
4-36
Follow these steps to enable root guard:
To do...
Use the command...
Remarks
Enter system view
system-view
—
Enter Ethernet
interface view, or
Layer 2
aggregate
interface view
interface interface-type
interface-number
Enter
interface view
or port group
view
Enter port group
view
port-group manual
port-group-name
Required
Use either command.
Enable the root guard function for
the port(s)
stp root-protection
Required
Disabled by default
Enabling Loop guard
By keeping receiving BPDUs from the upstream device, a device can maintain the state of the root port
and blocked ports. However, due to link congestion or unidirectional link failures, these ports may fail to
receive BPDUs from the upstream devices. In this case, the downstream device will reselect the port
roles: Those ports in forwarding state that failed to receive upstream BPDUs will become designated
ports, and the blocked ports will transition to the forwarding state, resulting in loops in the switched
network. The loop guard function can suppress the occurrence of such loops.
If a loop guard–enabled port fails to receive BPDUs from the upstream device, and if the port takes
part in STP calculation, all the instances on the port, no matter what roles the port plays, will be set to,
and stay in, the Discarding state.
Make this configuration on the root port or an alternate port of a device.
Follow these steps to enable loop guard:
To do...
Use the command...
Remarks
Enter system view
system-view
—
Enter Ethernet
interface view, or
Layer 2
aggregate
interface view
interface interface-type
interface-number
Enter
interface view
or port group
view
Enter port group
view
port-group manual
port-group-name
Required
Use either command.
Enable the loop guard function for
the ports
stp loop-protection
Required
Disabled by default
Enabling TC-BPDU guard
When receiving topology change (TC) BPDUs (the BPDUs used to notify topology changes), a switch
flushes its forwarding address entries. If someone forges TC-BPDUs to attack the switch, the switch
will receive a large number of TC-BPDUs within a short time and be busy with forwarding address
entry flushing. This affects network stability.
Содержание 4210G Series
Страница 459: ...4 8...
Страница 493: ...12 1...
Страница 968: ...19 6 000f e235 dc71 1 Config static GigabitEthernet 1 0 1 NOAGED 1 mac address es found...