TP-Link TL-SG3210 TL-SG3210 V1 CLI Reference Guide - Page 158

spanning-tree security

Page 158 highlights

Spanning Tree globally. To return to the default configuration, please use no spanning-tree tc-defend command. A switch removes MAC address entries upon receiving TC-BPDUs. If a malicious user continuously sends TC-BPDUs to a switch, the switch will be busy with removing MAC address entries, which may decrease the performance and stability of the network. Syntax spanning-tree tc-defend [ threshold threshold ] [ period period ] no spanning-tree tc-defend Parameter threshold -- TC Threshold, ranging from 1 to 100 packets. By default, it is 20. TC Threshold is the maximum number of the TC-BPDUs received by the switch in a TC Protect Cycle. period -- TC Protect Cycle, ranging from 1 to 10 in seconds. By default, it is 5. Command Mode Global Configuration Mode Example Configure TC Threshold as 30 packets, and TC Protect Cycle as 10 seconds: TP-LINK(config)# spanning-tree tc-defend threshold 30 period 10 spanning-tree security Description The spanning-tree security command is used to configure MSTP Port Protect. To return to the default configuration, please use no spanning-tree security command. Port Protect function is to prevent the devices from any malicious attack against STP features. Syntax spanning-tree security [loop { disable | enable }] [root { disable | enable }] [TC { disable | enable }] [defend { disable | enable }] [hold { disable | enable }] no spanning-tree security Parameter loop -- Enable/ Disable Loop Protect. By default, it is disabled. Loop Protect is to prevent the loops in the network brought by recalculating STP because of link failures and network congestions. root -- Enable/ Disable Root Protect. By default, it is disabled. Root Protect 146

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199

146
Spanning Tree globally. To return to the default configuration, please use
no
spanning-tree tc-defend
command. A switch removes MAC address entries
upon receiving TC-BPDUs. If a malicious user continuously sends TC-BPDUs to
a switch, the switch will be busy with removing MAC address entries, which may
decrease the performance and stability of the network.
Syntax
spanning-tree tc-defend
[
threshold
threshold
] [
period
period
]
no spanning-tree tc-defend
Parameter
threshold
——
TC Threshold, ranging from 1 to 100 packets. By default, it is 20.
TC Threshold is the maximum number of the TC-BPDUs received by the switch
in a TC Protect Cycle.
period
——
TC Protect Cycle, ranging from 1 to 10 in seconds. By default, it is
5.
Command Mode
Global Configuration Mode
Example
Configure TC Threshold as 30 packets, and TC Protect Cycle as 10 seconds:
TP-LINK(config)# spanning-tree tc-defend threshold
30
period
10
spanning-tree security
Description
The
spanning-tree security
command is used to configure MSTP Port Protect.
To return to the default configuration, please use
no spanning-tree security
command. Port Protect function is to prevent the devices from any malicious
attack against STP features.
Syntax
spanning-tree security
[
loop
{ disable | enable }] [
root
{ disable | enable }] [
TC
{ disable | enable }] [
defend
{ disable | enable }] [
hold
{ disable | enable }]
no spanning-tree security
Parameter
loop
——
Enable/ Disable Loop Protect. By default, it is disabled. Loop Protect
is to prevent the loops in the network brought by recalculating STP because of
link failures and network congestions.
root
——
Enable/ Disable Root Protect. By default, it is disabled. Root Protect