欢迎来到天天文库
浏览记录
ID:38646025
大小:64.00 KB
页数:5页
时间:2019-06-17
《二层安全(各种Guard)》由会员上传分享,免费在线阅读,更多相关内容在教育资源-天天文库。
1、BPDUGuardBPDUFilterROOTGuardLOOPGuardBPDUGuard当portfast特性的端口被错误连接到交换机时,可能导致交换环路。开启BPDUGuard后,当portfast特性的端口收到BPDU报文后,将进入error-disabled状态。配置方式1:intf0/1spanning-treebpduguardenable接口下开启BPDUGuard。spanning-treebpduguarddisabled接口下关闭BPDUGuard。配置方式2:spanning-treeportfastbpd
2、ugaurddefault全局开启BPDUGuard。【查看】showspanning-treeintf0/1detailshowerrdisabledetect查看本交换机error-disable的检测ErrDisableReasonDetectionstatus---------------------------------udldEnabledbpduguardEnabledrootguardEnabledpagp-flapEnableddtp-flapEnabledlink-flapEnabledshowerrdisable
3、recovery查看本交换机error-disable自动恢复的设置ErrDisableReasonTimerStatus-------------------------------udldDisabledbpduguardDisabledrootguardDisabledpagp-flapDisableddtp-flapDisabledlink-flapDisabledTimerinterval:300seconds这是默认设置的恢复时间Interfacesthatwillbeenabledatthenexttimeout:【参数设
4、置】Config)#errdisablerecoverycausebpduguard设置由于BPDUGuard导致的error-disabled端口能够自动恢复。Config)#errdisablerecoveryinterval120设置error-diabled自动恢复的时间为120秒(默认为300秒)接口下启用BPDUFilter,则此端口不再发出BPDU报文,并且收到BPDU报文后直接忽略。(不推荐使用)intf0/1spanning-treebpdufilterenable全局启用BPDUFilter,则本交换机的所有port
5、fast特性的端口不再发出BPDU报文,但是当PortFast特性的端口收到BPDU后,将失去PortFast特性,按照普通的端口处理BPDU报文。SW(config)#spanning-treeportfastbpdufilterdefault示例:交换机SW配置如下:SW(config)#spanning-treeportfastdefaultSW(config)#intf0/2SW(config-if)#switchportmodeaccess步骤1:此时F0/2具备PortFast特性,它会周期性发出BPDU报文:SW#show
6、spanning-treeintf0/2detailPort2(FastEthernet0/2)ofVLAN0001isdesignatedforwardingPortpathcost19,Portpriority128,PortIdentifier128.2.Designatedroothaspriority4097,address0015.f9bd.a100Designatedbridgehaspriority32769,address000f.900c.9500Designatedportidis128.2,designatedp
7、athcost19Timers:messageage0,forwarddelay0,hold0Numberoftransitionstoforwardingstate:1TheportisintheportfastmodebydefaultLinktypeispoint-to-pointbydefaultBPDU:sent4,received0SW#showspanning-treeintf0/2detailPort2(FastEthernet0/2)ofVLAN0001isdesignatedforwardingPortpathcos
8、t19,Portpriority128,PortIdentifier128.2.Designatedroothaspriority4097,address0015.f9bd.a100Designatedbr
此文档下载收益归作者所有