Switch 7700 Command reference Guide, v2.0

Table Of Contents
RSTP Configuration Commands 305
Example
Enable RSTP on a switch.
[SW7700]stp enable
Disable RSTP on Ethernet1/0/1.
[SW7700-Ethernet1/0/1]stp disable
stp bpdu-protection Syntax
stp bpdu-protection
undo stp bpdu-protection
View
System view
Parameter
None
Description
Using the stp bpdu-protection command, you can enable BPDU protection on a
switch. Using the
undo stp bpdu-protection command, you can resume the
default status of BPDU protection function.
By default, BPDU protection is not enabled.
For an access layer device, the access port is generally connected to the user
terminal (such as a PC) or file server directly and configured as an edge port to
implement the fast transition. When such port receives BPDU packet, the system
will set it to non-edge port and recalculate the spanning tree, which will cause
network topology flapping. In normal cases, these ports will not receive any BPDU
packets. However, someone may forge BPDU to maliciously attack the switch and
cause network flapping.
RSTP provides BPDU protection function against such attack. After BPDU
protection function is enabled on a switch, the system will disable an edge port
that has received BPDU and notify the network manager about it. The disabled
port can only be resumed by network manager.
Example
Enable BPDU protection function on a switch.
[SW7700]stp bpdu-protection
stp cost Syntax
stp cost cost
undo stp cost
View
Ethernet port view