Info needed on use of BPDU guard

The place where I am working, we have 7606 router which is connected to various LAN segments. Sub-interfaces are defined in Ethernet ports for VLAN segments. Each LAN segment is running RSTP in rings, so BPDU packets is expected on VLAN subinterfaces of router, but spanning-tree BPDU Guard is enabled on interface(not subinterface) as shown below.
interface GigabitEthernet1/6
 description "Towards xyz"
 mtu 9000
 no ip address
 storm-control broadcast level 0.10
 storm-control multicast level 0.10
 spanning-tree bpduguard enable
interface GigabitEthernet1/6.852
 description "Cluster 14"
 encapsulation dot1Q 852
 ip address 172.19.129.188 255.255.255.224
 standby version 2
 standby 83 ip 172.19.129.190
 standby 83 timers msec 300 1
 standby 83 priority 110
 standby 83 preempt
interface GigabitEthernet1/6.853
 description "Cluster 14"
 encapsulation dot1Q 853
 ip address 172.19.145.188 255.255.255.224
 standby version 2
 standby 84 ip 172.19.145.190
 standby 84 timers msec 300 1
 standby 84 priority 110
 standby 84 preempt
interface GigabitEthernet1/6.854
 description "Cluster 14"
 encapsulation dot1Q 854
 ip address 172.19.161.188 255.255.255.224
 standby version 2
 standby 85 ip 172.19.161.190
 standby 85 timers msec 300 1
 standby 85 priority 110
 standby 85 preempt
interface GigabitEthernet1/6.855
 description "Cluster 14"
 encapsulation dot1Q 855
 ip address 172.19.177.188 255.255.255.224
 standby version 2
 standby 86 ip 172.19.177.190
 standby 86 timers msec 300 1
 standby 86 priority 110
 standby 86 preempt
I need to know that will there be any effect of BPDU Guard in this situation?
Whats the point of enabling BPDU Guard here?
Will BPDU packets received on subinterface VLAN will disable the whole interface as BPDU Guard is enabled?

Please find spanning tree command output:
R1#sh spanning-tree  int gi1/6
no spanning tree info available for GigabitEthernet1/6
R1#sh spanning-tree interface GigabitEthernet1/6.852
no spanning tree info available for GigabitEthernet1/6.852
R1#sh spanning-tree
MST0
  Spanning tree enabled protocol mstp
  Root ID    Priority    4096
             Address     588d.09b5.8740
             This bridge is the root
             Hello Time   2 sec  Max Age 20 sec  Forward Delay 15 sec
  Bridge ID  Priority    4096   (priority 4096 sys-id-ext 0)
             Address     588d.09b5.8740
             Hello Time   2 sec  Max Age 20 sec  Forward Delay 15 sec
Interface           Role Sts Cost      Prio.Nbr Type
Gi1/1               Desg FWD 20000     128.1    P2p
Gi1/2               Desg FWD 20000     128.2    P2p
Gi1/3               Desg FWD 20000     128.3    P2p
Gi1/4               Desg FWD 20000     128.4    P2p
Gi1/15              Desg FWD 20000     128.15   P2p
Gi1/16              Desg FWD 20000     128.16   P2p
Gi2/4               Desg FWD 200000    128.260  P2p
Te2/11              Desg FWD 2000      128.267  P2p
I think port is not involved in STP. Now, I would like to know what will happen if BPDU packet is received on any VLAN sub-interface of this interface. Will it simply drop BPDU packet as STP not running on it or, BPDU guard will disable the port completely ??

Similar Messages

  • More info needed about using wifi in high reflective enviroment

    I am looking for documents about using wifi in highly reflective enviroments: rooms with aluminium floor, walls and ceiling en very little materials that absorb rf. (cleanroom enviroment)
    Any hints are appreciated.

    Thanks for your reply Mat,
    The cleanroom enviroment (ASML semiconductor industry) is a large room about 30 * 60 meter and 7m high. In this room are smaller cabinets (about 20) where the actual work is done. Here you can see some pictures:
    http://www.brecon.nl/images/brecon_brochure.pdf
    In full production there are about 120 engineers working with their 802.11b/g equipped laptops.
    Every wall, floor, ceiling, door is made with aluminium sandwich panels. We have major troubles getting a reliable wifi enviroment, and also DECT and GSM telefony is hardly working at all.
    Right now we have 10 AP's is the large room, and we are contemplating installing 1 AP in every cabinet with low power setting and using attenuators. We are also considering the use of leaky coaxial cable.
    Migrating to 802.11N is not really an option since the clients are b/g equipped.
    I will upload a plan soon.

  • I bought a used macbook air,  it didn't come with the flash drive to do a factory reset.  Can I download the info needed and save it to my own flash drive and then do a factory reset?  If not what can I do?

    I bought a used macbook air,  it didn't come with the flash drive to do a factory reset.  Can I download the info needed and save it to my own flash drive and then do a factory reset?  If not what can I do?

    If it originally shipped with Mac OS X 10.6.8 or earlier, click here, phone Apple, and order a replacement.
    If it originally shipped with Mac OS X 10.7 or newer, restart it with the Option, Command, and R keys held down.
    (113079)

  • Autofill pops up when I need it--but it no longer fills the info like it used to--this 'help' didn't help---HELP please. -..

    autofill pops up when I need it……but it no longer fills the info like it used to……this 'help' didn't help………HELP please. …..

    If you have a credit card on file on top of your gift card then it is asking you to confirm the security code for the card, which for a Visa or MasterCard is 3 digits located on the back, or AMEX has 4 digits on the front.  This happens just to ensure that you are the account holder, and would happen from time to time whether it was a free or paid app, even if you have a credit through your gift card.  This doesn't mean that your credit card will be charged.

  • How to configure PortFast & BPDU Guard on an Aruba controller.

    Requirement:
    An Aruba controller running 6.4.3.x and above.
    Solution:
    PortFast:
    PortFast feature basically causes a switch port or a trunk port to directly enter the forwarding state instead of going through listening and learning state of the STP.
    PortFast is usually configured on an edge port, which means this port should not receive any STP BPDUs.
    If this port receives any STP BPDU, this port moves back to normal/regular mode and will end up participating in listening and learning states.
    BPDU Guard:
    The BPDU Guard feature basically guards the port against receiving any BPDUs.
    If it detects any incoming BPDUs on the port, it would put the port into ErrDis (Error-Disable).
    This port remains in the ErrDis state unless until this port is manually changed by using a configuration command “shut” followed by a “no-shut” applied on this interface.
    Configuration:
    Below screen shot show the configuration of Portfast for both Trunk and Access ports.
    Below screen shot shows the configuration of BPDU Guard for switch ports.
    Verification
    We can verify if the Portfast is enabled using the commands shown in below screen shot.
    We can verify if the BPDU Guard is enabled using commands shown in below screen shot.

    I was having troubles with this as well when a customer had an older Aruba Controller and 2 Access Points. We went with a couple IAP-205s and needed LDAP integration. Using the above configuration there were some additional items needed. I found that I needed the DISPLAY NAME of the admin for the Admin-DN. I had created a user with the first name Aruba and the last name LDAP. This made the DISPLAY NAME "Aruba LDAP". This is what needs to be in the CN= for the Admin-DN.I also found there is a difference in using the CN= and OU=Currently our admin account is in the Users group which is a “Container”. Our actual user accounts are stored in an Orginizational Unit with sub OUs as well. So the Admin-DN needed the CN=Users and the Base-DN needed the OU=MyUserOU.For the windows machines I had to download and install the Aruba GTC Shim because the customer was previously using GTC and they were not going to a RADIUS server at the moment. My Android phone and IPHONE did not need any additional addins for the authentication.  The windows laptop I am using I needed to manually create a wireless profile with… Security Tab >“Choose a network authentication method:”Microsoft: Protected EAP (PEAP)Settings >Select “Trusted Root Certification Authorities”GeoTrust Global CASelect Authentication Method:EAP-Token (This is the Aruba GTC Shim) This allowed me to use my domain login credentialsUsernamePasswordDomain (This is blank because the Base-DN already has this, if anything is put in here the authentication fails)

  • BPDU Guard without ERR-Disable

    Hi Everyone, 
    I recently had an instance in one of my networks where a user plugged in a home router to our network. The router then started handing out incorrect IP addresses to clients. 
    I know I can use DHCP Snooping or BPDU guard to stop this happening again and we do have BPDU Guard running at other sites successfully. The problem has always been if we enable it in a new production network we might disable ports that have legitimate devices on the other end. For example someone is using a small switch to share a port between a PC and a printer.
    Is there a way of turning on BPDU guard but without it putting ports into an Err-Disabled mode and just alerting in the logs instead?
    Regards, Daniel

    Hi Leo, 
    Thanks for your input in the discussion. However I think you are misunderstanding why I am asking this question.
    I WANT to enable BPDU guard on this network, I know its not a PIA and I am well aware of what it does and why it would be implemented.
    The reason I am asking this question is because I need to transition from a network that doesn't have BPDU guard enabled to one that does. If i turn the feature on it will start disabling ports on switches and stop peoples workflow until it is resolved. The reason people have unidentified switches plugged into the network might be legitimate, but the way they got around their problem wasn't the best. 
    My goal is to find out where these rogue switches are, find out why they are there. Find an alternative way to connect these devices to the network by either purchasing new switches or running more cabling.  This network does not have any onsite IT and therefor all this needs to be figured out remotely.
    So the crux of the problem is. How to find STP devices that are plugged into my switches.
    Thoughts?

  • BPDU guard - weird situation

    Hi guys,
    This morning unpleasant surprise happened to me. One of critical ports was err-disabled because of BPDU guard (device B). This wouldn't be surprise if this port (on Device B) wasn't configured as L3 port (I agree that BPDU filter shouldn't be enabled at all here, this is legacy config), and other end have BPDU filter enabled (Device A). Here is port config:
    Device A:
    interface GigabitEthernet4/0/24
     switchport access vlan 10
     switchport trunk encapsulation dot1q
     switchport mode access
     switchport nonegotiate
     logging event trunk-status
     spanning-tree bpdufilter enable
    Device B:
    interface GigabitEthernet2/45
     no switchport
     ip address 10.0.0.1 255.255.252.0
     ip helper-address 172.16.249.5
     logging event link-status
     logging event trunk-status
     spanning-tree portfast
     spanning-tree bpduguard enable
    Log from Device B indicating that it was err-disabled:
    Apr 20 20:08:52.336 CETS: %SPANTREE-2-BLOCK_BPDUGUARD: Received BPDU on port Gi2/45 with BPDU Guard enabled. Disabling port.
    Apr 20 20:08:52.336 CETS: %PM-4-ERR_DISABLE: bpduguard error detected on Gi2/45, putting Gi2/45 in err-disable state
    Log form Device A indicating that BPDU never sent from this port:
    DeviceA#show spanning-tree vlan 10 detail
     Port 186 (GigabitEthernet4/0/24) of VLAN0010 is designated forwarding
       Port path cost 4, Port priority 128, Port Identifier 128.186.
       Designated root has priority 28740, address 001a.6da4.f000
       Designated bridge has priority 28740, address 001a.6da4.f000
       Designated port id is 128.186, designated path cost 0
       Timers: message age 0, forward delay 0, hold 0
       Number of transitions to forwarding state: 1
       Link type is point-to-point by default
       Bpdu filter is enabled
       BPDU: sent 0, received 0
    Did anyone had ever similar experience? By all logical explanations, this should never happen
    Thanks

    On the other hand, most SOHO switches do not implement Spanning Tree. If you are concerned about users installing switches, you need to take other precautions as well.
    You can stop the users using a switch to fan out a port, by configuring port security and only allowing one MAC address on the port.
    The BPDU guard will give you some protection against certain malicious user practices, even if the rogue switch does not do Spanning Tree. For example, the user who plug in a SOHO switch, and then plugs two other ports of that SOHO switch back-to-back with a cross-cable. In this case, your Catalyst will see its own BPDUs circulating round the loop, and will close the port down. (If the SOHO switch is not doing Spanning Tree, then it will pass the BPDUs through transparently.) This is why you should not have bdpu-guard and bpdu-filter on the same port.
    Kevin Dorrell
    Luxembourg

  • TS1543 my mac wont stop at single user it continues to root, how can i get to single user to enter info needed to reset password

    I my mac wont recognise my password, i have tried to reset password using single user but my mac wont stop at single user it just continues to root, how do i get it to stop at single user so i can add info needed to reset password?

    Are your sure that wasn't a Verbose boot (Cmd-V) you were trying? That would go on to a regular boot.
    Try a PRAM Reset, then try the single user, Cmd-S, at the startup chime. For the PRAM Reset, hold down Option - Cmd - P - R all together until it chimes a total of three times, then let go to finish booting.

  • How to convert word doc into pdf - which product of adobe i need to use- what upgrades - am a newbie

    How to convert word doc into pdf - which product of adobe i need to use- what upgrades - am a newbie -  simple answers please - Thanks in advance.

    @Pipeline2007 - which version of Microsoft Office have you got? Older versions of Acrobat aren't compatible with the latest versions of Office, see this link for info:
    http://helpx.adobe.com/acrobat/kb/compatible-web-browsers-pdfmaker-applications.html

  • To many security approvals need to use my Google maps! (Running KitKat)

    Now that my Verizon S3 phone has been updated to KitKat the number of security boilerplate approvals needed to use anything related to maps or GPS is unacceptable.
    I can't leave the GPS on as it drains that battery. So here is the problem:  I'm driving along and I need to see my maps, before I would just hit the map button and I would see the map in the approximate area, no GPS required.  Now when I do the same, I get a box for settings, I click on that and it sends me to a Location page where I need to turn on the GPS, now I need to Agree that I have turned on the GPS, now I get another box to Agree that Google apps are collecting my location info, at this point I need back step out to the map app to see where I'm at.
    Most users of the maps app will use it while driving (even if you don't think it's a good idea).  I don't think going from 1 step to 5 is making the situation any safer, it's now takes many more seconds of not looking at the road to getting the app working then it had before.
    If you have a fix for this, that would be great!

    Thanks for it, I was too looking for the hello world example
    of using externalInterface to load a Google Map into Flash using
    AS2, I had asked this question many here, but did not get proper
    answer, when I had googled I had got this page, I got the answer.
    Thanks again & hope I will get more info from this forum.

  • What are the pros and cons using Active Data Guard vs Data Guard?

    My understanding is that Active Data Guard is an additional database option for Oracle 11gR2 Enterprise Edition. I need to know the pros and cons using Active Data Guard vs Data Guard in order to decide whether to get pay extra for the Active Data Guard.
    Thanks for any help.

    Hemant K Chitale wrote:
    Before jumping in to Active Data Guard, one needs to evaluate :
    a. Is there really a need to run queries on the Standby ? The Standby could / should be at a remote site so queries are "across the network". Depending on the nature of the queries and the volume of output, the "performance" of the queries may not seem to be the same.
    b. If the database is not in Maximum Protection mode, the data "seen" at the standby may not be in "real-time" synch
    c. Not all applications are truely read-only when querying. Some applications use "jobs" that write to tables when querying. Such would not work with Active DataGuard. (example : EBusiness Suite). There are very complicated ways of handling this -- and one needs to consider if the complications can be introduced and supported.
    Over the network accessing standby read only is really not an good idea, I think no one will compare performance with primary and standby,
    But some of them they want to validate data which are very critical, as it is matching with primary or not, Its an added advantage with ACTIVE DATAGUARD
    Prior to that until unless stop MRP, open database and then we need to validate, So there is an interruption of recovery, I can say its also an advantage where there is no interruption of recovery.

  • I have created some music tracks as aiff files which I want to load onto my iPod Shuffle 4th Generation, but it won't play them - it just bleeps at me. I have changed them to AAC which works - what settings do I need to use to make aiffs work?

    I have created some music tracks as aiff files which I want to load onto my iPod Shuffle 4th Generation, but it won't play them - it just bleeps at me. I have changed them to AAC which works but would rather use aiffs. Can anyone tell me what settings do I need to use to make aiffs work? The info on the iPod says that it accepts aiff files!!

    I have created some music tracks as aiff files which I want to load onto my iPod Shuffle 4th Generation, but it won't play them - it just bleeps at me. I have changed them to AAC which works but would rather use aiffs. Can anyone tell me what settings do I need to use to make aiffs work? The info on the iPod says that it accepts aiff files!!

  • Info needed on how to get list price for a given MATNR and pricing Conditio

    Hi All,
    Can some one help me in finding List price for a given MATNR and pricing condition type.
    Basically, i need info regarding the tables that i need to use for this purpose.
    Thanks in advance.
    Regards,
    Udaya.
    PS: All helpful answers will be rewarded.

    Hi Udaya,
    A simple solution to all these kind of problems:
    Goto  Transation SE16
    Table :TSTC
    in Tcode :Give A* or V*  or anything...and find the relevant transctions and data.
    if found useful...reward points.
    Regards,
    Nisha

  • Info needed on how to get list price for a given MATNR and pricing Conditi

    Hi All,
    Can some one help me in finding List price for a given MATNR and pricing condition type.
    Basically, i need info regarding the tables that i need to use for this purpose.
    Thanks in advance.
    Regards,
    Udaya.
    PS: All helpful answers will be rewarded.

    Hi,
    I moved your topic to this forum
    Mario

  • Needing to use xml data source to populate richfaces tree nodes

    Hey I cant seem to figure this out. I know I probably need to write some java code but Im not sure how it should look. I have some xml and I need to use the data from within the elements to populate some nodes on a richfaces tree.
    I know how to use a .properties file as the data source for the nodes, and how to use some existign nodes to populate the nodes. Both are done with java code I can post here if needed.
    But I dont know how to go about writing the java code to take the data from xml elements, and then somehow parse it to use in a richfaces tree.
    Here is some info on what Im using with my project:
    eclipse
    simplexml
    httpclient
    jsf
    richfaces library

    Adobe Newsbot hopes that the following resources helps you.
    NewsBot is experimental and any feedback (reply to this post) on
    its utility will be appreciated:
    Flex 3 - Using item renderers with the AdvancedDataGrid
    control:
    Flex Data Visualization Developer's Guide / Advanced Data
    Grid Controls and .... that the item renderer is for column 2 of
    the control: <?xml version='1.0'?
    Link:
    http://livedocs.adobe.com/flex/3/html/advdatagrid_10.html
    DataGrid ItemRenderer - Flex India Community | Google Groups:
    Apr 28, 2008 ... My dataGrid itemRenderer displays a certain
    icon and sets fontStyle ... <mx:Label id='txt' fontWeight='bold'
    text='{data.subject}'/>
    Link:
    http://groups.google.com/group/flex_india/browse_thread/thread/bd30dd974da47d68
    Flex 3 - DataGrid control:
    <mx:Button label='Toggle Price Column'
    click='price.visible = !price.visible;' ... Flex lets you populate
    a DataGrid control from an ActionScript variable
    Link:
    http://livedocs.adobe.com/flex/3/html/dpcontrols_6.html
    Flex Fun - Advanced DataGrid Topics:
    You will notice that the datagrid doesn't have any header
    labels or vertical ..... After the opening tag we add a
    <mx:itemRenderer> telling Flex that we are
    Link:
    http://blog.paranoidferret.com/index.php/2007/08/29/flex-fun-advanced-datagrid-topics/
    Flex 3 - Instrumenting RandomWalk events:
    Flex Data Visualization Developer's Guide / Advanced Data
    Grid Controls and Automation Tools ... itemRenderer = child as
    Label; dispatchEvent(rEvent);
    Link:
    http://livedocs.adobe.com/flex/3/html/functest_components2_20.html
    Adobe Flex 2: Advanced DataGrid:
    Adobe Flex 2: Advanced DataGrid. Drop-in RadioButtonGroupBox;
    runtime computed .... Anatole authored number of books and articles
    on AJAX, XML, Internet and
    Link:
    http://flex.sys-con.com/node/311283
    Disclaimer: This response is generated automatically by the
    Adobe NewsBot based on Adobe
    Community
    Engine.

Maybe you are looking for

  • Error while saving Views in Portal - Technical name not valid.

    Hi, When saving Views in Portal, I'm getting the message The Technical name of object QVIW is not valid. I've searched the forums but couldn't find any solution to this issue. We are on SP 16. Any help would be appreciated. Thanks & Regards, Hari

  • Help required in JDBC Stored Procedure

    Hi All, i have a requirement where i need to update the Database table using Stored Procedure from PI. I have the receiver JDBC channel and have done the mapping. The stored procedure has inputs of type NUMBER, VARCHAR2,DATE. in the message mapping i

  • Backed up iTunes on external drive and lost my playlists

    Hey Everyone, So here is my issue. I use my macbook for DJing purposes and decided to backup my iTunes library to an external hard drive incase of a crash so I dont loose my precious music. So I went into my preferences, Advanced, and changed the iTu

  • Cs4 mpeg question

    I've been editing some mpg2 files off of dvds with no problems.  The last 2 files i've ripped however have been ripped successfully.  I can view them in media players and everything works fine, the timing is perfect.  Then when i import the files int

  • Offical iTunes 7 feedback.

    Does anyone know where to leave offical feedback on the glaring problems with iTunes 7? I am having a lot of problems with this upgrade and would like to report them through offical channels. Extremely dissapointed with this update, it's like going b