User`s guide
Configuring Spanguard
5-16 Configuring Spanning Trees
Configuring Spanguard
ThissectionprovidesinformationaboutthefollowingSpanguardtasks:
• OverviewoftheSpanguardFunction
• EnablingandAdjustingSpanguard
Overview of the Spanguard Function
EnterasysNetworks’SpanguardfunctionprovidestheabilityforEnterasysswitchestodetect
unauthorizedbridgesinthenetwork.ItprotectsagainstSpanningTreeDenialofService(DoS)
attacksaswellasunintentional/unauthorizedconnectedbridges.Thisisdonebyintercepting
receivedBPDUsonconfiguredportsandlockingtheseportssotheydonot
processanyreceived
packets—thusprotectingtheintegrityoftheSpanningTreetopology.
Bydefault,Spanguardisgloballydisabled.Whenenabled,receptionofaBPDUonaportthatis
administrativelyconfiguredasaspanningtreeedgeport(adminedge=True)willcausetheport
tobecomelockedandthestate
settoblocking.Whenthisconditionismet,packetsreceivedon
thatportwillnotbeprocessedforaspecifiedtimeou tperiod.Theportwillbecomeunlocked
wheneither:
•Thetimeoutexpires
•Theportismanuallyunlocked
•Theportisnolongeradministrativelyconfiguredasadminedge=True
•TheS pangua rdfunction isdisabled
TheportwillbecomelockedagainshouldanotheroffendingBPDUbereceivedonthatportafter
expirationofthetimeoutormanualunlockingofthatportoccurs.
IntheeventofaDoSattackwithSpanguardenabledandconfigured,nospanningtreetopology
changesortopologyreconfigurationswillbeseen.The
stateofthespanningtreewillbe
completelyunaffectedbythereceptionofanyspoofedBPDUsregardlessoftheBPDUtype,rate
receivedordurationoftheattack.
Bydefault,whenSNMPandSpanguardareenabled,atrapmessagewillbegeneratedwhen
Spanguarddetectsthatanunauthorizedporthastried
tojoinaSp anningTree.
Display the mapping of one or more filtering
database IDs (FIDs) to spanning trees. Since VLANs
are mapped to FIDs, this shows to which SID a
VLAN is mapped.
show spantree mstmap [fid fid]
Display the spanning tree ID(s) assigned to one or
more VLANs.
show spantree vlanlist [vlan-list]
Display MST configuration identifier elements,
including format selector, configuration name,
revision level, and configuration digest.
show spantree mstcfgid
Display protocol-specific MSTP counter information. show spantree debug [port port-string]
[sid sid] [active]
Table 5-4 Commands for Monitoring MSTP (continued)
Task Command