On the Loop in the Switching FabricOn the Loop in the Switching Fabric127

The monitoring system raised a clutch of alerts at once: high CPU usage on several access switches, users complaining the network had gone slow, some unable to reach the internet at all. I turned to the traffic logs, and they told the plain tale, a massive rise in broadcast traffic. Somewhere a storm had been loosed, and I had to find its source and cut it off before the whole plant drowned in its own chatter.

I went to the core switch by console cable, not trusting the network to carry me to its own sickbed. The spanning tree protocol (STP) status showed frequent topology changes, the mark of a loop the switches kept discovering and forgetting. I disabled the interfaces bearing the heaviest broadcast load, and the core steadied at once. Then I walked to where those interfaces led and found, beneath a desk, a small unmanaged switch, into which some user had plugged one cable’s two ends. A loop, contrived by accident and hidden by furniture.

I pulled the cable and so broke the loop, took the unmanaged switch away from the office, and re-enabled the interfaces on the access switch. Traffic returned to normal levels; CPU usage on the switches fell back where it belonged; the users reported the network quick again. Lest the same accident repeat, I amended the network security policy so that unauthorized ports disable themselves automatically.