Specifications

Understanding and Configuring SpanGuard
March 14, 2011 Page 21 of 29
•thetimeoutexpires,
•theportismanuallyunlocked,
•theportisnolongeradministrativelyconfiguredasadminedge=True,or
•theSpanGuardfunctionisdisabled.
TheportwillbecomelockedagainifitreceivesanotheroffendingBPDUafterthetimeoutexpires
oritismanuallyunlocked.
IntheeventofaDoSattack
withSpanGuardenabledandconfigured,noSpanningTreetopology
changesortopologyreconfigurationswillbeseeninyournetwork.ThestateofyourSpanning
TreewillbecompletelyunaffectedbythereceptionofanyspoofedBPDUs,regardlessofthe
BPDUtype,ratereceivedordurationoftheattack.
Bydefault,when
SNMPandSpanGuard areenabled,atrapmessagewillbegeneratedwhen
SpanGuarddetectsthatanunauthorizedporthastriedtojoinaSpanningTree.
Configuring SpanGuard
UsethefollowingcommandstoconfiguredeviceportsforSpanGuard,toenabletheSpanGuard
function,andtoreviewSpanGuardstatusonthedevice.
Reviewing and Setting Edge Port Status
Reviewandsetedgeportstatusasfollows:
1. Usetheshowcommandsdescribedin“DefiningEdgePortStatusonpage17todetermine
edgeportadministrativestatusonthedevice.
2. SetedgeportadministrativestatustofalseonallknownISLs.
3. Setedgeportadministrativestatustotrueonanyremainingports
whereSpanGuard
protectionisdesired.ThisindicatestoSpanGuardthattheseportsarenotexpectingtoreceive
anyBPDUs.IftheseportsdoreceiveBPDUs,theywillbecomelocked.
Enabling and Adjusting SpanGuard
UsethiscommandtoenableSpanGuardonthedevice:
set spantree spanguard enable
UsethiscommandtoadjusttheSpanGuardtimeoutvalue.Thissetsthelengthoftimethata
SpanGuardaffectedportwillremainlocked:
set spantree spanguardtimeout timeout
Validvaluesare065535seconds.Defaultis300seconds.Settingthevalueto0willsetthe
timeouttoforever.
UsethiscommandtomanuallyunlockaportthatwaslockedbytheSpanGuardfunction.This
overridesthespecified timeoutvariable:
set spantree spanguardlock port-string
Note: In order to utilize the SpanGuard function, you must know which ports are connected
between switching devices as ISLs (inter-switch links). Also, you must configure edge port status
(adminedge = true or false) on the entire switch, as described in “Defining Edge Port Status” on
page 17, before SpanGuard will work properly.