Enabling Tc-Bpdu Attack Guard; Displaying And Maintaining Mstp - 3Com MSR 50 Series Configuration Manual

3com msr 30-16: software guide
Hide thumbs Also See for MSR 50 Series:
Table of Contents

Advertisement

Enabling TC-BPDU
Attack Guard
Displaying and
Maintaining MSTP
To do...
Enter system view
Enter Ethernet
Enter Ethernet
interface view
interface view
or port group
Enter port
view
group view
Enable the loop guard function
for the ports(s)
When receiving a TC-BPDU (a PDU used as notification of topology change), the
device will delete the corresponding forwarding address entry. If someone forges
TC-BPDUs to attack the device, the device will receive a larger number of
TC-BPDUs within a short time, and frequent deletion operations bring a big
burden to the device and hazard network stability.
With the TC-BPDU guard function enabled, the device limits the maximum
number of times of immediately deleting forwarding address entries within 10
seconds after it receives TC-BPDUs to the value set with the stp tc-protection
threshold command (assume the value is X). At the same time, the system
monitors whether the number of TC-BPDUs received within that period of time is
larger than X. If so, the device will perform another deletion operation after that
period of time elapses. This prevents frequent deletion of forwarding address
entries.
Follow these steps to enable TC-BPDU attack guard
To do...
Enter system view
Enable the TC-BPDU attack guard
function
Configure the maximum number of
times the device deletes forwarding
address entries within a certain
period of time immediately after it
receives a TC-BPDU
n
We recommend that you keep this function enabled.
To do...
View the information about the
ports that are blocked abnormally
View the information about the
port blocked by STP

Displaying and Maintaining MSTP

Use the command...
system-view
interface interface-type
interface-number
port-group { manual
port-group-name |
aggregation agg-id }
stp loop-protection
Use the command...
system-view
stp tc-protection enable
stp tc-protection threshold
number
Use the command...
display stp abnormal-port
display stp down-port
481
Remarks
-
User either command
Configured in Ethernet
interface view, the setting is
effective on the current port
only; configured in port
group view, the setting is
effective on all ports in the
port group.
Required
Disabled by default
Remarks
-
Optional
Enabled by default
Optional
6 by default
Remarks
Available in any view
Available in any view

Hide quick links:

Advertisement

Table of Contents

Troubleshooting

loading

Table of Contents