Showing posts with label BPDU. Show all posts
Showing posts with label BPDU. Show all posts

Sunday, January 30, 2011

STP Enhancements

I wasn't being completely honest when I was talking about STP in my last post.  There are several versions of STP, and the one I introduced in the previous post is known as Common Spanning Tree (CST).  Now, this was the original spanning tree, but is rarely used in a modern network due to its limitations.  In fact, by default, it isn't run on Cisco switches.  Cisco switches run what is known as Per VLAN Spanning Tree (PVST).  It is just what its name suggests, PVST runs an instance of STP on each VLAN.  PVST is Cisco-proprietary, as is PVST+.  PVST+ runs PVST, but is backwards compatible with CST.  So if there is a single switch that is running CST, all PVST+ switches will revert back to CST, so only use it if you are sure you need to be able to switch to running CST quickly, while preserving your PVST information.

So why is running an instance of STP in each VLAN a good thing?  Well' it isn't always.  If you have a very large amount of VLANs and only a few switches, your root bridges will be overloaded with overhead.  There's a fix for that too, and it's known as MST, Multiple Spanning Tree.  MST breaks STP into zones, so it can handle a collection of VLANs in one instance.

Let's go over the individual enhancements to STP to overcome the limitations I discussed in my last post.

PortFast - Turns off STP on an interface.  Why oh why would you ever want to use this?!  Well, say you build a new computer with one of those fancy SSDs that makes your server boot up in 10 seconds flat.  Well, you'll have to wait another 40 seconds to use the network, since STP will take 50 seconds to converge.  Portfast bypasses this by saying "I'm not a switch, I'll never cause a switching loop so I don't need to participate in STP". Now, this command can be VERY DANGEROUS.  If you turn PortFast on and someone plugs in a switch to that port, or connects two ports via crossover cable, you have potential for a switching loop.  Only use PortFast on access ports, and only if you are sure no one will cause a loop on it.
Switch(config-if)#spanning-tree portfast

BPDUGuard/BPDUFilter - Many switches support this addition to PortFast.  Basically, this prevents the scenario I just described by monitoring for BPDUs on a PortFast enabled port.  If it hears a BPDU (this will mean a switching loop), it shuts down that port into errdisable state.  BPDUFilter accomplishes the same goal, but by disabling PortFast when it hears a BPDU, forcing that port to participate in STP.  Be sure to use one or the other when you turn on PortFast.
Switch(config-if)#spanning-tree bpduguard enable
Switch(config-if)#spanning-tree bpdufilter enable


UplinkFast - Cisco-specific feature that improves STP convergence time when a link failure occurs.  Used when the switch has at least one backup root port currently in blocking state.  Basically, if a primary link fails, the backup link comes online quickly, instead of waiting 50s for STP to re-converge.  Typically used on Access layer switches, and only those that know alternative paths.
Switch(config)#spanning-tree uplinkfast

BackboneFast - Used for speeding up convergence when a link not directly connected to the switch fails.  This one is a little tricky, if the switch hears what's called an "inferior BPDU"
In the picture above, A is the root bridge, and the link between A and C goes down.  C has lost its path to root, and has no alternate path to it, since it was using that link to get to bridge B.  So it think that it's the new root.  It'll send out BPDUs on the link to bridge B.  Bridge B will see these BPDUs, and say, "Well, wait a second, my link to the root bridge(A) is fine, these BPDUs are inferior".  So it'll ignore BPDUs on the blocked port.  After 20 seconds, max_age for the blocked port will time out, and B will send out a BPDU to bridge C, which will be better than the BPDUs C is sending out.  Bridge C will stop sending BPDUs, and the blocked port will go through listening, learning, and finally forwarding states.  The whole process takes about 50 seconds.

BackboneFast overcomes this by timing out the max_age as soon as an inferior BPDU is heard.  This saves 20 seconds.  Like I said, it's a little very confusing, just know that Cisco recommends enabling BackboneFast on all Catalyst switches so they can dtetect indirect link failures.
Switch(config)#spanning-tree backbonefast

Last, we have my favorite part of STP, 802.1w - or Rapid Spanning Tree Protocol (RSTP).  RSTP can run on all brands of switches, and includes all of the features I just discussed.  Remember, the enhancements I just wrote about were created by Cisco to fix the problems of CST, and as such, they were Cisco-proprietary.  RSTP essentially combines the Listening, Blocking, and Disabled modes into the new mode Discarding.  This is because all of these modes are simply not forwarding packets, and are not learning MAC addresses.  In RSTP bridges also send out BPDUs every hello time, not just when they hear a BPDU from their root port.  These two changes cause convergence time to drop to mere seconds, rather that 50 seconds of other versions.  That's why if you can run RSTP, you should, just make sure all switches are running it, since it'll provide no benefit if it has to conform to 802.1D (RSTP will work with regular STP, but will none of the enhancements).

Turning RSTP on is very simple.
Switch#conf t
Switch(config)#spanning-tree mode rapid-pvst

I'm going to wrap up with verification commands that should be memorized.

The show spanning-tree command show important information to see who is the root bridge, what priorities are set to the VLANs, what role ports are in, their costs, and priorities.  If you are running PVST (as all Cisco switches are by default), you can specify which VLAN to see information for.  If you don't, it'll show all of them.
S1#show spanning-tree
S1#show spanning-tree vlan 10

The show mac address table command shows what VLAN ports are in, what MAC address(es) is/are assigned to that port, and whether those MACs are statically or dynamically assigned.
S1#show mac address-table

This command helps verify the IP address of the switch
S1#sh int vlan 1

Thanks for reading!

Friday, January 28, 2011

Spanning Tree Protocol - 802.1D

My college campus used to have a gigantic problem with switching loops. The reason is, they didn't run STP.  All anyone had to do to bring the network to a complete standstill was plug a crossover cable from one port in the wall to another port in the wall.  This would cause a networking loop, leading to a broadcast storm, and obliterating the network.  Why are network loops so bad?  Isn't redundancy good?  Yes, but if you have more than one active path, broadcasts will obliterate your network.  Each time a broadcast it is sent out every port, this broadcast will reach the switch that sent it through the loop, and be forwarded again, and again, and again until there's no bandwidth left for legitimate traffic.

This is why it's so important to prevent loops, and STP is the way you accomplish that.  STP, the Spanning Tree Protocol eliminates loops in the network by essentially shutting down redundant links (paths) in a network.  Here's how it works.  All switches running STP send BPDUs (Bridge Protocol Data Units) as multicast packets to track down loops.  If these BPDUs find their way back to the originating switch, a loop was detected.  BPDUs are also essential to electing the Root Bridge, the pillar of the network.  All switches will try to find the most optimal path to the root bridge, and block all the other paths.  Now, STP is designed to work right out of the box, but without tweaking it can really slow down your network.  The reason for this is the way in which the root bridge is chosen, or elected.  Each switch has a Bridge ID, made of a priority and a MAC address.

Bridge ID = Priority.MACADDR.

It may seem counterintuitive, but lower is better when it comes to the bridge ID.  Out of the box, all switches have a default priority of 32768, so when the networking is choosing the root bridge, the switch with the lowest MAC address will be chosen, which is generally the oldest (going by manufacture date).  To rectify this you have several options.  You can lower the priority (in increments of 4096, don't ask me why) to a lower number than the default, but if there is a tie, they will default to MAC addresses to break it.  You can also use the following command, which will lower the priority to 24576 (IEEE's recommended value for the root):

Switch(config)#spanning-tree vlan 1 root primary

Making sure your root bridge is placed in an optimal location on a powerful switch is very important, otherwise your network will be slowed down by an outdated switch.

Once your root bridge has been elected, switches will start sending out BPDUs to find the best path to that switch.  It judges the path based on link cost.  The following Link Costs are assigned to these link types.
10 Mb/s   -  100
16 Mb/s   -  62
100 Mb/s -  19
1 Gb/s      -  4
2 Gb/s      -  2
4 Gb/s      -  1

So if a switch has to go across 3 100Mb/s links to get to the root bridge, that path will have a cost of 57.  If that switch connected directly to the root bridge over a 10 Mb/s link, it will prefer the former.

This leads us to the three different kinds of ports for STP.

Root Port - The port traffic goes out to reach the root bridge
Designated Port - Port that forwards traffic, there will be one of these per link.  It's either a port that leads to a host, a port on the root bridge, or a port opposite of one that is being blocked.
Blocking/Nondesignated - Port that is blocked by STP.  On a link that is blocked, only one port will be put in blocking mode, the other will remain designated.  Can you guess which side will be blocked?  Yup, the side of the switch with the higher MAC address, because in STP, lower is better.

Pop quiz, what are all the ports on the root bridge set to?  Answer: Designated.  Root ports are used to reach the root bridge, so it obviously won't want to reach itself, and it won't put any ports in blocking mode since other switches need to get to that switch.

It's a really good idea to go online and find some examples and sample problems to practice predicting which links will be shut down.

Let's say you have three switches, connected in a triangle.  Link 1 and 2 are active, and link 3 is in blocking.  Say someone unplugs link 2.  Well STP is going to see this and switch link 3 to a forwarding state, but it's going to take a while (30~50 seconds).  The reason it takes so long is that the ports on link 3 have several states to go through before they become designated ports.

Listening - Port listens to BPDUs to make sure it doesn't hear any loops on the network before it forwards frames.
Learning - Port listens to BPDUs and learns all paths on the network and populates the MAC address table.  The time it takes to go from listening to learning is known as a Forward Delay, and is set on the switch.
Forwarding - Sends and receives frames.  If the port is still a root port or a designated port at the end of the learning state, it will be put in this mode.
Blocking - Port will not send frames, but will listen for BPDUs.  When a switch is powered up, all ports are in this mode.
Disabled - Administratively shut down, does not forward frames or participate in STP.

When all ports in a network have entered a forwarding or blocking state, the switched network has converged.  While STP is in the process of converging, no host data is transmitting.  It usually takes about 50 seconds for the network achieve convergence (though you can reduce timers to lower this, I wouldn't recommend it for basic STP).  So every time there is a network change, your entire switched network goes down for 50 seconds!  Doesn't seem like a lot?  Well it's a huge amount of time in the networking world.  Imagine you have VOIP set up, it only takes a few seconds of downtime to drop your calls.  Credit card transactions won't go through, a server backup fails, and your boss can't get on Facebook.
Yikes.  Luckily there have been some major improvements to STP to speed up the process and make STP more efficient.

Thanks for reading!