Lammle.com
  • Instructor-Led Training
    • Browse by Course
      • All Courses
      • CompTIA Courses
      • CiscoŽ Courses
      • Microsoft Courses
      • Wireless Courses
      • IT & Security Courses
      • Attend Online
    • Browse by Date
    • Browse by City
    • Deals and Discounts
      • Spring Specials
      • From CCENT to CCNA in 2 Weeks
      • From CCNA to CCNP in 3 Weeks
      • Corporate Solutions
      • Government Solutions
        • Government Solutions
        • GSA Pricing
      • Recent Newsletters
    • Corporate Solutions
    • Government Solutions
      • Government Solutions
      • GSA Pricing
    • Testimonials
    • Internetworking Salary Survey
  • Locations
    • Atlanta
    • Austin
    • Chicago
    • Dallas/Fort Worth
    • Denver
    • Durham
    • Glendale
    • Houston
    • Live Online Only
    • Los Angeles
    • New Hampshire
    • New York
    • Orlando
    • Raleigh
    • San Diego
    • San Francisco
    • Santa Rosa
    • Washington D.C.
    • England
    • Germany
    Locations
  • Self-Paced Learning
    • Online Live Training
    • E-Learning
    • Online CCNA Video Training
    • Practice Questions
    • DVD and Audio (Lammle Press)
    • Books
  • Blog
  • Forum
  • GlobalNet Consulting
    • Overview
    • Experience
    • Our Team
    • Methodology
    • Projects
    • Contact Us
  • About
    • About Todd Lammle
    • About GlobalNet Training & Consulting
      • About GlobalNet Consulting
    • Student Complaint Policy
    • Terms of Service
      • Privacy Policy
      • Why was my account disabled?
  • Contact
    • Feedback Form
    • Site Map
Home Forum

Official Lammle User Forum


Go Back   Lammle Forum > Cisco® CCSP > Securing R&S
Reload this Page Various layer 2 security features
Register FAQ Members List Social Groups Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Display Modes
Prev Previous Post   Next Post Next
  #4  
Old 01-24-2011, 09:19 AM
Darby Weaver Darby Weaver is offline
Junior Member
 
Join Date: Jan 2011
Posts: 16
Default

Color me crazy...

1. spanning-tree portfast enable -> We all know why.

2. spanning-tree portfast bpduguard enable -> Stops send/receive of spanning-tree bpdu's BUT:

when BPDU is received on the port with bpdufilter enabled, the port is portfast status is disabled and port will participate in spanning-tree. At this time network needs to be protected from unauthorized device that might decide to participate in your spanning-tree topology and cause spanning-tree loop or try to hijack root.

So...

3. spanning-tree bpduguard enable -> Errdisables the port when a bpdu is received and may cause a little extra admin overhead but... that's what we get paid for... or you can use the errdisable recovery mechanism but you'll probably need to fix the situation anyway.

Umm... in my world it is far better to err-disable the newcomer rather that let me network take a hit that might affect production.

FYI - If it it of any consequence CiscoWorks will also note this in error if one uses one of the above without the other:

http://www.cisco.com/en/US/docs/net_...html#wp1112009
Reply With Quote
Darby Weaver
View Public Profile
Send a private message to Darby Weaver
Find all posts by Darby Weaver
 

Bookmarks
  • Submit Thread to Digg Digg
  • Submit Thread to del.icio.us del.icio.us
  • Submit Thread to StumbleUpon StumbleUpon
  • Submit Thread to Google Google
Thread Tools
Show Printable Version Show Printable Version
Email this Page Email this Page
Display Modes
Linear Mode Switch to Linear Mode
Hybrid Mode Switch to Hybrid Mode
Threaded Mode Threaded Mode

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Rules
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Layer 2 vs. Layer 3 broadcast ryan81 TCP / IP 11 01-05-2011 12:57 PM
New CCNA security book from sybex anurag007 Announcements 10 04-10-2010 02:17 AM
Layer 2 vs. Layer 3 broadcast ryan81 TCP / IP 0 12-12-2007 04:32 PM
What layer does SSL operate CISSP_Candidate CISSP Information 1 08-30-2006 08:23 AM
Q:204 which OSI layer does not provide security CISSP_Candidate CISSP Information 1 08-29-2006 04:57 PM


All times are GMT -5. The time now is 02:20 PM.

Contact Us - Lammle.com - Archive - Top

Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2013, vBulletin Solutions, Inc.

CCDA, CCDP, CCIE, CCIP, CCNA, CCNP, Cisco, Cisco IOS, Cisco Systems, the Cisco Systems logo, and Networking Academy are registered trademarks or trademarks of Cisco Systems, Inc. and/or its affiliates in the U.S. and certain other countries. All other trademarks mentioned in this document or Web site are the property of their respective owners. The content of this website is the copyrighted property of Lammle.com.
© 2013 Lammle.comPrivacy Policy