Configuration Guide MSTP Configuration
port, this port will enter the error-disabled status, indicating the configuration
error. At the same time, the port will be closed to show that some illegal users
may add a network device to the network, which change the network topology.
You can also use the
spanning-tree bpduguard enable
command to enable
BPDU guard on individual interface in the interface configuration mode (it is not
related to whether it is AutoEdge port or not ). Under this situation, it will enter
the error-disabled status if this interface receives the BPDU message.
Understanding BPDU Filter
The BPDU filter can be enabled globally or on individual interface. There are
some slightly difference between these two ways.
You can use the
spanning-tree portfast bpdufilter default
command to
enable the BPDU filter globally in the privileged mode. In this status, the BPDU
messages can not be received or sent through a Port Fast-enabled port or a
AutoEdge port, leading to no BPDU messages received by the host directly
connecting the port. The BPDU filter will be disabled when the Port Fast is
disabled for the AutoEdge port receives the BPDU message.
You can also use the
spanning-tree bpdufilter enable
command to enable the
BPDU filter on individual interface in the interface configuration mode (it is not
related to whether it is AutoEdge port or not). In this situation, this interface will
not receive or transmit the BPDU message, but execute the forwarding directly.
Understanding TC-protection
TC-BPDU messages are BPDU messages carrying with TC flag. When the L2
switch receives these messages, the network topology will change and the
MAC address table will be deleted. And for L3 switch, the route table will be
deleted and the port state in the ARP entry will change. To prevent the switch
from processing abovementioned operations when pseudo TC-BPDU
messages attack maliciously, too-heavy burden and network turbulance, the
TC-protection function comes into being.
Tc-protection can only be enabled or disabled globally. It is enabled by default.
Once Tc-protection is enabled, the switch will delete the message within a
certain period of time (usually 4 seconds) after receiving the TC-BPDU
message while monitoring the TC-BPDU message. If it receives the TC-BPDU
message during this period, it will perform the delete operation again after this
period expires. This eliminates the need of frequently deleting MAC address
entries and ARP entries.
Содержание RG-S2900G-E Series
Страница 1: ...RG S2900G E Series Switch RGOS Configuration Guide Release 10 4 2b12 p1 ...
Страница 91: ...Configuration Guide Configuring PoE Configuration ...
Страница 133: ...Configuration Guide EEE Configuration ...
Страница 319: ...Configuration Guide QinQ Configuration ...
Страница 408: ......
Страница 409: ...IP Routing Configuration 1 Static Route Configuration ...
Страница 412: ......
Страница 413: ...Multicast Configuration 1 IGMP Snooping Configuration 2 MLD Snooping Configuration ...
Страница 621: ...Configuration Guide CPU Protection Configuration udp helper 180 4 dhcp client 180 4 lacp 180 4 ...
Страница 757: ......
Страница 758: ...ACL QoS Configuration 1 Access Control List Configuration 2 QoS Configuration ...
Страница 801: ...Reliability Configuration 1 RLDP Configuration 2 TPP Configuration 3 SEM Configuration ...
Страница 901: ...Configuration Guide ERSPAN Configuration ...
Страница 902: ...Web based Configuration 1 Web based Configuration ...