DGS-3700-12/DGS-3700-12G Series Layer 2 Gigabit Ethernet User Manual
228
Click
Apply
to implement changes.
BPDU Attack Protection Settings
This window is used to configure the BPDU protection function for the ports on the switch. In generally, there are two
states in BPDU protection function. One is normal state, and another is under attack state. The under attack state
have three modes: drop, block, and shutdown. A BPDU protection enabled port will enter an under attack state when it
receives one STP BPDU packet. And it will take action based on the configuration. Thus, BPDU protection can only be
enabled on STP-disabled port.
BPDU protection has a higher priority than the Forward BPDU setting configured by configure STP command in the
determination of BPDU handling. That is, when Forward BPDU is configured to forward the STP BPDU but BPDU
protection is enabled, then the port will not forward STP BPDU.
BPDU protection also has a higher priority than the BPDU tunnel port setting in determination of BPDU handling. That
is, when a port is configured as BPDU tunnel port for STP, it will forward STP BPDU. But if the port is BPDU
protection enabled. Then the port will not forward STP BPDU.
To view this window, click
Security > BPDU Attack Protection
, as shown below:
Figure 8- 39 BPDU Protection Settings window
The fields that can be configured are described below:
Parameter Description
BPDU Attack
Protection State
Enable or disable the BPDU Attack Protection state.
Trap State
Specify the trap state. The default state is none.
Log State
Specify the log state. The default state is both.
Recover Time
Specify the BPDU protection Auto-Recovery timer. The default value is
60
seconds.
Alternatively, tick the Infinite check box.
From Port/To Port
Select a range of ports to use for this configuration.
State
Enable or disable the mode for a specific port.
Mode
Specify the BPDU protection mode. The default mode is
Shutdown
.
Drop
– Drop all received BPDU packets when the port enters under attack state.
Block
– Drop all packets (include BPDU and normal packets) when the port enters under
attack state.
Shutdown
– Shut down the port when the port enters under attack state.