User Guide
424
Configuring Spanning Tree
STP Security Configurations
Root Protect
Enable or disable Root Protect. It is recommended to enable this function on the
designated ports of the root bridge.
Switches with faulty configurations may produce a higher-priority BPDUs than
the root bridge’s, and this situation will cause recalculation of the spanning
tree. Root Protect is used to ensure that the desired root bridge will not lose
its position in the scenario above. With root protect enabled, the port will
temporarily transit to blocking state when it receives higher-priority BDPUs. After
two forward delays, if the port does not receive any other higher-priority BDPUs,
it will transit to its normal state.
TC Guard
Enable or disable the TC Guard function. It is recommended to enable this
function on the ports of non-root switches.
TC Guard function is used to prevent the switch from frequently changing the
MAC address table. With TC Guard function enabled, when the switch receives
TC-BPDUs, it will not process the TC-BPDUs at once. The switch will wait for a
fixed time and process the TC-BPDUs together after receiving the first TC-BPDU,
then it will restart timing.
BPDU Protect
Enable or disable the BPDU Protect function. It is recommended to enable this
function on edge ports.
Edge ports in spanning tree are used to connect to the end devices and it doesn’t
receive BPDUs in the normal situation. If edge ports receive BPDUs, it may be an
attack. BPDU Protect is used to protect the switch from the attack talked above.
With BPDU protect function enabled, the edge ports will be shutdown when
they receives BPDUs, and will report these cases to the administrator. Only the
administrator can restore the state of the ports.
BPDU Filter
Enable or disable BPDU Filter. It is recommended to enable this function on edge
ports.
With BPDU Filter function enabled, the port does not forward BPDUs from the
other switches.
BPDU Forward
Enable or disable BPDU Forward. This function only takes effect when the
spanning tree function is disabled globally.
With BPDU forward enabled, the port can still forward spanning tree BPDUs when
the spanning tree function is disabled.
4.2 Using the CLI
4.2.1 Configuring the STP Security
Follow these steps to configure the Root protect feature, BPDU protect feature and BPDU
filter feature for ports:
Step 1
configure
Enter global configuration mode.
Summary of Contents for JetStream T2600G-28TS
Page 264: ...Configuring VLAN VPN Configuration Examples User Guide 235 Figure 4 2 Create VLAN 100 ...
Page 265: ...User Guide 236 Configuring VLAN VPN Configuration Examples Figure 4 3 Create VLAN 200 ...
Page 268: ...Configuring VLAN VPN Configuration Examples User Guide 239 Figure 4 7 Creating VLAN 100 ...
Page 275: ...User Guide 246 Configuring VLAN VPN Configuration Examples Figure 4 11 Create VLAN 100 ...
Page 276: ...Configuring VLAN VPN Configuration Examples User Guide 247 Figure 4 12 Create VLAN 200 ...
Page 277: ...User Guide 248 Configuring VLAN VPN Configuration Examples Figure 4 13 Create VLAN 1050 ...
Page 280: ...Configuring VLAN VPN Configuration Examples User Guide 251 Figure 4 18 Creating VLAN 100 ...
Page 859: ...User Guide 830 Configuring ACL Configuration Example for ACL Figure 3 18 Configuring Rule 3 ...
Page 874: ...Configuring ACL User Guide 845 ...
Page 975: ...Part 33 Monitoring Traffic CHAPTERS 1 Traffic Monitor 2 Appendix Default Parameters ...