52
Enabling BPDU drop
About BPDU drop
In a spanning tree network, every BPDU arriving at the device triggers an STP calculation process
and is then forwarded to other devices in the network. Malicious attackers might use the vulnerability
to attack the network by forging BPDUs. By continuously sending forged BPDUs, they can make all
devices in the network continue performing STP calculations. As a result, problems such as CPU
overload and BPDU protocol status errors occur.
To avoid this problem, you can enable BPDU drop on ports. A BPDU drop-enabled port does not
receive any BPDUs and is invulnerable to forged BPDU attacks.
Procedure
1.
Enter system view.
system-view
2.
Enter Layer 2 Ethernet interface view.
interface interface-type interface-number
3.
Enable BPDU drop on the interface.
bpdu-drop any
By default, BPDU drop is disabled.
Enabling PVST BPDU guard
About PVST BPDU guard
This feature takes effect only when the device is operating in MSTP mode.
An MSTP-enabled device forwards PVST BPDUs as data traffic because it cannot recognize PVST
BPDUs. If a PVST-enabled device in another independent network receives the PVST BPDUs, a
PVST calculation error might occur. To avoid PVST calculation errors, enable PVST BPDU guard on
the MSTP-enabled device. The device shuts down a port if the port receives PVST BPDUs.
Procedure
1.
Enter system view.
system-view
2.
Enable PVST BPDU guard.
stp pvst-bpdu-protection
By default, PVST BPDU guard is disabled.
Disabling dispute guard
About dispute guard
Dispute guard can be triggered by unidirectional link failures. If an upstream port receives inferior
BPDUs from a downstream designated port in forwarding or learning state because of a
unidirectional link failure, a loop appears. Dispute guard blocks the upstream designated port to
prevent the loop.
As shown in
, in normal conditions, the spanning tree calculation result is as follows:
•
Device A is the root bridge, and Port A1 is a designated port.
•
Port B1 is blocked.
When the link between Port A1 and Port B1 fails in the direction of Port A1 to Port B1 and becomes
unidirectional, the following events occur:
Содержание S6850 Series
Страница 108: ...48 WGE1 0 3 32768 49153 50100 0x7b 0001 0001 0001 ACDEF...
Страница 259: ...21 6 N A 200 6...
Страница 337: ...ii...