Omitir para ir al contenido principal
  • Hacer pedidos rápida y fácilmente
  • Ver pedidos y realizar seguimiento al estado del envío
  • Cree y acceda a una lista de sus productos
  • Administre sus sitios, productos y contactos de nivel de producto de Dell EMC con Administración de la empresa.

Dell PowerEdge FN I/O Module Configuration Guide 9.10(0.0)

PDF

Prevent Network Disruptions with BPDU Guard

Configure the Portfast (and Edgeport, in the case of RSTP, PVST+, and MSTP) feature on ports that connect to end stations. End stations do not generate BPDUs, so ports configured with Portfast/ Edgport (edgeports) do not expect to receive BDPUs.

If an edgeport does receive a BPDU, it likely means that it is connected to another part of the network, which can negatively affect the STP topology. The BPDU Guard feature blocks an edgeport after receiving a BPDU to prevent network disruptions, and the system displays the following message.
3w3d0h: %RPM0-P:RP2 %SPANMGR-5-BPDU_GUARD_RX_ERROR: Received Spanning Tree BPDU on
                                 BPDU guard port. Disable GigabitEthernet 3/41.
                              

Enable BPDU Guard using the bpduguard option when enabling PortFast or EdgePort. The bpduguard shutdown-on-violation option causes the interface hardware to be shut down when it receives a BPDU. Otherwise, although the interface is placed in an Error Disabled state when receiving the BPDU, the physical interface remains up and spanning-tree will only drop packets after a BPDU violation.

The following example shows a scenario in which an edgeport might unintentionally receive a BPDU. The port on the Dell Networking system is configured with Portfast. If the switch is connected to the hub, the BPDUs that the switch generates might trigger an undesirable topology change. If you enable BPDU Guard, when the edge port receives the BPDU, the BPDU is dropped, the port is blocked, and a console message is generated.

  • NOTE: Unless you enable the shutdown-on-violation option, spanning-tree only drops packets after a BPDU violation; the physical interface remains up.
Dell Networking OS Behavior: Regarding bpduguard shutdown-on-violation behavior:
  • If the interface to be shut down is a port channel, all the member ports are disabled in the hardware.
  • When you add a physical port to a port channel already in the Error Disable state, the new member port is also disabled in the hardware.
  • When you remove a physical port from a port channel in the Error Disable state, the Error Disabled state is cleared on this physical port (the physical port is enabled in the hardware).
  • You can clear the Error Disabled state with any of the following methods:
    • Perform a shutdown command on the interface.
    • Disable the shutdown-on-violation command on the interface (the no spanning-tree stp-id portfast [bpduguard | [shutdown-on-violation]] command).
    • Disable spanning tree on the interface (the no spanning-tree command in INTERFACE mode).
    • Disabling global spanning tree (the no spanning-tree in CONFIGURATION mode).
Figure 1. Enabling BPDU Guard Illustration of enabling BPDU guard.

Dell Networking OS Behavior: BPDU guard and BPDU filtering (refer to Removing an Interface from the Spanning Tree Group ) both block BPDUs, but are two separate features.

BPDU guard is used on edgeports and blocks all traffic on edgeport if it receives a BPDU.

Example of Blocked BPDUs

Dell#show spanning-tree 0 brief
                                 Executing IEEE compatible Spanning Tree Protocol
                                 Root ID Priority 32768, Address 0001.e88a.fdb3 Cost 1
                                 Root Port 2 (Port-channel 1)
                                 Root Bridge hello time 2, max age 20, forward delay 15
                                 Bridge ID Priority 32768, Address 001e.c9f1.00cf
                                 Configured hello time 2, max age 20, forward delay 15
                                 Bpdu filter disabled globally
                                 Interface                      Designated
                                 Name    PortID Prio Cost Sts Cost Bridge ID             PortID
                                 ---------- ------- ---- ------ ----------- ------ ------ ------
                                 Po 1    8.2    8    1    FWD  0   32768 0001.e88a.fdb3  8.2
                                 Te 3/20 8.317  8    4    EDS  1   32768 001e.c9f1.00cf  8.317
                                 Te 4/20 8.373  8    4    FWD  1   32768 001e.c9f1.00cf  8.373
                                 Te 4/21 8.374  8    4    FWD  1   32768 001e.c9f1.00cf  8.374
                                 Dell#show ip int br ten 3/20
                                 Interface IP-Address OK Method Status Protocol
                                 TenGigabitEthernet 3/20 unassigned YES None up up
                                 Dell#
                              

Califique este contenido

Preciso
Útil
Fácil de comprender
¿Este artículo fue útil?
0/3000 characters
  Proporcione calificaciones (1 a 5 estrellas).
  Proporcione calificaciones (1 a 5 estrellas).
  Proporcione calificaciones (1 a 5 estrellas).
  Seleccione si el artículo fue útil o no.
  Los comentarios no pueden contener estos caracteres especiales: <>"(", ")", "\"