sk185110 - How to enable forwarding of STP / BPDU packets through a bridge interface in a Maestro Security Group

How to enable forwarding of STP / BPDU packets through a bridge interface in a Maestro Security Group

Solution

Overview

This feature configures a Maestro Orchestrator to forward Spanning Tree Protocol (STP) / BPDU packets that arrive at the Uplink and at the Management ports to a Maestro Security Group configured with a bridge interface.

Without this feature enabled, Maestro Orchestrators drop STP / BPDU packets that arrive at the Uplink and at the Management ports.

Example topology that shows how STP packets can pass between Switch "A" and Switch "B":

 [Network "A"]      [Network "B"]
      |                  |
      |                  |
  [Switch "A"]       [Switch "B"]
   [with STP]         [with STP]
      |                  |
      |                  |
 (Uplink or         (Uplink or)
  Mgmt port)         Mgmt port)
      |                  |
+------------------------------+
|     Maestro Orchestrator     |
+------------------------------+
              | |
         (Downlink ports)
              | |
        [Security Group]
    [with a Bridge interface]

Availability

This feature is available starting from:

Important Notes

To minimize the traffic impact, configure one Maestro Orchestrator at a time.

This way, it is not necessary to schedule a full maintenance window.

Configuration Instructions for each Maestro Orchestrator

  1. Install the Jumbo Hotfix Accumulator on the Maestro Orchestrator and reboot.

Refer to sk168597 - How to install a Hotfix.

  1. Connect to the command line on the Maestro Orchestrator.

  2. Log in to the Expert mode.

  3. Enable the BPDU forwarding:

jsont -f /etc/maestro.json -s /mho_stp_forward/state -v enabled
  1. Restart the daemon:
orchd restart

Warning - No traffic flows through the Maestro Orchestrator while this daemon is restarting.

Article Properties

Access Level: General

Status: Approved

Date Created: 2026-06-29

Last Modified: 2026-07-22