03-11-2010 07:46 AM - edited 03-06-2019 10:05 AM
Hi,
Could someone please confirm if applying bpdu filter enable on access ports with portfast enabled is best practice?
Thanks
Darren
Solved! Go to Solution.
03-11-2010 09:32 AM
BPDU guard will error disable the port if it detect BPDU (another switch).
BPDU filter will turn off portfast if it detect BPDU.
If a BPDU is received on a Port Fast-enabled interface, the interface loses its Port Fast-operational status, and BPDU filtering is disabled.
HTH,
jerry
03-11-2010 02:05 PM
Personally, for an access port, I'd go for STP portfast and BPDU Guard enabled. For trunk ports I have both disabled.
03-12-2010 02:14 AM
Hello Darren,
>> Could someone please confirm if applying bpdu filter enable on access ports with portfast enabled is best practice?
No it isn't, use bpdu guard + portfast it is more safe.
if you make a search in the forums you will find several issues caused by bpdu filter (possible bridging loops)
Hope to help
Giuseppe
03-11-2010 07:55 AM
Depend on your company's policy. If you want the port to be hard down when someone plug a switch into a portfast enabled port, then you should use bpdu guard. If your policy is to allow switch into portfast enabled port, then bpdu filter is a better approach.
HTH,
jerry
03-11-2010 09:24 AM
I thought you could use both. BPDU guard to protect a port if it receives a BPDU so error disables the port.
Then BPDU filter simply to stop sending BPDU's from the port.
03-11-2010 09:32 AM
BPDU guard will error disable the port if it detect BPDU (another switch).
BPDU filter will turn off portfast if it detect BPDU.
If a BPDU is received on a Port Fast-enabled interface, the interface loses its Port Fast-operational status, and BPDU filtering is disabled.
HTH,
jerry
03-11-2010 02:05 PM
Personally, for an access port, I'd go for STP portfast and BPDU Guard enabled. For trunk ports I have both disabled.
03-12-2010 02:14 AM
Hello Darren,
>> Could someone please confirm if applying bpdu filter enable on access ports with portfast enabled is best practice?
No it isn't, use bpdu guard + portfast it is more safe.
if you make a search in the forums you will find several issues caused by bpdu filter (possible bridging loops)
Hope to help
Giuseppe
03-12-2010 08:33 AM
Many thanks for everyone's replies. A CCIE engineer recently came and configured two Nexus 7000 switches for us and applied the spanning-tree bpduguard enable and spanning-tree bpdufilter enable on every access port which I found strange. Now I have confirmation I will remove the spanning-tree bpdufilter command from the access ports.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide