Enabling Bpdu Filtering - Cisco 3845 - Security Bundle Router Software Manual

Software configuration guide
Hide thumbs Also See for 3845 - Security Bundle Router:
Table of Contents

Advertisement

Chapter 15
Configuring Optional Spanning-Tree Features
Configure Port Fast only on STP ports that connect to end stations; otherwise, an accidental topology
Caution
loop could cause a data packet loop and disrupt switch and network operation.
You also can use the spanning-tree bpduguard enable interface configuration command to enable
BPDU guard on any STP port without also enabling the Port Fast feature. When the interface receives a
BPDU, it is put in the error-disabled state.
You can enable the BPDU guard feature if your switch is running PVST+, rapid PVST+, or MSTP.
Beginning in privileged EXEC mode, follow these steps to globally enable the BPDU guard feature. This
procedure is optional.
Command
Step 1
configure terminal
Step 2
spanning-tree portfast bpduguard default
Step 3
interface interface-id
Step 4
spanning-tree portfast
Step 5
end
Step 6
show running-config
Step 7
copy running-config startup-config
To disable BPDU guard, use the no spanning-tree portfast bpduguard default global configuration
command.
You can override the setting of the no spanning-tree portfast bpduguard default global configuration
command by using the spanning-tree bpduguard enable interface configuration command on an STP
port.

Enabling BPDU Filtering

When you globally enable BPDU filtering on Port Fast-enabled STP ports, it prevents interfaces that are
in a Port Fast-operational state from sending or receiving BPDUs. The interfaces still send a few BPDUs
at link-up before the switch begins to filter outbound BPDUs. You should globally enable BPDU filtering
on a switch so that hosts connected to these interfaces do not receive BPDUs. If a BPDU is received on
a Port Fast-enabled STP port, the interface loses its Port Fast-operational status, and BPDU filtering is
disabled.
Caution
Configure Port Fast only on STP ports that connect to end stations; otherwise, an accidental topology
loop could cause a data packet loop and disrupt switch and network operation.
OL-23400-01
Purpose
Enter global configuration mode.
Globally enable BPDU guard. (By default, BPDU guard is
disabled.)
Globally enabling BPDU guard enables it only on STP
Note
ports; the command has no effect on ports that are not
running STP.
Specify the interface connected to an end station, and enter
interface configuration mode.
Enable the Port Fast feature.
Return to privileged EXEC mode.
Verify your entries.
(Optional) Save your entries in the configuration file.
Cisco ME 3800X and 3600X Switch Software Configuration Guide
Configuring Optional Spanning-Tree Features
15-7

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Me 3800xMe 3600x

Table of Contents