Comware

 View Only
last person joined: yesterday 

Expand all | Collapse all

PVID Mismatch between HP 5900 and Aruba 2530

This thread has been viewed 45 times
  • 1.  PVID Mismatch between HP 5900 and Aruba 2530

    Posted Jun 07, 2023 06:17 AM

    Hello

    I'm using a an HP5900 with this configuration:

    <SW001>display current-configuration
    #
     version 7.1.045, Release 2432P06
    #
     sysname SW001
    #
     clock timezone UTC+1 add 01:00:00
     clock summer-time FDT 02:00:00 March last Sunday 03:00:00 October last Sunday 01:00:00
     clock protocol ntp
    #
     irf mac-address persistent timer
     irf auto-update enable
     undo irf link-delay
     irf member 1 priority 32
     irf member 2 priority 31
     irf mode normal
    #
     lldp global enable
    #
     system-working-mode standard
     fan prefer-direction slot 2 port-to-power
     password-recovery enable
    #
    vlan 1
    #
    vlan 11
     name MGMT_001
    #
    vlan 12
     name MGMT_002
    #
    vlan 201
     name PRODUCTION_001
    #
    vlan 202
     name PRODUCTION_002
    #
    vlan 300
     name PC_002
    #
    vlan 4094
     description MAD-BFD
    #
    irf-port 1/1
     port group interface FortyGigE1/0/51
    #
    irf-port 1/2
     port group interface FortyGigE1/0/52
    #
    irf-port 2/1
     port group interface FortyGigE2/0/51
    #
    irf-port 2/2
     port group interface FortyGigE2/0/52
    #
     stp mode rstp
     stp bpdu-protection
     stp global enable
    #
    interface Bridge-Aggregation21
     description TRUNK_LINK_TO_SVV002_MGMT
     port link-type trunk
     undo port trunk permit vlan 1
     port trunk permit vlan 12
     link-aggregation mode dynamic
    #
    interface Bridge-Aggregation31
     description TRUNK_LINK_TO_SVE001
     port access vlan 12
     link-aggregation mode dynamic
    #
    interface Bridge-Aggregation32
     description TRUNK_LINK_TO_SVE002
     port access vlan 12
     link-aggregation mode dynamic
    #
    interface Bridge-Aggregation1001
     description LACP_LINK_TO_SW002
     port link-type trunk
     undo port trunk permit vlan 1
     port trunk permit vlan 202 300
     port trunk pvid vlan 202
     link-aggregation mode dynamic
    #
    interface NULL0
    #
    interface Vlan-interface12
     ip address 10.20.12.201 255.255.255.0
    #
    interface Vlan-interface4094
     mad bfd enable
     mad ip address 10.99.99.1 255.255.255.0 member 1
     mad ip address 10.99.99.2 255.255.255.0 member 2
    #
    interface FortyGigE1/0/49
     port link-mode bridge
    #
    interface FortyGigE1/0/50
     port link-mode bridge
    #
    interface FortyGigE2/0/49
     port link-mode bridge
    #
    interface FortyGigE2/0/50
     port link-mode bridge
    #
    interface FortyGigE1/0/51
    #
    interface FortyGigE1/0/52
    #
    interface FortyGigE2/0/51
    #
    interface FortyGigE2/0/52
    #
    interface M-GigabitEthernet0/0/0
    #
    interface Ten-GigabitEthernet1/0/1
     port link-mode bridge
     
     port link-type trunk
     undo port trunk permit vlan 1
     port trunk permit vlan 12 202 300
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet1/0/2
     port link-mode bridge
     
     port link-type trunk
     port trunk permit vlan 1 11 201
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet1/0/3
     port link-mode bridge
     
     port link-type trunk
     undo port trunk permit vlan 1
     port trunk permit vlan 202 300
     port trunk pvid vlan 202
     broadcast-suppression pps 100
     undo lldp tlv-enable dot1-tlv port-vlan-id
     port link-aggregation group 1001
    #
    interface Ten-GigabitEthernet1/0/4
     port link-mode bridge
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet1/0/5
     port link-mode bridge
     
     port access vlan 202
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet1/0/6
     port link-mode bridge
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet1/0/7
     port link-mode bridge
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet1/0/8
     port link-mode bridge
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet1/0/9
     port link-mode bridge
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet1/0/10
     port link-mode bridge
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet1/0/11
     port link-mode bridge
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet1/0/12
     port link-mode bridge
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet1/0/13
     port link-mode bridge
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet1/0/14
     port link-mode bridge
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet1/0/15
     port link-mode bridge
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet1/0/16
     port link-mode bridge
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet1/0/17
     port link-mode bridge
     
     port link-type trunk
     undo port trunk permit vlan 1
     port trunk permit vlan 11 to 12 201 to 202
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet1/0/18
     port link-mode bridge
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet1/0/19
     port link-mode bridge
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet1/0/20
     port link-mode bridge
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet1/0/21
     port link-mode bridge
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet1/0/22
     port link-mode bridge
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet1/0/23
     port link-mode bridge
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet1/0/24
     port link-mode bridge
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet1/0/25
     port link-mode bridge
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet1/0/26
     port link-mode bridge
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet1/0/27
     port link-mode bridge
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet1/0/28
     port link-mode bridge
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet1/0/29
     port link-mode bridge
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet1/0/30
     port link-mode bridge
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet1/0/31
     port link-mode bridge
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet1/0/32
     port link-mode bridge
     description "PC MGMT"
     port access vlan 202
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet1/0/33
     port link-mode bridge
     
     port link-type trunk
     undo port trunk permit vlan 1
     port trunk permit vlan 12
     broadcast-suppression pps 100
     port link-aggregation group 21
    #
    interface Ten-GigabitEthernet1/0/34
     port link-mode bridge
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet1/0/35
     port link-mode bridge
     
     port access vlan 202
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet1/0/36
     port link-mode bridge
     
     port access vlan 202
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet1/0/37
     port link-mode bridge
     
     port access vlan 12
     broadcast-suppression pps 100
     port link-aggregation group 31
    #
    interface Ten-GigabitEthernet1/0/38
     port link-mode bridge
     
     port access vlan 12
     broadcast-suppression pps 100
     port link-aggregation group 32
    #
    interface Ten-GigabitEthernet1/0/39
     port link-mode bridge
     
     port access vlan 12
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet1/0/40
     port link-mode bridge
     
     port access vlan 12
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet1/0/41
     port link-mode bridge
     port access vlan 12
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet1/0/42
     port link-mode bridge
     port access vlan 12
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet1/0/43
     port link-mode bridge
     port access vlan 12
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet1/0/44
     port link-mode bridge
     port access vlan 12
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet1/0/45
     port link-mode bridge
     port access vlan 12
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet1/0/46
     port link-mode bridge
     port access vlan 12
     shutdown
    #
    interface Ten-GigabitEthernet1/0/47
     port link-mode bridge
     description MAD_LINK
     port access vlan 4094
     duplex full
     undo stp enable
     stp edged-port
    #
    interface Ten-GigabitEthernet1/0/48
     port link-mode bridge
     description MAD_LINK
     port access vlan 4094
     duplex full
     undo stp enable
     stp edged-port
    #
    interface Ten-GigabitEthernet2/0/1
     port link-mode bridge
     
     port link-type trunk
     undo port trunk permit vlan 1
     port trunk permit vlan 12 202 300
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet2/0/2
     port link-mode bridge
     
     port link-type trunk
     port trunk permit vlan 1 11 201
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet2/0/3
     port link-mode bridge
     
     port link-type trunk
     undo port trunk permit vlan 1
     port trunk permit vlan 202 300
     port trunk pvid vlan 202
     broadcast-suppression pps 100
     undo lldp tlv-enable dot1-tlv port-vlan-id
     port link-aggregation group 1001
    #
    interface Ten-GigabitEthernet2/0/4
     port link-mode bridge
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet2/0/5
     port link-mode bridge
     
     port access vlan 202
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet2/0/6
     port link-mode bridge
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet2/0/7
     port link-mode bridge
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet2/0/8
     port link-mode bridge
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet2/0/9
     port link-mode bridge
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet2/0/10
     port link-mode bridge
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet2/0/11
     port link-mode bridge
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet2/0/12
     port link-mode bridge
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet2/0/13
     port link-mode bridge
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet2/0/14
     port link-mode bridge
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet2/0/15
     port link-mode bridge
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet2/0/16
     port link-mode bridge
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet2/0/17
     port link-mode bridge
     
     port link-type trunk
     undo port trunk permit vlan 1
     port trunk permit vlan 11 to 12 201 to 202
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet2/0/18
     port link-mode bridge
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet2/0/19
     port link-mode bridge
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet2/0/20
     port link-mode bridge
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet2/0/21
     port link-mode bridge
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet2/0/22
     port link-mode bridge
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet2/0/23
     port link-mode bridge
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet2/0/24
     port link-mode bridge
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet2/0/25
     port link-mode bridge
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet2/0/26
     port link-mode bridge
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet2/0/27
     port link-mode bridge
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet2/0/28
     port link-mode bridge
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet2/0/29
     port link-mode bridge
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet2/0/30
     port link-mode bridge
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet2/0/31
     port link-mode bridge
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet2/0/32
     port link-mode bridge
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet2/0/33
     port link-mode bridge
     
     port link-type trunk
     undo port trunk permit vlan 1
     port trunk permit vlan 12
     broadcast-suppression pps 100
     port link-aggregation group 21
    #
    interface Ten-GigabitEthernet2/0/34
     port link-mode bridge
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet2/0/35
     port link-mode bridge

     port access vlan 202
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet2/0/36
     port link-mode bridge
     
     port access vlan 202
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet2/0/37
     port link-mode bridge
     
     port access vlan 12
     broadcast-suppression pps 100
     port link-aggregation group 31
    #
    interface Ten-GigabitEthernet2/0/38
     port link-mode bridge
     
     port access vlan 12
     broadcast-suppression pps 100
     port link-aggregation group 32
    #
    interface Ten-GigabitEthernet2/0/39
     port link-mode bridge
     
     port access vlan 12
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet2/0/40
     port link-mode bridge
     
     port access vlan 12
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet2/0/41
     port link-mode bridge
     port access vlan 12
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet2/0/42
     port link-mode bridge
     port access vlan 12
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet2/0/43
     port link-mode bridge
     port access vlan 12
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet2/0/44
     port link-mode bridge
     port access vlan 12
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet2/0/45
     port link-mode bridge
     port link-type trunk
     undo port trunk permit vlan 1
     port trunk permit vlan 12
     port trunk pvid vlan 12
     broadcast-suppression pps 100
    #
    interface Ten-GigabitEthernet2/0/46
     port link-mode bridge
     port access vlan 12
     shutdown
    #
    interface Ten-GigabitEthernet2/0/47
     port link-mode bridge
     description MAD_LINK
     port access vlan 4094
     duplex full
     undo stp enable
     stp edged-port
    #
    interface Ten-GigabitEthernet2/0/48
     port link-mode bridge
     description MAD_LINK
     port access vlan 4094
     duplex full
     undo stp enable
     stp edged-port
    #
     scheduler logfile size 16
    #
    line class aux
     user-role network-admin
    #
    line class vty
     user-role network-operator
    #
    line aux 0 1
     user-role network-admin
    #
    line vty 0 15
     authentication-mode scheme
     user-role network-operator
     protocol inbound ssh
    #
    line vty 16 63
     user-role network-operator
    #
     ssh server enable
     undo ssh server compatible-ssh1x enable
     ssh user admin service-type stelnet authentication-type password
    #
     ntp-service enable
     ntp-service source M-GigabitEthernet0/0/0
     ntp-service unicast-peer 192.168.21.51
     ntp-service unicast-peer 192.168.20.51
     ntp-service unicast-server 192.168.21.51
     ntp-service unicast-server 192.168.20.51
    #
     header motd %
    *****************************************************************************
    *                        UNAUTHORISED ACCESS PROHIBITED                     *
    * This system is for the use of authorised users only. Individuals using    *
    * this computer system without authority, or in excess of their authority,  *
    * are subject to having all of their activities on this system monitored and*
    * recorded by system personnel.                                             *
    *                                                                           *
    * In the course of monitoring individuals improperly using this system, or  *
    * in the course of system maintenance, the activities of authorised users   *
    * may also be monitored.                                                    *
    *                                                                           *
    * Anyone using this system expressly consents to such monitoring and is     *
    * advised that if such monitoring reveals possible evidence of criminal     *
    * activity, system personnel may provide evidence of such monitoring to     *
    * security officials.                                                       *
    *                                                                           *
    * The above notice also applies when using this system, or parts of it, to  *
    * gain access to other systems.                                             *
    *****************************************************************************
    %
    #
    radius scheme system
     user-name-format without-domain
    #
    domain system
    #
     domain default enable system
    #
    role name level-0
     description Predefined level-0 role
    #
    role name level-1
     description Predefined level-1 role
    #
    role name level-2
     description Predefined level-2 role
    #
    role name level-3
     description Predefined level-3 role
    #
    role name level-4
     description Predefined level-4 role
    #
    role name level-5
     description Predefined level-5 role
    #
    role name level-6
     description Predefined level-6 role
    #
    role name level-7
     description Predefined level-7 role
    #
    role name level-8
     description Predefined level-8 role
    #
    role name level-9
     description Predefined level-9 role
    #
    role name level-10
     description Predefined level-10 role
    #
    role name level-11
     description Predefined level-11 role
    #
    role name level-12
     description Predefined level-12 role
    #
    role name level-13
     description Predefined level-13 role
    #
    role name level-14
     description Predefined level-14 role
    #
    user-group system
    #
    local-user admin class manage
     password hash dddd
     service-type ssh terminal
     authorization-attribute user-role network-admin
     authorization-attribute user-role network-operator
    #
    return
    <SW001>


    For the moment a trunk between the HP 5900 and Aruba 2530 is made by the BAGG 1001 and works fine.

    On each switch I've got the same vlans. BAGG1001 is mainly allowing traffic to vlan 202.

    I wanted to dedicate a port for VLAN 12 between the 2 equipments using the port Ten-GigabiEthernet 2/0/45 on the 5900 and an untagged port from my HP 2530.

    Pb is when I plug a wire, I've got no traffic and I can see in logs the message : "PVID mismatch discovered on Ten-GigabitEthernet2/0/45 (PVID 1) and HP2530 1/037 (PVID 12)


    Any idea of this behavior ?

    regards





  • 2.  RE: PVID Mismatch between HP 5900 and Aruba 2530

    EMPLOYEE
    Posted Jun 07, 2023 01:05 PM

    Hi,

    Where do you see that PVID mismatch error message - on 5900 or on 2530? Please, double-check the message, because what it says does not match the configuration of the 5900 XGE2/0/45.

    As per configuration shared the XGE 2/0/45 has PVID 12:

    interface Ten-GigabitEthernet2/0/45
     port link-mode bridge
     port link-type trunk
     undo port trunk permit vlan 1
     port trunk permit vlan 12
     port trunk pvid vlan 12
     broadcast-suppression pps 100

    So that error message is misleading. It will help if you paste it here as-is to avoid any misinterpretations. Also you need to check the configuration of PVID on the 2530's side of the link.



    ------------------------------
    Ivan Bondar
    ------------------------------



  • 3.  RE: PVID Mismatch between HP 5900 and Aruba 2530

    Posted Jun 08, 2023 05:24 AM

    Hello Ivan

    Here are the logs from the 5900:

    %Jul 15 06:12:30:411 2011 SWDRNTE001 SHELL/6/SHELL_CMD: -Line=vty0-IPAddr=10.20.12.11-User=admindr; Command is ping 10.20.12.187
    %Jul 15 06:12:07:394 2011 SWDRNTE001 LLDP/5/LLDP_PVID_INCONSISTENT: -Slot=2; PVID mismatch discovered on Ten-GigabitEthernet2/0/45 (PVID 12), with SWDRNTE002 37 (PVID 0).

    And my conf on the other switch is : 

    vlan 1
       name "DEFAULT_VLAN"
       no untagged 1/37-1/42,2/37-2/42,2/45,Trk1
       untagged 1/1-1/36,1/43-1/47,1/49-1/51,2/1-2/36,2/43-2/44,2/46-2/47,2/49-2/51
       no ip address
       ipv6 enable
       ipv6 address dhcp full
       exit
    vlan 12
       name "VLAN_MGMT"
       untagged 1/37-1/42,2/37-2/42
       ip address 10.20.12.202 255.255.255.0
       exit
    vlan 202
       name "VLAN_SRV"
       untagged Trk1
       ip address 192.168.20.202 255.255.255.0
       exit
    vlan 300
       name "VLAN_PC"
       untagged 2/45
       tagged Trk1
       no ip address
       exit

    For the moment the only traffic working between the 2 swtichs is between the BAGG 1001 (HP5900) and the trunk Trk1 (Aruba)

    For management purposes, I wanted to connect again the 2 switchs by one wire between the VLAN 12, so between the port Ten 2/0/45 (HP5900) and the 1/37 (Aruba)




  • 4.  RE: PVID Mismatch between HP 5900 and Aruba 2530

    EMPLOYEE
    Posted Jun 08, 2023 12:32 PM

    Ok, so PVID is 12 on 5900 side and 0 on the ArubaOS side. PVID 0 means that the port 37 on Aruba doesn't carry any untagged traffic and will drop any inbound untagged frames. This could be the reason why traffic from 5900 in VLAN 12 that goes out the port 2/0/45 as untagged doesn't get through. However, that state on ArubaOS switch is really strange, because from what I see in its configuration the port 37 should be untagged in VLAN 12. 

    BTW, another possible problem - you've got a working LAG (BAGG) between switches and you have another link (that troublesome link in VLAN12) between switches. While VLAN12 is present on either of those links, it's not a problem, there is no danger of a L2 loop, however I'm afraid RSTP that you seem to be using at least on 5900 doesn't know nothing about VLANs, it maintains single STP tree for ALL Vlans and from its perspective that VLAN12 link should be blocked. When you resolve issue on Aruba with PVID 0, please, check STP state of that link on both switches, as one of the sides may block its port.



    ------------------------------
    Ivan Bondar
    ------------------------------



  • 5.  RE: PVID Mismatch between HP 5900 and Aruba 2530

    Posted Jun 09, 2023 11:22 AM

    Something is wierd, because when I'm doing an show interface brief on the aruba side, the port 1/37 is PVID 12.

    The 5900 seems showing this port as PVID 0, this is not normal




  • 6.  RE: PVID Mismatch between HP 5900 and Aruba 2530

    EMPLOYEE
    Posted Jun 09, 2023 02:10 PM

    Let's reveal the truth. For that I suggest you to use debugging on the 5900:

    Open an SSH or Console session to the 5900 and execute following commands one by one:

    terminal monitor
    terminal debug
    debug lldp packet receive interface gig2/0/45 verbose
    

    Wait for a minute to get 1-2 LLDP packets from the adjacent switch and disable the debug:

    undo debugging all

    Then paste the console session's output here and we will see which device is wrong - Aruba sends out incorrect PVID or Comware incorrectly interprets the data received.



    ------------------------------
    Ivan Bondar
    ------------------------------



  • 7.  RE: PVID Mismatch between HP 5900 and Aruba 2530

    Posted Jun 12, 2023 09:36 AM

    Hi,

    Here my results:

    <SW001>debug lldp packet receive interface ten
    <SW001>debug lldp packet receive interface Ten-GigabitEthernet 2/0/45
    <SW001>*Jul 20 02:57:12:022 2011 SWDRNTE001 LLDP/7/Packet received: -Slot=2;
    Interface Ten-GigabitEthernet2/0/45 nearest-bridge; Length is 259.
     Chassis type        : MAC address
     Chassis ID          : 9460-d5f2-6a0b
     Port ID type        : Locally assigned
     Port ID             : 37
     Time to live        : 120

    *Jul 20 02:57:42:022 2011 SWDRNTE001 LLDP/7/Packet received: -Slot=2;
    Interface Ten-GigabitEthernet2/0/45 nearest-bridge; Length is 259.
     Chassis type        : MAC address
     Chassis ID          : 9460-d5f2-6a0b
     Port ID type        : Locally assigned
     Port ID             : 37
     Time to live        : 120

    *Jul 20 02:58:12:022 2011 SWDRNTE001 LLDP/7/Packet received: -Slot=2;
    Interface Ten-GigabitEthernet2/0/45 nearest-bridge; Length is 259.
     Chassis type        : MAC address
     Chassis ID          : 9460-d5f2-6a0b
     Port ID type        : Locally assigned
     Port ID             : 37
     Time to live        : 120

    *Jul 20 02:58:42:022 2011 SWDRNTE001 LLDP/7/Packet received: -Slot=2;
    Interface Ten-GigabitEthernet2/0/45 nearest-bridge; Length is 259.
     Chassis type        : MAC address
     Chassis ID          : 9460-d5f2-6a0b
     Port ID type        : Locally assigned
     Port ID             : 37
     Time to live        : 120

    *Jul 20 02:59:12:022 2011 SWDRNTE001 LLDP/7/Packet received: -Slot=2;
    Interface Ten-GigabitEthernet2/0/45 nearest-bridge; Length is 259.
     Chassis type        : MAC address
     Chassis ID          : 9460-d5f2-6a0b
     Port ID type        : Locally assigned
     Port ID             : 37
     Time to live        : 120

    *Jul 20 02:59:42:022 2011 SWDRNTE001 LLDP/7/Packet received: -Slot=2;
    Interface Ten-GigabitEthernet2/0/45 nearest-bridge; Length is 259.
     Chassis type        : MAC address
     Chassis ID          : 9460-d5f2-6a0b
     Port ID type        : Locally assigned
     Port ID             : 37
     Time to live        : 120

    *Jul 20 03:00:12:022 2011 SWDRNTE001 LLDP/7/Packet received: -Slot=2;
    Interface Ten-GigabitEthernet2/0/45 nearest-bridge; Length is 259.
     Chassis type        : MAC address
     Chassis ID          : 9460-d5f2-6a0b
     Port ID type        : Locally assigned
     Port ID             : 37
     Time to live        : 120

    *Jul 20 03:00:42:022 2011 SWDRNTE001 LLDP/7/Packet received: -Slot=2;
    Interface Ten-GigabitEthernet2/0/45 nearest-bridge; Length is 259.
     Chassis type        : MAC address
     Chassis ID          : 9460-d5f2-6a0b
     Port ID type        : Locally assigned
     Port ID             : 37
     Time to live        : 120

    Here is my spanning tree display result :

    <SW001>display stp brief
     MST ID   Port                                Role  STP State   Protection
     0        Bridge-Aggregation21                DESI  FORWARDING  NONE
     0        Bridge-Aggregation31                DESI  FORWARDING  NONE
     0        Bridge-Aggregation1001              ROOT  FORWARDING  NONE
     0        Ten-GigabitEthernet1/0/1            DESI  FORWARDING  NONE
     0        Ten-GigabitEthernet1/0/17           DESI  FORWARDING  NONE
     0        Ten-GigabitEthernet1/0/40           DESI  FORWARDING  NONE
     0        Ten-GigabitEthernet1/0/41           DESI  FORWARDING  NONE
     0        Ten-GigabitEthernet1/0/42           DESI  FORWARDING  NONE
     0        Ten-GigabitEthernet1/0/43           DESI  FORWARDING  NONE
     0        Ten-GigabitEthernet1/0/44           DESI  FORWARDING  NONE
     0        Ten-GigabitEthernet2/0/1            DESI  FORWARDING  NONE
     0        Ten-GigabitEthernet2/0/17           DESI  FORWARDING  NONE
     0        Ten-GigabitEthernet2/0/39           DESI  FORWARDING  NONE
     0        Ten-GigabitEthernet2/0/40           DESI  FORWARDING  NONE
     0        Ten-GigabitEthernet2/0/41           DESI  FORWARDING  NONE
     0        Ten-GigabitEthernet2/0/43           DESI  FORWARDING  NONE
     0        Ten-GigabitEthernet2/0/44           DESI  FORWARDING  NONE
     0        Ten-GigabitEthernet2/0/45           ALTE  DISCARDING  NONE





  • 8.  RE: PVID Mismatch between HP 5900 and Aruba 2530

    EMPLOYEE
    Posted Jun 12, 2023 09:52 AM

    Yes, you have two issues:

    1. Aruba doesn't send any PVID attribute in LLDP, that's why Comware assumes it is '0'. It is a cosmetic issue and doesn't affect any traffic forwarding. You can just disable LLDP on the Comware port, I think it should help. Maybe newer Aruba s/w version include proper PVID to the LLDP PDUs, I am not sure as I don't have much of experience with PVOS (AOS) devices. 
    2. STP blocks the redundant path, which is expected for the STP protocols that keep one topology for all VLANs. Solutions can be many - tweak MSTP instances, use PVST or disable STP on that link completely.


    ------------------------------
    Ivan Bondar
    ------------------------------



  • 9.  RE: PVID Mismatch between HP 5900 and Aruba 2530

    EMPLOYEE
    Posted Jun 12, 2023 10:00 AM

    Ok, I've found a better solution for LLDP instead of disabling it on the port:



    ------------------------------
    Ivan Bondar
    ------------------------------



  • 10.  RE: PVID Mismatch between HP 5900 and Aruba 2530

    Posted Jun 12, 2023 11:24 AM

    Not better, i've still have the STP discarding the port Ten 2/0/45.

     I think this is because we already have the 2 ports from Trk1 connected to the BAGG 1001.

    Best solution should to tag the vlan 12 in the bagg as well, and let the port 1/37 untagged in the vlan 12, it should be better isn't it ?




  • 11.  RE: PVID Mismatch between HP 5900 and Aruba 2530

    EMPLOYEE
    Posted Jun 12, 2023 02:57 PM

    "lldp ignore-pvid inconsistency" is the solution for the messages like this one:

    %Jul 15 06:12:07:394 2011 SWDRNTE001 LLDP/5/LLDP_PVID_INCONSISTENT: -Slot=2; PVID mismatch discovered on Ten-GigabitEthernet2/0/45 (PVID 12), with SWDRNTE002 37 (PVID 0).

    And it is better than disabling LLDP on the port XGE2/0/45, that's what I mean.

    As I said, you have two independent issues - LLDP alarms on the 5900 (we know how to solve it) and STP block of the additional link between switches.

    "Best solution should to tag the vlan 12 in the bagg as well, and let the port 1/37 untagged in the vlan 12, it should be better isn't it ?" Yes, you can do it and it will even work, though I can't get the purpose of that backup link 1/37<->2/0/45. Keep it blocked until Trk1 is up and activate it only when it goes down? Ok, why not, but why just don't add this link to the BAGG/Trk if you don't have anything against running VLAN12 over the Trk1? Somehow I can't see the purpose of that link...



    ------------------------------
    Ivan Bondar
    ------------------------------