
Operation Manual – MSTP
H3C S9500 Series Routing Switches
Chapter 1 MSTP Configuration
1-48
A device removes the corresponding forwarding entries upon receiving a TC-BPDU (a
PDU notifying of a topology change). If a malicious user forges large amount of
TC-BPDUs and sends them to a device in a short period, the device may be busy
removing the forwarding entries, decreasing the performance of the switch and
introducing potential stability risks.
The TC-BPDU attack guard function can relieve a switch from this dilemma. With this
function enabled, the device removes the forwarding address entries only once within a
specific period (10 seconds) after it receives a TC-BPDU. At the same time, the system
monitors whether other TC-BPDUs are received within that period. If so, the device will
perform another removing operation after the period elapses. This prevents removing
forwarding address entries frequently.
1.9.1 Configuration Prerequisites
MSTP has been correctly configured on the device.
1.9.2 Enabling the BPDU Guard Function
Note:
We recommend that you enable the BPDU guard function.
I. Configuration procedure
Following these steps to enable the BPDU guard function:
To do...
Use the command...
Remarks
Enter system view
system-view
—
Enable the BPDU guard
function for the device
stp bpdu-protection
Required
Disabled by default
II. Configuration example
# Enable the BPDU guard function.
<Sysname> system-view
[Sysname] stp bpdu-protection