![H3C S12500R Series Configuration Examples Download Page 4](http://html1.mh-extra.com/html/h3c/s12500r-series/s12500r-series_configuration-examples_575185004.webp)
2
Example: Configuring link layer attack
protection
Network configuration
, Device A, Device B, and Device C run MSTP. Device B acts as the root bridge,
and HundredGigE 1/0/1 on Device C is blocked.
Configure the following features to prevent link layer attacks:
•
Configure root guard on HundredGigE 1/0/1 and HundredGigE 1/0/2 of Device B for Device B to
act as the root bridge.
•
Configure loop guard on HundredGigE 1/0/2 of Device C to prevent temporary loops. The loop
guard feature keeps the port in
Discarding
state in all MSTIs when it receives no BPDU.
•
Configure BPDU guard on ports at the access side of Device A and Device C. The BPDU guard
feature prevents the ports from performing spanning tree calculations when it receives forged
BPDUs with a higher priority.
•
Enable TC-BPDU guard on Device A, Device B, and Device C. The TC-BPDU guard feature
prevents a large number of TC-BPDUs from affecting the network in a short time.
•
Configure broadcast and multicast suppression on the designated ports of Device B and all
ports on Device A and Device C. When incoming broadcast or multicast traffic exceeds the
threshold (6400 pps), an interface discards broadcast or multicast packets until the traffic drops
below the threshold.
Figure 1 Network diagram
Device A
Device B
Device C
HGE1/0/1
HGE1/0/2
HGE1/0/1
HGE1/0/2
HGE1/0/2
HGE1/0/1
Dep 1
Dep 2
Dep 3
Dep 4
Dep 5
Network
HGE1/0/3
HGE1/0/3