BPDU Guard / Port Security
Hi all, I'm in the process of installing a couple of XGS1935-52HP switches (SW01 & SW02) using Nebula Control Centre, both connected directly to our router. The switches aren't connected directly to each other. I've enabled BPDU Guard on all the access ports on both switches, and then connected a managed Netgear switch into one of the access ports on SW02 - BPDU Guard didn't kick in and disable the access port. When creating a loop on the managed Netgear switch, LoopGuard kicked in and disabled the uplink port on SW01. The uplink ports on SW01 and SW02 have RSTP disabled and LoopGuard enabled.
Questions:
- Why didn't BPDU guard disable the access port on SW01?
- How do I prevent unauthorised switches from being connected to the network? I was looking at Port Security as a solution, but don't appear to be able to configure this without using Mac-based authentication.
All Replies
-
Hi @sysit
Why didn't BPDU guard disable the access port on SW01?
BPDU is a control packet of spanning tree. If the BPDU guard doesn't disable the port, it could be because the connecting device didn't send BPDU packet.
Since you didn't mention the Netgear setting, please share if it enables spanning tree.
How do I prevent unauthorised switches from being connected to the network? I was looking at Port Security as a solution, but don't appear to be able to configure this without using Mac-based authentication.
The best one is the MAC authentication. The unauthorised switches might not all be managed switches, but also unmanaged switches. But the more important part is that the connecting device is under the unauthorised switches. Here is the FAQ to setup MAC authentication:
Zyxel Melen0
Categories
- All Categories
- 442 Beta Program
- 2.9K Nebula
- 219 Nebula Ideas
- 127 Nebula Status and Incidents
- 6.5K Security
- 588 USG FLEX H Series
- 344 Security Ideas
- 1.7K Switch
- 84 Switch Ideas
- 1.4K Wireless
- 52 Wireless Ideas
- 7K Consumer Product
- 298 Service & License
- 477 News and Release
- 91 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 4.8K FAQ
- 34 Documents
- 87 About Community
- 102 Security Highlight
Freshman Member
Zyxel Employee