51
Configuring TC-BPDU transmission restriction
About TC-BPDU transmission restriction
Make this configuration on the port that connects to the user access network.
The topology change to the user access network might cause the forwarding address changes to the
core network. When the user access network topology is unstable, the user access network might
affect the core network. To avoid this problem, you can enable TC-BPDU transmission restriction on
a port. With this feature enabled, when the port receives a TC-BPDU, it does not forward the
TC-BPDU to other ports.
Restrictions and guidelines
Enabling TC-BPDU transmission restriction on a port might cause the previous forwarding address
table to fail to be updated when the topology changes.
Procedure
1.
Enter system view.
system-view
2.
Enter interface view.
interface interface-type interface-number
3.
Enable TC-BPDU transmission restriction.
stp tc-restriction
By default, TC-BPDU transmission restriction is disabled.
Enabling TC-BPDU guard
About TC-BPDU guard
When a device receives topology change (TC) BPDUs (the BPDUs that notify devices of topology
changes), it flushes its forwarding address entries. If someone uses TC-BPDUs to attack the device,
the device will receive a large number of TC-BPDUs within a short time. Then, the device is busy with
forwarding address entry flushing. This affects network stability.
TC-BPDU guard allows you to set the maximum number of immediate forwarding address entry
flushes performed within 10 seconds after the device receives the first TC-BPDU. For TC-BPDUs
received in excess of the limit, the device performs a forwarding address entry flush when the time
period expires. This prevents frequent flushing of forwarding address entries.
Restrictions and guidelines
As a best practice, enable TC-BPDU guard.
Procedure
1.
Enter system view.
system-view
2.
Enable the TC-BPDU guard feature.
stp tc-protection
By default, TC-BPDU guard is enabled.
3.
(Optional.) Configure the maximum number of forwarding address entry flushes that the device
can perform every 10 seconds.
stp tc-protection threshold number
The default setting is 6.
Содержание S6850 Series
Страница 108: ...48 WGE1 0 3 32768 49153 50100 0x7b 0001 0001 0001 ACDEF...
Страница 259: ...21 6 N A 200 6...
Страница 337: ...ii...