3
Configure CIST parameters
for ports
Required. Configure CIST parameters for ports on
Spanning Tree
→
Port Config
→
Port Config
page.
4
Configure the MST region
Required. Create the MST region, VLAN-Instance
mapping and the priority of the switch in the
corresponding region on
Spanning Tree
→
MSTP
Instance
→
Region Config and Instance Config
page.
5
Configure MSTP parameters
for instance ports
Optional. Configure different instances in the MST
region and configure MSTP parameters for instance
ports on
Spanning Tree
→
MSTP Instance
→
Instance
Port Config
page.
8.4
STP Security
Configuring protection function for devices can prevent devices from any malicious attack
against STP features. The STP Security function can be implemented on
Port Protect
page.
Port Protect function is to prevent the devices from any malicious attack against STP features.
8.4.1
Port Protect
STP Security prevents the loops caused by wrong configurations or BPDU attacks. It contains
Loop Protect, Root Protect, BPDU Protect, BPDU Filter, TC Protect and BPDU flood functions.
Loop Protect
Loop Protect function is used to prevent loops caused by link congestions or link failures. It is
recommended to enable this function on root ports and alternate ports.
If the switch cannot receive BPDUs because of link congestions or link failures, the root port
will become a designated port and the alternate port will transit to forwarding status, so loops
will occur.
With Loop Protect function enabled, the port will temporarily transit to blocking state when the
port does not receive BPDUs. After the link restores to normal, the port will transit to its normal
state, so loops can be prevented.
Root Protect
Root Protect function is used to ensure that the desired root bridge will not lose its position. It
is recommended to enable this function on the designated ports of the root bridge.
Generally, the root bridge will lose its position once receiving higher-priority BPDUs caused by
wrong configurations or malicious attacks. In this case, the spanning tree will be regenerated,
and traffic needed to be forwarded along high-speed links may be lead to low-speed links.
With root protect function enabled, when the port receives higher-priority BDPUs, it will
temporarily transit to blocking state. After two times of forward delay, if the port does not
receive any higher-priority BDPUs, it will transit to its normal state.
TC Protect
TC Protect function is used to prevent the switch from frequently removing MAC address
entries and TC-BPDU flooding.
122
Содержание T3700G-28TQ
Страница 1: ...User Guide T3700G 28TQ T3700G 52TQ 1910012358 REV3 0 0 November 2018...
Страница 11: ...XI...