RSTP problem
Posted: Mon Jan 18, 2021 2:25 pm
Having an RSTP problem recently where the switches are discovering a customer routers LAN port (due to customer moving cable to wrong port), so the customer router became the root bridge and so a topology change occured on a Netonix switch which is actually another site, not same site as customer connects to.
This should be impossible as I considered this from the start and everything is isolated with VLANs, I've verified before that there is no Layer 2 connectivity between customers or between sites.
or do BPDUs leak through the switches regardless of VLAN configs?
Yes customers have "layer 2 access" as all the UBNT CPEs are bridged in order to maximize performance, but each CPE has its own management VLAN per site.
Each customer then connects straight to the Mikrotik router via PPPoE.
Each AP has its own VLAN, tagged on the switches router interface, untagged on AP interface.
VLAN 1 is excluded from all interfaces on all switches.
For example in this segment of the network:
customer router -> PowerBeam M5 -> Rocket M5 -> ToughSwitch -> Mikrotik RB450G
then from ToughSwitch theres a PtP link to another site, on a tagged VLAN, to the Netonix.
So basically, the Netonix swtich at Site 1 found the customer router connected at Site 2 as the root bridge, and it still happens even if I completely disable RSTP on the ToughSwitch.
RSTP enabled on all ports of Netonix.
Netonix running firmware 1.5.2
Attached images should help
Thanks
This should be impossible as I considered this from the start and everything is isolated with VLANs, I've verified before that there is no Layer 2 connectivity between customers or between sites.
or do BPDUs leak through the switches regardless of VLAN configs?
Yes customers have "layer 2 access" as all the UBNT CPEs are bridged in order to maximize performance, but each CPE has its own management VLAN per site.
Each customer then connects straight to the Mikrotik router via PPPoE.
Each AP has its own VLAN, tagged on the switches router interface, untagged on AP interface.
VLAN 1 is excluded from all interfaces on all switches.
For example in this segment of the network:
customer router -> PowerBeam M5 -> Rocket M5 -> ToughSwitch -> Mikrotik RB450G
then from ToughSwitch theres a PtP link to another site, on a tagged VLAN, to the Netonix.
So basically, the Netonix swtich at Site 1 found the customer router connected at Site 2 as the root bridge, and it still happens even if I completely disable RSTP on the ToughSwitch.
RSTP enabled on all ports of Netonix.
Netonix running firmware 1.5.2
Attached images should help
Thanks