DGS-1510/ME Series Metro Ethernet Switch CLI Reference Guide
118
Chapter 11
BPDU Attack Protection Command
List
config bpdu_protection ports
[<portlist> | all ] {state [enable | disable] | mode [ drop | block | shutdown} (1)
config bpdu_protection recovery_timer
[<sec 60-1000000> | infinite]
config bpdu_protection
[trap | log] [none | attack_detected | attack_cleared | both]
enable bpdu_protection
disable bpdu_protection
show bpdu_protection
{ports {<portlist>}}
11-1
config bpdu_protection ports
Description
This command is used to configure the BPDP protection function for the ports on the Switch. In generally, there are
two states in BPDU protection function. One is normal state, and another is under attack state. The under attack
state have three modes: drop, block, and shutdown. A BPDU protection enabled port will enter under attack state
when it receives one STP BPDU packet. And it will take action based on the configuration. Thus, BPDU protection
can only be enabled on STP-disabled port.
BPDU protection has a higher priority than the Forward BPDU (FBPDU) setting configured by configure STP
command in the determination of BPDU handling. That is, when FBPDU is configured to forward STP BPDU but
BPDU protection is enabled, then the port will not forward STP BPDU.
Format
config bpdu_protection ports [<portlist> | all ] {state [enable | disable] | mode [ drop | block | shutdown]}(1)
Parameters
<portlist>
- Specifies a range of ports to be configured (port number).
all
- Specifies that all the port will be configured.
state
- Specifies the BPDU protection state. The default state is disable
enable
- Specifies to enable BPDU protection.
disable
- Specifies to disable BPDU protection.
mode
- Specifies the BPDU protection mode. The default mode is shutdown
drop
- Specifies to drop all received BPDU packets when the port enters under_attack state.
block
- Specifies to drop all packets (include BPDU and normal packets) when the port enters under_attack
state.
shutdown
- Specifies to shut down the port when the port enters under_attack state.
Restrictions
Only Administrators, Operators and Power-Users can issue this command.
Example
To set the port state enable and drop mode:
Содержание DGS-1510/ME Series
Страница 1: ......