Bpdu Filtering - Cisco Nexus 7000 Series Configuration Manual

Nx-os layer 2 switching
Hide thumbs Also See for Nexus 7000 Series:
Table of Contents

Advertisement

Configuring STP Extensions Using Cisco NX-OS
Layer 2 LAN interface signals an invalid configuration, such as the connection of an unauthorized device.
BPDU Guard, when enabled globally, shuts down all spanning tree edge ports when they receive a BPDU.
When enabled globally, BPDU Guard applies to all operational spanning tree edge interfaces.
Note
You can configure BPDU Guard at the interface level, using the following steps:
• BPDU Guard is configured in interface configuration mode using the spanning-tree bpduguard enable
• For a trunk port, specify an allowed VLAN list using the switchport trunk allowed vlan vlan list
BPDUs are dropped if they are not in the allowed VLAN list and BPDU Guard is enabled on the port.
In Cisco NX-OS Release 6.2(10) and later releases, the port will be error disabled when a BPDU is received
on any VLAN and BPDU Guard is enabled on the port.
The native VLAN on the trunk port is an exception. BPDUs arriving on the native VLAN are passed on
Note
to the supervisor.
BPDU Guard provides a secure response to invalid configurations, because you must manually put the Layer 2
LAN interface back in service after an invalid configuration.

BPDU Filtering

You can use BPDU Filtering to prevent the device from sending or even receiving BPDUs on specified ports.
When configured globally, BPDU Filtering applies to all operational spanning tree edge ports. You should
connect edge ports only to hosts, which typically drop BPDUs. If an operational spanning tree edge port
receives a BPDU, it immediately returns to a normal spanning tree port type and moves through the regular
transitions. In that case, BPDU Filtering is disabled on this port, and spanning tree resumes sending BPDUs
on this port.
In addition, you can configure BPDU Filtering by the individual interface. When you explicitly configure
BPDU Filtering on a port, that port does not send any BPDUs and drops all BPDUs that it receives. You can
effectively override the global BPDU Filtering setting on individual ports by configuring the specific interface.
This BPDU Filtering command on the interface applies to the entire interface, whether the interface is trunking
or not.
Caution
Use care when configuring BPDU Filtering per interface. If you explicitly configure BPDU Filtering on
a port that is not connected to a host, it can result in bridging loops because the port will ignore any BPDU
that it receives and go to forwarding.
This table lists all the BPDU Filtering combinations.
command.
command.
Cisco Nexus 7000 Series NX-OS Layer 2 Switching Configuration Guide, Release 5.x
BPDU Filtering
181

Advertisement

Table of Contents
loading

Table of Contents