Configuring Tc-Bpdu Attack Guard - H3C S5100-SI Operation Manual

Ethernet switches
Hide thumbs Also See for H3C S5100-SI:
Table of Contents

Advertisement

period, the switch selects a new root port; the original root port becomes a designated port; and the
blocked ports turns to the forwarding state. This may cause loops in the network.
The loop guard function suppresses loops. With this function enabled, if link congestions or
unidirectional link failures occur, both the root port and the blocked ports become designated ports and
turn to the discarding state. In this case, they stop forwarding packets, and thereby loops can be
prevented.
You are recommended to enable loop guard on the root port and alternate port of a non-root bridge.
Loop guard, root guard, and edge port settings are mutually exclusive. With one of these functions
enabled on a port, any of the other two functions cannot take effect even if you have configured it
on the port.
Configuration Prerequisites
MSTP runs normally on the switch.
Configuration procedure
Follow these steps to configure loop guard:
To do...
Enter system view
Enter Ethernet port view
Enable the loop guard function on
the current port
Configuration example
# Enable the loop guard function on GigabitEthernet 1/0/1.
<Sysname> system-view
[Sysname] interface GigabitEthernet 1/0/1
[Sysname-GigabitEthernet1/0/1] stp loop-protection

Configuring TC-BPDU Attack Guard

Normally, a switch removes its MAC address table and ARP entries upon receiving Topology Change
BPDUs (TC-BPDUs). If a malicious user sends a large amount of TC-BPDUs to a switch in a short
period, the switch may be busy in removing the MAC address table and ARP entries, which may affect
spanning tree calculation, occupy large amount of bandwidth and increase switch CPU utilization.
With the TC-BPDU attack guard function enabled, a switch performs a removing operation upon
receiving a TC-BPDU and triggers a timer (set to 10 seconds by default) at the same time. Before the
timer expires, the switch only performs the removing operation for limited times (up to six times by
Use the command...
system-view
interface interface-type
interface-number
stp loop-protection
1-37
Remarks
Required
The loop guard function is
disabled by default.

Advertisement

Table of Contents
loading

This manual is also suitable for:

H3c s5100-ei

Table of Contents