3Com 7700 Configuration Manual page 180

Hide thumbs Also See for 7700:
Table of Contents

Advertisement

172
C
8: STP O
HAPTER
PERATION
Perform the following configurations in Ethernet port view.
Table 15 Set mCheck for the Port
Operation
Set mCheck for the port
This command can be used when the bridge runs RSTP in RSTP mode, but it
cannot be used when the bridge runs RSTP in STP-compatible mode.
Configuring the Switch Security Function
An RSTP switch provides BPDU protection and root protection functions.
For an access device, the access port is generally directly connected to the user PC
or a file server, and the access port is set to edge port to implement fast transition.
When this port receives a BPDU packet, the system automatically sets it as a
non-edge port and recalculates the spanning tree, which causes network topology
flapping. In a normal case, these ports do not receive STP BPDU. If someone forges
BPDU to attack the switch, the network flaps. BPDU protection function is used
against such network attack.
In case of configuration error or malicious attack, the primary root may receive the
BPDU with a higher priority and then loose its place, which causes network
topology change errors. Due to the erroneous change, the traffic that is supposed
to travel over the high-speed link may be pulled to the low-speed link and
congestion occurs on the network. The root protection function is used against
such a problem.
The root port and other blocked ports maintain their state according to the BPDUs
send by the uplink switch. Once the link is blocked or is encountering a faulty
condition, the ports cannot receive BPDUs and the switch selects the root port
again. In this case, the root port becomes a BDPU-specified port and the former
blocked ports enter a forwarding state. As a result, a link loop is generated.
The security functions can control the generation of a loop. After it is enabled, the
root port cannot be changed, the blocked port remains in the discarding state and
does not forward packetsto avoid link loop.
Perform the following configuration in the designated views.
Table 16 Configure the Switch Security Function
Operation
Configure switch BPDU
protection (from system view)
Restore the disabled BPDU
protection state, as defaulted,
(from system view).
Configure switch Root
protection (from system view)
Restore the disabled Root
protection state, as defaulted,
(from Ethernet port view)
Command
stp mcheck
Command
stp bpdu-protection
undo stp bpdu-protection
stp root-protection
undo stp root-protection

Advertisement

Table of Contents
loading

Table of Contents