Configuring STP Extensions Using Cisco NX-OS
BPDU Guard
This figure shows the network with Bridge Assurance enabled, and the STP topology progressing normally
with bidirectional BPDUs issuing from every STP network port.
Figure 16: Network STP Topology Running Bridge Assurance
This figure shows how the potential network problem does not happen when you have Bridge Assurance
enabled on your network.
Figure 17: Network Problem Averted with Bridge Assurance Enabled
BPDU Guard
Enabling BPDU Guard shuts down that interface if a BPDU is received.
You can configure BPDU Guard at the interface level. When configured at the interface level, BPDU Guard
shuts the port down as soon as the port receives a BPDU, regardless of the port type configuration.
When you configure BPDU Guard globally, it is effective only on operational spanning tree edge ports. In a
valid configuration, Layer 2 LAN edge interfaces do not receive BPDUs. A BPDU that is received by an edge
Cisco Nexus 9000 Series NX-OS Layer 2 Switching Configuration Guide, Release 7.x
154