HP VPN Firewall Appliances Network Management Command Reference
109
• stp root primary
stp root-protection
Use stp root-protection to enable the root guard function on the ports.
Use undo stp root-protection to disable the root guard function on the ports.
Syntax
stp root-protection
undo stp root-protection
Default
The root guard function is disabled.
Views
Ethernet interface view, Layer 2 aggregate interface view
Default command level
2: System level
Usage guidelines
Configured in Ethernet interface view, the setting takes effect only on the interface.
Configured in Layer 2 aggregate interface view, the setting takes effect only on the aggregate interface.
Configured on a member port in an aggregation group, the setting takes effect only after the port leaves
the aggregation group.
You cannot configure root guard and loop guard on a port at the same time.
Examples
# Enable the root guard function for GigabitEthernet 0/1.
<Sysname> system-view
[Sysname] interface gigabitethernet 0/1
[Sysname-GigabitEthernet0/1] stp root-protection
Related commands
stp loop-protection
stp tc-protection
Use stp tc-protection enable to enable the TC-BPDU attack guard function for the device.
Use stp tc-protection disable to disable the TC-BPDU attack guard function for the device.
Syntax
stp tc-protection enable
stp tc-protection disable
Default
The TC-BPDU attack guard function is enabled.