UDLD needs to be enabled globally and will take effect on all full-duplex fiber interfaces. You need not worry about this affecting a neighbor switch without UDLD because until a UDLD neighbor is first formed there is no impact on the interface.
Loop-Guard does NOT need to be enabled globally and can be turned on per-interface. In fact, this is the safest way to do it. Only enable loop-guard on Root and Alternate ports. Do not enable loop-gurad on Designated ports. Loop-guard is a local setting and does not require interaction with a neighbor for its operation. Loop-guard simply says, 'If I stop receiving BPDUs on this port, put this port in loop-inconsistent state, do not transition to forwarding.'
If you are having Spanning-Tree problems, in addition to UDLD and Loop-Guard, you should make sure you have PortFast BPDU-Guard enabled globally on all switches with portfast ports.
Most Spanning-Tree loops are created in the access layer when a well intentioned user patches two switches together on portfast ports, or patches a hub to the network with two ports. Portfast and BPDU-Guard will protect you from this.
Also, consider Root-Guard. This will protect the integrity of your Spanning-Tree Root Bridge. If a new switch is mistakenly added to the network with a lower priority Root-Guard will prevent it from becoming a root bridge. Root-Guard simply says, 'If I receive a superior BPDU on this interface put it in root-inconsistent state rather than treating it as a new Root port.' Only enable Root-Guard on Designated ports at the Root bridge.
You should also double-check that all VLANs show the Root bridge to be what you expect it to be. Sometimes people add new VLANs to their LAN and forget to assign root priorities.
Hi everyone, I would like to thank you in advance for any help you can provide a newcomer like myself!
Im studying the 100-105 book by Odom and am currently on the topic of Port security. I purchased a used 2960 and I'm trying to follow a...
While deploying a number of 18xx/2802/3802 model access points (APs), which run AP-COS as their operating platform. It can be observed on some occasions that while many of their access points were able to join the fabric WLC withou...
I am going to design and build an LAN network under a tunnel underground with long distance between the switches.
I will have 2 Catalyst switches and 8 Industrial IE3000, and they will be connected with fiber.
For now I am planning on use Layer-2 s...