<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: BDPU/Spanning Tree issue in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/BDPU-Spanning-Tree-issue/m-p/95498#M18807</link>
    <description>&lt;P&gt;There is no virtual switch involved.&amp;nbsp; This is just a single 10gb connection assigned to the VS setup as a trunk.&amp;nbsp; It is directly hooked up to a Cisco 9K.&lt;/P&gt;</description>
    <pubDate>Fri, 28 Aug 2020 12:21:24 GMT</pubDate>
    <dc:creator>Bill_Ng</dc:creator>
    <dc:date>2020-08-28T12:21:24Z</dc:date>
    <item>
      <title>BDPU/Spanning Tree issue</title>
      <link>https://community.checkpoint.com/t5/General-Topics/BDPU-Spanning-Tree-issue/m-p/95398#M18798</link>
      <description>&lt;P&gt;All,&lt;/P&gt;&lt;P&gt;We are running into an issue where our Cisco switch port goes into err-disable due to BPDU guard.&amp;nbsp; It only happens on this one port which is a trunk.&amp;nbsp; This is a VSX FW cluster running multiple VSs.&amp;nbsp; It only happens to one particular VS instance.&amp;nbsp; We also are running VMACs as well on the cluster.&amp;nbsp; This seems to occur at random times and between the active and standby nodes.&amp;nbsp; &amp;nbsp; eth1-04 is the interface in questions.&amp;nbsp; It is a 10gb connection.&lt;/P&gt;&lt;P&gt;Sync UP sync(secured), broadcast&lt;BR /&gt;eth1-03 UP non sync(non secured), multicast&lt;BR /&gt;eth2-08 UP non sync(non secured), multicast&lt;BR /&gt;eth1-04 UP non sync(non secured), multicast (eth1-04.112)&lt;/P&gt;&lt;P&gt;Any ideas/help on trying to troubleshoot this from a FW perspective?&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Bill&lt;/P&gt;</description>
      <pubDate>Thu, 27 Aug 2020 14:10:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/BDPU-Spanning-Tree-issue/m-p/95398#M18798</guid>
      <dc:creator>Bill_Ng</dc:creator>
      <dc:date>2020-08-27T14:10:10Z</dc:date>
    </item>
    <item>
      <title>Re: BDPU/Spanning Tree issue</title>
      <link>https://community.checkpoint.com/t5/General-Topics/BDPU-Spanning-Tree-issue/m-p/95448#M18803</link>
      <description>&lt;P&gt;Is there a virtual switch between the VS and the cisco switch or is it just a virtual firewall connected to that vlan interface? I'm a bit rusty on VSX FYI.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Aug 2020 22:21:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/BDPU-Spanning-Tree-issue/m-p/95448#M18803</guid>
      <dc:creator>John_Fleming</dc:creator>
      <dc:date>2020-08-27T22:21:22Z</dc:date>
    </item>
    <item>
      <title>Re: BDPU/Spanning Tree issue</title>
      <link>https://community.checkpoint.com/t5/General-Topics/BDPU-Spanning-Tree-issue/m-p/95498#M18807</link>
      <description>&lt;P&gt;There is no virtual switch involved.&amp;nbsp; This is just a single 10gb connection assigned to the VS setup as a trunk.&amp;nbsp; It is directly hooked up to a Cisco 9K.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Aug 2020 12:21:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/BDPU-Spanning-Tree-issue/m-p/95498#M18807</guid>
      <dc:creator>Bill_Ng</dc:creator>
      <dc:date>2020-08-28T12:21:24Z</dc:date>
    </item>
    <item>
      <title>Re: BDPU/Spanning Tree issue</title>
      <link>https://community.checkpoint.com/t5/General-Topics/BDPU-Spanning-Tree-issue/m-p/126893#M23274</link>
      <description>&lt;P&gt;Hi Bill,&lt;/P&gt;&lt;P&gt;Did you manage to solve this issue, i was wondering if you did because we have this problem also and are a bit in the dark why this is happening. :S&lt;/P&gt;</description>
      <pubDate>Fri, 13 Aug 2021 06:30:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/BDPU-Spanning-Tree-issue/m-p/126893#M23274</guid>
      <dc:creator>Gertjan</dc:creator>
      <dc:date>2021-08-13T06:30:11Z</dc:date>
    </item>
    <item>
      <title>Re: BDPU/Spanning Tree issue</title>
      <link>https://community.checkpoint.com/t5/General-Topics/BDPU-Spanning-Tree-issue/m-p/215669#M35660</link>
      <description>&lt;P&gt;I'm running into the same issue as well, haven't yet found a concludent solution.&lt;/P&gt;</description>
      <pubDate>Thu, 30 May 2024 11:49:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/BDPU-Spanning-Tree-issue/m-p/215669#M35660</guid>
      <dc:creator>Daniel_Cimpeanu</dc:creator>
      <dc:date>2024-05-30T11:49:10Z</dc:date>
    </item>
    <item>
      <title>Re: BDPU/Spanning Tree issue</title>
      <link>https://community.checkpoint.com/t5/General-Topics/BDPU-Spanning-Tree-issue/m-p/216069#M35854</link>
      <description>&lt;P&gt;Not to be trite, but BPDU guard &amp;nbsp;means the switch is seeing a spanning-tree BPDU come in on a port where none is expected. &amp;nbsp;Your switch is likely configured with "spanning-tree portfast bpduguard default". &amp;nbsp;For trunk ports, you may also have "spanning-tree portfast trunk", unless you have bpduguard per-port.&lt;/P&gt;
&lt;P&gt;Are you seeing BPDUguard on ALL VLANs of the trunk port, or just certain VLANs? &amp;nbsp;This would help you determine the exact cause:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;show spann int TeX/Y/Z&lt;/LI-CODE&gt;
&lt;P&gt;Are you running VS in active-active bridge mode? &amp;nbsp; This will emit 802.1d frames. &amp;nbsp;VMACs won't cause BPDUguard, tho.&lt;/P&gt;
&lt;P&gt;You can see details of spanning-tree on the port with "show spann int TeX/Y/Z details" to get some idea of what's coming into the port. &amp;nbsp;If you have a port-channel, and you're only seeing BPDUguard on a single port of the bundle, then you have a port configuration mismatch.&lt;/P&gt;
&lt;P&gt;If, for some reason you NEED to have BPDUs through this port, you can still allow them but not allow a lower priority BPDU:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;int TeX/Y/Z
spanning-tree bpduguard disable
spanning-tree guard root
&lt;/LI-CODE&gt;
&lt;P&gt;If you are using Active/Active Bridge mode VS, then this is the config you on your port. &amp;nbsp; Root guard will prevent your spanning tree topology from pivoting towards a new lower priority, or lower bridge ID, root bridge. &amp;nbsp;Which would be terrible&lt;/P&gt;
&lt;P&gt;You *DO* want to take care of your spanning tree topology, however. &amp;nbsp;I presume you understand STP enough to set your preferred primary and secondary root bridges on your network. &amp;nbsp; Make sure your root is where you think it is.&lt;/P&gt;
&lt;P&gt;Lemme know if you have any questions with it.&lt;/P&gt;
&lt;P&gt;Good luck!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 01 Jun 2024 15:57:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/BDPU-Spanning-Tree-issue/m-p/216069#M35854</guid>
      <dc:creator>Duane_Toler</dc:creator>
      <dc:date>2024-06-01T15:57:15Z</dc:date>
    </item>
  </channel>
</rss>

