3Com Switch 8800 Configuration Guide Chapter 38 MSTP Region-configuration
38-31
Note:
For the loop protection-enabled port, if the port participates in STP calculation, all the
instances of the port will be always set to be in discarding state regardless of the port
role.
IV. TC-protection
As a general rule, the switch deletes the corresponding entries in the MAC address
table and ARP table upon receiving TC-BPDU packets. Under malicious attacks of
TC-BPDU packets, the switch shall receive a great number of TC-BPDU packets in a
very short period. Too frequent delete operations shall consume huge switch resources
and bring great risk to network stability.
When the protection from TC-BPDU packet attack is enabled, the switch just perform
one delete operation in a specified period (generally, 15 seconds) after receiving
TC-BPDU packets, as well as monitoring whether it receives TC-BPDU packets during
this period. Even if it detects a TC-BPDU packet is received in a period shorter than the
specified interval, the switch shall not run the delete operation till the specified interval
is reached. This can avoid frequent delete operations on the MAC address table and
ARP table.
You can use the following command to configure the protection functions of the switch.
Perform the following configuration in corresponding configuration modes.
Table 38-26 Configure the switch protection function
Operation Command
Configure BPDU protection of the switch (from
system view) stp bpdu-protection
Restore the disabled BPDU protection state as
defaulted (from system view) undo stp bpdu-protection
Configure Root protection of the switch (from
system view)
stp interface interface-list
root-protection
Restore the disabled Root protection state as
defaulted (from system view)
undo stp interface
interface-list root-protection
Configure Root protection of the switch (from
Ethernet port view) stp root-protection
Restore the disabled Root protection state as
defaulted (from Ethernet port view) undo stp root-protection
Configure loop protection function of the switch
(from Ethernet port view) stp loop-protection
Restore the disabled loop protection state, as
defaulted (from Ethernet port view) stp loop-protection