Portfast和BPDU护卫队的跨越树
Portfast和BPDUBridge Protocol Data Unit. A BPDU is a data message transmitted across a local area network to detect loops in network topologies.后卫功能增强了2层的网络可靠性,可管理性和安全性STP生成树协议。STP是一个网络协议that builds a logical loop-free topology for Ethernet networks.。
Some devices and local stacks running on systems or workstations are capable of generating potentialSTP生成树协议。STP是一个网络协议that builds a logical loop-free topology for Ethernet networks.BPDUs that cause DOS attacks. PortFast andBPDUBridge Protocol Data Unit. A BPDU is a data message transmitted across a local area network to detect loops in network topologies.Guard features provide stability and security for network topologies to prevent such attacks, and can be applied either independently or together.
以下各节描述:
Portfast
引入了PortFast功能,以避免网络连接问题。这些问题是由延误引起的STP生成树协议。STP是一个网络协议that builds a logical loop-free topology for Ethernet networks.从聆听和学习状态过渡后,启用从阻塞状态到转发状态的端口。STP生成树协议。STP是一个网络协议that builds a logical loop-free topology for Ethernet networks.启用了连接到单个开关,工作站或服务器等设备的端口,只有在传递所有这些之后才能访问网络STP生成树协议。STP是一个网络协议that builds a logical loop-free topology for Ethernet networks.状态。一些应用程序需要立即连接到网络,否则它们将超时。
启用PortFast功能会导致开关或中继端口进入STP生成树协议。STP是一个网络协议that builds a logical loop-free topology for Ethernet networks.立即或在链接事件发生后转发状态,从而绕开听力和学习状态。PortFast功能在端口级别启用,此端口可以是物理或逻辑端口。当在开关或中继端口上启用PortFast功能时,该端口立即过渡到STP生成树协议。STP是一个网络协议that builds a logical loop-free topology for Ethernet networks.forwarding state.
尽管启用了PortFast,但端口仍在参与STP生成树协议。STP是一个网络协议that builds a logical loop-free topology for Ethernet networks.。If the port happens to be part of topology that could form a loop, the port eventually transitions intoSTP生成树协议。STP是一个网络协议that builds a logical loop-free topology for Ethernet networks.阻止模式。PortFast通常在边缘端口上配置,这意味着该端口不应接收任何STP生成树协议。STP是一个网络协议that builds a logical loop-free topology for Ethernet networks.bpdus。如果港口收到任何STP生成树协议。STP是一个网络协议that builds a logical loop-free topology for Ethernet networks.BPDUBridge Protocol Data Unit. A BPDU is a data message transmitted across a local area network to detect loops in network topologies.,它可以回到正常或常规模式,并将参与聆听和学习状态。
In most deployments, edge ports are access ports. However, in this scenario there are no restrictions in enabling the PortFast feature. The mode of the port changes from PortFast to non-PortFast when the port receives aSTP生成树协议。STP是一个网络协议that builds a logical loop-free topology for Ethernet networks.BPDUBridge Protocol Data Unit. A BPDU is a data message transmitted across a local area network to detect loops in network topologies.。要在端口上重新启用此功能,请运行 命令,然后是 命令在接口或端口级别。
在非边缘端口上配置PortFast可能会导致不稳定STP生成树协议。STP是一个网络协议that builds a logical loop-free topology for Ethernet networks.拓扑。 |
BPDUGuard
BPDUBridge Protocol Data Unit. A BPDU is a data message transmitted across a local area network to detect loops in network topologies.防护功能可保护港口免受接收STP生成树协议。STP是一个网络协议that builds a logical loop-free topology for Ethernet networks.BPDUs, however the port can transmitSTP生成树协议。STP是一个网络协议that builds a logical loop-free topology for Ethernet networks.bpdus。当一个STP生成树协议。STP是一个网络协议that builds a logical loop-free topology for Ethernet networks.BPDUBridge Protocol Data Unit. A BPDU is a data message transmitted across a local area network to detect loops in network topologies.收到BPDUBridge Protocol Data Unit. A BPDU is a data message transmitted across a local area network to detect loops in network topologies.Guard enabled port, the port is shutdown and the state of the port changes to (误差)状态。端口留在 状态直到使用配置命令手动更改端口状态 然后是 applied on the interface. In most deployments,BPDUBridge Protocol Data Unit. A BPDU is a data message transmitted across a local area network to detect loops in network topologies.Guard feature is configured over the PortFast enabledSTP生成树协议。STP是一个网络协议that builds a logical loop-free topology for Ethernet networks.ports, but in this implementation theBPDUBridge Protocol Data Unit. A BPDU is a data message transmitted across a local area network to detect loops in network topologies.Guard feature can be enabled on any of theSTP生成树协议。STP是一个网络协议that builds a logical loop-free topology for Ethernet networks.端口,在这些端口上启用或不带有PortFast功能。
Portfast和BPDU警卫支持的场景
Portfast和BPDUBridge Protocol Data Unit. A BPDU is a data message transmitted across a local area network to detect loops in network topologies.Guard features are applied at the port or interface level. These features can also be applied in the following scenarios:
RSTP快速跨越树协议。RSTP在拓扑变更后提供了更快的跨越树的收敛速度,引入了新的收敛行为和桥梁端口角色。andPVSTPer-VLAN Spanning Tree. PVST provides load balancing of VLANs across multiple ports resulting in optimal usage of network resources.模式
Access and Trunk ports
Physical and Logical ports
在全球RSTP快速跨越树协议。RSTP在拓扑变更后提供了更快的跨越树的收敛速度,引入了新的收敛行为和桥梁端口角色。模式,只有一个RSTP快速跨越树协议。RSTP在拓扑变更后提供了更快的跨越树的收敛速度,引入了新的收敛行为和桥梁端口角色。实例在整个中运行移动大师。If the port that is enabled with PortFast andBPDUBridge Protocol Data Unit. A BPDU is a data message transmitted across a local area network to detect loops in network topologies.后卫收到任何STP生成树协议。STP是一个网络协议that builds a logical loop-free topology for Ethernet networks.BPDUBridge Protocol Data Unit. A BPDU is a data message transmitted across a local area network to detect loops in network topologies.,它影响所有端口,作为全局RSTP快速跨越树协议。RSTP在拓扑变更后提供了更快的跨越树的收敛速度,引入了新的收敛行为和桥梁端口角色。以端口为基础。
在里面PVSTPer-VLAN Spanning Tree. PVST provides load balancing of VLANs across multiple ports resulting in optimal usage of network resources.模式,可以有多个实例RSTP快速跨越树协议。RSTP在拓扑变更后提供了更快的跨越树的收敛速度,引入了新的收敛行为和桥梁端口角色。跑步,因为它们的基础Vlan虚拟局域网。在计算机网络中,可以对单层2网络进行分区,以创建多个不同的广播域,它们是相互隔离的,因此数据包只能通过一个或多个路由器之间传递它们。这样的域称为虚拟局域网,虚拟LAN或VLAN。。虽然是根据Vlan虚拟局域网。在计算机网络中,可以对单层2网络进行分区,以创建多个不同的广播域,它们是相互隔离的,因此数据包只能通过一个或多个路由器之间传递它们。这样的域称为虚拟局域网,虚拟LAN或VLAN。,它仍然以与全球相同的方式行为RSTP快速跨越树协议。RSTP在拓扑变更后提供了更快的跨越树的收敛速度,引入了新的收敛行为和桥梁端口角色。mode. For example, if there are fiveVlans虚拟局域网。在计算机网络中,可以对单层2网络进行分区,以创建多个不同的广播域,它们是相互隔离的,因此数据包只能通过一个或多个路由器之间传递它们。这样的域称为虚拟局域网,虚拟LAN或VLAN。和每个Vlan虚拟局域网。在计算机网络中,可以对单层2网络进行分区,以创建多个不同的广播域,它们是相互隔离的,因此数据包只能通过一个或多个路由器之间传递它们。这样的域称为虚拟局域网,虚拟LAN或VLAN。有一个单独的RSTP快速跨越树协议。RSTP在拓扑变更后提供了更快的跨越树的收敛速度,引入了新的收敛行为和桥梁端口角色。实例运行,然后STP生成树协议。STP是一个网络协议that builds a logical loop-free topology for Ethernet networks.BPDUBridge Protocol Data Unit. A BPDU is a data message transmitted across a local area network to detect loops in network topologies.在这五个端口中的任何一个端口中都收到了所有端口。
If anSTP生成树协议。STP是一个网络协议that builds a logical loop-free topology for Ethernet networks.BPDUBridge Protocol Data Unit. A BPDU is a data message transmitted across a local area network to detect loops in network topologies.从五个中的任何一个收到RSTP快速跨越树协议。RSTP在拓扑变更后提供了更快的跨越树的收敛速度,引入了新的收敛行为和桥梁端口角色。实例运行,启用的端口BPDUBridge Protocol Data Unit. A BPDU is a data message transmitted across a local area network to detect loops in network topologies.警卫闭嘴去 状态。换句话说,Portfast和BPDUBridge Protocol Data Unit. A BPDU is a data message transmitted across a local area network to detect loops in network topologies.Guard features are applied on a port basis for both globalRSTP快速跨越树协议。RSTP在拓扑变更后提供了更快的跨越树的收敛速度,引入了新的收敛行为和桥梁端口角色。andPVSTPer-VLAN Spanning Tree. PVST provides load balancing of VLANs across multiple ports resulting in optimal usage of network resources.模式,即使PVSTPer-VLAN Spanning Tree. PVST provides load balancing of VLANs across multiple ports resulting in optimal usage of network resources.runs on a perVlan虚拟局域网。在计算机网络中,可以对单层2网络进行分区,以创建多个不同的广播域,它们是相互隔离的,因此数据包只能通过一个或多个路由器之间传递它们。这样的域称为虚拟局域网,虚拟LAN或VLAN。基础。
在端口上启用Portfast
以下过程在端口上启用PortFast:
1。在里面 节点层次结构,选择设备并导航到 。
2。在里面 表,单击要启用portfast的端口号和BPDUBridge Protocol Data Unit. A BPDU is a data message transmitted across a local area network to detect loops in network topologies.警卫。
3。选择 链接在底部 tab .
4。选择 复选框。
5。点击 。
6。点击 。
7.在里面 窗口,选择复选框,然后单击 。
建议仅在访问端口类型上启用PortFast。但是,可以通过选择portfast在中继端口上启用 WebUI中的复选框。 |
执行以下命令启用PortFast:
(主机)[myNode](config)#interface gigabitinternet <插槽>/<模块>/
(主机)[myNode](config-if)#spanning-tree portfast
执行以下命令禁用PortFast:
(主机)[myNode](config)#interface gigabitinternet <插槽>/<模块>/
(host) [mynode] (config-if) #no spanning-tree portfast
执行以下命令以在中继端口上启用PortFast:
(主机)[myNode](config)#interface gigabitethernet <插槽>/<模块>/
(主机)[myNode](config-if)#Spanning-Tree Portfast Trunk
执行以下显示命令以显示STP生成树协议。STP是一个网络协议that builds a logical loop-free topology for Ethernet networks.端口:
(host) [mynode] (config-if) #show spanning-tree interface gigabitethernet
在港口启用BPDU警卫
以下CLI命令行接口。带有命令行壳的控制台接口,允许用户执行文本输入为命令,并将这些命令转换为适当的函数。command enables PortFast andBPDUBridge Protocol Data Unit. A BPDU is a data message transmitted across a local area network to detect loops in network topologies.警卫:
(主机)[myNode](config)#interface gigabitinternet <插槽>/<模块>/
(主机)[myNode](config-if)#spanning-tree bpduguard