AOS-CX Switch Simulator

 View Only
last person joined: yesterday 

Expand all | Collapse all

STP problem

This thread has been viewed 171 times
  • 1.  STP problem

    EMPLOYEE
    Posted May 10, 2021 01:15 PM
    Have tried this L2 setup with 10.06, 10.07 and on EVE-NG, GNS3 and even plain on ESXi and when it is started up CX1 becomes the root as it is configured with the priority to become root and all other ports configure themselves correctly and the setup is stable until you try to ping from VPC1 to VPC2. First ping is OK but after that a gratuitous ARP is looping around and also the STP starts converging. MAC address of VPC1 also moves from the correct port 1/1/3 to 1/1/1.  I have tried both RSTP and MSTP but same result.

    Only when I replace the CX devices with other devices (tried Aruba VMC)  in the same setup does it work correctly.



    Thanks,
    John

    ------------------------------
    John Schaap
    ------------------------------


  • 2.  RE: STP problem

    EMPLOYEE
    Posted May 11, 2021 05:06 AM
    Thanks John for sharing your experience.
    Have you compared with the Lab guide (configuration) on this Lab?  
    https://community.arubanetworks.com/community-home/digestviewer/viewthread?GroupId=565&MessageKey=bca5bc66-ab2d-46e9-b2f5-675af866d83b&CommunityKey=aa40c287-728e-4827-b062-5eff4ed6410b&tab=digestviewer&ReturnUrl=%2fcommunity-home%2fdigestviewer%3fcommunitykey%3daa40c287-728e-4827-b062-5eff4ed6410b%26tab%3ddigestviewer

    May be worth sharing your configuration so that others may take a look.

    ------------------------------
    Vincent Giles
    ------------------------------



  • 3.  RE: STP problem

    EMPLOYEE
    Posted May 11, 2021 12:14 PM
    Hi Vincent,

    Yes, I have looked at that guide and configured everything the same but no matter which STP I use it always fails when you start to ping from VPC1 to VPC2. I have use RPVST and MSTP but no difference. As I wrote when I started this thread, it works fine with a stable tree as long as you do not produce any packets on the VPC's. I do suspect something strange with the OVA's and wonder if the person that wrote the RPVST guide has send traffic from the VPC.

    CX1# sh running-config

    Current configuration:

    !

    !Version ArubaOS-CX Virtual.10.07.0004

    !export-password: default

    hostname CX1

    user admin group administrators password ciphertext AQBapU+lm+w5Mb7ijhAn7/RfIkwrRStcEZl30JFy8i50u1DRYgAAAKR7alXEKEnp0vlKYd+BIhqpEsc3V7FbhCOFIhBhOi4evIIjhbFeTRpU6ed+vCwOyc75KZ3nxe60x8zpgleQXK9LJkH5SVFyK

    w6Tegf4OoBnXoT4dvoDaQ9ffIElZZd6FEND

    led locator on

    clock timezone europe/amsterdam

    ntp server pool.ntp.org minpoll 4 maxpoll 4 iburst

    ntp enable

    !

    ssh server vrf mgmt

    vlan 1,1111-1112

    spanning-tree mode rpvst

    spanning-tree

    spanning-tree vlan 1111,1112

    spanning-tree vlan 1111 priority 1

    spanning-tree vlan 1112 priority 1

    interface mgmt                                                

        no shutdown

        ip dhcp

    interface 1/1/1

        no shutdown

        no routing

        vlan trunk native 1

        vlan trunk allowed all

    interface 1/1/2

        no shutdown

        no routing

        vlan trunk native 1

        vlan trunk allowed all

    interface 1/1/3

        no shutdown

        no routing

        vlan trunk native 1

        vlan trunk allowed all

    !

    https-server vrf mgmt                                         

    CX1#

     

    CX2# sh running-config

    Current configuration:

    !

    !Version ArubaOS-CX Virtual.10.07.0004

    !export-password: default

    hostname CX2

    user admin group administrators password ciphertext AQBapWRTU6S4p5wtMFPOT0L2t4/o3eBjA+ouCv1Derjz6Sd7YgAAAFmbHpyDpNF/QtAe2rW9TDV3VfQE0j1mLUZIwTiSStbOW2RPQH6Pj2UHf//t4CVvqBRaMn55FG96IvU2BGbCE/R51hdycfnSH

    mwv9m3sT2FtaUBi/uCJBJOAAGHjh5PZVL2x

    led locator on

    clock timezone europe/amsterdam

    ntp server pool.ntp.org minpoll 4 maxpoll 4 iburst

    ntp enable

    !

    ssh server vrf mgmt

    vlan 1,1111-1112

    spanning-tree mode rpvst

    spanning-tree

    spanning-tree vlan 1111,1112

    spanning-tree vlan 1111 priority 2

    spanning-tree vlan 1112 priority 2

    interface mgmt                                                

        no shutdown

        ip dhcp

    interface 1/1/1

        no shutdown

        no routing

        vlan trunk native 1

        vlan trunk allowed all

    interface 1/1/2

        no shutdown

        no routing

        vlan trunk native 1

        vlan trunk allowed all

    interface 1/1/3

        no shutdown

        no routing

        vlan trunk native 1

        vlan trunk allowed all

    !

    https-server vrf mgmt

     

     

    CX3# sh running-config

    Current configuration:

    !

    !Version ArubaOS-CX Virtual.10.07.0004

    !export-password: default

    hostname CX3

    user admin group administrators password ciphertext AQBapQpm5IjdsrWIIZSWk25pSosSy2lcwLJZTlpRvcrl0s2wYgAAAKYpguLVQ2FweNa1j04YDwM9qbLcyNw3/tW7DLn5iJRwOswEjWy79CwlVODkhGN3e/cgTG4fJqJx5KlUn3QhKH/LshGYLqhyi

    iNTna4puIGqKOfTKVQsfp9FwkH50sgxxNaz

    led locator on

    clock timezone europe/amsterdam

    ntp server pool.ntp.org minpoll 4 maxpoll 4 iburst

    ntp enable

    !

    ssh server vrf mgmt

    vlan 1,1111-1112

    spanning-tree mode rpvst

    spanning-tree

    spanning-tree vlan 1111,1112

    interface mgmt

        no shutdown

        ip dhcp                                                   

    interface 1/1/1

        no shutdown

        no routing

        vlan trunk native 1

        vlan trunk allowed all

    interface 1/1/2

        no shutdown

        no routing

        vlan trunk native 1

        vlan trunk allowed all

    interface 1/1/3

        no shutdown

        no routing

        vlan access 1112

        spanning-tree port-type admin-edge

    !

    https-server vrf mgmt

    CX3#

     

    CX4# sh running-config

    Current configuration:

    !

    !Version ArubaOS-CX Virtual.10.07.0004

    !export-password: default

    hostname CX4

    user admin group administrators password ciphertext AQBapS+SSAfY7a5YHxVkSKcN/ZQY45AsdXX4WFY01xX5dg+LYgAAANci0ZaRmLC7FdsfrbmWdDWkbAmNzcY3QbusWKlpEytfZTfcjY976XNXOQivdz4unQValZQG57rJ8/Vr5XhgmJzLs2AG2Pch3

    0/ay3bdcSVHJ9KOnl/5iqSiZl6OHqRLBBKx

    led locator on

    clock timezone europe/amsterdam

    ntp server pool.ntp.org minpoll 4 maxpoll 4 iburst

    ntp enable

    !

    ssh server vrf mgmt

    vlan 1,1111-1112

    spanning-tree mode rpvst

    spanning-tree

    spanning-tree vlan 1111,1112

    interface mgmt

        no shutdown

        ip dhcp                                                    

    interface 1/1/1

        no shutdown

        no routing

        vlan trunk native 1

        vlan trunk allowed all

    interface 1/1/2

        no shutdown

        no routing

        vlan trunk native 1

        vlan trunk allowed all

    interface 1/1/3

        no shutdown

        no routing

        vlan access 1112

        spanning-tree port-type admin-edge

    !

    https-server vrf mgmt

    CX4#

     

     



    ------------------------------
    John Schaap
    ------------------------------



  • 4.  RE: STP problem

    EMPLOYEE
    Posted May 12, 2021 07:55 PM
    HI John, 

    I'm seeing what could be similar behavior from the VPCS.  We'll investigate and see where the issue is.

    Justin

    ------------------------------
    Justin Noonan
    ------------------------------



  • 5.  RE: STP problem

    Posted Jan 24, 2023 06:01 PM
    Is this still a limitation of the simulator or plan to work as expected at some point?  Using latest 10.11 image for cx switch and can't pass normal traffic as expected.



  • 6.  RE: STP problem

    EMPLOYEE
    Posted Feb 21, 2023 12:27 AM

    I don't see this issue, i am using simulator version 10_10_1000



    ------------------------------
    If my post was useful accept solution and/or give kudos.
    Any opinions expressed here are solely my own and not necessarily that of HPE or Aruba.
    ------------------------------



  • 7.  RE: STP problem

    Posted Feb 22, 2023 02:39 AM

    Hi ariyap

    I jumped right to testing. And I'm running my test in EVE-NG Pro with 3 devices on 10.10.1000.

    Spanning tree is still broken when I'm testing. The problem is packets are transmitted out on interfaces in blocking state.

    Are you sure you have a loop free topology and packets are discarded out on interfaces in blocking?

    Which hypervisor are you using?



    ------------------------------
    Arne Opdal
    ------------------------------



  • 8.  RE: STP problem

    MVP EXPERT
    Posted Feb 22, 2023 09:24 AM

    Testing latest 10.11.xx.xx version with EVE-NG aswell pnetlab and having the same issues John described. After the first ping from a vPC the gracious arp packages are looped. When not using vPCs but connect switches in a ring-topology i don't had this issue.



    ------------------------------
    Marcel Koedijk | MVP Expert 2022 | ACEP | ACMP | ACCP | ACDP | Ekahau ECSE | Not an HPE Employee | Opinions are my own
    ------------------------------



  • 9.  RE: STP problem

    Posted Mar 10, 2023 11:02 AM

    I've been fighting this problem for two weeks with 10.10 and 10.11 CX switches on EVE.

    I thought I was missing something stupid.  Glad to know that's not the case.  

    I'm trying to follow the labs in the ASCA study guide and they're all build up from this starting point.

    Very frustrating.




  • 10.  RE: STP problem

    EMPLOYEE
    Posted Mar 14, 2023 05:44 AM

    STP cannot be tested normally, even the simplest 3 switches loop will have problems. Test version 10.11. eve-ng version 5.0.1-10-Community




  • 11.  RE: STP problem

    Posted Mar 17, 2023 03:28 AM

    I'm testing spanning-tree in the simulator without using any traffic. The protocol and states etc. looks correct so for verifying your configurations and learning the protocols is possible, but keep in mind the simulator sends out packets on interfaces in blocking.

    Using the simulator to verify configuration changes before implementing it in production could be smart. Just don't try to send traffic ;-)

    I'm using the simulator to verify my Ansible playbooks etc and I think it's a lot of good ways to use the simulator, also for STP verification.



    ------------------------------
    Arne Opdal
    ------------------------------



  • 12.  RE: STP problem

    Posted Apr 26, 2023 05:43 PM

    Confirmed to be an issue on 10.11.xxx as well, really hoping this gets a solution at some point to properly test STP.




  • 13.  RE: STP problem

    Posted Feb 28, 2024 04:18 PM

    same problem. it was driving me crazy. Waiting for it to be solved soon