the ICX-7450 or ICX-7750
unknown
Awesome. I am guessing you turned off BPDUguard???
😉
unknown
I had already done that on the Cisco side. Honestly not sure what fixed it. I just defaulted the config on the Cisco side port, then add the access vlan back on it.
jon_maiman_iyni
ICX's can be configured to interop with the various flavors of Cisco PVST so that spanning tree will have a consistent state in both the Ruckus (Brocade/Foundry) portion of the network and the Cisco portion of the network. I have implemented this many times. Besides the different BPDU frame formats, PVST typically transmits the BPDU's on an untagged native VLAN (default VLAN is 1). So the ICX also needs to be configured to have the native VLAN be untagged (dual-mode in older FastIron code).
--Jon
Quick Links
🗂️ All Categories
📄 Recent Posts
❓ Unanswered
🆘 Help
Tags
SmartZone or vSZ
RUCKUS Self-Help
Cloudpath
ICX
AP Management
vSZ
Access points
ICX Switch Management
Lennar homes
SmartZone