After bridge protocol data unit (BPDU) protection is enabled on a device, the device shuts down an edge port if the edge port receives a BPDU, and notifies the NMS of the shutdown event.
Edge ports are directly connected to user terminals and normally, the edge ports will not receive bridge protocol data units (BPDUs). Some attackers may send pseudo BPDUs to attach the device. If the edge ports receive the BPDUs, the device automatically sets the edge ports as non-edge ports and triggers new spanning tree calculation. Network flapping then occurs. BPDU protection can be used to protect devices against network attacks.
Do as follows on a device having an edge port:
The system view is displayed.
The MSTP process view is displayed.
This step is needed only when you perform configurations in an MSTP process with a non-zero ID. If you perform configurations in the MSTP process 0, skip is step.
BPDU protection is enabled on the device.
The configuration is committed.