STP Optional Characteristic Configuration I Table of Contents Table of Contents Chapter 1 Configuring STP Optional Characteristic..............................................1 1.1 STP Optional Characteristic Introduction..............................................................................1 1.1.1 Port Fast...................................................................................................................1 1.1.2 BPDU Guard............................................................................................................2 1.1.3 BPDU Filter.............................................................................................................. 2 1.1.4 Uplink Fast............................................................................................................... 3 1.1.5 Backbone Fast.........................................................................................................4 1.1.6 Root Guard...............................................................................................................6 1.1.7 Loop Guard.............................................................................................................. 6 1.2 Configuring STP Optional Characteristic.............................................................................. 7 1.2.1 STP Optional Characteristic Configuration Task...............................................7 1.2.2 Configuring Port Fast............................................................................................. 7 1.2.3 Configuring BPDU Guard......................................................................................7 1.2.4 Configuring BPDU Filter........................................................................................ 8 1.2.5 Configuring Uplink Fast..........................................................................................9 1.2.6 Configuring Backbone Fast...................................................................................9 1.2.7 Configuring Root Guard.........................................................................................9 1.2.8 Configuring Loop Guard........................................................................................ 9 1.2.9 Configuring Loop Fast..........................................................................................10 1.2.10 Configuring Address Table Aging Protection................................................ 11 1.2.11 Configuring FDB-Flush......................................................................................11 1.2.12 Configuring BPDU Terminal............................................................................. 12 II STP Optional Characteristic Configuration Chapter 1 Configuring STP Optional Characteristic 1.1 STP Optional Characteristic Introduction The spanning tree protocol module of the switch supports seven additional characteristics (the so-called optional characteristics). These characteristics are not configured by default. The supported condition of various spanning tree protocol modes towards the optional characteristics are as follows: Optional Single STP PVST RSTP MSTP Characteristic Port Fast Yes Yes No No BPDU Guard Yes Yes Yes Yes BPDU Filter Yes Yes No No Uplink Fast Yes Yes No No Backbone Fast Yes Yes No No Root Guard Yes Yes Yes Yes Loop Guard Yes Yes Yes Yes 1.1.1 Port Fast Port Fast immediately brings an interface to the forwarding state, bypassing the listening and learning states. In SSTP and PVST mode, you can use Port Fast on interfaces connected to the host or server, to allow those devices to immediately connect to the network. Port Fast is applicable for connecting ports of the host. As these ports will not receive BPDU and will not affect the network topology, they can enter the forward state without waiting. If the Port Fast function is configured on the interface connecting to the switch, there may cause a loop. Port Fast Characteristics can be configured in global configuration mode or interface configuration mode. When in global configuration mode, all interfaces will be taken as Port Fast interfaces and fast enter Forwarding state. Thus, it is more likely to cause loop. For avoiding the network loop resulting from Port Fast function, use BPDU Guard or BPDU Filter to protect the interface. 1 STP Optional Characteristic Configuration Figure 1.1 Port Fast Note: The rapid convergent spanning tree protocol, RSTP and MSTP can immediately bring an interface to the forwarding state, and therefore there is no need to use Port Fast feature. 1.1.2 BPDU Guard If one Port Fast receives BPDU, it may because of the false network configuration. When one Port Fast receives BPDU, BPDU Guard will protect it passively. In different STP modes, BPDU Guard acts differently. In SSTP/PVST mode, if a port that has the BPDU Guard function and the Portfast function configured receives BPDU, this port will be manadatorily shut down. You have to configure the port manually to resume this port. In RSTP/MSTP mode, if a BPDU-Guard-configured port receives BPDU, the port will be set to the Blocking state in a period of time. BPDU Guard characteristics can be configured independent of Port Fast. In all STP modes, the interfaces configured with BPDU Guard will not send BPDU. But the interface can receive BPDU and process it. In RSTP/MSTP mode, you can configure BPDU Guard on the port to ensure the device connected to the switch will not receive BPDU. BPDU Guard characteristics can be configured in global or interface mode. In global configuration mode, run command spanning-tree portfast bpduguard to block all interfaces sending BPDU. Note that inappropriate use of BPDU Guard will cause loop in complicated network. 1.1.3 BPDU Filter With the BPDU filtering characteristic, the switch will block BPDU to send out in SSTP/PVST mode, and also from a protection of the Port Fast. 2 STP Optional Characteristic Configuration In SSTP/PVST mode, if a Port Fast port with BPDU filter configured receives the BPDU, the characteristic BPDU Filter and Port Fast at the port will be automatically disabled, resuming the port as a normal port. Before entering the Forwarding state, the port must be in the Listening state and Learning state. The same with BPDU Guard, BPDU Filter characteristic can be configured in global configuration mode or in port configuration mode. In global configuration mode, run the command spanning-tree portfast bpdufilter to block all ports to send BPDU out. The port, however, can still receive and process BPDU. 1.1.4 Uplink Fast The characteristic Uplink Fast enables new root ports to rapidly enter the Forwarding state when the connection between the switch and the root bridge is disconnected. A complex network always contains multiple layers of devices, as shown in figure 1.2. Both aggregation layer and the access layer of the switch have redundancy connections with the upper layer. These redundancy connections are normally blocked by the STP to avoid loops. Figure 1.2 Switching network topology Suppose the connection between a switch and the upper layer is disconnected (called as Direct Link Failure), the STP chooses the Alternate port on the redundancy line as the root port. Before entering the Forwarding state, the Alternate port must be in the Listening state and Learning state. If the Uplink Fast feature is configured by running the command spanning-tree uplinkfast in global configuration mode, new root port can directly enter the forwarding state, resuming the connection between the switch and the upper layer. Figure 1.3 shows the working principle of the Uplink Fast feature. The port for device C to connect device B is the standby port when the port is in the original state. When the connection between device C and root device A is disconnected, the previous Alternate port is selected as new root port and immediately starts forwarding. 3 STP Optional Characteristic Configuration Figure 1.3 Uplink Fast Note: The Uplink Fast characteristic adjusts to the slowly convergent SSTP and PVST. In RSTP and MSTP mode, new root port can rapidly enter the Forwarding state without the Uplink Fast function. 1.1.5 Backbone Fast The Backbone Fast characteristic is a supplement of the Uplink Fast technology. The Uplink Fast technology makes the redundancy line rapidly work in case the direct connection to the designated switch is disconnected, while the Backbone Fast technology detects the indirect-link network blackout in the upper-layer network and boosts the change of the port state. In figure 1.3, Connection L2 between switch C and switch A is called as the direct link between switch C and root switch A. If the connection is disconnected, the Uplink Fast function can solve the problem. Connection L1 between devices A and B is called as the indirect link of device C. The disconnected indirect link is called as indirect failure, which is handled by the Backbone Fast function. The working principle of the Backbone Fast function is shown in Figure 1.4. 4 STP Optional Characteristic Configuration Figure 1.4 Backbone Fast Suppose the bridge priority of switch C is higher than that of switch B. When L1 is disconnected, device B is selected to send BPDU to device C because the bridge priority is used as root priority. To device C, the information contained by BPDU is not prior to information contained by its own. When Backbone Fast is not enabled, the port between device C and device B ages when awaiting the bridge information and then turns to be the designated port. The aging normally takes a few seconds. After the function is configured in global configuration mode by running the command spanning-tree backbonefast, when the Alternate port of device C receives a BPDU with lower priority, device C thinks that an indirect-link and root-device-reachable connection on the port is disconnected. Device C then promptly update the port as the designated port without waiting the aging information. After the Backbone Fast function is enabled, if BPDU with low priority is received at different ports, the switch will perform different actions. If the Alternate port receives the message, the port is updated to the designated port. If the root port receives the low-priority message and there is no other standby port, the switch turns to be the root switch. Note that the Backbone Fast feature just omits the time of information aging. New designated port still needs to follow the state change order: the listening state, then the learning state and finally the forwarding state. Note: Similar to Uplink Fast, the Backbone Fast characteristic is effective in SSTP and 5 STP Optional Characteristic Configuration PVST modes. 1.1.6 Root Guard The Root Guard attribute can prevent a port from serving as a root port after it receives a higher-priority BPDU. In a complicated layer-2 network, the administrator may hope a switch in the core layer as the root of the network, but it cannot manage all switches in the access layer (That's because the switch in the access layer may belong to other clients.) Thus, the inappropriate configuration of other switches may cause the core switch cannot become the root. To avoid the root role is occupied by switches outside the management area, you can configure Root Guard function on the boundary switch. If an interface configured Root Guard receives information that a higher BPDU is chosen as Port Port, Root Guard will automatically set the port as the blocking state and resumes it as the designated port. In PVST and MSTP mode, Root Guard can work independently in each STP. In MSTP mode, if a boundary interface in CIST is blocked because of Root Guard, the interface will be blocked in all MSTI. The boundary interfaces are those connected to the LAN host, STP switch, RSTP switch or MSTP switch outside the region. In interface configuration mode, run command spanning-tree guard root to enable Root Guard characteristic. Note: Root Guard characteristic acts differently somehow in SSTP/PVST and RSTP/MSTP. In SSTP/PVST mode, Root port is always blocked by Root Guard. In RSTP/MSTP mode, Root port won’t be blocked until receiving higher level BPDU. A port which formerly plays the Root role will not be blocked. 1.1.7 Loop Guard The Loop Guard attribute can protect a port after it changes from a root port or an alternate port to a designated port. This function can prevent a port from generating a loop when the port cannot receive BPDU continuously. You can enable this feature by using the spanning-tree loopguard default global configuration command. After enabled the command, a Root port or Alternate port wil change to designated port and set as the block state. If the port receives high priority BODU in a while, it will resumes from Loop Guard automatically. In PVST and MSTP mode, Loop Guard can work independently in each STP. In MSTP mode, if a boundary interface in CIST is blocked because of Root Guard, the interface will be blocked in all MSTI. Note: Root Guard characteristic acts differently somehow in SSTP/PVST and RSTP/MSTP. In SSTP/PVST mode, designated port is always blocked by Loop Guard. In RSTP/MSTP mode, the port will be blocked when it changes to designated port if it cannot receive BPDU. An interface receiving low priority BPDU and is of the designated role will not be blocked by 6 STP Optional Characteristic Configuration Loopt Guard. 1.2 Configuring STP Optional Characteristic 1.2.1 STP Optional Characteristic Configuration Task  Configuring Port Fast  Configuring BPDU Guard  Configuring BPDU Filter  Configuring Uplink Fast  Configuring Backbone Fast  Configuring Root Guard  Configuring Loop Guard  Configuring Loop Fast  Configuring Address Table Aging Protection  Configuring FDB-Flush  Configuring BPDU Terminal 1.2.2 Configuring Port Fast In SSTP/PVST mode, Port Fast immediately brings an interface to the forwarding state, bypassing the listening and learning states. The function is invalid in other STP mode. Use the following command to configure the port fast feature in the global configuration mode: Command Purpose spanning-tree portfast default Globally enables port fast feature. It is valid to all interfaces. no spanning-tree portfast default Globally disables port fast feature. It has no effect on the interface configuration. Note: The port fast feature only applies to the interface that connects to the host. The BPDU Guard or BPDU Filter must be configured at the same time when the port fast feature is configured globally. Use the following command to configure the port fast feature in the interface configuration mode: Command Purpose spanning-tree portfast Disables port fast feature on the interface. It has no effect on the global configuration. no spanning-tree portfast Globally disables port fast feature. It has no effect on the interface configuration. 1.2.3 Configuring BPDU Guard BPDU Guard feature acts when receiving BPDU. The interface configured BPDU Guard feature will not send BPDU. In different STP modes, BPDU Guard acts differently. In SSTP/PVST mode, if a configured 7 STP Optional Characteristic Configuration port that has the BPDU Guard function and the Portfast function receives BPDU, this port will be shut down mandatorily. You have to configure the port manually to resume this port. In RSTP/MSTP mode, if a BPDU-Guard-configured port receives BPDU, the port will be set to the Blocking state in a period of time. In global configuration mode, run command BPDU Guard: Command Purpose spanning-tree portfast bpduguard Globally enables BPDU Guard feature. It is valid to all interfaces. no spanning-tree portfast bpduguard Globally disables bpdu guard feature. Note: Globally enabling port fast feature may result in broadcast storm. The BPDU Guard or BPDU Filter should be configured for protection sake. Use the following command to configure the BPDU Guard feature in the interface configuration mode: Command Purpose spanning-tree bpduguard enable Enables bpdu guard feature on the interface. spanning-tree bpduguard disable Disables bpdu guard feature on the interface. It has no effect on the global configuration. no spanning-tree bpduguard Disables bpdu guard feature on the interface. It has no effect on the global configuration. 1.2.4 Configuring BPDU Filter With the BPDU filtering characteristic, the switch will block BPDU to send out in SSTP/PVST mode, and also from a protection of the Port Fast. In global configuration mode, run command BPDU Filter: Command Purpose spanning-tree portfast bpdufilter Globally enables BPDU Filter feature. It is valid to all interfaces. no spanning-tree portfast bpdufilter Globally disables BPDU Filter feature. Note: Globally enabling port fast feature may result in broadcast storm. The BPDU Guard or BPDU Filter should be configured for protection sake. Use the following command to configure the BPDU Filter feature in the interface configuration mode: Command Purpose spanning-tree bpdufilter enable Enables BPDU Filter feature on the interface. spanning-tree bpdufilter disable Disables BPDU Filter feature on the interface. It has no effect on the global configuration. 8 STP Optional Characteristic Configuration no spanning-tree bpdufilter Disables BPDU Filter feature on the interface. It has no effect on the global configuration. 1.2.5 Configuring Uplink Fast The characteristic Uplink Fast enables new root ports to rapidly enter the Forwarding state when the connection between the switch and the root bridge is disconnected. The Uplink Fast function validates only in SSTP/PVST mode. In global configuration mode, run command Uplink Fast characteristic: Command Purpose spanning-tree uplinkfast Enables uplink fast feature. no spanning-tree uplinkfast Disables Uplink Fast feature. 1.2.6 Configuring Backbone Fast The Backbone Fast characteristic is a supplement of the Uplink Fast technology. The Uplink Fast technology makes the redundancy line rapidly work in case the direct connection to the designated switch is disconnected, while the Backbone Fast technology detects the indirect-link network blackout in the upper-layer network and boosts the change of the port state. The backbonefast function validates only in SSTP/PVST mode. In global configuration mode, run command Backbone Fast characteristic: Command Purpose spanning-tree backbonefast Enables backbone fast feature. no spanning-tree backbonefast Disables backbone fast feature. 1.2.7 Configuring Root Guard The Root Guard attribute can prevent a port from serving as a root port after it receives a higher-priority BPDU. Root Guard characteristic acts differently somehow in SSTP/PVST and RSTP/MSTP. In SSTP/PVST mode, Root port is always blocked by Root Guard. In RSTP/MSTP mode, Root port won’t be blocked until receiving higher level BPDU. A port which formerly plays the Root role will not be blocked. Use the following command to configure the Root Guard feature in the interface configuration mode: Command Purpose spanning-tree guard root Enables Root Guard feature on the interface. no spanning-tree guard Disables root guard and loop guard features on the interface. spanning-tree guard none Disables root guard and loop guard features on the interface. 1.2.8 Configuring Loop Guard The Loop Guard attribute can protect a port after it changes from a root port or an alternate port to a designated port. This function can prevent a port from generating a loop when the 9 STP Optional Characteristic Configuration port cannot receive BPDU continuously. Root Guard characteristic acts differently somehow in SSTP/PVST and RSTP/MSTP. In SSTP/PVST mode, designated port is always blocked by Loop Guard. In RSTP/MSTP mode, the port will be blocked when it changes to designated port if it cannot receive BPDU. An interface receiving low priority BPDU and is of the designated role will not be blocked by Loopt Guard. In global configuration mode, run command Loop Guard: Command Purpose spanning-tree loopguard default Globally enables loop guard feature. It is valid to all interfaces. no spanning-tree loopguard default Globally disables loop guard. Use the following command to configure the Loop Guard feature in the interface configuration mode: Command Purpose spanning-tree guard loop Enables loop guard feature on the interface. no spanning-tree guard Disables root guard and loop guard features on the interface. spanning-tree guard none Disables root guard and loop guard features on the interface. 1.2.9 Configuring Loop Fast Note: Please configure this command under the guide of technical engineers. Loop Fast feature is applied to improve the network convergence in a limited range in special network environment. For instance, enable Loop Fast feature for all interfaces in the ring network with a dozen of switches. Run following commands in global mode to configure Loop Fast feature: Command Purpose spanning-tree loopfast Globally enables Loop Fast feature. It is valid to all interfaces. no spanning-tree loopfast Globally disables Loop Fast. Use the following command in interface configuration mode to enable Loop Fast: Command Purpose spanning-tree loopfast Enables loop fast feature on the interface. no spanning-tree loopfast Disables Loop Fast feature on the interface. If the global loop fast is configured, the feature on the interface remains effective. spanning-tree loopfast disable Disables Loop Fast on the interface. 10 STP Optional Characteristic Configuration 1.2.10 Configuring Address Table Aging Protection Under the circumstance of changeable network topology, the configuration of address table aging protection will not affect communication as a result of STP frequently changing the MAC address table. STPs, such as RSTP and MSTP, will clear the MAC address table of the switch when detecting the STP topology change (delete the old MAC address and update the MAC address), so that the communication can be recovered rapidly. By default, clear action is finished through MAC address table fast aging. Most switches can finish MAC address table fast aging within 1 minute and has little effect on the performance of CPU. After enabling the address table aging protection function, STP enables protection timer after running the first aging. Before the timeout, another aging will not run. The timer is 15 seconds by default. If the network topology changes within 15 seconds, STP will run a second aging automatically after the timeout. Note: The command no spanning-tree fast-aging can disable STP running address table aging. Before running the configuration, please ensure the network does not exist loop. Otherwise, the terminal device may need5 mins or even longer time to resume the communication after the network topology changes In global configuration mode, run following command to configure the address table aging protection function. Command Purpose spanning-tree fast-aging Enable/disable address table aging function. spanning-tree fast-aging protection Enable/disable address table aging protection function. spanning-tree fast-aging protection time Sets the time of address table aging protection. Before the time, STP can only run address table aging once. The default value is 15 second. Use the no form of this command to resume the default setting 1.2.11 Configuring FDB-Flush Note: Please configure this command under the guide of technical engineers. By default, RSTP and MSTP of the switch clear the old MAC address by way of address table fast aging, rather than FDB-Flush. In global configuration mode, run the following command to configure FDB-Flush: Command Purpose spanning-tree fast-aging flush-fdb Enable FDB-Flush. 11 STP Optional Characteristic Configuration no spanning-tree fast-aging flush-fdb Disable FDB-Flush. Note that FDB-Flush is independent of fast aging. FDB-Flush can be configured while no spanning-tree fast-aging is configured. But fast aging protection function has no effect on FDB-Flush. 1.2.12 Configuring BPDU Terminal By default, the device will forward the received BPDU when there is no STP running. BPDU terminal function can forbid forwarding BPDU when there is no STP running. In global configuration mode, run the following command to configure BPDU Terminal: Command Purpose spanning-tree bpdu-terminal Enables BPDU Terminal. no spanning-tree bpdu-terminal Disables BPDU Terminal. 12