Cisco – In a multi-tenant environment what should be done to make your switchports silent on Cisco and Juniper switches

ciscojuniperswitch

For example preventing it from sending arp, stp, etc and to reveal as little as possible about the rest of the network.

Example use case would be connecting to a peering exchange.

Best Answer

You can check the Amsterdam Internet Exchange's Config Guide for hints on how to silence switches from a variety of vendors.

In my experience there are vendors whose software is so bad that their equipment is never silent, for example they ARP out every interface when they boot, or send out some upon a link up event on a port. Juniper, Cisco, Brocade can be muffled with varying degrees of persuasion, Extreme loops everything during EAPS transitions.

Some things to disable/consider:

  • Discovery protocols (LLDP, CDP, FDP, 'dynamic-vlan-discovery')
  • VTP, DTP
  • STP (disable for the VLAN a port is in)
  • Ethernet keepalives or loop frames (useless on full-duplex media)
  • Weird stuff like DECnet MOP (topic of another question a few days ago)
  • Have a separate management VLAN for the switch's own IP address
  • You'll want to disable PIM snooping on a Cisco as this breaks IPv6.
Related Topic