Bridging + VLANS + RSTP / MSTP

kevin k at kevinkevin.com
Tue Feb 22 12:20:47 UTC 2011


>There is a also the caveat:  The switch will probably _not_ forward the STP
BPDU's from one port to another. 

You were correct -- my initial testing confirmed this. Would the same issue
arise if I employed a gateway IP on the /bridge/ instead, and used CARP as a
failover mechanism? The firewall no longer becomes transparent pass
through/firewall. I have not done carp with bridges and I'm not 100% certain
the same STP forwarding problems wouldn't arise, even with an IP assigned.

Such as :

[switch 1 (vlan 1)]
   |       |
 [fw1 gw1] -- CARP -- [fw2 gw1]
   |       |
[switch 1 (vlan 2)]


Thanks,

Kevin




More information about the freebsd-net mailing list