Chapter 16
| Spanning Tree Commands
– 379 –
conjunction with edge ports which should only connect end stations to the
switch, and therefore do not need to process BPDUs. However, note that if a
trunking port connected to another switch or bridging device is mistakenly
configured as an edge port, and BPDU filtering is enabled on this port, this
might cause a loop in the spanning tree.
◆
Before enabling BPDU Filter, the interface must first be configured as an edge
port with the
spanning-tree edge-port
command.
Example
Console(config)#interface ethernet 1/5
Console(config-if)#spanning-tree edge-port
Console(config-if)#spanning-tree bpdu-filter
Console(config-if)#
Related Commands
spanning-tree edge-port (381)
spanning-tree
bpdu-guard
This command shuts down an edge port (i.e., an interface set for fast forwarding) if
it receives a BPDU. Use the
no
form to disable this feature.
Syntax
[
no
]
spanning-tree
bpdu-guard
Default Setting
Disabled
Command Mode
Interface Configuration (Ethernet, Port Channel)
Command Usage
◆
An edge port should only be connected to end nodes which do not generate
BPDUs. If a BPDU is received on an edge port, this indicates an invalid network
configuration, or that the switch may be under attack by a hacker. If an
interface is shut down by BPDU Guard, it must be manually re-enabled using
the
no
spanning-tree spanning-disabled
command.
◆
Before enabling BPDU Guard, the interface must be configured as an edge port
with the
spanning-tree edge-port
command. Also note that if the edge port
attribute is disabled on an interface, BPDU Guard will also be disabled on that
interface.
Summary of Contents for EX-3524
Page 2: ......
Page 28: ...Figures 28 ...
Page 34: ...Section I Getting Started 34 ...
Page 58: ...Chapter 1 Initial Switch Configuration Setting the System Clock 58 ...
Page 72: ...Chapter 2 Using the Command Line Interface CLI Command Groups 72 ...
Page 156: ...Chapter 5 SNMP Commands Notification Log Commands 156 ...
Page 164: ...Chapter 6 Remote Monitoring Commands 164 ...
Page 218: ...Chapter 7 Authentication Commands Management IP Filter 218 ...
Page 268: ...Chapter 8 General Security Measures Port based Traffic Segmentation 268 ...
Page 292: ...Chapter 9 Access Control Lists ACL Information 292 ...
Page 312: ...Chapter 10 Interface Commands Power Savings 312 ...
Page 324: ...Chapter 11 Link Aggregation Commands Trunk Status Display Commands 324 ...
Page 366: ...Chapter 15 Address Table Commands 366 ...
Page 428: ...Chapter 17 VLAN Commands Configuring Voice VLANs 428 ...
Page 572: ...Chapter 25 IP Interface Commands IPv6 Interface 572 ...
Page 578: ...Section I Appendices 578 ...