Enabling Tc-Bpdu Guard; Enabling Bpdu Drop - H3C S7500E-X Configuration Manual

Layer 2 lan switching
Hide thumbs Also See for H3C S7500E-X:
Table of Contents

Advertisement

Make this configuration on the port that connects to the user access network.
To configure TC-BPDU transmission restriction:
Step
Enter system view.
1.
Enter Layer 2 Ethernet or
2.
aggregate interface view.
Enable TC-BPDU
3.
transmission restriction.

Enabling TC-BPDU guard

When a device receives topology change (TC) BPDUs (the BPDUs that notify devices of topology
changes), it flushes its forwarding address entries. If someone uses TC-BPDUs to attack the device,
the device will receive a large number of TC-BPDUs within a short time. Then, the device is busy with
forwarding address entry flushing. This affects network stability.
TC-BPDU guard allows you to set the maximum number of immediate forwarding address entry
flushes performed within 10 seconds after the device receives the first TC-BPDU. For TC-BPDUs
received in excess of the limit, the device performs a forwarding address entry flush when the time
period expires. This prevents frequent flushing of forwarding address entries. As a best practice,
enable TC-BPDU guard.
To enable TC-BPDU guard:
Step
Enter system view.
1.
Enable the TC-BPDU guard feature.
2.
(Optional.) Configure the maximum
3.
number of forwarding address entry
flushes that the device can perform
every 10 seconds.

Enabling BPDU drop

In a spanning tree network, every BPDU arriving at the device triggers an STP calculation process
and is then forwarded to other devices in the network. Malicious attackers might use the vulnerability
to attack the network by forging BPDUs. By continuously sending forged BPDUs, they can make all
devices in the network continue performing STP calculations. As a result, problems such as CPU
overload and BPDU protocol status errors occur.
To avoid this problem, you can enable BPDU drop on ports. A BPDU drop-enabled port does not
receive any BPDUs and is invulnerable to forged BPDU attacks.
To enable BPDU drop on an Ethernet interface:
Step
Enter system view.
1.
Command
system-view
interface interface-type
interface-number
stp tc-restriction
Command
system-view
stp tc-protection
stp tc-protection threshold
number
Command
system-view
97
Remarks
N/A
N/A
By default, TC-BPDU
transmission restriction is
disabled.
Remarks
N/A
By default, TC-BPDU guard
is enabled.
As a best practice, do not
disable this feature.
The default setting is 6.
Remarks
N/A

Advertisement

Table of Contents
loading

Table of Contents