Command Manual (For Soliton) – MSTP
H3C S3100 Series Ethernet Switches
Chapter 1 MSTP Configuration Commands
1-54
entries frequently, which may affect spanning tree calculation, occupy large amount of
bandwidth and increase switch CPU utilization.
With the TC-BPDU attack guard function enabled, a switch performs a removing
operation upon receiving a TC-BPDU and triggers a timer (set to 10 seconds by default)
at the same time. Before the timer expires, the switch only performs the removing
operation for limited times (up to six times by default) regardless of the number of the
TC-BPDUs it receives. Such a mechanism prevents a switch from being busy in
removing the MAC address table and ARP entries.
Examples
# Enable the TC-BPDU attack guard function on the switch.
<Sysname> system-view
System View: return to User View with Ctrl+Z.
[Sysname] stp tc-protection enable
1.1.49 stp tc-protection threshold
Syntax
stp tc-protection threshold number
undo stp tc-protection threshold
View
System view
Parameters
number
: Maximum number of times that a switch can remove the MAC address table
and ARP entries within each 10 seconds, in the range of 1 to 255.
Description
Use the
stp tc-protection threshold
command to set the maximum number of times
that a switch can remove the MAC address table and ARP entries within each 10
seconds.
Use the
undo stp tc-protection threshold
command to restore the default.
Normally, a switch removes the MAC address table and ARP entries upon receiving a
TC-BPDU. If a malicious user sends large amount of TC-BPDUs to a switch in a short
period, the switch may be busy in removing the MAC address table and ARP entries,
which may affect spanning tree calculation, occupy a large amount of bandwidth and
increase switch CPU utilization.
With the TC-BPDU attack guard function enabled, a switch performs a removing
operation upon receiving a TC-BPDU and triggers a timer (set to 10 seconds by default)
at the same time. Before the timer expires, the switch only performs the removing