BPDU Guard

From: Richard Anderson (richard.p.anderson@sbcglobal.net)
Date: Sun Jul 11 2004 - 16:21:16 GMT-3


I have a 600 node switched network. All ports of 3560 switches running Data
Voice vlans such as:

interface FastEthernet0/1
switchport trunk encapsulation dot1q
switchport mode trunk
switchport voice vlan 31
no ip address
spanning-tree portfast trunk

Since all ports are portfast enabled, is it recommendable to globally enable
a command "SPANNING-TREE PORTFAST BPDUGUARD DEFAULT" incase a client by
mistake connects a switch instead of a host.

1) Can this command be also configured on a backbone switch since 48-port
blade of the backbone switch is also configured to support data and voice
vlans.

2) Can this command be enabled on a live network or I should arrange a
downtime.

Thanks,

Richard



This archive was generated by hypermail 2.1.4 : Sun Aug 01 2004 - 10:11:52 GMT-3