Enabling Bpdu Guard - Cisco ME 3400G-2CS - Ethernet Access Switch Software Configuration Manual

Ethernet access switch
Hide thumbs Also See for ME 3400G-2CS - Ethernet Access Switch:
Table of Contents

Advertisement

Configuring Optional Spanning-Tree Features
Beginning in privileged EXEC mode, follow these steps to enable Port Fast. This procedure is optional.
Command
Step 1
configure terminal
Step 2
interface interface-id
Step 3
spanning-tree portfast [trunk]
Step 4
end
Step 5
show spanning-tree interface
interface-id portfast
Step 6
copy running-config startup-config
You can use the spanning-tree portfast default global configuration command to globally enable the
Note
Port Fast feature on all nontrunking NNIs.
To disable the Port Fast feature, use the spanning-tree portfast disable interface configuration
command.

Enabling BPDU Guard

When you globally enable BPDU guard on NNIs that are Port Fast-enabled (the interfaces are in a Port
Fast-operational state), spanning tree shuts down Port Fast-enabled NNIs that receive BPDUs.
In a valid configuration, Port Fast-enabled interfaces do not receive BPDUs. Receiving a BPDU on a
Port Fast-enabled interface signals an invalid configuration, such as the connection of an unauthorized
device, and the BPDU guard feature puts the interface in the error-disabled state. The BPDU guard
feature provides a secure response to invalid configurations because you must manually put the interface
back in service. Use the BPDU guard feature in a service-provider network to prevent an access port
from participating in the spanning tree.
Cisco ME 3400 Ethernet Access Switch Software Configuration Guide
16-6
Chapter 16
Purpose
Enter global configuration mode.
Specify an interface to configure, and enter interface configuration
mode. If the interface is not an NNI, you must enter the port-type nni
interface configuration command before enabling Port Fast.
Enable Port Fast on an access port connected to a single workstation or
server. By specifying the trunk keyword, you can enable Port Fast on a
trunk port.
Note
To enable Port Fast on trunk ports, you must use the
spanning-tree portfast trunk interface configuration command.
The spanning-tree portfast command does not work on trunk
ports.
Make sure that there are no loops in the network between the
Caution
trunk port and the workstation or server before you enable
Port Fast on a trunk port.
By default, Port Fast is disabled on all NNIs. UNIs do not participate in
STP.
Return to privileged EXEC mode.
Verify your entries.
(Optional) Save your entries in the configuration file.
Configuring Optional Spanning-Tree Features
78-17058-01

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents