HP 1606 Converged Enhanced Ethernet Command Reference v6.4.0 (53-1001762-01, J - Page 172

spanning-tree guard root, The root port provides the best path from the switch to the root switch.

Page 172 highlights

9 spanning-tree guard root DRAFT: BROCADE CONFIDENTIAL spanning-tree guard root Synopsis Operands Defaults Command Modes Description Usage Guidelines Note Examples See Also Enables the guard root to restrict which interface is allowed to be the spanning-tree root port or the path-to-the root for the switch. spanning-tree guard root no spanning-tree guard root none Guard root is disabled. Interface configuration mode Use this command to enable the guard root on the interface. Use the no spanning-tree guard root command to disable guard root on the selected interface. The root port provides the best path from the switch to the root switch. Guard root protects the root bridge from malicious attacks and unintentional misconfigurations where a bridge device that is not intended to be the root bridge becomes the root bridge. This causes severe bottlenecks in the datapath. Guard root ensures that the port on which it is enabled is a designated port. If the guard root enabled port receives a superior Bridge Protocol Data Unit (BPDU), it goes to a discarding state. To enable guard root: switch(conf-if-te-0/1)#spanning-tree guard root spanning-tree cost 154 Converged Enhanced Ethernet Command Reference 53-1001762-01

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252

154
Converged Enhanced Ethernet Command Reference
53-1001762-01
spanning-tree guard root
9
DRAFT: BROCADE CONFIDENTIAL
spanning-tree guard root
Enables the guard root to restrict which interface is allowed to be the spanning-tree root port or the
path-to-the root for the switch.
Synopsis
spanning-tree guard root
no spanning-tree guard root
Operands
none
Defaults
Guard root is disabled.
Command
Modes
Interface configuration mode
Description
Use this command to enable the guard root on the interface. Use the
no spanning-tree guard root
command to disable guard root on the selected interface.
Usage
Guidelines
The root port provides the best path from the switch to the root switch.
Note
Guard root protects the root bridge from malicious attacks and unintentional misconfigurations
where a bridge device that is not intended to be the root bridge becomes the root bridge. This
causes severe bottlenecks in the datapath. Guard root ensures that the port on which it is enabled
is a designated port. If the guard root enabled port receives a superior Bridge Protocol Data Unit
(BPDU), it goes to a discarding state.
Examples
To enable guard root:
switch(conf-if-te-0/1)#
spanning-tree guard root
See Also
spanning-tree cost