Optional Spanning-Tree Features

ccie-data-center
Edge ports, BPDU filter and guard, root guard, UDLD, loop guard, and bridge assurance, and the failure each one is there to stop.
Published

Apr 23, 2022

STP Features

In this section we will discuss on different improvement which added to the Rapid spanning-tree. In particular we talk about:

  • Convergence Optimization
    • Edge Port
  • STP Filters
    • BPDU Filter
    • BPDU Guard
    • Root Guard
  • Unidirectional Link Detection
    • Loop Guard
    • Bridge Assurance

Convergence Optimization

Spanning-Tree Edge Port

This is equivalent of PortFast feature with Common Spanning-Tree. An Edge Port immediately becomes Designated Forwarding after coming up. It still sends BPDUs, but it expects not to receive any. Should a BPDU be received by an Edge port, this port will revert to the Non-Edge type and start operating as a common RSTP port.

Spanning-Tree Filters

Spanning-Tree BPDU Guard

BPDU guard is typically configured with all host-facing ports that are enabled with Edge port. This feature is a safety mechanism that shuts down ports configured with Edge port upon receipt of a BPDU

N9K01(config)# configure terminal
N9K01(config-if)# interface ethernet 1/7
N9K01(config-if)# spanning-tree bpduguard enable

Spanning-Tree BPDU Filter

I do not see reason on why you would want to enable BPDU Filter other than in the Lab. Most network designs do not require BPDU Filter. BPDU Filter disables BPDU from being sent or received on a switchport.

! Enable BPDU Filter on all ports, then exclude the ports you don't want or
! filter the BPDU on:
N9K01(config)# configure terminal
N9K01(config)# spanning-tree port type edge bpdufilter default
N9K01(config)# interface e1/1 
N9K01(config-if)# no spanning-tree bpdufilter enable 


! Or enable BPDU Filter per interface
N9K01(config)# configure terminal
N9K01(config-if)# interface ethernet 1/1
N9K01(config-if)# spanning-tree bpdufilter enable

Spanning-Tree Root Guard

The NX-OS sends and processes BPDUs normally but if a switch suddenly sends a BPDU with a superior (better) bridge ID you will not accept it as the root bridge.

N9K01(config)# configure terminal
N9K01(config)# interface ethernet 1/1
N9K01(config-if)# spanning-tree guard root

Workshop

We will continue from the same topology and configuration in the workshop that we have had if the this post.

Workshop - STP Enhancements

N9K01

  configure terminal
    spanning-tree vlan 1-3967 priority 0
    interface ethernet 1/7
      spanning-tree bpduguard enable
    exit
    interface ethernet 1/1-2
      spanning-tree guard root
    exit
    spanning-tree loopguard default

N9K02

  configure terminal
    spanning-tree vlan 1-3967 priority 4096
    interface ethernet 1/7
      spanning-tree bpdufilter enable
    exit
    spanning-tree loopguard default

N9K03

  configure terminal
    interface ethernet 1/7
      spanning-tree bpdufilter enable
    exit
    spanning-tree loopguard default

N9K02 Verification

N9K02# show spanning-tree interface ethernet 1/3 detail

 Port 3 (Ethernet1/3) of VLAN0100 is designated forwarding
   Port path cost 4, Port priority 128, Port Identifier 128.3
   Designated root has priority 4196, address 5002.0000.1b08
   Designated bridge has priority 4196, address 5002.0000.1b08
   Designated port id is 128.3, designated path cost 0
   Timers: message age 0, forward delay 0, hold 0
   Number of transitions to forwarding state: 1
   The port type is network
   Link type is point-to-point by default
   Loop guard is enabled by default
   BPDU: sent 1862, received 1863
Back to top