72. BPDU Guard of STP security configuration experiment
1. BPDU Guard parsing
In order to protect the stability of Spanningtree, BPDU Guard is configured on the non-switch port of the switch. When BPDU is received on the interface configured with BPDU Guard, the interface state becomes err-disabled, and the physical and link state of the interface is down.
Configuration method:
Global configuration mode: spanning-tree portfast bpduguard default
API configuration mode: spanning-tree bpduguard enable is enabled
Interface configuration mode: spanning-tree bpduguard disable is down
Recovery method:
Manual recovery: shutdown the interface after no shutdown
Automatic recovery: errdisable recovery cause bpduguard
Recovery interval: errdisable recovery interval 30
2. Configure BPDU Guard
We now turn on bgduguard on the S4 interface and set the automatic recovery interval to 30s. When we connect S1 to the e0and0 of S4, observe the state change of the interface.