STP Guard Setting

OmarMunir
Conversationalist

STP Guard Setting

Hi everyone,

 

Below is a topology that Im working on and that site is having some issues related to DHCP, on the router everything looks good, we can ping to and from DHCP but we keep getting these errors:
'Client made a request to the DHCP server, but it did not respond.'

I wanted to reconfirm port settings for the basement switch. 

Basement switch is connected tot he router running DHCP and forwarding to other two switches. What STP setting should the the ports on the basement switch connected to the other two switches? Any other suggestions are most welcome!

Capture.PNG

6 Replies 6
ww
Kind of a big deal
Kind of a big deal

Loop guard it typically not used on designated ports.

 

OmarMunir
Conversationalist

So STP should be disabled on those two ports?

ww
Kind of a big deal
Kind of a big deal

No i would keep stp  running.

And force the basement switch to be root https://documentation.meraki.com/MS/Port_and_VLAN_Configuration/Configuring_Spanning_Tree_on_Meraki_...

 

 

OmarMunir
Conversationalist

So I have to select one of the 3 options there, Loop, BPDU or Root. I didn't think it would be BPDU, so Root guard?

ww
Kind of a big deal
Kind of a big deal

RSTP should be enabled.

STP Guard is optional. If you forced basement to root. Then you could use the root guard (only on the basement switch ports).

GIdenJoe
Kind of a big deal
Kind of a big deal

The basement switch should obviously be the root of your STP topology.
The downstream ports from basement to the other switches should be configured as trunks and as a best practice you should enable root guard to prevent some other downstream switch from claiming root and changing your STP topology.

 

The ports on the downstream switches that connect to the basement switch should actually have loop guard however Meraki won't let you do that because those links will be the uplinks towards dashboard.  So no STP guard for uplink ports then.

 

STP doesn't really do anything to block DHCP specifically so there might be another issue going on in your network.

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels