About Bpdu Guard - Cisco Catalyst 4500 Series Configuration Manual

Release ios xe 3.3.0sg and ios 15.1(1)sg
Hide thumbs Also See for Catalyst 4500 Series:
Table of Contents

Advertisement

About BPDU Guard

About BPDU Guard
Spanning Tree BPDU guard shuts down PortFast-configured interfaces that receive BPDUs, rather than
putting them into the spanning tree blocking state. In a valid configuration, PortFast-configured
interfaces do not receive BPDUs. Reception of a BPDU by a PortFast-configured interface signals an
invalid configuration, such as connection of an unauthorized device. BPDU guard provides a secure
response to invalid configurations, because the administrator must manually put the interface back in
service.
Note
When the BPDU guard feature is enabled, spanning tree applies the BPDU guard feature to all
PortFast-configured interfaces.
Note
Enabling BPDU Guard
To enable BPDU guard to shut down PortFast-configured interfaces that receive BPDUs, perform this
task:
Command
Step 1
Switch(config)# [no] spanning-tree portfast
bpduguard
Step 2
Switch(config)# end
Step 3
Switch# show spanning-tree summary totals
This example shows how to enable BPDU guard:
Switch(config)# spanning-tree portfast bpduguard
Switch(config)# end
Switch#
This example shows how to verify the BPDU configuration:
Switch# show spanning-tree summary totals
Root bridge for: none.
PortFast BPDU Guard is enabled
Etherchannel misconfiguration guard is enabled
UplinkFast is disabled
BackboneFast is disabled
Default pathcost method used is short
Name
-------------------- -------- --------- -------- ---------- ----------
Switch#
Software Configuration Guide—Release IOS XE 3.3.0SG and IOS 15.1(1)SG
23-8
To prevent the port from shutting down, use the errdisable detect cause bpduguard shutdown
vlan global configuration command to shut down only the offending VLAN on the port where
the violation occurred.
Blocking Listening Learning Forwarding STP Active
34 VLANs 0
Purpose
Enables BPDU guard on all the switch's
PortFast-configured interfaces.
Use the no keyword to disable BPDU guard.
Exits configuration mode.
Verifies the BPDU configuration.
0
0
36
Chapter 23
Configuring Optional STP Features
36
OL-25340-01

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents