HP 6125G HP 6125G & 6125G/XG Blade Switches Layer 2 - LAN Switching Co - Page 88

Configuring Digest Snooping, Configuration restrictions and guidelines, Configuration procedure

Page 88 highlights

NOTE: An mCheck operation takes effect on a device that operates in MSTP or RSTP mode. Configuring Digest Snooping As defined in IEEE 802.1s, connected devices are in the same region only when their MST region-related configurations (region name, revision level, and VLAN-to-instance mappings) are identical. A spanning tree device identifies devices in the same MST region by determining the configuration ID in BPDU packets. The configuration ID includes the region name, revision level, and configuration digest, which is in 16-byte length and is the result calculated via the HMAC-MD5 algorithm based on VLAN-to-instance mappings. Spanning tree implementations vary with vendors, and the configuration digests calculated using private keys is different, so devices of different vendors in the same MST region cannot communicate with each other. To enable communication between an HP device and a third-party device, enable the Digest Snooping feature on the port that connects the HP device to the third-party device in the same MST region. Configuration restrictions and guidelines • Before you enable Digest Snooping, make sure that associated devices of different vendors are connected and run spanning tree protocols. • With digest snooping enabled, in-the-same-region verification does not require comparison of configuration digest, so the VLAN-to-instance mappings must be the same on associated ports. • With global Digest Snooping enabled, modification of VLAN-to-instance mappings and removal of the current region configuration via the undo stp region-configuration command are not allowed. You can modify only the region name and revision level. • To make Digest Snooping take effect, you must enable it both globally and on associated ports. To make the configuration effective on all configured ports and while reducing impact on the network, enable Digest Snooping on all associated ports first and then globally. • To prevent loops, do not enable Digest Snooping on MST region edge ports. • HP recommends you to enable Digest Snooping first and then the spanning tree feature. To avoid causing traffic interruption, do not configure Digest Snooping when the network is already working well. Configuration procedure You can enable Digest Snooping only on the HP device that is connected to a third-party device that uses its private key to calculate the configuration digest. To configure Digest Snooping: Step 1. Enter system view. Command system-view Remarks N/A 79

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231

79
NOTE:
An mCheck operation takes effect on a device that operates in MSTP or RSTP mode.
Configuring Digest Snooping
As defined in IEEE 802.1s, connected devices are in the same region only when their MST region-related
configurations (region name, revision level, and VLAN-to-instance mappings) are identical. A spanning
tree device identifies devices in the same MST region by determining the configuration ID in BPDU
packets. The configuration ID includes the region name, revision level, and configuration digest, which is
in 16-byte length and is the result calculated via the HMAC-MD5 algorithm based on VLAN-to-instance
mappings.
Spanning tree implementations vary with vendors, and the configuration digests calculated using private
keys is different, so devices of different vendors in the same MST region cannot communicate with each
other.
To enable communication between an HP device and a third-party device, enable the Digest Snooping
feature on the port that connects the HP device to the third-party device in the same MST region.
Configuration restrictions and guidelines
Before you enable Digest Snooping, make sure that associated devices of different vendors are
connected and run spanning tree protocols.
With digest snooping enabled, in-the-same-region verification does not require comparison of
configuration digest, so the VLAN-to-instance mappings must be the same on associated ports.
With global Digest Snooping enabled, modification of VLAN-to-instance mappings and removal of
the current region configuration via the
undo stp region-configuration
command are not allowed.
You can modify only the region name and revision level.
To make Digest Snooping take effect, you must enable it both globally and on associated ports. To
make the configuration effective on all configured ports and while reducing impact on the network,
enable Digest Snooping on all associated ports first and then globally.
To prevent loops, do not enable Digest Snooping on MST region edge ports.
HP recommends you to enable Digest Snooping first and then the spanning tree feature. To avoid
causing traffic interruption, do not configure Digest Snooping when the network is already working
well.
Configuration procedure
You can enable Digest Snooping only on the HP device that is connected to a third-party device that uses
its private key to calculate the configuration digest.
To configure Digest Snooping:
Step
Command
Remarks
1.
Enter system view.
system-view
N/A