cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
795
Views
15
Helpful
7
Replies

use of portfast and BPDU guard

knaik99
Level 1
Level 1

Can we enable portfast and BPDU guard on switch port where AP is connected?

Can we enable port security also on switch port where AP is connected?

7 Replies 7

Arshad Safrulla
VIP Alumni
VIP Alumni

Definitely you can enable port fast in the AP connecting ports, irrespective whether the port is configured as trunk or access. Please find the below.

  • if the AP is in Flex and port is configured as trunk - spanning-tree portfast trunk
  • If the AP is in Local mode and port is configured as access - spanning-tree portfast 

You can enable bpduguard on the access ports connecting to the Local mode APs, however I don't recommend enabling bpduguard in the AP connecting trunk ports. (APs doesn't usually send BPDUs)

Can we enable portfast and BPDU guard on switch port where AP is connected? Yes you can 

Can we enable port security also on switch port where AP is connected? NO you can not because of the Wireless client if roaming then the port is showdown since the mac address (mac of wireless client ) is learn from two or more port. 

Rich R
VIP
VIP

We actually use portfast with this as our standard:
spanning-tree bpdufilter enable
spanning-tree bpduguard disable

This ever since we had some trouble with AP ports and bpduguard some years back and TAC recommended using bpdufilter instead.  You don't want to shut the port - just drop all BPDUs.

@Arshad Safrulla "(APs doesn't usually send BPDUs)" - correct - except they apparently sometimes do (buggy software?) and that causes havoc ...

BPDU-Guard error-disables the port and BPDU Filter can not shut down the port but drops the BPDU received i.e. Not receiving BPDU coming ,right?

 

May I ask what is the goal behind enabling these features? I have never enabled these features for AP connecting ports in most of my deployments till today. I Don't recommend enabling bpdu guard or bpdu filter on any AP connecting ports. It is not recommended by Cisco as well.

@Arshad Safrulla I don't know what the history was but I inherited some switchports with bpduguard enabled - probably a security directive or something - which caused problems (obviously) when APs sent BPDU's on startup.  TAC recommended the bpdufilter config instead.  We've used it since without any problems.

Rich R
VIP
VIP

BPDU-Guard error-disables the port and BPDU Filter can not shut down the port but drops the BPDU received i.e. Not receiving BPDU coming ,right?

Exactly

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card