Global System Configuration
Assign Global Configuration Information
34
Best Practice User Guide for the Catalyst 3850 and Catalyst 3650 Switch Series
A switch in VTP transparent mode can create, modify, and delete VLANs (the same way as VTP
servers), but the switch does not send dynamic propagation of VLAN information across the network
and does not synchronize its VLAN configuration based on advertisements received. Configuration
changes made when the switch is in this mode are saved in the switch’s running configuration, and can
be saved to the switch’s startup configuration file.
Note
The default VTP mode for the switch is VTP server mode. This mode allows you to create, modify, and
delete VLANs and specify other configuration parameters for the entire VTP domain. VTP servers
advertise their VLAN configuration to other switches in the same VTP domain and synchronize their
VLAN configuration with other switches based on advertisements received over trunk links.
Enable Rapid Per-VLAN Spanning Tree Plus
Step 3
Enable Rapid Per-VLAN Spanning Tree Plus (PVST+), to improve the detection of indirect failures or
linkup restoration events over classic spanning tree.
Rapid PVST+ provides an instance of RSTP (IEEE 802.1w) for each VLAN, and PVST+ improves the
detection of indirect failures or linkup restoration events over the classic spanning tree (IEEE 802.1D).
Recommendation
: Enable spanning tree even if your deployment is created without any Layer 2 loops.
By enabling spanning tree, you ensure that if physical or logical loops are accidentally configured, no
actual Layer 2 loops occur.
Configure BPDU Guard for Spanning-Tree PortFast Interfaces
Step 4
Configure the Bridge Protocol Data Unit (BPDU) guard globally to protect all Spanning-Tree
PortFast-enabled interfaces.
The BPDU guard protects against a user plugging a switch into an access port, which many cause a
catastrophic, undetected spanning-tree loop.
If a Spanning-Tree PortFast-configured interface receives a BPDU, an invalid configuration exists, such
as the connection of an unauthorized device. The BPDU Guard feature prevents loops by moving a
nontrunking interface into an errdisable state when a BPDU is received on an interface when STPF is
enabled.
The BPDU configuration protects STPF-enabled interfaces by disabling the port if another switch is
plugged into the port.
This command should configured globally, not at the interface level.