163
SIGNAMAX LLC • www.signamax.eu
You can use the following command to enable the BPDU protection function of the port. The no
format of the command can be used to disable the function.
spanning-tree bpdu guard
no spanning-tree bpdu guard
By default, the BPDU protection function of the port is disabled. For the confirmed edge ports,
to avoid the attack of forged BPDU packets, it is recommended to enable the protection
function.
The BPDU protection function takes effect only on the ports configured with edge port
attributes. For the ports that are configured with edge port attributes, but change to non-edge
ports because of receiving BPDU packets from other ports, enabling the BPDU protection
function can take effect only when the ports are re-started and recover to edge ports.
spanning-tree bpdu filter
After being configured with BPDU filtering function, the edge port does not send or receive
BPDU packets. You can use the following command to configure the BPDU filtering function.
The no format of the command can be used to disable the function.
spanning-tree bpdu filter
no spanning-tree bpdu filter
By default, the BPDU filtering function of a port is disabled.
The BPDU filtering function takes effect only on the ports configured with edge port attributes.
For the ports that are configured with edge port attributes, but change to non-edge ports
because of receiving BPDU packets from other ports, enabling the BPDU filtering function can
take effect only when the ports are re-started and recover to edge ports.
spanning-tree guard root
The root bridge of the spanning tree and the standby root bridge should be in the same
domain. Usually, the root bridge and standby root bridge of CIST are placed in a high-
bandwidth core domain during network design. But because of the wrong configuration of the
maintenance staff or vicious attacks in the network, the legal root bridge in the network may
receive the BPDU with higher priority.
Here, the current legal root bridge loses the place of the root bridge, which causes the wrong
Содержание 065-7434
Страница 1: ...24 Port 10 100 L3 Switch Model 065 7434 Configuration Guide Revision A1 ...
Страница 245: ...245 SIGNAMAX LLC www signamax eu Application Example Example of configuring DHCP Snooping ...
Страница 302: ...302 SIGNAMAX LLC www signamax eu Default status no switching interface ...
Страница 368: ......
Страница 655: ...287 SIGNAMAX LLC www signamax eu Sub VLAN members in the system ...