10-33
Catalyst 3550 Multilayer Switch Software Configuration Guide
78-11194-03
Chapter10 Configuring STP Configuring Advanced STP Features
Configuring BPDU Guard
When the BPDU guard feature is enabled on the switch, STP shuts down Port Fast-enabled interfaces
that receive BPDUs rather than putting them into the blocking state.
Caution The BPDU guard feature works on Port Fast-enable interfaces. Configure Por t Fast only on int erfaces
that connect to end stations; otherwise, an accidental topology loop could cause a data pack et loop
and disrupt switch and network operation.
Beginning in privileged EXEC mode, follow these steps to enable the BPDU guard feature on the switch:
In a valid configuration, Port Fast-enabled interfaces do not receive BPDUs. Receiving a BPDU on a
Port Fast-enabled interface means an invalid configuration, such as the connection of an unauthorized
device. If a BPDU is received on Port Fast-enabled interface, the BPDU guard feature places the
interface into the ErrDisable state. The BPDU guard feature provides a secure response to invalid
configurations because you must manually put the interface back in service.
To disable BPDU guard, use the no spanning-tree portfast bpduguard global configuration command.
Command Purpose
Step1 configure terminal Enter global configuration mode.
Step2 spanning-tree portfast bpduguard Enable BPDU guard on the switch.
By default, BPDU guard is disabled on the switch.
Step3 end Return to privileged EXEC mode.
Step4 show spanning-tree summary total Verify your entries.
Step5 copy running-config startup-config (Optional) Save your entries in the configuration file.