STP Operation More Details
To understand the attacks that a hacker is likely to carry out against STP, network administrators must gain a solid understanding of STP's inner workings. The protocol builds a loop-free topology that looks like a tree. At the base of the tree is a root bridge— an election process takes place to determine which bridge becomes the root. The switch with the lowest bridge ID (a concatenation of a 16-bit user-assigned priority and the switch's MAC address) wins. The root-bridge election process begins by having every switch in the domain believe it is the root and claiming it throughout the network by means of Bridge Protocol Data Units (BPDU). BPDUs are Layer 2 frames multicast to a well-known MAC address in case of IEEE STP (01-80-C2-00-00-00) or vendor-assigned addresses, in other cases. When receiving a BPDU from a neighbor, a bridge compares the sender's bridge ID with its own to determine which switch has the lowest ID. Only the one with the lowest ID keeps on generating BPDUs, and the process continues until a single switch wins the designated root-bridge election. STP assigns roles and functions to network ports. Every nonroot bridge has one root port: It is the port that leads to the root bridge.
STP uses a path cost-based method to build its loop-free tree. Every port is configured with a port cost—most switches are capable of autoassigning costs based on link speed.
A port's cost is inversely proportional to its bandwidth. Each time a port receives a BPDU, the port's path cost is added to the path cost contained in the BPDU. The root sends BPDUs with the path cost equal to 0, and the cost keeps increasing as the network diameter increases. When two BPDUs are received on a switch because of redundant links in the network, the one with the higher cost is logically disabled—it is put in blocked mode. The bridge that is responsible for forwarding packets on a given segment is called the designated bridge. After a while, ranging from less than a second to just under a minute depending on the STP flavor, the network converges and a single-rooted loop-free tree is built. Before a port transitions to forwarding, it goes through several states:
• Disabled. The port is electrically inactive and does not send or receive any traffic. Once enabled, the port transitions to the next state (blocking).
• Blocking. Discards all data frames except BPDUs.
• Listening. Switches listen to BPDUs to build the loop-free tree. Data packets are not forwarded (15 sec by default with 802.1D timers).
• Learning. Forwarding tables are built using the source MAC addresses of data frames; data frames are not forwarded.
• Forwarding. Data traffic. At this point, the port is fully operational.
NOTE Although this chapter paints a detailed portrait of STP's inner workings, we recommend that you look at the reference material available online2 if you are interested in a more detailed overview.
After the network converges, STP network-wide timers maintain its stability. (A network can be a VLAN.)
Network-Wide Timers
Several STP timers exist:
Hello. Time between each BPDU that is sent on a port. By default, this time is equal to 2 sec, but you can tune the time to be between 1 and 10 sec.
Forward delay. Time spent in the listening and learning state. By default, this time is equal to 15 sec, but you can tune the time to be between 4 and 30 sec.
Max age. Controls the maximum length of time that passes before a bridge port saves its configuration BPDU information. By default, this time is 20 sec, but you can tune the time to be between 6 and 40 sec.
Each configuration BPDU contains these three parameters. In addition, each BPDU configuration contains another time-related parameter, known as the message age. The message age is not a fixed value. The message age contains the length of time that has passed since the root bridge initially originated the BPDU. The root bridge sends all its BPDUs with a message age value of 0, and all subsequent switches add 1 to this value. Effectively, this value contains the information on how far you are from the root bridge when you receive a BPDU.
In 802.1D, bridges actually have no idea whether their BPDUs are heard by neighboring switches. For example, the root bridge is not sure that everyone acknowledges its presence—the protocol contains no provision to ensure this. The protocol simply relies on the timers (as just explained) to assume BPDUs are properly delivered to every bridge in the network. Table 3-1 represents an 802.1D BPDU.
Table 3-1 802.1D BPDU Frame Format
|
Field |
Value |
|
Destination MAC |
01 80 c2 00 00 00 IEEE reserved BPDU MAC |
|
Source MAC |
00 00 0c a0 01 96 Port's MAC address |
|
LENGTH |
00 26 |
|
Destination Service Access Point |
42 |
|
Source Service Access Point |
42 |
|
Unnumbered Information |
03 |
|
PROTOCOL |
00 00 |
|
PROTOCOL VERSION |
00 |
|
BPDU TYPE |
00 |
|
BPDU FLAGS |
00 |
|
20 00 00 d0 00 f6 ba 04 |
|
|
PATH COST |
00 00 00 00 |
|
BRIDGE ID |
20 00 00 d0 00 f6 ba 04 |
|
PORT |
81 14 |
|
MESSAGE AGE |
00 00 |
|
MAXIMUM AGE |
14 00 |
|
HELLO TIME |
02 00 |
|
FORWARD DELAY |
0f 00 |
In a converged network, the root bridge sends a BPDU out each port every hello interval (2 sec, by default). Every BPDU contains an age field that represents how long it has been in transit. It starts from 0 at the root and increases as the BPDU makes its way through the switched network. A maximum valid age is defined for the network (max_age parameter— 20 sec, by default). When a BPDU is received on a port, the switch extracts the age contained in the BPDU and starts running a port clock initialized with that value. For example, if the BPDU is 6 sec old, the clock starts counting from 6. Normally, the next
BPDU is supposed to arrive 2 sec later, but because of various conditions (packet loss, unreliable software, excessive CPU utilization, unidirectional links, and so on), BPDUs are known to sometimes fail to show on time. Meanwhile, the port clock runs until it reaches max_age. If it reaches max_age, the bridge starts the election process again, claiming to be the root! Ports go back to blocking/listening/learning before finally forwarding, potentially causing massive traffic blackouts.
Another property of the STP is its ability to influence the forwarding table's aging time by using a particular bit in the BPDU. Figure 3-3 shows the Flags field found in every BPDU.
Figure 3-3 BPDU Packet Capture —TC Bit
Figure 3-3 BPDU Packet Capture —TC Bit
In 802.1D, the Flags field can take two values: 1000 0000 or 0000 0001. When the low-order bit is set, it indicates that the BPDU is actually a topology-change notification (TCN) BPDU. It is a lightweight BPDU whose purpose is to inform the upstream switches all the way to the root bridge that a connectivity event occurred on this switch. A switch sends a TCN BPDU whenever a link or port transitions up or down. Bridges located between the originator of the TCN BPDU and the root immediately acknowledge the reception of the
TCN BPDU, without being certain that the root still exists. When the TCN BPDU finally reaches the root bridge, it acknowledges this by setting the high-order bit of the Flags field (TC-ACK bit) in BPDU it generates. This notifies every bridge to reduce its forwarding table's aging time to forward_delay sec (15, by default). The TC bit is set for a certain period of time (max_age + forward_delay sec, or 35 sec with timers using default values). Figure 3-4 shows a scenario where this mechanism plays a crucial role in restoring network connectivity faster.
Figure 3-4 TC Bit Plays a Crucial Role
Link Failure
Figure 3-4 TC Bit Plays a Crucial Role
Link Failure
Blocking
Suppose traffic flows between PC A and PC B through switches 1, 2, 3, and 4, and all forwarding tables are correctly populated, with switch 1 pointing to switch 2 to reach B. Now, the link between switches 2 and 3 fails. As a result, switch 4 removes the link to switch 1 from its blocked mode and puts it in forwarding. Traffic from A arrives on switch 1, only to be sent to switch 2. Indeed, nobody told switch 1 that it should use switch 4 to reach B. Naturally, this creates a temporary traffic "black hole." In this particular case, relying on the usual forwarding-table aging time alone is not sufficient. Thanks to the TCN/ TC-ACK bits, however, switch 1's forwarding table can age out faster and soon point to the correct switch 1-to-4 link to reach B.
NOTE The rapid STP defined in 802.1w in 1999 introduces a proposal/agreement mechanism between switches, thereby significantly reducing the timer-based dependency. It also discards the information contained in the forwarding table altogether when a topology change occurs. Albeit faster than its 802.1D predecessor, 802.1w was designed with no concern for security. BPDUs are not signed or authenticated, the protocol is stateless, and an 802.1w implementation must be capable of understanding 802.1D BPDUs. Therefore, any attack launched against the 802.1D STP works on switches running 802.1w.
Many vendors have augmented the original 802.1D and 802.1w specs to provide a per-VLAN 802.1D or 802.1w for better flexibility in network design. Cisco's own proprietary version of 802.1D and 802.1w is called per-VLAN (rapid) spanning-tree plus (PVST+). Other than a Cisco-specific destination MAC address and a Subnetwork Access Protocol (SNAP) frame header, the BPDU payload contains exactly the same information as a regular 802.1D or 802.1w BPDU, as Table 3-2 shows.
Table 3-2 Cisco PVST+ BPDU in VLAN10
|
Field |
Value |
Explanation |
|
DMAC |
01 00 0c cc cc cd |
Cisco SSTP BPDU MAC |
|
SMAC |
00 02 fc 90 08 38 |
Port MAC |
|
PROTOCOL TYPE IDENTIFIER |
81 00 |
802.1Q Ethertype |
|
TAG CONTROL INFO |
00 0a |
COS and VLAN ID (VLAN 10) |
|
LENGTH |
00 32 |
|
|
802.2 Logical Link Control HEADER |
||
|
DSAP |
Aa |
Indicates SNAP encap |
|
SSAP |
Aa |
|
|
UI |
03 |
|
|
VENDOR ID |
00 00 0c |
Cisco Systems |
|
TYPE |
01 0b |
SSTP |
|
PROTOCOL |
00 00 |
|
|
PROTOCOL VERSION |
00 |
|
|
BPDU TYPE |
00 |
|
|
BPDU FLAGS |
00 |
|
|
ROOT ID |
20 00 00 d0 00 66 2c 0a |
|
|
PATH COST |
00 00 00 00 |
|
|
BRIDGE ID |
20 00 00 d0 00 66 2c 0a |
Bridge ID in VLAN 10 |
|
PORT |
81 41 |
|
|
MESSAGE AGE |
00 00 |
|
|
MAXIMUM AGE |
14 00 |
|
|
ROOT HELLO TIME |
02 00 |
|
|
ROOT FORWARD DELAY |
0f 00 |
|
Field |
Value |
Explanation |
|
VLAN ID Type Length Value |
||
|
PAD |
34 |
|
|
TYPE |
00 00 |
|
|
LENGTH |
00 02 |
|
|
VLAN ID |
00 0a |
VLAN 10 |
NOTE The actual destination MAC address may vary depending on the flavor of STP you are running. For example, the address reserved by the IEEE is 01:80:C2:00:00:00. Cisco uses a MAC address of its choosing for its per-VLAN rapid spanning-tree implementation, because the standard itself does not define a per-VLAN specification.
Continue reading here: Let the Games Begin
Was this article helpful?