02-16-2025 06:55 AM
Hello,
If you enable BPDU Guard and BPDU Filter on an interface, then how does your switch detect an unmanaged switch?
Because if only BPDU Guard is enabled, and the unmanaged switch has two of its interfaces connected, then your switch's BPDUs circle back to itself. That's because your switch sends out BPDUs towards the unmanaged switch, and the unmanaged switch sends those BPDUs out all of its other ports, which then send it back via the port that's connected to your switch.
But with BPDU Filter, your managed switch doesn't send any BPDUs, which means there's no chance that they can circle back to your managed switch. Which means it can't detect the loop.
Thanks!
02-16-2025 07:02 AM
That why you must never never use bpdu filter when connect two SW via two link'
Control plane can not detect loop because of bpdu filter and ypur network will be crash due to l2 storm.
Only one case we use bpdu filter between two SW when there is only one link.
MHM
02-16-2025 07:13 AM
Thank you for the quick response!
I wonder what you think about this use case for BPDU Filter:
Two switches from two different companies are connected directly. Both companies want to have their separate STP topologies. Normally, that's not possible, because the switches will keep sending BPDUs to each other.
So, if you enable BPDU Filter, none of the two switches send any BPDUs to the other switch. Which means their STP topologies will remain unchanged.
What do you think? I recall reading about this somewhere, but I haven't saved the source unfortunately.
02-16-2025 07:17 AM
You can use bpdu filter in case
There is one link.
Why? With one link there is no l2 loop'
When one SW receive broadcast it never re-send again via same interface it receive from' this make ypu safety apply bpdu filter abd isolate stp domain in both groups.
MHM
02-16-2025 07:55 AM
Hello @MHM Cisco World
Bpdu-filter CAN be used in a switch with multiple links to another switch
globally it works with portfast interfaces and you would not have PF on trunks interconnections towards other switchs
At an interface level is works independently without PF as such it can be decremental on trunks towards other switches as it WILL filter stp and possibly cause loops
02-16-2025 08:02 AM
Loop from where ?
Loop need two link between two SW' I clearly mention one link.
Please read my comment' this last time I reply to you.
MHM
02-16-2025 08:10 AM
Hello
@MHM Cisco World wrote:
That why you must never never use bpdu filter when connect two SW via two link'
02-16-2025 08:13 AM
That why you must never never use bpdu filter when connect two SW via two link' <<- you not see this words ??
I have little time and you waste it.
Dont mention me anymore' reply to OP directly.
MHM
02-16-2025 07:36 AM
Hello
bpdu-filter works well with guard at a global level -however when applied at an interface level it will take precedence over guard as such guard isn’t even used which would result in the filtering of bpdus which could potentially cause loops in your network
02-16-2025 08:50 AM
Hello,
First of all, you need to manage your network, /
If you do not want to face any issues on your network / you need to disable DTP and shut all unused ports / if the port is an access port you can enable port-sec (max 2 or 3 MAC addresses allowed).
If you want to learn how it will work at STP /, you can also use Port Guard (or UDLD ).
Thanks!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide