Specifications
Understanding and Configuring SpanGuard
March 14, 2011 Page 20 of 29
Understanding and Configuring SpanGuard
ThissectionprovidesinformationaboutthefollowingSpanGuardtopicsandtasks:
• WhatIsSpanGuard?(page20)
• HowDoesItOperate?(page20)
• ConfiguringSpanGuard(page21)
What Is SpanGuard?
AsdescribedpreviouslyintheoverviewofSpanGuardonpage5,thisfeatureenablesEnterasys
switchingdevicestodetectunauthorizedbridgesinyournetwork,resolvingthethreatofrepeated
topologychangenotificationsornewrootbridgeannouncementscausingaDenialofService
(DoS)condition.ItpreventsSpanningTreerespansthatcan
occurwhenBPDUsarereceivedon
userportsandnotifiesyou(networkmanagement)theywereattempted.
IfaSpanGuardenabledportreceivesaBPDU,itbecomeslockedandtransitionstotheblocking
state.Itwillonlytransitionoutoftheblockingstateafteragloballyspecifiedtimeorwhenitis
manuallyunlocked.
Bydefault,SpanGuardisgloballydisabledonN‐Series,S‐Series,stackable,and standaloneswitch
devicesandmustbegloballyenabledtooperateonalluserports.Forconfigurationinformation,
referto“ConfiguringSpanGuard”onpage 21.
How Does It Operate?
SpanGuardhelpsprotectagainstSpanningTreeDenialofService(DoS)SpanGuardattacksas
wellasunintentional/unauthorizedconnectedbridgesbyinterceptingreceivedBPDUson
configuredportsandlockingtheseportssotheydonotprocessanyreceivedpackets.
Whenenabled,receptionofaBPDUonaportthatisadministrativelyconfiguredas
aSpanning
Treeedgeport(adminedge=True)willcausetheporttobecomelockedandthestatesetto
blocking.Whenthisconditionismet,packetsreceivedonthatportwillnotbeprocessedfora
specifiedtimeoutperiod.Theportwillbecomeunlockedwheneither:
Display a list of MSTIs configured on the device. show spantree mstilist
Display the mapping of one or more filtering
database IDs (FIDs) to Spanning Trees. Since
VLANs are mapped to FIDs, this shows to which SID
a VLAN is mapped.
show spantree mstmap [fid fid]
Display the Spanning Tree ID(s) assigned to one or
more VLANs.
show spantree vlanlist [vlan-list]
Display MST configuration identifier elements,
including format selector, configuration name,
revision level, and configuration digest.
show spantree mstcfgid
Display protocol-specific MSTP counter information. show spantree debug [port port-string]
[sid sid] [active]
Table 6 Commands for Monitoring MSTP (continued)
Task Command