94
Configuring protection features
A spanning tree device supports the following protection features:
•
BPDU guard
•
Root guard
•
Loop guard
•
Port role restriction
•
TC-BPDU transmission restriction
•
TC-BPDU guard
•
BPDU drop
Configuring BPDU guard
For access layer devices, the access ports can directly connect to the user terminals (such as PCs)
or file servers. The access ports are configured as edge ports to allow rapid transition. When these
ports receive configuration BPDUs, the system automatically sets the ports as non-edge ports and
starts a new spanning tree calculation process. This causes a change of network topology. Under
normal conditions, these ports should not receive configuration BPDUs. However, if someone uses
configuration BPDUs maliciously to attack the devices, the network will become unstable. The
spanning tree protocol provides the BPDU guard feature to protect the system against such attacks.
You can configure BPDU guard globally or on a per-interface basis. When an edge port enabled with
BPDU guard receives a configuration BPDU, the device performs the following operations:
•
Shuts down the port.
•
Notifies the NMS that the port has been shut down by the spanning tree protocol.
The device reactivates the shutdown port after the port status detection interval set by using the
shutdown-interval
command. You can also use the
stp port shutdown permanent
command to
disable the device to reactivate the shutdown port. The
stp port shutdown permanent
command
applies to edge ports that are shut down after you configure the
stp port shutdown permanent
command. To bring up these ports, use the
undo shutdown
command. For more information about
the
shutdown-interval
command, see
Fundamentals Command Reference
.
Configuration restrictions and guidelines
•
BPDU guard does not take effect on loopback-testing-enabled ports. For more information
about loopback testing, see
Interface Configuration Guide
.
•
Configure BPDU guard on a device with edge ports configured.
•
An edge port preferentially uses the port-specific BPDU guard configuration. If no port-specific
BPDU guard configuration is available, the edge port uses the global BPDU guard
configuration.
Configuration procedure
To configure BPDU guard:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
(Optional.) Disable the
device to reactivate edge
ports shut down by BPDU
guard.
stp port shutdown permanent
By default, a device reactivates
the shutdown edge ports after a
port status detection interval.
3.
Configure the BPDU guard
•
Enable BPDU guard globally:
Use one or both of the methods.
Содержание H3C S7500E-X
Страница 70: ...57 ...