Cisco WS-C4003 Software Guide - Page 135

Disabling Spanning Tree PortFast, Understanding How PortFast BPDU Guard Works

Page 135 highlights

Chapter 8 Configuring Spanning Tree PortFast, UplinkFast, and BackboneFast, and Loop Guard Understanding How PortFast BPDU Guard Works 4/1 524 blocking 19 4/1 1003 not-connected 19 4/1 1005 not-connected 19 Console> (enable) 20 enabled 20 enabled 4 enabled Disabling Spanning Tree PortFast To disable PortFast on a switch port, perform this task in privileged mode: Task Step 1 Disable PortFast on a switch port. Step 2 Verify the PortFast setting. Command set spantree portfast mod_num/port_num disable show spantree mod_num/port_num This example shows how to disable PortFast on port 3 of module 4: Console> (enable) set spantree portfast 4/1 disable Spantree port 4/1 fast start disabled. Console> (enable) Understanding How PortFast BPDU Guard Works To prevent loops from occuring in a network, the spanning tree PortFast mode is supported only on nontrunking access ports because these ports typically do not transmit or receive BPDUs. The most secure implementation of PortFast is to enable it only on ports that connect end stations to switches. Because PortFast can be enabled on nontrunking ports connecting two switches, spanning tree loops can occur because BPDUs are still being transmitted and received on those ports. PortFast BPDU guard prevents loops by moving a nontrunking port into an errdisable state when a BPDU is received on that port. When BPDU guard is enabled on the switch, spanning tree shuts down PortFast-configured interfaces that receive BPDUs, instead of putting them into the spanning tree blocking state. In a valid configuration, PortFast-configured interfaces do not receive BPDUs. If a PortFast-configured interface receives a BPDU, an invalid configuration exists, such as connection of an unauthorized device. BPDU guard provides a secure response to invalid configurations because the administrator must manually put the interface back in service. Note When enabled on the switch, spanning tree applies BPDU guard to all PortFast-configured interfaces. Configuring PortFast BPDU Guard These sections describe how to configure PortFast BPDU guard on the switch: • Enabling PortFast BPDU Guard, page 8-4 • Disabling PortFast BPDU Guard, page 8-5 78-12647-02 Software Configuration Guide-Catalyst 4000 Family, Catalyst 2948G, Catalyst 2980G, Releases 6.3 and 6.4 8-3

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420
  • 421
  • 422
  • 423
  • 424
  • 425
  • 426
  • 427
  • 428
  • 429
  • 430
  • 431
  • 432
  • 433
  • 434
  • 435
  • 436
  • 437
  • 438
  • 439
  • 440
  • 441
  • 442
  • 443
  • 444
  • 445
  • 446
  • 447
  • 448
  • 449
  • 450
  • 451
  • 452
  • 453
  • 454
  • 455
  • 456
  • 457
  • 458
  • 459
  • 460
  • 461
  • 462
  • 463
  • 464
  • 465
  • 466
  • 467
  • 468
  • 469
  • 470
  • 471
  • 472
  • 473
  • 474
  • 475
  • 476
  • 477
  • 478
  • 479
  • 480
  • 481
  • 482
  • 483
  • 484
  • 485
  • 486
  • 487
  • 488
  • 489
  • 490
  • 491
  • 492
  • 493
  • 494
  • 495
  • 496
  • 497
  • 498
  • 499
  • 500
  • 501
  • 502
  • 503
  • 504
  • 505
  • 506
  • 507
  • 508
  • 509
  • 510

8-3
Software Configuration Guide—Catalyst 4000 Family, Catalyst 2948G, Catalyst 2980G, Releases 6.3 and 6.4
78-12647-02
Chapter 8
Configuring Spanning Tree PortFast, UplinkFast, and BackboneFast, and Loop Guard
Understanding How PortFast BPDU Guard Works
4/1
524
blocking
19
20
enabled
4/1
1003
not-connected
19
20
enabled
4/1
1005
not-connected
19
4
enabled
Console> (enable)
Disabling Spanning Tree PortFast
To disable PortFast on a switch port, perform this task in privileged mode:
This example shows how to disable PortFast on port 3 of module 4:
Console> (enable)
set spantree portfast 4/1 disable
Spantree port 4/1 fast start disabled.
Console> (enable)
Understanding How PortFast BPDU Guard Works
To prevent loops from occuring in a network, the spanning tree PortFast mode is supported only on
nontrunking access ports because these ports typically do not transmit or receive BPDUs. The most
secure implementation of PortFast is to enable it only on ports that connect end stations to switches.
Because PortFast can be enabled on nontrunking ports connecting two switches, spanning tree loops can
occur because BPDUs are still being transmitted and received on those ports.
PortFast BPDU guard prevents loops by moving a nontrunking port into an errdisable state when a BPDU
is received on that port. When BPDU guard is enabled on the switch, spanning tree shuts down
PortFast-configured interfaces that receive BPDUs, instead of putting them into the spanning tree
blocking state. In a valid configuration, PortFast-configured interfaces do not receive BPDUs. If a
PortFast-configured interface receives a BPDU, an invalid configuration exists, such as connection of an
unauthorized device. BPDU guard provides a secure response to invalid configurations because the
administrator must manually put the interface back in service.
Note
When enabled on the switch, spanning tree applies BPDU guard to all PortFast-configured interfaces.
Configuring PortFast BPDU Guard
These sections describe how to configure PortFast BPDU guard on the switch:
Enabling PortFast BPDU Guard, page 8-4
Disabling PortFast BPDU Guard, page 8-5
Task
Command
Step 1
Disable PortFast on a switch port.
set spantree portfast
mod_num
/
port_num
disable
Step 2
Verify the PortFast setting.
show spantree
mod_num/port_num