Enabling STP BPDU Guard

STP BPDU Guard can be enabled on an individual port or on a set of ports.
When a BPDU guard-enabled port is disabled by BPDU guard, the RUCKUS device will place the port in errdisable state and display a message on the console indicating that the port is errdisabled (refer to BPDU Guard Status Example Console Messages ).
Note: STP BPDU Guard is disabled by default.
  1. Enter the global configuration mode.
    device# configure terminal
  2. Enable STP BPDU guard on a specific port or on a set of ports.
    device(config)# interface ethernet 1/1/1
    device(config-if-e1000-1/1/1)# stp-bpdu-guard
    device(config)# interface ethernet 1/1/1 to 1/1/9
    device(config-mif-1/1/1-1/1/9)# stp-bpdu-guard
    Note: Spanning tree must be enabled on the corresponding VLAN.
  3. Re-enable an error-disabled port using one of the following methods:
    • Re-enable an error-disabled port manually.
    device(config)# interface ethernet 1/1/2
    device(config-if-e1000-1/1/2)# disable
    device(config-if-e1000-1/1/2)# enable
    To re-enable an error-disabled port manually, first use the disable command and then the enable command from the interface configuration mode.
    • Re-enable an error-disabled port automatically.
    device(config)# errdisable recovery cause bpduguard
    To re-enable a port to recover automatically from the error-disabled state, use the errdisable recovery cause command in global configuration mode.
  4. Check port status using the show interface command.
    device# show interface ethernet 1/1/2
    Gigabit Ethernet1/1/2 is ERR-DISABLED (bpduguard), line protocol is down
    The show interface command output indicates that the port is in errdisable state.

The following example shows how to enable STP BPDU guard on a specific port.

device# configure terminal
device(config)# interface ethernet 1/1/1
device(config-if-e1000-1/1/1)# stp-bpdu-guard

The following example shows how to enable STP BPDU guard on a set of ports.

device# configure terminal
device(config)# interface ethernet 1/1/1 to 1/1/9
device(config-mif-1/1/1-1/1/9)# stp-bpdu-guard