Huawei Quidway S3500 Series Operation Manual page 457

Hide thumbs Also See for Quidway S3500 Series:
Table of Contents

Advertisement

Operation Manual - STP
Quidway S3500 Series Ethernet Switches
When the protection from TC-BPDU packet attack is enabled, the switch just perform
one delete operation in a specified period after receiving TC-BPDU packets, as well as
monitoring whether it receives TC-BPDU packets during this period. Even if it detects a
TC-BPDU packet is received in a period shorter than the specified interval, the switch
shall not run the delete operation till the specified interval is reached. This can avoid
frequent delete operations to the MAC address table and ARP table.
You can use the following command to configure the security functions of the switch.
Perform the following configuration in corresponding configuration modes.
Table 1-22 Configure the switch security function
Configure switch BPDU protection (from
system view)
Restore the disabled BPDU protection state as
defaulted (from system view)
Configure switch Root protection (from system
view)
Restore the disabled Root protection state as
defaulted (from system view)
Configure
Ethernet port view)
Restore the disabled Root protection state as
defaulted (from Ethernet port view)
Configure switch loop protection function (from
Ethernet port view)
Restore the disabled loop protection state, as
defaulted (from Ethernet port view)
Configure switch TC protection (from system
view)
Disabled TC protection state as defaulted
(from system view)
After configured with BPDU protection, the switch will disable the edge port through
MSTP, which receives a BPDU, and notify the network manager at same time. These
ports can be resumed by the network manager only.
The port configured with Root protection only plays a role of designated port on every
instance. Whenever such port receives a higher-priority BPDU, that is, it is about to turn
into non-designated port, it will be set to listening state and not forward packets any
more (as if the link to the port is disconnected). If the port has not received any
higher-priority BPDU for a certain period of time thereafter, it will resume the normal
state.
Operation
switch
Root
protection
Huawei Technologies Proprietary
1-25
Chapter 1 MSTP Region-configuration
Command
stp bpdu-protection
undo stp bpdu-protection
stp
interface
root-protection
undo stp interface interface-list
root-protection
(from
stp root-protection
undo stp root-protection
stp loop-protection
undo stp loop-protection
stp tc-protection enable
undo stp tc-protection disable
interface-list

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents