C H A P T E R 8 Configuring Spanning Tree Portfast, Uplinkfast, And Backbonefast, And Loop Guard; Disabling Spanning Tree Portfast; Understanding How Portfast Bpdu Guard Works; Configuring Portfast Bpdu Guard - Cisco WS-C4003 - Catalyst 4000 Chassis Switch Software Configuration Manual

Software guide
Table of Contents

Advertisement

Chapter 8
Configuring Spanning Tree PortFast, UplinkFast, and BackboneFast, and Loop Guard
4/1
4/1
4/1
Console> (enable)

Disabling Spanning Tree PortFast

To disable PortFast on a switch port, perform this task in privileged mode:
Task
Step 1
Disable PortFast on a switch port.
Step 2
Verify the PortFast setting.
This example shows how to disable PortFast on port 3 of module 4:
Console> (enable) set spantree portfast 4/1 disable
Spantree port 4/1 fast start disabled.
Console> (enable)

Understanding How PortFast BPDU Guard Works

To prevent loops from occuring in a network, the spanning tree PortFast mode is supported only on
nontrunking access ports because these ports typically do not transmit or receive BPDUs. The most
secure implementation of PortFast is to enable it only on ports that connect end stations to switches.
Because PortFast can be enabled on nontrunking ports connecting two switches, spanning tree loops can
occur because BPDUs are still being transmitted and received on those ports.
PortFast BPDU guard prevents loops by moving a nontrunking port into an errdisable state when a BPDU
is received on that port. When BPDU guard is enabled on the switch, spanning tree shuts down
PortFast-configured interfaces that receive BPDUs, instead of putting them into the spanning tree
blocking state. In a valid configuration, PortFast-configured interfaces do not receive BPDUs. If a
PortFast-configured interface receives a BPDU, an invalid configuration exists, such as connection of an
unauthorized device. BPDU guard provides a secure response to invalid configurations because the
administrator must manually put the interface back in service.
Note
When enabled on the switch, spanning tree applies BPDU guard to all PortFast-configured interfaces.

Configuring PortFast BPDU Guard

These sections describe how to configure PortFast BPDU guard on the switch:
78-12647-02
524
blocking
1003
not-connected
1005
not-connected
Enabling PortFast BPDU Guard, page 8-4
Disabling PortFast BPDU Guard, page 8-5
Software Configuration Guide—Catalyst 4000 Family, Catalyst 2948G, Catalyst 2980G, Releases 6.3 and 6.4
Understanding How PortFast BPDU Guard Works
19
20
enabled
19
20
enabled
19
4
enabled
Command
set spantree portfast mod_num/port_num
disable
show spantree mod_num/port_num
8-3

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Catalyst 4000 seriesCatalyst 2948gCatalyst 2980g

Table of Contents