Stp Bpdu-Protection - Huawei Quidway S3900 series Command Manual

Hide thumbs Also See for Quidway S3900 series:
Table of Contents

Advertisement

Command Manual – MSTP
Quidway S3900 Series Ethernet Switches-Release 1510
[Quidway] interface ethernet 1/0/1
[Quidway-Ethernet1/0/1] stp disable

1.1.11 stp bpdu-protection

Syntax
stp bpdu-protection
undo stp bpdu-protection
View
System view
Parameter
None
Description
Use the stp bpdu-protection command to enable the BPDU protection function.
Use the undo stp bpdu-protection command to revert to the default state of the
BPDU protection function.
By default, the BPDU protection function is disabled.
Normally, the access ports of the devices operating on the access layer directly connect
to terminals (such as PCs) or file servers. These ports are usually configured as edge
ports to achieve rapid transition. But they resume non-edge ports automatically upon
receiving configuration BPDUs, which causes spanning trees regeneration and
network topology jitter.
Normally, no configuration BPDU will reach edge ports. But malicious users can attack
a network by sending configuration BPDUs deliberately to edge ports to cause network
jitter. You can prevent this type of attacks by utilizing the BPDU protection function.
With this function enabled on a switch, the switch shuts down the edge ports that
receive configuration BPDUs and then reports these cases to the administrator. If a port
is shut down, only the administrator can restore it.
Example
# Enable the BPDU protection function.
<Quidway> system-view
System View: return to User View with Ctrl+Z.
[Quidway] stp bpdu-protection
Huawei Technologies Proprietary
1-11
Chapter 1 MSTP Configuration Commands

Hide quick links:

Advertisement

Chapters

Table of Contents
loading

Table of Contents