Stp Tc-Protection - 3Com 5500-EI PWR Reference Manual

Hide thumbs Also See for 5500-EI PWR:
Table of Contents

Advertisement

Examples
# Enable the root guard function on Ethernet 1/0/1.
Enable the root guard function on Ethernet 1/0/1 in Ethernet port view.
<Sysname> system-view
System View: return to User View with Ctrl+Z.
[Sysname] interface Ethernet 1/0/1
[Sysname-Ethernet1/0/1] stp root-protection
Enable the root guard function on Ethernet 1/0/1 in system view.
<Sysname> system-view
System View: return to User View with Ctrl+Z.
[Sysname] stp interface Ethernet 1/0/1 root-protection
# Enable the root guard function on Ethernet 1/0/2 to Ethernet 1/0/4 in system view.
<Sysname> system-view
System View: return to User View with Ctrl+Z.
[Sysname] stp interface Ethernet 1/0/2 to Ethernet 1/0/4 root-protection

stp tc-protection

Syntax
stp tc-protection enable
stp tc-protection disable
View
System view
Parameters
None
Description
Use the stp tc-protection enable command to enable the TC-BPDU attack guard function.
Use the stp tc-protection disable command to disable the TC-BPDU attack guard function.
By default, the TC-BPDU guard attack function is enabled, and the MAC address table and ARP entries
can be removed for up to six times within 10 seconds.
Normally, a switch removes the MAC address table and ARP entries upon receiving TC-BPDUs. If a
malicious user sends a large amount of TC-BPDUs to a switch in a short period, the switch may be busy
in removing the MAC address table and ARP entries frequently, which may affect spanning tree
calculation, occupy large amount of bandwidth and increase switch CPU utilization.
With the TC-BPDU attack guard function enabled, a switch performs a removing operation upon
receiving a TC-BPDU and triggers a timer (set to 10 seconds by default) at the same time. Before the
timer expires, the switch only performs the removing operation for limited times (up to six times by
default) regardless of the number of the TC-BPDUs it receives. Such a mechanism prevents a switch
from being busy in removing the MAC address table and ARP entries.
Examples
# Enable the TC-BPDU attack guard function on the switch.
1-39

Advertisement

Chapters

Table of Contents
loading

This manual is also suitable for:

5500-ei series

Table of Contents