Configuring Root Protection on a Port
Context
If a root bridge receives BPDUs with a higher priority than its own due to incorrect configurations or malicious attacks, the root bridge is incorrectly changed. As a result, traffic may be switched from high-speed links to low-speed links, leading to network congestion. You can configure root protection on a designated port, which prevents the port role from being changed.
Perform the following steps on the root bridge in an MST region.
Procedure
- Run system-view
The system view is displayed.
- Run interface interface-type interface-number
The view of an interface participating in STP calculation is displayed.
- Run stp root-protection
Root protection is enabled on the interface.
By default, root protection is disabled on an interface. Root protection takes effect only on designated ports. Root protection and loop protection cannot be configured on the same interface.
- Run commit
The configuration is committed.