Operation Manual – MSTP
H3C S5100-SI/EI Series Ethernet Switches
Chapter 1 MSTP Configuration
1-47
III. Configuration example
# Enable the TC-BPDU attack guard function
<Sysname> system-view
[Sysname] stp tc-protection enable
# Set the maximum times for the switch to remove the MAC address table and ARP
entries within 10 seconds to 5.
<Sysname> system-view
[Sysname] stp tc-protection threshold 5
1.6.7 Configuring BPDU Dropping
Follow these steps to configure BPDU dropping:
To do...
Use the command...
Remarks
Enter system view
system-view
—
Enter Ethernet port view
interface
interface-name
—
Enable BPDU dropping
bpdu-drop any
Required
BPDU dropping is
disabled by default.
# Enable BPDU dropping on GigabitEthernet 1/0/1.
<Sysname>system-view
[Sysname] interface GigabitEthernet 1/0/1
[Sysname-GigabitEthernet1/0/1] bpdu-drop any
1.7 Configuring Digest Snooping
1.7.1 Introduction
According to IEEE 802.1s, two interconnected switches can communicate with each
other through MSTIs in an MST region only when the two switches have the same MST
region-related configuration. Interconnected MSTP-enabled switches determine
whether or not they are in the same MST region by checking the configuration IDs of
the BPDUs between them (A configuration ID contains information such as region ID
and configuration digest).
As some other manufacturers' switches adopt proprietary spanning tree protocols, they
cannot communicate with the other switches in an MST region even if they are
configured with the same MST region-related settings as the other switches in the MST
region.
This problem can be overcome by implementing the digest snooping feature. If a port
on an S5100 Ethernet switch is connected to another manufacturer's switch that has