DGS-1210/ME Metro Ethernet Switch CLI Reference Guide
299
37
BPDU ATTACK PROTECTION COMMANDS
The BPDU Attack Protection commands in the Command Line Interface (CLI) are listed (along with the
appropriate parameters) in the following table.
Command
Parameter
config bpdu_protection
ports
[<portlist> | all ] [state [enable | disable] | mode [ drop | block | shutdown ]]
config bpdu_protection
recovery_timer
[<sec 60-1000000> | infinite]
config bpdu_protection
[ trap | log ] [ none | attack_detected | attack_cleared | both ]
enable bpdu_protection
disable
bpdu_protection
show bpdu_protection
Each command is listed in detail, as follows:
config bpdu_protection ports
Purpose
Used to configure the BPDU Attack Protection state and mode of a
port.
Syntax
config bpdu_protection ports [<portlist> | all ] [state [enable |
disable] | mode [ drop | block | shutdown ]]
Description
The
config bpdu_protection ports
command is used to setup the
BPDU Attack Protection function for the ports on the switch.
The config bpdu_protection ports command is used to configure the
BPDU protection function for ports on the Switch. There are two
states of BPDU attack protection function; the normal state and the
under attack state. The under attack state has three moDGS: drop,
block, and shutdown moDGS. A BPDU attack protection enabled
port will enter under attack state when it receives an STP BPDU
frame, then take action based on the configuration mode. BPDU
attack protection can ONLY be used for ports that do not have STP
enabled.
STP for ports and BPDU attack protection on ports are not
compatible. Furthermore BPDU attack protection enabled on a port
effectively disables all STP function on the port. Keep in mind the
following points regarding this:
BPDU attack protection has a higher priority than STP BPDU
forwarding (i.e. the fbpdu setting of the config stp command is
enabled) when determining how to handle BPDU. That is, when
fbpbu is enabled to forward STP BPDU frames AND the BPDU
attack protection function is enabled, the port will not forward STP
BPDU frames.
BPDU attack protection has a higher priority than BPDU tunnel port
setting (i.e. config bpdu_tunnel ports command) when determining