Spanning-Tree BPDUFilter

Hello Görgen

The purpose of applying BPDU Filter globally is to cause a port configured with PortFast, to lose its PortFast status.

Remember that PortFast is applied to interfaces that we expect to be connected to hosts. BPDUs should not be received on such ports. If a BPDU is received on such a port, then it is likely that a switch has been connected to this port, or some malicious user is up to no good. In such a case, it is safer for the port to revert to functioning as a normal interface, going through the normal listening/learning/forwarding process rather than remain in the PortFast state. Does that make sense?

I hope this has been helpful!

Laz

1 Like