06-22-2021 03:05 AM
Yesterday we had network degradation due to a broadcast storm, which came about because someone had plugged both the ports of a Cisco 7965 phone into an X440-G2 running 31.1.1.3-patch1-1. Surely STP should have detected this and blocked one of the ports?
I did find this post which suggest putting on a broadcast rate limit on all ports, which I’m going to do, but is there some spanning tree config I’m missing to stop this happening at all?
(The degradation was because we’re still running an S4 at the core and it caused switch packet processing to hit the CPU limit https://extremeportal.force.com/ExtrArticleDetail?an=000075727 )
06-28-2021 01:36 AM
In nodealias I did see a BPDU from the switch itself:
2:7 02:04:96:cd:2e:53 138036794 06-21-2021 21:52:16 0 bpdu
show system reports 02:04:96:CD:2E:53 as the system MAC.
06-22-2021 10:26 AM
Hello,
it depends on the phone if STP would have prevented this. If the phones don’t forward BPDUs then there is no chance for the switch to detect the loop.
We usually go with ELRP + Rate-Limit (Multicast, Broadast, Unknown-Unicast)