STP guard?
Accepted Solution
-
Hi @Alex_91
Yes, loop guard is for the ports that you design where end devices will connect with. Nebula default set all ports enable RSTP is because we want to prevent the customer connect a ring topology without configure it and cause loop.
Below is the possible result or issue/behavior for each scenario for you to reference:
Scenario
Possible result or issue / behavior
RSTP enable only (STP guard disable)
Spanning tree topology changes when receiving untrusted BPDU packet and causes network issue.
RSTP enable + Root guard
Prevent root bridge changes when receiving higher priority BPDU packet. The port will change to err-disable status.
RSTP enable + BPDU guard
Prevent receiving any BPDU packets. The port will change to err-disable status.
Zyxel Melen0
All Replies
-
Hi @Alex_91
The STP guard option only displays when the port enables RSTP. Below is the explanation/behavior of each STP guard option:
- Root guard is to prevent any switch in your ring topology do spanning tree topology change when receive BPDU that has higher priority than root bridge.
- BPDU guard is to prevent any switch in your ring topology receive any BPDU packets.
Both of them will block the port when receiving related packets.
With none of these protections, your ring topology might have topology change when receive any BPDU and cause temporary network down.
Zyxel Melen0 -
and what happens if you keep the option disabled?
0 -
Hi @Alex_91
Which option? STP guard? If STP guard is disabled, the switch won't disable switch port to protect your ring topology when receiving any BPDU packets.
Zyxel Melen0 -
0
-
No, to summarize:
Loop Guard is recommended on ports where end devices (PCs, hubs, etc.) are connected.
RSTP is recommended on ports used to connect other switches (only?). But what difference does enabling or disabling the various options make? What if I enable RSTP but leave none on STP guard?
0 -
Hi @Alex_91
Yes, loop guard is for the ports that you design where end devices will connect with. Nebula default set all ports enable RSTP is because we want to prevent the customer connect a ring topology without configure it and cause loop.
Below is the possible result or issue/behavior for each scenario for you to reference:
Scenario
Possible result or issue / behavior
RSTP enable only (STP guard disable)
Spanning tree topology changes when receiving untrusted BPDU packet and causes network issue.
RSTP enable + Root guard
Prevent root bridge changes when receiving higher priority BPDU packet. The port will change to err-disable status.
RSTP enable + BPDU guard
Prevent receiving any BPDU packets. The port will change to err-disable status.
Zyxel Melen0
Categories
- All Categories
- 442 Beta Program
- 3.1K Nebula
- 234 Nebula Ideas
- 6.7K Security
- 706 USG FLEX H Series
- 369 Security Ideas
- 1.8K Switch
- 87 Switch Ideas
- 1.4K Wireless
- 56 Wireless Ideas
- 7.1K Consumer Product
- 313 Service & License
- 512 News and Release
- 99 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 5.2K FAQ
- 34 Documents
- 89 About Community
- 116 Security Highlight
Ally Member
Zyxel Employee