HP StorageWorks 1606 Brocade Converged Enhanced Ethernet Command Reference v6. - Page 172

Guard root protects the root bridge from malicious attacks and unintentional misconfigurations

Page 172 highlights

9 spanning-tree guard root spanning-tree guard root Enables the guard root to restrict which interface is allowed to be the spanning-tree root port or the path-to-the root for the switch. Synopsis spanning-tree guard root no spanning-tree guard root Operands none Defaults Guard root is disabled. Command Interface configuration mode Modes Description Use this command to enable the guard root on the interface. Use the no spanning-tree guard root command to disable guard root on the selected interface. Usage The root port provides the best path from the switch to the root switch. Guidelines Note Guard root protects the root bridge from malicious attacks and unintentional misconfigurations where a bridge device that is not intended to be the root bridge becomes the root bridge. This causes severe bottlenecks in the datapath. Guard root ensures that the port on which it is enabled is a designated port. If the guard root enabled port receives a superior Bridge Protocol Data Unit (BPDU), it goes to a discarding state. Examples To enable guard root: switch(conf-if-te-0/1)#spanning-tree guard root See Also spanning-tree cost 154 Converged Enhanced Ethernet Command Reference 53-1001347-01

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234

154
Converged Enhanced Ethernet Command Reference
53-1001347-01
spanning-tree guard root
9
spanning-tree guard root
Enables the guard root to restrict which interface is allowed to be the spanning-tree root port or the
path-to-the root for the switch.
Synopsis
spanning-tree guard root
no spanning-tree guard root
Operands
none
Defaults
Guard root is disabled.
Command
Modes
Interface configuration mode
Description
Use this command to enable the guard root on the interface. Use the
no spanning-tree guard root
command to disable guard root on the selected interface.
Usage
Guidelines
The root port provides the best path from the switch to the root switch.
Note
Guard root protects the root bridge from malicious attacks and unintentional misconfigurations
where a bridge device that is not intended to be the root bridge becomes the root bridge. This
causes severe bottlenecks in the datapath. Guard root ensures that the port on which it is enabled
is a designated port. If the guard root enabled port receives a superior Bridge Protocol Data Unit
(BPDU), it goes to a discarding state.
Examples
To enable guard root:
switch(conf-if-te-0/1)#
spanning-tree guard root
See Also
spanning-tree cost