Wireless Access

Reply
Super Contributor II
Posts: 355
Registered: ‎02-22-2011

LLDP - Incorrect VLAN sent out ArubaOS 6.3

Hi All,

 

I came across a strange issue which i think is a bug in 6.3.1.7.

 

Our AP's are connected using native VLAN (1) to the access switch. The access switch (HP) is reporting a native VLAN mismatch in the logs. When i checked the LLDP stats on the switch, the AP is sending a PVID of 0.

 

I'm guessing this relates to the default setting in the AP provisioning page which sets the Uplink VLAN to 0 when tagged ports are not in use.

 

This smells like a bug to me. Any thoughts?

 

Scott

Super Contributor I
Posts: 274
Registered: ‎04-04-2014

Re: LLDP - Incorrect VLAN sent out ArubaOS 6.3

 

I have similar log-droppings on HP switches.  However there actually is a PVID difference in that we set the access vlan to a value not known to the AP.

 

I haven't gone looking for options to prevent the PVID field from being sent on untagged ports from the Aruba side.  Looked a bit on the HP side to see if there was an "ignore that" option, but didn't find anything there yet either.  DIdn't have much luck using a dot1q tag on the AP uplink when I tried, which means setting up DSCP mappings is going to be mandatory if we ant QoS.

 

 

 

 

Guru Elite
Posts: 8,637
Registered: ‎09-08-2010

Re: LLDP - Incorrect VLAN sent out ArubaOS 6.3

You'll get these errors on Cisco switches from the CDP engine as well. I don't think it's a bug, just an annoyance on the access switch. The switch shouldn't be expecting a native VLAN on an access port but the implementation of the discovery protocol appears to be treating all ports like a trunk.

Tim Cappalli | Aruba Security TME
@timcappalli | timcappalli.me | ACMX #367 / ACCX #480
Super Contributor I
Posts: 274
Registered: ‎04-04-2014

Re: LLDP - Incorrect VLAN sent out ArubaOS 6.3

 

I just issued a "no lldp config XX dot1TlvEnable port-vlan-id" on one of my AP links on an HP switch.  In about a half hour I should know if that stops the logs.

 

I noticed that older procurve software versions do not report sending a PVID TLV, didn't have the command for it, and also don't complain when they get one, so knock on wood.

 

 

 

Super Contributor II
Posts: 355
Registered: ‎02-22-2011

Re: LLDP - Incorrect VLAN sent out ArubaOS 6.3

I'd expect that the VLAN ID would be sent out by LLDP as VLAN 1 as in the AP system profile this is the access VLAN that is set.

 

We have also tried turning off that TLV in the LLDP profile for the AP ethernet port. Will see if that works.

 

Scott

Super Contributor I
Posts: 274
Registered: ‎04-04-2014

Re: LLDP - Incorrect VLAN sent out ArubaOS 6.3

 

FWIW:

 

"802.1AB

F.2.1 port VLAN identifier (PVID) The port VLAN identifier field shall contain the VLAN ID for the bridge port as defined in 8.4.4 of IEEE 802.1Q-1998. A value of zero shall be used if the system either does not know the PVID or does not support port-based VLAN operation."

 

I'd agree and also say HP is probably treating this situation incorrectly as well, since a device that claims it doesn't do VLANs (even if it is faking it) should not be flagged in the logs.  The standard also of course mentions that it is legitimate to connect different PVIDs if you know what you're doing, so really vendors should provide a way to disable to warnings, and what Aruba chose to do here makes a bit of sense to deal with those that do not, with the exception of those that also warn on 0.

 

No dice on that command, unfortunately.

 

 

 

 

 

Super Contributor I
Posts: 274
Registered: ‎04-04-2014

Re: LLDP - Incorrect VLAN sent out ArubaOS 6.3

 

Another note, if the MAS ArubaOS is an indicator of the direction of development for things wired, that lets you select/deselect TLVs.

 

Super Contributor II
Posts: 355
Registered: ‎02-22-2011

Re: LLDP - Incorrect VLAN sent out ArubaOS 6.3

thanks, it does sound like it's normal then. I think the TLV changes in the LLDP profile should work, just waiting to hear back from client.

Super Contributor I
Posts: 274
Registered: ‎04-04-2014

Re: LLDP - Incorrect VLAN sent out ArubaOS 6.3

 

HP just brought the 15.14 chain out of ED with 15.14.0007 for some models.  It contains enhancement CR0000127014 which allows per-port suppression of PVID log messages, if that chain is supported by the switch models in question.

 

 

 

Super Contributor II
Posts: 355
Registered: ‎02-22-2011

Re: LLDP - Incorrect VLAN sent out ArubaOS 6.3

thanks i'll give that a try!

Search Airheads
Showing results for 
Search instead for 
Did you mean: