Related commands: stp interface root-protection.
Examples
# Enable the root guard function on Ethernet 1/0/1.
<Sysname> system-view
System View: return to User View with Ctrl+Z.
[Sysname] interface Ethernet 1/0/1
[Sysname-Ethernet1/0/1] stp root-protection
stp tc-protection
Syntax
stp tc-protection enable
stp tc-protection disable
View
System view
Parameters
None
Description
Use the stp tc-protection enable command to enable the TC-BPDU attack guard function.
Use the stp tc-protection disable command to disable the TC-BPDU attack guard function.
By default, the TC-BPDU guard attack function is enabled, and the MAC address table and ARP entries
can be removed for up to six times within 10 seconds.
Normally, a switch removes the MAC address table and ARP entries upon receiving TC-BPDUs. If a
malicious user sends a large amount of TC-BPDUs to a switch in a short period, the switch may be busy
in removing the MAC address table and ARP entries frequently, which may affect spanning tree
calculation, occupy large amount of bandwidth and increase switch CPU utilization.
With the TC-BPDU attack guard function enabled, a switch performs a removing operation upon
receiving a TC-BPDU and triggers a timer (set to 10 seconds by default) at the same time. Before the
timer expires, the switch only performs the removing operation for limited times (up to six times by
default) regardless of the number of the TC-BPDUs it receives. Such a mechanism prevents a switch
from being busy in removing the MAC address table and ARP entries.
Examples
# Enable the TC-BPDU attack guard function on the switch.
<Sysname> system-view
System View: return to User View with Ctrl+Z.
[Sysname] stp tc-protection enable
stp tc-protection threshold
Syntax
stp tc-protection threshold number
1-45
Need help?
Do you have a question about the s3600 series and is the answer not in the manual?
Questions and answers