![Huawei AR3200 Series Скачать руководство пользователя страница 198](http://html.mh-extra.com/html/huawei/ar3200-series/ar3200-series_configuration-manual-lan_169302198.webp)
l
Supports STP/RSTP interoperability between Huawei devices and non-Huawei devices.
Certain parameters must be set on Huawei devices to ensure uninterrupted communication.
Table 7-4
RSTP Protection Function
Protection
Function
Scenario
Configuration Impact
BPDU
protection
An edge port changes into
a non-edge port after
receiving a BPDU, which
triggers spanning tree
recalculation. If an attacker
keeps sending pseudo
BPDUs to a switching
device, network flapping
occurs.
After BPDU protection is enabled, the
switching device shuts down the edge port
if the edge port receives an RST BPDU.
Then the device notifies the NMS of the
shutdown event. The attributes of the edge
port are not changed.
TC
protection
Generally, after receiving
TC BPDUs (packets for
advertising network
topology changes), a
switching device needs to
delete MAC entries and
ARP entries. Frequent
deletions exhaust CPU
resources.
TC protection is used to suppress TC
BPDUs. You can configure the number of
times a switching device processes TC
BPDUs within a given time period. If the
number of TC BPDUs that the switching
device receives within a given time
exceeds the specified threshold, the
switching device processes only the
specified number of TC BPDUs. After the
specified time period expires, the device
processes the excess TC BPDUs for once.
This function prevents the switching
device from frequently deleting MAC
entries and ARP entries, saving CPU
resources.
Root
protection
Due to incorrect
configurations or
malicious attacks on the
network, a root bridge may
receive BPDUs with a
higher priority than its own
priority. Consequently, the
legitimate root bridge is no
longer able to serve as the
root bridge and the
network topology is
changed, triggering
spanning tree
recalculation. This may
transfer traffic from high-
speed links to low-speed
links, causing traffic
congestion.
If a designated port is enabled with the root
protection function, the role of the port
cannot be changed. Once a designated port
that is enabled with root protection
receives RST BPDUs with a higher
priority, the port enters the Discarding state
and does not forward packets. If the port
does not receive any RST BPDUs with a
higher priority before a period (generally
two Forward Delay periods) expires, the
port automatically enters the Forwarding
state.
Huawei AR3200 Series Enterprise Routers
Configuration Guide - LAN
7 STP/RSTP Configuration
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
187