BPDU Guard

This Cisco STP feature protects the network from loops that could occur if BPDUs were received on a PortFast port. Because BPDUs should never arrive at these ports, their reception indicates a misconfiguration or a security breach. BPDU Guard causes the port to errordisable upon the reception of these frames.

You can configure BPDU Guard globally to have the feature enabled for all PortFast ports on the system. The command to do this is as follows:

spanning-tree portfast bpduguard

You can also enable the feature at the interface level. Use this command:

spanning-tree bpduguard enable

You can enable this feature at the interface level even if PortFast is not enabled on the port. Once again, the receipt of a BPDU causes the port to error-disable.

No comments:

Post a Comment