102
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enable the TC-BPDU guard function.
stp tc-protection
By default, TC-BPDU guard
is enabled.
As a best practice, do not
disable this feature.
3.
(Optional.) Configure the maximum
number of forwarding address entry
flushes that the device can perform
every 10 seconds.
stp tc-protection threshold
number
The default setting is 6.
Enabling BPDU drop
In a spanning tree network, every BPDU arriving at the device triggers an STP calculation process
and is then forwarded to other devices in the network. Malicious attackers might use the vulnerability
to attack the network by forging BPDUs. By continuously sending forged BPDUs, they can make all
devices in the network continue performing STP calculations. As a result, problems such as CPU
overload and BPDU protocol status errors occur.
To avoid this problem, you can enable BPDU drop on ports. A BPDU drop-enabled port does not
receive any BPDUs and is invulnerable to forged BPDU attacks.
To enable BPDU drop on an Ethernet interface:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter Layer 2 Ethernet
interface view.
interface interface-type
interface-number
N/A
3.
Enable BPDU drop on the
current interface.
bpdu-drop any
By default, BPDU drop is
disabled.
Displaying and maintaining the spanning tree
Execute
display
commands in any view and
reset
command in user view.
Task Command
Display information about ports blocked by spanning
tree protection functions.
display stp abnormal-port
Display BPDU statistics on ports.
display stp bpdu-statistics
[
interface
interface-type interface-number
[
instance
instance-list
] ]
Display information about ports shut down by spanning
tree protection functions.
display stp down-port
Display the historical information of port role calculation
for the specified MSTI or all MSTIs.
display stp
[
instance
instance-list
|
vlan
vlan-id-list
]
history
[
slot
slot-number
]
Display the statistics of TC/TCN BPDUs sent and
received by all ports in the specified MSTI or all MSTIs.
display stp
[
instance
instance-list
|
vlan
vlan-id-list
]
tc
[
slot
slot-number
]
Display the spanning tree status and statistics.
display stp
[
instance instance-list
|
vlan
vlan-id-list
]
[
interface interface-list
|
slot