A method and device for boundary protection based on bidirectional interactive spanning tree protocol.

By setting a root protection policy at the domain boundary port of the access device and sending back STP response messages, the problem of network-wide recalculation caused by private network user expansion is solved, topology damage is prevented, the cause of the fault is identified, and the user experience and fault location efficiency of the private network are improved.

CN122137777APending Publication Date: 2026-06-02NEW H3C TECH CO LTD

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
NEW H3C TECH CO LTD
Filing Date
2026-03-23
Publication Date
2026-06-02

AI Technical Summary

Technical Problem

In public networks based on the Multiple Spanning Tree Protocol (MSTP), the expansion of private network users can trigger a network-wide recalculation of high-priority STP packets, leading to changes in blocked ports and refreshes of media access control entries. This can result in severe packet loss or even paralysis of the public network. Existing protection mechanisms cannot accurately pinpoint the cause of the fault, impacting the user experience of private networks and increasing the difficulty of fault location.

Method used

By identifying the domain boundary port of the access device as the root protection policy, setting the root protection blocking state, and sending back an STP response message carrying the valid root identifier and the maximum abnormal root path cost, the root migration is prevented, ensuring the normal link layer connection. The access device performs root protection processing based on the returned message.

Benefits of technology

To prevent high-priority STP packets from private networks from damaging the public topology, to clearly identify the cause of the fault and provide feedback to private network users, to reduce the difficulty of fault location, and to improve the user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122137777A_ABST
    Figure CN122137777A_ABST
Patent Text Reader

Abstract

This application provides a method and apparatus for bidirectional interactive Spanning Tree Protocol (STP) boundary protection. In this method, a handover device across multiple STP domains identifies the protection policy of the domain boundary port of a received STP message as a root protection policy; determines that the root bridge priority of the STP message is higher than the overall root bridge priority of the MSTP domain to which the device belongs; sets a root protection blocking state for the domain boundary port while maintaining normal link-layer connectivity; and sends back an STP response message through the domain boundary port. The STP response message carries a specified valid root identifier and the maximum abnormal root path cost. This enables the device receiving the STP response message to perform root protection processing based on the maximum abnormal root path cost, thereby preventing root migration.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to communication technology, specifically a method and device for bidirectional interactive spanning tree protocol boundary protection. Background Technology

[0002] In public networks based on the Multiple Spanning Tree Protocol (MSTP), as user capacity expands, private network users often extend ports through access devices. Some access devices support the Spanning Tree Protocol (STP). If the bridge priority they send is higher than the MSTP domain root bridge, it will trigger a network-wide recalculation within the domain, leading to root bridge migration, changes in blocking ports, and updates to Media Access Control (MAC) and Address Resolution Protocol (ARP) entries, causing severe packet loss or even network paralysis in the public network.

[0003] To mitigate this risk, administrators typically configure protection mechanisms on the boundary port: one is BPDU (Bridge Protocol Data Unit) protection, which means that the boundary port automatically shuts down when it receives an STP message; the other is root guard, which forces the port to enter a blocking state when it receives a high-priority message, preventing the message from propagating into the domain.

[0004] However, the existing solution has significant drawbacks. Private network users do not have permission to perceive public network configurations, and may misjudge network connectivity failures on open edge ports as physical link (such as cable, optical module) failures, thus failing to locate STP logical forwarding blocking triggered by the MSTP domain boundary device on the other end.

[0005] Therefore, while ensuring the stability of public networks, it causes connectivity failures for private network users, reduces the user experience of private network users, and increases the difficulty of locating private network failures. Summary of the Invention

[0006] The purpose of this application is to provide a method and device for spanning tree protocol boundary protection based on bidirectional interaction, which notifies the access device of STP logical forwarding blocking triggered by MSTP domain boundary protection at a remote end.

[0007] To achieve the above objectives, this application provides a method for Spanning Tree Protocol (STP) boundary protection based on bidirectional interaction. The method includes: identifying the protection policy of the first domain boundary port of a received first STP message as a root protection policy; determining that the root bridge priority of the first STP message is higher than the total root bridge priority of the MSTP domain to which the device belongs; setting a root protection blocking state for the first domain boundary port while maintaining normal link-layer connectivity; and sending back a first STP response message through the first domain boundary port; wherein the first STP response message carries a first designated valid root identifier and the maximum abnormal root path cost; and causing the device receiving the first STP response message to perform root protection processing based on the maximum abnormal root path cost, thereby preventing root migration.

[0008] To achieve the above objectives, this application provides a device for bidirectional interactive Spanning Tree Protocol (STP) boundary protection. The device includes a processor, a machine-readable storage medium, an application-specific integrated circuit (ASIC), and a network interface. The processor executes machine-executable instructions recorded on the machine-readable storage medium to perform the following operations: identifying the protection policy of the first domain boundary port of the received first STP message as a root protection policy; determining that the root bridge priority of the first STP message is higher than the total root bridge priority of the MSTP domain to which the device belongs; setting a root protection blocking state for the first domain boundary port while maintaining normal link-layer connectivity; and sending back a first STP response message through the first domain boundary port. The first STP response message carries a first designated valid root identifier and the maximum abnormal root path cost. This causes the device receiving the first STP response message to perform root protection processing based on the maximum abnormal root path cost, thereby preventing root migration.

[0009] To achieve the above objectives, this application provides a method for Spanning Tree Protocol (STP) boundary protection based on bidirectional interaction, applied to access devices in an STP domain. The method includes: sending STP protocol messages through an edge port; wherein the root bridge priority in the STP protocol messages is configured as the highest allowed priority for each VLAN to which the edge port belongs; receiving STP response messages through the edge port; wherein the STP response messages carry a valid root identifier and the maximum root path cost; and performing loop detection within each VLAN to which the edge port belongs.

[0010] To achieve the above objectives, this application provides a device for bidirectional interactive Spanning Tree Protocol (STP) boundary protection. This device is applied to access devices in an STP domain and includes a processor, a machine-readable storage medium, an application-specific integrated circuit (ASIC), and a network interface. The processor executes machine-executable instructions recorded on the machine-readable storage medium. The operations performed include sending STP protocol messages through an edge port; wherein the root bridge priority in the STP protocol message is configured as the highest allowed priority for each VLAN belonging to the edge port; receiving STP response messages through the edge port; wherein the STP response message carries a valid root identifier and the maximum root path cost; and performing loop detection within each VLAN belonging to the edge port.

[0011] The beneficial effects of this application are that it can prevent high-priority STP packets in private networks from damaging the public topology, and can clearly report the cause of the fault to the access devices in private networks, thereby improving the user experience in private networks and reducing the difficulty of fault location when remote MSTP domain boundary protection triggers STP logical forwarding blocking. Attached Figure Description

[0012] Figure 1 A flowchart illustrating an embodiment of a bidirectional interactive spanning tree protocol boundary protection method provided in this application; Figure 2 This is a schematic diagram of a two-domain spanning tree network provided in an embodiment of this application; Figure 3 A schematic diagram of an embodiment of the spanning tree protocol boundary protection device based on bidirectional interaction provided in this application; Figure 4 This is a schematic diagram of another embodiment of the spanning tree protocol boundary protection device based on bidirectional interaction provided in this application. Detailed Implementation

[0013] The following detailed description will be provided with reference to several examples illustrated in the accompanying figures. In this detailed description, numerous specific details are used to provide a comprehensive understanding of the present application. Known methods, steps, components, and circuits are not described in detail in the examples to avoid obscuring their meaning.

[0014] In the terminology used, the term "including" means including but not limited to; the term "containing" means including but not limited to; the terms "above," "within," and "below" include the number itself; the terms "greater than" and "less than" mean not including the number itself. The term "based on" means based on at least a portion of them.

[0015] Figure 1 The flowchart shown here, illustrating an embodiment of a spanning tree protocol boundary protection method based on bidirectional interaction provided in this application, includes the following steps: Step 101: Identify the protection policy of the domain boundary port of the received Spanning Tree Protocol (STP) message as the root protection policy; Step 102: Determine that the root bridge priority of the STP message is higher than the total root bridge priority of the MSTP domain to which this device belongs; Step 103: Set the root protection blocking state for the domain boundary port while maintaining normal link layer connectivity; Step 104: Send back an STP response message through the domain boundary port; the STP response message carries the first designated valid root identifier and the maximum abnormal root path cost; so that the device receiving the STP response message performs root protection processing based on the maximum abnormal root path cost, thereby preventing root migration.

[0016] Figure 1 The beneficial effects of this embodiment are that it can prevent high-priority STP packets in the private network from damaging the public topology, clearly identify the cause of the fault to be reported to the access device in the private network, improve the user experience in the private network, and reduce the difficulty of fault location when the remote MSTP domain boundary protection triggers STP logical forwarding blocking. Figure 2 This is a schematic diagram of a two-domain spanning tree network provided in an embodiment of this application.

[0017] Figure 2 In the private network, the edge port P11 of STP instance 1 access device 1 is connected to the domain boundary port P31 of the MSTP domain switching device 3, and the edge interface P21 of STP instance 2 access device 2 in the private network is connected to the domain boundary port P32 of the switching device 3 via the STP pass-through device.

[0018] On switching device 3, the domain boundary port P31 directly connected to device 1 is configured with BPDU Protection; the domain boundary port P32 directly connected to the STP pass-through device is configured with Root Guard; STP anomaly notification is enabled on both domain boundary ports P31 and P32.

[0019] When access device 1 sends an STP protocol message and the BridgePriority field of the STP protocol message carries the highest allowed priority for each VLAN belonging to edge interface P11.

[0020] After receiving the STP message from access device 1, the domain boundary port P31 of switching device 3 sets the domain boundary port P31 to the domain boundary port blocking state to maintain the normal link layer connection, thereby blocking the data forwarding within all VLANs.

[0021] Switching device 3 replaces the BridgePriority field and the root bridge MAC field in the Root Identifier of the STP message from access device 1 with the current total root device priority and total root bridge MAC address 3 of this device, sets the Root Path Cost field to the maximum value FF FF FF FE, and uses the MAC address MAC 31 of the domain boundary port P31 as the source MAC address to send back the STP message to access device 31.

[0022] In this application, the switching device 3 informs the access device 1 of the MAC address of the root bridge in the MSTP domain and that the root bridge is unreachable by modifying the Root Identifier in the STP message from the access device 1.

[0023] After receiving the STP message returned by the switching device 3, access device 1 can print an alarm log to remind private network users.

[0024] Access device 1 enables loop detection for each VLAN belonging to edge port P11, and globally enables loop detection by disabling it, which means that the port where a loop is detected is shut down, thereby shutting down the physical link.

[0025] When access device 1 detects a loop in any of the VLANs belonging to edge port P11, it shuts down edge port P1.

[0026] Access device 1 sends an STP error response message through edge port P11; the BridgePriority field of Root Identifier, the MAC address field of the root bridge device, and the Root Path Cost are all filled with F.

[0027] Access device 1 sets the Root Identifier field (including the BridgePriority field and the root bridge device MAC address field) of the STP abnormal response message to all F, that is, it notifies access device 1 that its root bridge ID is greater than the root bridge ID of switching device 3, so that switching device 3 knows that the root bridge is unreachable.

[0028] Access device 1 disables STP on edge port P11, preventing edge port P11 from participating in STP protocol calculations.

[0029] Switching device 3 receives an STP abnormal response message from the access device through the domain boundary port P31, removes the edge port protection blocking state, and restores the forwarding state.

[0030] In one example, if access device 1 does not send an STP error response message, switching device 3 determines that the domain boundary port P31 received an STP message from access device 1 for a preset time, cancels the edge port protection blocking state of domain boundary port P31, and restores the forwarding state of domain boundary port P31.

[0031] When access device 2 sends an STP protocol message and the Bridge Priority field of the STP protocol message carries the highest allowed priority for each VLAN belonging to edge interface P21.

[0032] The STP pass-through device sends the STP protocol from access device 2 to the domain boundary port P32 of switching device 3.

[0033] After receiving the STP message from access device 2, the domain boundary port P32 of switching device 3 sets the domain boundary port P32 to root protection blocking state to maintain normal link layer connection, thereby blocking data forwarding within all VLANs.

[0034] Switching device 3 replaces the BridgePriority field and the root bridge MAC field in the Root Identifier of the STP message from access device 2 with the current total root device priority and total root bridge MAC address MAC3 of this device, sets the Root Path Cost field to the maximum value FF FF FF FE, and uses the MAC address MAC32 of the domain boundary port P32 as the source MAC address to send back the STP message to access device 2.

[0035] In this application, the switching device 3 informs the access device 2 that the root bridge is unreachable by modifying the Root Identifier in the STP message from the access device 2.

[0036] After receiving the STP message returned by the switching device 3, access device 2 can print an alarm log to remind private network users of the failure.

[0037] Access device 2 enables loop detection for each VLAN belonging to edge port P21, and globally enables loop detection by disabling it, i.e., disabling ports that detect loops.

[0038] If access device 2 detects a loop in any of the VLANs belonging to edge port P21, it will shut down the physical link connection of edge port P21.

[0039] Access device 2 sends an STP error response message through edge port P21; the BridgePriority field of Root Identifier, the MAC address field of root bridge device, and Root Path Cost are all filled with F.

[0040] Access device 2 sets the Root Identifier field of the STP error response message to be greater than the root bridge ID of switching device 3, so that switching device 3 knows that the root bridge is unreachable.

[0041] Access device 2 disables STP on edge port P21, preventing edge port P21 from participating in STP protocol calculation.

[0042] Switching device 3 receives an STP abnormal response message from the access device through the domain boundary port P32, cancels the root protection blocking state of the domain boundary port P32, and restores it to the forwarding state.

[0043] In one example, if access device 2 does not send an STP exception response message, switching device 3 determines that the domain boundary port P32 received an STP message from access device 2 for a preset time, cancels the root protection blocking state of domain boundary port P32, and restores the forwarding state of domain boundary port P32.

[0044] This application not only avoids high-priority STP messages from private networks from damaging the public topology, but also provides feedback on the cause of the fault to the access devices in the private network. Furthermore, it reduces the complexity of protocol interaction and simplifies the processing logic of access device A. This allows access devices 1 and 2 in the private network to quickly exit the root election based on the "maximum abnormal root path cost" in the Root Identifier field of the returned STP response message as a "unified feedback mechanism," regardless of whether the blockage is due to root protection in the MSTP domain or BPDU blockage.

[0045] Figure 3 This is a schematic diagram of an embodiment of a bidirectional interactive spanning tree protocol boundary protection device provided in this application; the device 30 can be applied as a switching device in an MSTP domain. The device 30 includes a processor 31, a machine-readable storage medium 32, an application-specific integrated circuit (ASIC) 33, and a network interface 331.

[0046] The processor 31 executes the machine-executable instructions recorded in the machine-readable storage medium 32 to perform the following operations: identify the protection policy of the first domain boundary port of the received first Spanning Tree Protocol (STP) message as a root protection policy; determine that the root bridge priority of the first STP message is higher than the total root bridge priority of the MSTP domain to which this device belongs; set the root protection blocking state for the first domain boundary port while maintaining normal link layer connectivity; and send back a first STP response message through the first domain boundary port; wherein the first STP response message carries a first designated valid root identifier and the maximum abnormal root path cost; so that the device receiving the first STP response message performs root protection processing based on the maximum abnormal root path cost, thereby preventing root migration.

[0047] The processor 31, by executing machine-executable instructions recorded in the machine-readable storage medium 32, also performs the following operations: receiving a first STP anomaly response message through the first domain boundary port; wherein the first STP anomaly response message carries the maximum anomaly root path cost and the lowest root bridge priority; and canceling the root protection blocking state of the first domain boundary port.

[0048] The processor 31, by executing machine-executable instructions recorded in the machine-readable storage medium 32, also performs the following operations: determining that the root protection blocking state of the first domain boundary port has reached a preset maximum time, and canceling the root protection blocking state of the first domain boundary port.

[0049] The processor 31, by executing machine-executable instructions recorded in the machine-readable storage medium 32, also performs the following operations: identifies the protection policy of the second domain boundary port of the received second Spanning Tree Protocol (STP) message as a boundary port protection policy; sets the boundary port protection blocking state for the second domain boundary port while maintaining normal link layer connectivity; and sends back a second STP response message through the second domain boundary port; wherein the second STP response message carries a second designated valid root identifier and the maximum abnormal root path cost; so that the device receiving the second STP response message performs root protection processing based on the maximum abnormal root path cost.

[0050] The processor 31, by executing the machine-executable instructions recorded in the machine-readable storage medium 32, also performs the following operations: receiving a second STP exception response message through the second domain boundary port; wherein the second STP exception response message carries the maximum exception root path cost and the lowest root bridge priority; and canceling the boundary port protection blocking state of the second domain boundary port.

[0051] The processor 30, by executing machine-executable instructions recorded in the machine-readable storage medium 31, also performs the following operations: determining that the boundary port protection blocking state of the second domain boundary port has reached a preset maximum time, and canceling the boundary port protection blocking state of the second domain boundary port.

[0052] Figure 4 This is a schematic diagram of another embodiment of the Spanning Tree Protocol (STP) boundary protection device provided in this application. The device 40 can be applied as an access device in an STP domain. The device 40 includes a processor 41, a machine-readable storage medium 42, an application-specific integrated circuit (ASIC) 43, and a network interface 431.

[0053] Processor 41 performs the following operations by executing machine-executable instructions recorded in machine-readable storage medium 42: sending STP protocol messages through the edge port, wherein the root bridge priority in the STP protocol messages is configured as the highest allowed priority for each VLAN to which the edge port belongs; receiving STP response messages through the edge port, wherein the STP response messages carry a valid root identifier and the maximum root path cost; and performing loop detection within each VLAN to which the edge port belongs.

[0054] The processor 41 performs the following operations by executing machine-executable instructions recorded in the machine-readable storage medium 42: sending an STP anomaly response message through the edge port; wherein the STP anomaly response message carries the maximum anomaly root path cost and the lowest root bridge priority.

[0055] The processor 41 performs the following operations by executing machine-executable instructions recorded in the machine-readable storage medium 42: disabling the edge port from participating in STP protocol settlement.

[0056] The processor 41 performs the following operations by running machine-executable instructions recorded on the machine-readable storage medium 42: detecting a loop in any of the VLANs belonging to the edge port; and shutting down the physical link connection of the edge port.

[0057] The beneficial effects of this application are that it can both prevent high-priority STP packets from private networks from damaging the public topology and clearly report the cause of the fault to the access devices of the private network, thereby improving the user experience of the private network and reducing the difficulty of fault location when remote MSTP domain boundary protection triggers STP logical forwarding blocking. In this disclosure, machine-readable storage media can be any electronic, magnetic, optical, or other physical storage device used to store or contain information (such as executable instructions, data, etc.). For example, any machine-readable storage medium described herein can be any type of random access memory (RAM), volatile memory, non-volatile memory, flash memory, storage drive (such as hard disk drive), solid-state drive, any type of storage optical disk (such as optical disk, DVD, etc.), and similar devices, or combinations thereof. Furthermore, any machine-readable storage medium described herein can be a non-transitory machine-readable storage medium.

[0058] The above description is merely a preferred embodiment of this application and is not intended to limit this application. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of protection of this application.

Claims

1. A method for boundary protection based on a bidirectional interactive spanning tree protocol, characterized in that, The method includes, The protection policy of the first domain boundary port of the first received Spanning Tree Protocol (STP) message is identified as the root protection policy; The root bridge priority of the first STP message is determined to be higher than the total root bridge priority of the MSTP domain to which this device belongs; Set the root protection blocking state for the first domain boundary port while maintaining normal link layer connectivity; The first STP response message is transmitted back through the first domain boundary port; wherein the first STP response message carries a first designated valid root identifier and the maximum abnormal root path cost; so that the device receiving the first STP response message performs root protection processing based on the maximum abnormal root path cost, thereby preventing root migration.

2. The method according to claim 1, characterized in that, The method also includes, The first STP anomaly response message is received through the first domain boundary port; wherein the first STP anomaly response message carries the maximum anomaly root path cost and the lowest root bridge priority. Cancel the root protection blocking state of the first domain boundary port; or, If it is determined that the root protection blocking state of the first domain boundary port has reached a preset maximum time, the root protection blocking state of the first domain boundary port is cancelled.

3. The method according to claim 1, characterized in that, The method also includes, The protection policy of the second domain boundary port of the received second spanning tree protocol (STP) message is identified as the boundary port protection policy. Set the boundary port protection blocking state for the second domain boundary port while maintaining normal link layer connectivity; The second STP response message is transmitted back through the second domain boundary port; wherein the second STP response message carries a second designated valid root identifier and the maximum abnormal root path cost; so that the device receiving the second STP response message performs root protection processing based on the maximum abnormal root path cost.

4. The method according to claim 3, characterized in that, The method also includes, The second STP anomaly response message is received through the second domain boundary port; wherein the second STP anomaly response message carries the maximum anomaly root path cost and the lowest root bridge priority; Cancel the boundary port protection blocking state of the second domain boundary port; or, If it is determined that the boundary port protection blocking state of the second domain boundary port has reached a preset maximum time, then the boundary port protection blocking state of the second domain boundary port is cancelled.

5. A device for boundary protection based on bidirectional interactive spanning tree protocol, characterized in that, The invention includes a processor, a machine-readable storage medium, an application-specific integrated circuit (ASIC), and a network interface; characterized in that the processor executes the method described in any one of claims 1-4 by running machine-executable instructions recorded on the machine-readable storage medium.

6. A method for boundary protection based on a bidirectional interactive spanning tree protocol, characterized in that, The method includes, Send STP protocol messages via the edge port; The root bridge priority in the STP protocol message is configured as the highest allowed priority for each VLAN to which the edge port belongs; The STP response message is received through the edge port; wherein the STP response message carries the valid root identifier and the maximum root path cost; Loop detection is performed within each VLAN of the edge port.

7. The method according to claim 6, characterized in that, The method also includes, An STP anomaly response message is sent through the edge port; wherein the STP anomaly response message carries the maximum anomaly root path cost and the lowest root bridge priority.

8. The method according to claim 6, characterized in that, The method also includes, The aforementioned edge port is prohibited from participating in STP protocol settlement.

9. The method according to claim 8, characterized in that, The method also includes, A loop was detected at the edge port in any of its VLANs; Disable the physical link connection of the corresponding edge port.

10. A device for boundary protection based on a bidirectional interactive spanning tree protocol, characterized in that, The invention includes a processor, a machine-readable storage medium, an application-specific integrated circuit (ASIC), and a network interface; characterized in that the processor executes the method described in any one of claims 6-9 by running machine-executable instructions recorded on the machine-readable storage medium.