Configuring MSTP Root Guard

MSTP root guard can be enabled on an individual port of an interface.
  1. Enter the global configuration mode.
    device# configure terminal
  2. Enable MSTP root guard on a port by using the spanning-tree root-protect command at the interface configuration level.
    device(config)# interface ethernet 1/1/1
    device(config-if-e10000-1/1/1)# spanning-tree root-protect
  3. Exit the interface configuration mode and enter the global configuration mode.
    device(config-if-e10000-1/1/1)# exit
    device# configure terminal
  4. Setting MSTP root guard timeout value by using the mstp root-protect timeout command.
    device(config)# mstp root-protect timeout 60

The following example shows how to configure MSTP root guard.

device# configure terminal
device(config)# interface ethernet 1/1/1
device(config-if-e10000-1/1/1)# spanning-tree root-protect
device(config-if-e10000-1/1/1)# exit
device# configure terminal
device(config)# mstp root-protect timeout 60