| Spanning Tree Commands
C
33
HAPTER
spanning-tree bpdu-
guard
E
XAMPLE
Console(config)#interface ethernet 1/5
Console(config-if)#spanning-tree edge-port
Console(config-if)#spanning-tree bpdu-filter
Console(config-if)#
R
C
ELATED
OMMANDS
spanning-tree edge-port (798)
This command shuts down an edge port (i.e., an interface set for fast
forwarding) if it receives a BPDU. Use the no form to disable this feature.
S
YNTAX
[no] spanning-tree bpdu-guard
D
S
EFAULT
ETTING
Disabled
C
M
OMMAND
ODE
Interface Configuration (Ethernet, Port Channel)
C
U
OMMAND
SAGE
◆
An edge port should only be connected to end nodes which do not
generate BPDUs. If a BPDU is received on an edge port, this indicates
an invalid network configuration, or that the switch may be under
attack by a hacker. If an interface is shut down by BPDU Guard, it must
be manually re-enabled using the
command.
Before enabling BPDU Guard, the interface must be configured as an
◆
edge port with the
spanning-tree edge-port
the edge port attribute is disabled on an interface, BPDU Guard will also
be disabled on that interface.
E
XAMPLE
Console(config)#interface ethernet 1/5
Console(config-if)#spanning-tree edge-port
Console(config-if)#spanning-tree bpdu-guard
Console(config-if)#
R
C
ELATED
OMMANDS
spanning-tree edge-port (798)
spanning-tree spanning-disabled (805)
– 796 –
no spanning-tree spanning-disabled
command. Also note that if