Presentation is loading. Please wait.

Presentation is loading. Please wait.

Minimizing Service Loss and Data Theft in a Campus Network

Similar presentations


Presentation on theme: "Minimizing Service Loss and Data Theft in a Campus Network"— Presentation transcript:

1 Minimizing Service Loss and Data Theft in a Campus Network
STP 安全机制

2 保护 STP 的运行 Protection against switches being added on PortFast ports.
BPDU guard shuts ports down. BPDU filter specifies action to be taken when BPDUs are received.

3 启用和检验 BPDU 防护 Enables BPDU guard
Switch(config)#spanning-tree portfast bpduguard Enables BPDU guard Switch#show spanning-tree summary totals Displays BPDU guard configuration information Switch#show spanning-tree summary totals Root bridge for: none. PortFast BPDU Guard is enabled Etherchannel misconfiguration guard is enabled UplinkFast is disabled BackboneFast is disabled Default pathcost method used is short Name Blocking Listening Learning Forwarding STP Active VLANs

4 BPDU 过滤 Enables BPDU filtering
Switch(config)#spanning-tree portfast bpdufilter default Enables BPDU filtering Switch#show spanning-tree summary totals Displays BPDU filtering configuration information Switch#show spanning-tree summary totals Root bridge for:VLAN0010 EtherChannel misconfiguration guard is enabled Extended system ID is disabled Portfast is enabled by default PortFast BPDU Guard is disabled by default Portfast BPDU Filter is enabled by default Loopguard is disabled by default UplinkFast is disabled BackboneFast is disabled Pathcost method used is long Name Blocking Listening Learning Forwarding STP Active 2 vlans

5 描述根守护

6 根守护的配置命令 Configures root guard Verifies root guard
Switch(config-if)#spanning-tree guard root Configures root guard Switch#show running-config interface fa 0/1 Switch#show spanning-tree inconsistentports Verifies root guard

7 检查根守护 Displays interface configuration information
Switch#show running-config interface interface mod/port Displays interface configuration information Switch#show spanning-tree inconsistentports Displays information about ports in inconsistent states Switch#show running-config interface fastethernet 5/8 Building configuration... Current configuration: 67 bytes ! interface FastEthernet5/8 switchport mode access spanning-tree guard root Switch#show spanning-tree inconsistentports Name Interface Inconsistency VLAN FastEthernet3/ Port Type Inconsistent VLAN FastEthernet3/ Port Type Inconsistent VLAN FastEthernet3/ Port Type Inconsistent Number of inconsistent ports (segments) in the system :3

8 总结 BPDU guard and BPDU filtering protect the operation of STP on PortFast-configured ports. When BPDU guard is configured globally, it affects all PortFast configured ports. BPDU guard can be configured per port, even on those ports not configured with PortFast. BPDU filtering can be configured globally or per port. The root switch cannot be elected via BPDUs received on a root-guard-configured port. Root guard can be configured and verified using various commands.

9


Download ppt "Minimizing Service Loss and Data Theft in a Campus Network"

Similar presentations


Ads by Google