Configuring Mstp Protection Functions; Establishing The Configuration Task - Huawei Quidway S7700 Configuration Manual - Ethernet

Smart routing switch
Hide thumbs Also See for Quidway S7700:
Table of Contents

Advertisement

Quidway S7700 Smart Routing Switch
Configuration Guide - Ethernet
Procedure
l
----End

9.5 Configuring MSTP Protection Functions

MSTP protection functions are as follows, and you can configure one or more functions as
required.

9.5.1 Establishing the Configuration Task

Before configuring MSTP protection functions, familiarize yourself with the applicable
environment, complete the pre-configuration tasks, and obtain the required data. This will help
you complete the configuration task quickly and accurately.
Applicable Environment
MSTP provides the following protection functions, as listed in
Table 9-6 MSTP protection
MSTP
Protection
BPDU
protection
TC protection Generally, after receiving
Issue 01 (2011-07-15)
Run the display stp [ instance instance-id ] [ interface { interface-type interface-
number } ] [ brief ] command to view spanning-tree status and statistics.
Scenario
An edge port changes to be a
non-edge port after
receiving a BPDU, which
triggers spanning tree
recalculation. If an attacker
keeps sending bogus BPDUs
to a switching device,
network flapping occurs.
TC BPDUs (packets for
advertising network
topology changes), a
switching device needs to
delete MAC entries and ARP
entries. Frequent deletion
operations will exhaust CPU
resources.
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
Table
9-6.
Configuration Impact
After BPDU protection is enabled on the
switching device, the switching device shuts
down the edge port if the edge port receives
an RST BPDU, and notifies the NMS of the
shutdown event. The attributes of the edge
port are not changed.
TC protection is used to suppress TC-BPDUs.
The number of times that TC-BPDUs are
processed by a switching device within a
given time period is configurable. If the
number of TC-BPDUs that the switching
device receives within the given time exceeds
the specified threshold, the switching device
handles TC-BPDUs only for the specified
number of times. Excessive TC-BPDUs are
processed by the switching device as a whole
for once after the timeout period expires. This
protects the switching device from frequently
deleting MAC entries and ARP entries, thus
avoiding over-burden.
9 MSTP Configuration
448

Advertisement

Table of Contents
loading

This manual is also suitable for:

Quidway s9300

Table of Contents