Operation Manual – MSTP
H3C S3610&S5510 Series Ethernet Switches
Chapter 1 MSTP Configuration
1-47
z
Root guard
z
Loop guard
z
TC-BPDU attack guard
Note:
z
The support for the BPDU guard, root guard and loop guard functions depends on
the specific device model.
z
Among loop guard, root guard and edge port setting, only one function can take
effect on the same port at the same time.
1.9.1 Configuration prerequisites
MSTP has been correctly configured on the device.
1.9.2 Enabling BPDU Guard
Note:
z
The support for this feature depends on the specific device model.
z
We recommend that you enable BPDU guard if your device supports this function.
For access layer devices, the access ports generally connect directly with user
terminals (such as PCs) or file servers. In this case, the access ports are configured as
edge ports to allow rapid transition of these ports. When these ports receive
configuration BPDUs, the system will automatically set these ports as non-edge ports
and start a new spanning tree calculation process. This will cause a change of network
topology. Under normal conditions, these ports should not receive configuration BPDUs.
However, if someone forges configuration BPDUs maliciously to attack the devices,
network instability will occur.
MSTP provides the BPDU guard function to protect the system against such attacks.
With the BPDU guard function enabled on the devices, when edge ports receive
configuration BPDUs, MSTP will close these ports and notify the NMS that these ports
have been closed by MSTP. Those ports closed thereby can be restored only by the
network administers.