meeting room a medium-sized (three consultants and a client ...)
[Consultant 1] Hey Joseph. I need to get off the mail to receive the latest version of PowerPoint.
[Customer] OK. Connect to this outlet.
[Consultant 2] Well, I too would be good to connect.
[Guest] You yourself ...
[Consultant 3] I can ... ?
[Guest] Yes of course.
[Consultant 3] As sockets are not free ...
[Consultant 1] Tranquilo Tomas, I have a switch ... Look what we connect to the wall and both of us to switch.
....
[outside voices] Do you have Internet? .. I do not, do you? ... I get an error the Excel ...
Meanwhile in the network operating room ...
[Engineer 1] Michael, I need the budget for next year's maintenance of radio links ..
[Engineer 2] Yes .. and you asked me yesterday ...
red light appears on the screen of monitoring systems
[Engineer 1] Shit. Gone is the office network of Teruel.
The emergence of a uncontrolled switch a network can bring you down and leaving no months of planning, configuration and stability of your network users.
You can not trust that users do not connect anything to the network (though always swear not to), so we have to control ourselves.
The main problem of connecting an uncontrolled switch in our network is capable of producing a change in the topology of the tree of STP . These changes can be subtle or cause problems (IP Telephony do not like the changes.)
midrange switches allow two actions to the problem: Ignore
- STP protocol messages to send a non-controlled switch. Block
- takes you connect a switch uncontrolled. Warn
- via SNMP , the network operators.
In applying these policies is very important to have a network map with the physical connection of equipment, and that we should allow BPDU traffic on those links connected physically (whether active or disabled by STP) to avoid surprises pathways activated backup (before the fall of a switch can change bastente topology as the network that has been mounted).
To configure these protections simply must enter the settings spanning-treey securing activate these options.
In HP:
switch06 (config) # spanning-tree 1-47 BPDU BPDU-filter-protection
0 comments:
Post a Comment