11-15-2022 11:47 PM
Can we enable portfast and BPDU guard on switch port where AP is connected?
Can we enable port security also on switch port where AP is connected?
11-16-2022 12:19 AM - edited 11-16-2022 12:21 AM
Definitely you can enable port fast in the AP connecting ports, irrespective whether the port is configured as trunk or access. Please find the below.
You can enable bpduguard on the access ports connecting to the Local mode APs, however I don't recommend enabling bpduguard in the AP connecting trunk ports. (APs doesn't usually send BPDUs)
11-16-2022 12:26 AM
Can we enable portfast and BPDU guard on switch port where AP is connected? Yes you can
Can we enable port security also on switch port where AP is connected? NO you can not because of the Wireless client if roaming then the port is showdown since the mac address (mac of wireless client ) is learn from two or more port.
11-16-2022 09:00 AM
We actually use portfast with this as our standard:
spanning-tree bpdufilter enable
spanning-tree bpduguard disable
This ever since we had some trouble with AP ports and bpduguard some years back and TAC recommended using bpdufilter instead. You don't want to shut the port - just drop all BPDUs.
@Arshad Safrulla "(APs doesn't usually send BPDUs)" - correct - except they apparently sometimes do (buggy software?) and that causes havoc ...
11-16-2022 09:37 AM
BPDU-Guard error-disables the port and BPDU Filter can not shut down the port but drops the BPDU received i.e. Not receiving BPDU coming ,right?
11-16-2022 10:17 AM
May I ask what is the goal behind enabling these features? I have never enabled these features for AP connecting ports in most of my deployments till today. I Don't recommend enabling bpdu guard or bpdu filter on any AP connecting ports. It is not recommended by Cisco as well.
11-16-2022 10:26 AM
@Arshad Safrulla I don't know what the history was but I inherited some switchports with bpduguard enabled - probably a security directive or something - which caused problems (obviously) when APs sent BPDU's on startup. TAC recommended the bpdufilter config instead. We've used it since without any problems.
11-16-2022 10:16 AM - edited 11-16-2022 10:28 AM
> BPDU-Guard error-disables the port and BPDU Filter can not shut down the port but drops the BPDU received i.e. Not receiving BPDU coming ,right?
Exactly
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: