Tc-Bpdu Attack Prevention Configuration; Digest Snooping Configuration; Introduction - Huawei Quidway S3100 Series Operation Manual

Table of Contents

Advertisement

Operation Manual – MSTP
Quidway S3100 Series Ethernet Switches

1.5.6 TC-BPDU Attack Prevention Configuration

I. Configuration procedure
Table 1-34 Enable the TC-BPDU attack prevention function
Operation
Enter system view
Enable
TC-BPDU
prevention function
II. Configuration example
# Enable the TC-BPDU attack prevention function
<Quidway> system-view
System View: return to User View with Ctrl+Z.
[Quidway] stp tc-protection enable

1.6 Digest Snooping Configuration

1.6.1 Introduction

According to IEEE 802.1s, two interconnected MSTP switches can interwork with each
other through MSTIs in an MST region only when the two switches have the same MST
region-related configuration. Interconnected MSTP switches determine whether or not
they are in the same MST region by checking the configuration IDs of the BPDUs
between them. (A configuration ID contains information such as region ID and
configuration digest.)
As some partners' switches adopt proprietary spanning tree protocols, they cannot
interwork with other switches in an MST region even if they are configured with the
same MST region-related settings as other switches in the MST region.
This problem can be overcome by implementing the digest snooping feature. If a port
on a S3100 series switch is connected to a partner's switch that has the same MST
region-related configuration as its own but adopts a proprietary spanning tree protocol,
you can enable digest snooping on the port. Then the S3100 switch regards the
partner's switch as in the same region; it records the configuration digests carried in the
BPDUs received from the partner's switch, and put them in the BPDUs to be send to the
partner's switch.. In this way, the S3100 switches can interwork with the partners'
switches in the same MST region.
Command
system-view
the
attack
stp tc-protection enable
Huawei Technologies Proprietary
1-36
Chapter 1 MSTP Configuration
Description
Required
The
TC-BPDU
prevention
function
disabled by default.
attack
is

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents