Cisco WS-C4003 Software Guide - Page 135
Disabling Spanning Tree PortFast, Understanding How PortFast BPDU Guard Works
View all Cisco WS-C4003 manuals
Add to My Manuals
Save this manual to your list of manuals |
Page 135 highlights
Chapter 8 Configuring Spanning Tree PortFast, UplinkFast, and BackboneFast, and Loop Guard Understanding How PortFast BPDU Guard Works 4/1 524 blocking 19 4/1 1003 not-connected 19 4/1 1005 not-connected 19 Console> (enable) 20 enabled 20 enabled 4 enabled Disabling Spanning Tree PortFast To disable PortFast on a switch port, perform this task in privileged mode: Task Step 1 Disable PortFast on a switch port. Step 2 Verify the PortFast setting. Command set spantree portfast mod_num/port_num disable show spantree mod_num/port_num This example shows how to disable PortFast on port 3 of module 4: Console> (enable) set spantree portfast 4/1 disable Spantree port 4/1 fast start disabled. Console> (enable) Understanding How PortFast BPDU Guard Works To prevent loops from occuring in a network, the spanning tree PortFast mode is supported only on nontrunking access ports because these ports typically do not transmit or receive BPDUs. The most secure implementation of PortFast is to enable it only on ports that connect end stations to switches. Because PortFast can be enabled on nontrunking ports connecting two switches, spanning tree loops can occur because BPDUs are still being transmitted and received on those ports. PortFast BPDU guard prevents loops by moving a nontrunking port into an errdisable state when a BPDU is received on that port. When BPDU guard is enabled on the switch, spanning tree shuts down PortFast-configured interfaces that receive BPDUs, instead of putting them into the spanning tree blocking state. In a valid configuration, PortFast-configured interfaces do not receive BPDUs. If a PortFast-configured interface receives a BPDU, an invalid configuration exists, such as connection of an unauthorized device. BPDU guard provides a secure response to invalid configurations because the administrator must manually put the interface back in service. Note When enabled on the switch, spanning tree applies BPDU guard to all PortFast-configured interfaces. Configuring PortFast BPDU Guard These sections describe how to configure PortFast BPDU guard on the switch: • Enabling PortFast BPDU Guard, page 8-4 • Disabling PortFast BPDU Guard, page 8-5 78-12647-02 Software Configuration Guide-Catalyst 4000 Family, Catalyst 2948G, Catalyst 2980G, Releases 6.3 and 6.4 8-3