Command Line Reference Guide
shutdown-on-
violation
(OPTIONAL) Enter the keywords shutdown-on-violation to
hardware disable an interface when a BPDU is received and the port
is disabled.
err-disable Enter the keywords err-disable to enable the port to be put into
the error-disable state (EDS) if an error condition occurs.
vlan
vlan-range
Enter the keyword vlan followed by the VLAN number(s). The range
is 1 to 4094.
cost
number
Enter the keyword cost followed by the port cost value. The range is
1 to 200000.
Defaults:
• 1-Gigabit Ethernet interface = 20000.
• 10-Gigabit Ethernet interface = 2000.
• 40-Gigabit Ethernet interface = 2000
• Port Channel interface with one 1-Gigabit Ethernet = 20000.
• Port Channel interface with one 10-Gigabit Ethernet = 2000.
• Port Channel interface with one 40-Gigabit Ethernet = 2000.
• Port Channel with two 1-Gigabit Ethernet = 18000.
• Port Channel with two 10-Gigabit Ethernet = 1800.
• Port Channel with two 40-Gigabit Ethernet = 1800.
priority
value
Enter the keyword priority followed the Port priority value in
increments of 16. The range is 0 to 240. The default is
128.
loopguard Enter the keyword loopguard to enable loop guard on a PVST+
port or port-channel interface.
rootguard Enter the keyword rootguard to enable root guard on a PVST+ port
or port-channel interface.
Defaults Not configured.
Command Modes INTERFACE
Command History
Version 9.0(1.3) Introduced on the S5000.
Usage
Information
The BPDU guard option prevents the port from participating in an active STP topology in case a
BPDU appears on a port unintentionally, or is misconfigured, or is subject to a DOS attack. This
option places the port into an the Error Disable state if a BPDU appears, and a message is
logged so that the administrator can take corrective action.
NOTE: A port configured as an edge port, on a PVST switch, immediately transitions to the
forwarding state. Only ports connected to end-hosts should be configured as an edge port.
Consider an edge port similar to a port with a spanning-tree portfast enabled.
If you do not enable shutdown-on-violation, BPDUs are still sent to the stack-unit CPU.
You cannot enable root guard and loop guard at the same time on a port. For example,
if you configure
loop guard on a port on which root guard is already configured, the
following error message is displayed: % Error: RootGuard is configured.
Cannot configure LoopGuard.
1029