Bpdu Attack Protection - D-Link DXS-3600 Series Reference Manual

Layer 2/3 managed 10gigabut ethernet switch
Hide thumbs Also See for DXS-3600 Series:
Table of Contents

Advertisement

DXS-3600 Series Layer 3 Managed 10Gigabit Ethernet Switch Web UI Reference Guide
The fields that can be configured in ARP Spoofing Prevention are described below:
Parameter
Unit
From Port ~ To Port
Gateway IP
Gateway MAC
Click the Apply button to accept the changes made.
Click the Delete button to remove the specified entry.

BPDU Attack Protection

This window is used to view and configure the BPDU attack protection settings. In generally, there are
two states in the BPDU attack protection function. One is normal state, and another is under attack state.
The under attack state have three modes: drop, block, and shutdown. A BPDU protection enabled port
will enter an under attack state when it receives one STP BPDU packet and it will take action based on
the configuration. Thus, BPDU protection can only be enabled on the STP-disabled port.
BPDU protection has a higher priority than the (Forward BPDU) FBPDU setting configured by configure
STP command in the determination of BPDU handling. That is, when FBPDU is configured to forward
STP BPDU but BPDU protection is enabled, then the port will not forward STP BPDU.
BPDU protection also has a higher priority than the BPDU tunnel port setting in determination of BPDU
handling. That is, when a port is configured as BPDU tunnel port for STP, it will forward STP BPDU. But if
the port is BPDU protection enabled. Then the port will not forward STP BPDU.
To view the following window, click Security > BPDU Attack Protection, as shown below:
Figure 9-62 ARP Spoofing Prevention Window
Description
Select the switch unit that will be used for this configuration here.
Select the appropriate port range used for the configuration here.
Enter the gateway's IP address used here.
Enter the gateway's MAC address used here.
509

Advertisement

Table of Contents
loading

Table of Contents