Re: BPDU Filtering

From: Bob Sinclair (bsinclair@netmasterclass.net)
Date: Thu Apr 07 2005 - 17:02:17 GMT-3


Hi Gladston,

Yes, portfast ports do send configuration bpdus, by default. You can verify
this by using a crossover to connect two portfast ports - one will block. As
Clark and Hamilton say in Cisco LAN Switching, portfast is a forward delay
optimization.

Portfast ports do not trigger TCNs, however. When a non-portfast port cycles
in or out of forwarding state, the switch issues a Topology Change
Notification (TCN) upstream to the Root bridge. This sets the TCN flag in the
configuration bpdus, and switches reduce their aging time to forward delay
time, cleaning out their mac address tables so the new topology can be
learned. Since portfast ports are intended to be access rather than
infrastructure ports, there is no need for TCNs if a simple access port flaps.

HTH,

Bob Sinclair
CCIE #10427, CCSI 30427, CISSP
www.netmasterclass.net

  ----- Original Message -----
  From: gladston@br.ibm.com
  To: ccielab@groupstudy.com
  Sent: Thursday, April 07, 2005 1:01 PM
  Subject: BPDU Filtering

  Any help trying to understand this Cisco explanation highly appreciated.

  ================================
  quoted

  Understanding BPDU Filtering

  At the global level, you can enable BPDU filtering on Port Fast-enabled
ports by using the spanning-tree portfast bpdufilter default global
configuration command. This command prevents ports that are in a Port
Fast-operational state from sending or receiving BPDUs.

  http://www.cisco.com/univercd/cc/td/doc/product/lan/c3550/12225seb/scg/swst
popt.htm#wp1046220
  =================================

  So does it mean that a port configured with just Portfast (no bpdu
filtering) will send BPDUs?

  ==========================================
  quoted

  If a BPDU is received on a Port Fast-enabled port, the port loses its Port
Fast-operational status, and BPDU filtering is disabled.
  ==========================================

  Can I understand it as "if a port is configured just with Portfast, if a
BPDU is received, nothing is done."

  =================================
  quoted

  At the interface level, you can enable BPDU filtering on any port without
also enabling the Port Fast feature by using the spanning-tree bpdufilter
enable interface configuration command. This command prevents the port from
sending or receiving BPDUs.
  ==================================

  The behaviour of 'interface level' is the same of 'global configuration" on
the sense that "If a BPDU is received on a Port Fast-enabled port, the port
loses its Port Fast-operational status, and BPDU filtering is disabled."?

  _______________________________________________________________________
  Subscription information may be found at:
  http://www.groupstudy.com/list/CCIELab.html



This archive was generated by hypermail 2.1.4 : Tue May 03 2005 - 07:54:54 GMT-3