13
Question
Command or method
Result
Remarks
tree feature on the ports.
Is the device running
MSTP, STP, or RSTP, and
working with a Cisco
PVST+ device?
display stp
□
OK
□
Not OK
□
Not related
As a best practice to avoid
interoperability issues, set
up a Layer 3 connection to
the Cisco device.
Do the topologies of MSTIs
meet the design?
Are there as few
overlapping paths as
possible among MSTIs?
display
current-configuration
interface
□
OK
□
Not OK
□
Not related
If the topologies deviate
from the design, reassign
ports to VLANs and revise
the VLAN and instance
mappings.
For optimal load balancing,
plan VLANs and
VLAN-to-instance
mappings to minimize
overlapping paths among
different MSTIs.
Does a TC attack exist to
cause frequent STP status
changes on any ports?
display stp tc
display stp history
□
OK
□
Not OK
□
Not related
Examine the following
items in the command
output for TC attacks:
•
Incoming and
outgoing
TC/TCN
BPDU statistics.
•
Historical port role
calculation
information.
There is a risk of TC attack
if frequent STP status
changes occur on a stable
network.
Make sure you have
configured the following
settings:
•
Configure ports
connected to end-user
devices as edge ports,
and enable BPDU
guard. Alternatively,
disable the spanning
tree feature on the
ports.
•
Disable the spanning
tree feature on ports
connected to devices
that do not support
spanning tree
protocols.
•
Do not disable
TC-BPDU guard.
VRRP
Is the handshake interval
correctly set?
Are the handshake
intervals of the two ends
the same?
display vrrp
□
OK
□
Not OK
□
Not related
Change the handshake
interval to 3 seconds if the
number of VRRP groups is
smaller than 5.
If five or more VRRP
groups exist, assign three
or five VRRP groups to one
group, and configure the