1-41
By keeping receiving BPDUs from the upstream device, a device can maintain the state of the root port
and blocked ports. However, due to link congestion or unidirectional link failures, these ports may fail to
receive BPDUs from the upstream devices. In this case, the downstream device will reselect the port
roles: those ports in forwarding state that failed to receive upstream BPDUs will become designated
ports, and the blocked ports will transition to the forwarding state, resulting in loops in the switched
network. The loop guard function can suppress the occurrence of such loops.
If a loop guard–enabled port fails to receive BPDUs from the upstream device, and if the port took part
in STP calculation, all the instances on the port, no matter what roles the port plays, will be set to, and
stay in, the Discarding state.
Follow these steps to enable loop guard:
To do...
Use the command...
Remarks
Enter system view
system-view
—
Enter Ethernet
interface view,
or Layer 2
aggregate
interface view
interface interface-type
interface-number
Enter
interface view
or port group
view
Enter port
group view
port-group manual
port-group-name
Required
Use either command.
Configurations made in
interface view will take effect
on the current port only;
configurations made in port
group view will take effect on
all ports in the port group.
Enable the loop guard function
for the port(s)
stp loop-protection
Required
Disabled by default
Enabling TC-BPDU Guard
When receiving topology change (TC) BPDUs (the BPDUs used to notify topology changes), a switch
flushes its forwarding address entries. If someone forges TC-BPDUs to attack the switch, the switch will
receive a larger number of TC-BPDUs within a short time and be busy with forwarding address entry
flushing. This affects network stability.
With the TC-BPDU guard function, you can set the maximum number of immediate forwarding address
entry flushes that the switch can perform within 10 seconds after receiving the first TC-BPDU. For
TC-BPDUs received in excess of the limit, the switch performs forwarding address entry flush only
when the 10-second timer expires. This prevents frequent flushing of forwarding address entries.
Follow these steps to enable TC-BPDU guard:
To do...
Use the command...
Remarks
Enter system view
system-view
—
Enable the TC-BPDU guard
function
stp tc-protection enable
Optional
Enabled by default
Configure the maximum
number of forwarding address
entry flushes that the device
can perform within a specific
time period after it receives the
first TC-BPDU
stp tc-protection threshold
number
Optional
6 by default
Содержание S5120-SI Series
Страница 61: ...7 8 Sysname ip http acl 2030...
Страница 138: ...2 10 PORT VLAN MODE GigabitEthernet1 0 1 2 MANUAL...
Страница 186: ...1 46 Instance Vlans Mapped 0 1 to 9 11 to 19 21 to 29 31 to 4094 1 10 2 20 3 30...
Страница 218: ...ii Displaying and Maintaining BOOTP Client Configuration 4 2 BOOTP Client Configuration Example 4 3...
Страница 255: ...1 12...
Страница 381: ...ii Troubleshooting RADIUS 1 32...
Страница 577: ...1 8 Return to the upper directory Sysname cd Display the current working directory Sysname pwd flash...