Enabling Bpdu Guard - Cisco 3020 - Catalyst Blade Switch Configuration Manual

Cisco catalyst blade switch 3020 for hp software configuration guide, rel. 12.2(25)sef1
Hide thumbs Also See for 3020 - Cisco Catalyst Blade Switch:
Table of Contents

Advertisement

Chapter 15
Configuring Optional Spanning-Tree Features
You can use the spanning-tree portfast default global configuration command to globally enable the
Note
Port Fast feature on all nontrunking ports.
To disable the Port Fast feature, use the spanning-tree portfast disable interface configuration
command.

Enabling BPDU Guard

When you globally enable BPDU guard on interfaces that are Port Fast-enabled (the interfaces are in a
Port Fast-operational state), spanning tree shuts down Port Fast-enabled interfaces that receive BPDUs.
In a valid configuration, Port Fast-enabled interfaces do not receive BPDUs. Receiving a BPDU on a
Port Fast-enabled interface signals an invalid configuration, such as the connection of an unauthorized
device, and the BPDU guard feature puts the interface in the error-disabled state. The BPDU guard
feature provides a secure response to invalid configurations because you must manually put the interface
back in service. Use the BPDU guard feature in a service-provider network to prevent an access port
from participating in the spanning tree.
Configure Port Fast only on interfaces that connect to end stations; otherwise, an accidental topology
Caution
loop could cause a data packet loop and disrupt switch and network operation.
You also can use the spanning-tree bpduguard enable interface configuration command to enable
BPDU guard on any interface without also enabling the Port Fast feature. When the interface receives a
BPDU, it is put in the error-disabled state.
You can enable the BPDU guard feature if your switch is running PVST+, rapid PVST+, or MSTP.
Beginning in privileged EXEC mode, follow these steps to globally enable the BPDU guard feature. This
procedure is optional.
Command
Step 1
configure terminal
Step 2
spanning-tree portfast bpduguard default
Step 3
interface interface-id
Step 4
spanning-tree portfast
Step 5
end
Step 6
show running-config
Step 7
copy running-config startup-config
To disable BPDU guard, use the no spanning-tree portfast bpduguard default global configuration
command.
You can override the setting of the no spanning-tree portfast bpduguard default global configuration
command by using the spanning-tree bpduguard enable interface configuration command.
OL-8915-01
Purpose
Enter global configuration mode.
Globally enable BPDU guard.
By default, BPDU guard is disabled.
Specify the interface connected to an end station, and enter
interface configuration mode.
Enable the Port Fast feature.
Return to privileged EXEC mode.
Verify your entries.
(Optional) Save your entries in the configuration file.
Cisco Catalyst Blade Switch 3020 for HP Software Configuration Guide
Configuring Optional Spanning-Tree Features
15-11

Advertisement

Table of Contents
loading

Table of Contents