<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RE: Best way to prevent topology changes...? in ExtremeSwitching (EOS)</title>
    <link>https://community.extremenetworks.com/t5/extremeswitching-eos/best-way-to-prevent-topology-changes/m-p/17665#M561</link>
    <description>Hi,&lt;BR /&gt;
&lt;BR /&gt;
you can add a security profile to the radius reply. This security profile triggers a UPM which can afterwards change the STP config.&lt;BR /&gt;
&lt;BR /&gt;
Regards&lt;BR /&gt;
André</description>
    <pubDate>Thu, 21 Sep 2017 12:22:00 GMT</pubDate>
    <dc:creator>André_Herkenrat</dc:creator>
    <dc:date>2017-09-21T12:22:00Z</dc:date>
    <item>
      <title>Best way to prevent topology changes...?</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-eos/best-way-to-prevent-topology-changes/m-p/17661#M557</link>
      <description>Brief description of the environment:&lt;BR /&gt;
K-12 School District&lt;BR /&gt;
S4 Core [08.62.04.001]&lt;BR /&gt;
x460-G2 (40G uplink) distribution layer [21.1.1.4]&lt;BR /&gt;
x450-G2 (10G uplink) edge layer [21.1.1.4]&lt;BR /&gt;
Management, Control, Analytics 8.x&lt;BR /&gt;
&lt;BR /&gt;
x460-G2+x450-G2 stacks (building mdf)&lt;BR /&gt;
x450-G2 stacks (building idf)&lt;BR /&gt;
&lt;BR /&gt;
x430 (1G uplink) "classroom layer" [16.2.3.5] - connects Kramer VP-773A, Crestron MPC-M10, Epson Projector, HP PC, and spare ethernet for laptop in every classroom (200+ district-wide), a few (&amp;lt;5) have a Mitel phone plugged in&lt;BR /&gt;
&lt;BR /&gt;
Interswitch edge devices of interest include:&lt;BR /&gt;
3935i/3965i APs in lacp lags&lt;BR /&gt;
Mitel 5304 (no PC port), 5320/5330/5360 (includes PC port) IP Phones&lt;BR /&gt;
&lt;BR /&gt;
Access edge devices of interest include:&lt;BR /&gt;
Avigilon IP Cameras&lt;BR /&gt;
Windows/Mac Devices&lt;BR /&gt;
IP Intercom Devices&lt;BR /&gt;
IP Physical Access Control Devices&lt;BR /&gt;
IP Building Management (BMS) Devices&lt;BR /&gt;
Digital Signage Devices&lt;BR /&gt;
&lt;BR /&gt;
My S4 STP config is very simple:&lt;BR /&gt;
set spantree priority 0 0&lt;BR /&gt;
set spantree adminedge ge.X.xx true (where access edge device)&lt;BR /&gt;
&lt;BR /&gt;
My x430, x450-G2, x460-G2 STP config is:&lt;BR /&gt;
configure mstp revision 3&lt;BR /&gt;
configure stpd s0 mode mstp cist&lt;BR /&gt;
enable s0 auto-bind vlan 1-4094&lt;BR /&gt;
configure stpd s0 ports link-type edge X:xx (where access edge device)&lt;BR /&gt;
configure stpd s0 ports edge-safeguard enable X:xx (where access edge device)&lt;BR /&gt;
configure stpd s0 ports bpdu-restrict enable X:xx (where access edge device)&lt;BR /&gt;
enable stpd s0&lt;BR /&gt;
&lt;BR /&gt;
Here is my question... What are my options to prevent excessive topology changes if someone plugs in an access edge device into a port that was programmed for a interswitch edge device?&lt;BR /&gt;
&lt;BR /&gt;
1. maclock seems heavy handed&lt;BR /&gt;
&lt;BR /&gt;
2. &lt;A href="https://community.extremenetworks.com/extreme/topics/network-loop-through-voip-phone" target="_blank" rel="nofollow noreferrer noopener"&gt;This is interesting but feels like duct tape&lt;/A&gt;&lt;BR /&gt;
&lt;BR /&gt;
3. Dedicated phone, camera, classroom switch is a possibility in some spots but someone could still accidentally plug in the wrong thing&lt;BR /&gt;
&lt;BR /&gt;
Wired dot1x is not fully deployed. MAC auth is used to identify Mitel phones, Avigilon cameras, intercom, BMS, and digital signage devices. I am not finding a way to apply STP port rules via Policy.&lt;BR /&gt;
&lt;BR /&gt;
Am I missing something?&lt;BR /&gt;
&lt;BR /&gt;
Thanks in advance,&lt;BR /&gt;
Jeff</description>
      <pubDate>Thu, 21 Sep 2017 06:49:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-eos/best-way-to-prevent-topology-changes/m-p/17661#M557</guid>
      <dc:creator>Jeff</dc:creator>
      <dc:date>2017-09-21T06:49:00Z</dc:date>
    </item>
    <item>
      <title>RE: Best way to prevent topology changes...?</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-eos/best-way-to-prevent-topology-changes/m-p/17662#M558</link>
      <description>Hi Jeff,&lt;BR /&gt;
I have no experience with Extreme Switches but Enterasys has a feature called spanguard that will disable the port if a stp sending device is connected.&lt;BR /&gt;
That will not fix all your problems but perhaps some?&lt;BR /&gt;
Regards,&lt;BR /&gt;
Axel&lt;BR /&gt;</description>
      <pubDate>Thu, 21 Sep 2017 10:35:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-eos/best-way-to-prevent-topology-changes/m-p/17662#M558</guid>
      <dc:creator>ar1</dc:creator>
      <dc:date>2017-09-21T10:35:00Z</dc:date>
    </item>
    <item>
      <title>RE: Best way to prevent topology changes...?</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-eos/best-way-to-prevent-topology-changes/m-p/17663#M559</link>
      <description>Hi Jeff,&lt;BR /&gt;
&lt;BR /&gt;
The EXOS equivalent of spanguard is "&lt;I&gt;edge safeguard&lt;/I&gt;". Please take a look at the link below. By configuring user ports as "edge ports", you will also prevent the topology changes initiated from end-devices such as PCs, phones, IP cams each time they plug-unplug to the network.&lt;BR /&gt;
&lt;BR /&gt;
&lt;A href="https://gtacknowledge.extremenetworks.com/articles/How_To/How-to-configure-a-port-in-an-STP-domain-to-edge-safeguard-mode-with-bpdu-restrict/?q=exos+edge+safeguard&amp;amp;#38;l=en_US&amp;amp;#38;fs=Search&amp;amp;#38;pn=1" target="_blank" rel="nofollow noreferrer noopener"&gt;https://gtacknowledge.extremenetworks.com/articles/How_To/How-to-configure-a-port-in-an-STP-domain-t...&lt;/A&gt;&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Thu, 21 Sep 2017 11:38:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-eos/best-way-to-prevent-topology-changes/m-p/17663#M559</guid>
      <dc:creator>Emre_Kurtman</dc:creator>
      <dc:date>2017-09-21T11:38:00Z</dc:date>
    </item>
    <item>
      <title>RE: Best way to prevent topology changes...?</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-eos/best-way-to-prevent-topology-changes/m-p/17664#M560</link>
      <description>Thank you for your comment. I am already using edge-safeguard on my EXOS switches. My question is not concerning edge ports, but interswitch ports where edge devices are inadvertently plugged in.</description>
      <pubDate>Thu, 21 Sep 2017 11:38:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-eos/best-way-to-prevent-topology-changes/m-p/17664#M560</guid>
      <dc:creator>Jeff</dc:creator>
      <dc:date>2017-09-21T11:38:00Z</dc:date>
    </item>
    <item>
      <title>RE: Best way to prevent topology changes...?</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-eos/best-way-to-prevent-topology-changes/m-p/17665#M561</link>
      <description>Hi,&lt;BR /&gt;
&lt;BR /&gt;
you can add a security profile to the radius reply. This security profile triggers a UPM which can afterwards change the STP config.&lt;BR /&gt;
&lt;BR /&gt;
Regards&lt;BR /&gt;
André</description>
      <pubDate>Thu, 21 Sep 2017 12:22:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-eos/best-way-to-prevent-topology-changes/m-p/17665#M561</guid>
      <dc:creator>André_Herkenrat</dc:creator>
      <dc:date>2017-09-21T12:22:00Z</dc:date>
    </item>
    <item>
      <title>RE: Best way to prevent topology changes...?</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-eos/best-way-to-prevent-topology-changes/m-p/17666#M562</link>
      <description>Andre,&lt;BR /&gt;
&lt;BR /&gt;
Can you elaborate on this? Is this documented somewhere? This seems like the best solution, but I am not seeing the way to it. I have policy fully deployed and identifying interswitch devices by mac. I am using Control, Manage, and Policy. Is it possible with these two products?&lt;BR /&gt;
&lt;BR /&gt;
Jeff</description>
      <pubDate>Thu, 21 Sep 2017 12:22:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-eos/best-way-to-prevent-topology-changes/m-p/17666#M562</guid>
      <dc:creator>Jeff</dc:creator>
      <dc:date>2017-09-21T12:22:00Z</dc:date>
    </item>
  </channel>
</rss>

