06-29-2006 03:19 AM - edited 03-03-2019 03:51 AM
Does BPDU guard stop end users from installing ANY switch (including the SOHO switches - Netgear, Linksys, D-Link, etc)?
06-29-2006 04:35 AM
Anything that sends BPDU packets will cause the port to shutdown. If the switch uses Spanning tree it should shut it down.
06-29-2006 04:46 AM
To elaborate... things that don't participate in STP - e.g hubs or APs with STP turned off... would likely not be prevented from being added.
To prevent that sort of thing you could use MAC port security with aging to allow only 2 or so MAC addresses per port...
Regards
Aaron
Please rate helpful posts...
06-29-2006 04:45 AM
On the other hand, most SOHO switches do not implement Spanning Tree. If you are concerned about users installing switches, you need to take other precautions as well.
You can stop the users using a switch to fan out a port, by configuring port security and only allowing one MAC address on the port.
The BPDU guard will give you some protection against certain malicious user practices, even if the rogue switch does not do Spanning Tree. For example, the user who plug in a SOHO switch, and then plugs two other ports of that SOHO switch back-to-back with a cross-cable. In this case, your Catalyst will see its own BPDUs circulating round the loop, and will close the port down. (If the SOHO switch is not doing Spanning Tree, then it will pass the BPDUs through transparently.) This is why you should not have bdpu-guard and bpdu-filter on the same port.
Kevin Dorrell
Luxembourg
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide