136
C
HAPTER
20: MSTP C
ONFIGURATION
Performing the mCheck operation in system view
Performing the mCheck operation in Ethernet port view
CAUTION:
The
stp mcheck
command takes effect only when the switch operate in
MSTP mode, and does not take effect when the switch operates in STP/RSTP mode.)
Configuration Example
1
Perform the mCheck operation on GigabitEthernet1/0/1 port (assuming that the
switch operates in MSTP mode and the port operates in the STP/RSTP mode).
■
Configure in system view.
<S4200G>
system-view
System View: return to User View with Ctrl+Z.
[4200G]
stp interface GigabitEthernet1/0/1 mcheck
■
Configure in Ethernet port view.
<S4200G>
system-view
System View: return to User View with Ctrl+Z.
[4200G]
interface GigabitEthernet1/0/1
[4200G-GigabitEthernet1/0/1]
stp mcheck
Protection Function
Configuration
Introduction
The following protection functions are provided on MSTP-enabled switches: BPDU
protection, root protection, loop prevention, and TC-BPDU attack prevention.
BPDU protection
Normally, the access ports of the devices operating on the access layer directly
connect to terminals (such as PCs) or file servers. These ports are usually configured as
edge ports to achieve rapid transition. But they resume non-edge ports automatically
upon receiving configuration BPDUs, which causes spanning tree regeneration and
network topology jitter.
Normally, no configuration BPDU will reach edge ports. But malicious users can attack
a network by sending configuration BPDUs deliberately to edge ports to cause
network jitter. You can prevent this type of attacks by utilizing the BPDU protection
function. With this function enabled on a switch, the switch shuts down the edge
ports that receive configuration BPDUs and then reports these cases to the
administrator. If a port is shut down, only the administrator can restore it.
Table 109
Perform the mCheck operation in system view
Operation
Command
Description
Enter system view
System-view
—
Perform the mCheck
operation
stp
[
interface
interface-list
]
mcheck
Required
Table 110
Perform the mCheck operation in Ethernet port view
Operation
Command
Description
Enter system view
system-view
—
Enter Ethernet port
view
interface
interface-type
interface-number
—
Perform the mCheck
operation
stp mcheck
Required
Summary of Contents for 4200G 12-Port
Page 10: ...8 CONTENTS...
Page 14: ...4 ABOUT THIS GUIDE...
Page 46: ...32 CHAPTER 5 LOGGING IN THROUGH WEB BASED NETWORK MANAGEMENT SYSTEM...
Page 48: ...34 CHAPTER 6 LOGGING IN THROUGH NMS...
Page 60: ...46 CHAPTER 9 VLAN CONFIGURATION...
Page 64: ...50 CHAPTER 10 MANAGEMENT VLAN CONFIGURATION...
Page 80: ...66 CHAPTER 13 GVRP CONFIGURATION...
Page 98: ...84 CHAPTER 15 LINK AGGREGATION CONFIGURATION...
Page 112: ...98 CHAPTER 18 MAC ADDRESS TABLE MANAGEMENT...
Page 126: ...112 CHAPTER 19 LOGGING IN THROUGH TELNET...
Page 162: ...148 CHAPTER 20 MSTP CONFIGURATION...
Page 274: ...260 CHAPTER 29 IGMP SNOOPING CONFIGURATION...
Page 276: ...262 CHAPTER 30 ROUTING PORT JOIN TO MULTICAST GROUP CONFIGURATION...
Page 298: ...284 CHAPTER 33 SNMP CONFIGURATION...
Page 304: ...290 CHAPTER 34 RMON CONFIGURATION...
Page 338: ...324 CHAPTER 36 SSH TERMINAL SERVICES...
Page 356: ...342 CHAPTER 38 FTP AND TFTP CONFIGURATION...
Page 365: ...Information Center Configuration Example 351 S4200G terminal logging...
Page 366: ...352 CHAPTER 39 INFORMATION CENTER...
Page 378: ...364 CHAPTER 40 BOOTROM AND HOST SOFTWARE LOADING...
Page 384: ...370 CHAPTER 41 Basic System Configuration and Debugging...
Page 388: ...374 CHAPTER 43 NETWORK CONNECTIVITY TEST...
Page 406: ...392 CHAPTER 45 CONFIGURATION OF NEWLY ADDED CLUSTER FUNCTIONS...