1-38
stp root-protection
Syntax
z
Ethernet port view:
stp root-protection
undo stp
root-protection
z
System view:
stp interface interface-list root-protection
undo stp
interface interface-list root-protection
View
System view, Ethernet port view
Parameters
interface-list
: Ethernet port list. You can specify multiple Ethernet ports by providing this argument in the
form of
interface-list =
{
interface-type interface-number
[
to
interface-type interface-number
] } &<1-10>,
where &<1-10> means that you can provide up to 10 port indexes/port index ranges for this argument.
Description
z
Use the
stp root-protection
command to enable the root guard function on the current port. Use
the
undo stp root-protection
command to restore the root guard function to the default state on
the current port.
z
Use the
stp interface root-protection
command to enable the root guard function on specified
port(s) in system view. Use the
undo stp interface root-protection
command to restore the root
guard function to the default state on specified port(s) in system view.
By default, the root guard function is disabled.
Because of configuration errors or malicious attacks, the valid root bridge in the network may receive
configuration BPDUs with their priorities higher than that of the root bridge, which causes new root
bridge to be elected and network topology jitter to occur. In this case, flows that should have traveled
along high-speed links are led to low-speed links, causing network congestion.
You can avoid this problem by utilizing the root guard function. Root-guard-enabled ports can only be
kept as designated ports in all MSTIs. When a port of this type receives configuration BPDUs with
higher priorities, it turns to the discarding state before it is specified as a non-designated port and stops
forwarding packets (as if it is disconnected from the link). It resumes the normal state if it does not
receive any configuration BPDUs with higher priorities for a specified period.
z
You are recommended to enable root guard on the designated ports of a root bridge.
z
Loop guard, root guard, and edge port settings are mutually exclusive. With one of these functions
enabled on a port, any of the other two functions cannot take effect even if you have configured it
on the port.
Summary of Contents for 5500-EI Series
Page 43: ...2 6 ...
Page 76: ...1 17 ...
Page 228: ...ii stp transmit limit 1 44 vlan mapping modulo 1 45 vlan vpn tunnel 1 46 ...
Page 477: ...5 24 Sysname vlan 2 Sysname vlan2 service type multicast ...
Page 503: ...2 3 System View return to User View with Ctrl Z Sysname dot1x url http 192 168 19 23 ...
Page 519: ...iii ...
Page 597: ...2 2 security policy server 192 168 0 1 user name format without domain ...
Page 648: ...1 9 Examples Clear static ARP entries Sysname reset arp static ...
Page 663: ...4 3 Sysname resilient arp interface vlan interface 2 ...
Page 767: ...1 28 From 12 00 Jan 1 2008 to 12 00 Jun 1 2008 ...
Page 1111: ...ii xmodem get 3 18 ...
Page 1314: ...A 44 Z ...