# Spanning-Tree BPDUGuard

**URL:** https://forum.networklessons.com/t/spanning-tree-bpduguard/1142
**Category:** Lessons Discussion
**Created:** [December 27, 2016, 4:31pm UTC](https://forum.networklessons.com/t/spanning-tree-bpduguard/1142 "2016-12-27T16:31:29Z")
**Posts on this page:** 20
**Page:** 1

<div class="post-metadata">

### Author: ![ReneMolenaar](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/renemolenaar/32/488_2.png) [@ReneMolenaar](https://forum.networklessons.com/u/ReneMolenaar)
#### Post date: [December 27, 2016, 4:31pm UTC](https://forum.networklessons.com/t/spanning-tree-bpduguard/1142/1 "2016-12-27T16:31:29Z")

</div>

This topic is to discuss the following lesson:

> **[Spanning Tree BPDU Guard](https://networklessons.com/spanning-tree/spanning-tree-bpduguard)**
>
> BPDUGuard helps to protect your spanning-tree topology. When an interface that has this enabled receives a BPDU, it will go into err-disabled mode.

---

<div class="post-metadata">

### Author: ![jorotz](https://cdn-forum.networklessons.com/letter_avatar_proxy/v4/letter/j/3ec8ea/32.png) [@jorotz](https://forum.networklessons.com/u/jorotz)
#### Post date: [June 22, 2015, 4:48pm UTC](https://forum.networklessons.com/t/spanning-tree-bpduguard/1142/2 "2015-06-22T16:48:55Z")

</div>

awesome explaination Renee .  
I really enjoy reading your topics and make me feel more confortable and confident when I learn it  
thanks

---

<div class="post-metadata">

### Author: ![iamhere64](https://cdn-forum.networklessons.com/letter_avatar_proxy/v4/letter/i/97f17d/32.png) [@iamhere64](https://forum.networklessons.com/u/iamhere64)
#### Post date: [August 9, 2015, 4:05am UTC](https://forum.networklessons.com/t/spanning-tree-bpduguard/1142/3 "2015-08-09T04:05:29Z")

</div>

Good stuffs!

---

<div class="post-metadata">

### Author: ![ahmedhosnyaly](https://cdn-forum.networklessons.com/letter_avatar_proxy/v4/letter/a/b5ac83/32.png) [@ahmedhosnyaly](https://forum.networklessons.com/u/ahmedhosnyaly)
#### Post date: [November 8, 2015, 3:48pm UTC](https://forum.networklessons.com/t/spanning-tree-bpduguard/1142/4 "2015-11-08T15:48:49Z")

</div>

Hi Rene,

I am more curious if STP will send BPDUs on Access ports enabled with Portfast or this will be out of the STP topology, Let be more specific with my query

In case i have 2 SWs running RSTP a third SW is introduced which happens to be not supporting STP and is connected to my 2 Sws with portfast enabled

In case BPDUs is being sent on portfast then i assume BPDUGuard will save the day for me on the 2nd SW as it will shut down the port once it receives BPDU on its access port, Is this correct?

&nbsp;

&nbsp;

&nbsp;

&nbsp;

---

<div class="post-metadata">

### Author: ![ReneMolenaar](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/renemolenaar/32/488_2.png) [@ReneMolenaar](https://forum.networklessons.com/u/ReneMolenaar)
#### Post date: [November 9, 2015, 11:26am UTC](https://forum.networklessons.com/t/spanning-tree-bpduguard/1142/5 "2015-11-09T11:26:13Z")

</div>

Hi Ahmed,

Enabling portfast doesn’t disable STP and the interface will still send BPDUs. Take a look at this post:

> **[Does portfast disable Spanning Tree?](https://networklessons.com/spanning-tree/does-portfast-disable-spanning-tree)**
>
> This lesson explains exactly what happens when you enable spanning-tree portfast on an interface. Portfast does not disable STP on the interface.

In your example, you shouldn’t enable portfast on interfaces that connect to other switches. Only use this for “end” devices like computers, laptops, servers, etc. In your case, BPDUguard will ensure that the interface will go down.

Mixing PVST and rapid PVST is no problem btw, they are compatible.

Rene

---

<div class="post-metadata">

### Author: ![ahmedhosnyaly](https://cdn-forum.networklessons.com/letter_avatar_proxy/v4/letter/a/b5ac83/32.png) [@ahmedhosnyaly](https://forum.networklessons.com/u/ahmedhosnyaly)
#### Post date: [November 9, 2015, 2:51pm UTC](https://forum.networklessons.com/t/spanning-tree-bpduguard/1142/6 "2015-11-09T14:51:35Z")

</div>

Thanks Rene, The point here is usually you don’t know the end host capability, I saw cases loop can happen from a server with NIC bridging without STP capability.

Just wanted to make sure Portfast + BPDUGuard can address this case

&nbsp;

&nbsp;

---

<div class="post-metadata">

### Author: ![ReneMolenaar](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/renemolenaar/32/488_2.png) [@ReneMolenaar](https://forum.networklessons.com/u/ReneMolenaar)
#### Post date: [November 9, 2015, 4:42pm UTC](https://forum.networklessons.com/t/spanning-tree-bpduguard/1142/7 "2015-11-09T16:42:34Z")

</div>

Hi Ahmed,

In that case it might be wise to enable BPDUguard. If someone connects something that isn’t supposed to send BPDUs then it’s best to shut the interface with BPDUguard 🙂

Rene

---

<div class="post-metadata">

### Author: ![sims](https://cdn-forum.networklessons.com/letter_avatar_proxy/v4/letter/s/c6cbf5/32.png) [@sims](https://forum.networklessons.com/u/sims)
#### Post date: [May 13, 2016, 9:15am UTC](https://forum.networklessons.com/t/spanning-tree-bpduguard/1142/8 "2016-05-13T09:15:29Z")

</div>

Hi,

spanning-tree portfast is enough ? or also spanning-tree portfast bpduguard must be enaled globally

Thanks

---

<div class="post-metadata">

### Author: ![andrew](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/andrew/32/645_2.png) [@andrew](https://forum.networklessons.com/u/andrew)
#### Post date: [May 13, 2016, 2:24pm UTC](https://forum.networklessons.com/t/spanning-tree-bpduguard/1142/9 "2016-05-13T14:24:38Z")

</div>

Sims,  
In almost all cases you want to pair BPDUGuard with Portfast

---

<div class="post-metadata">

### Author: ![adave1103](https://cdn-forum.networklessons.com/letter_avatar_proxy/v4/letter/a/3ab097/32.png) [@adave1103](https://forum.networklessons.com/u/adave1103)
#### Post date: [July 28, 2016, 3:27pm UTC](https://forum.networklessons.com/t/spanning-tree-bpduguard/1142/10 "2016-07-28T15:27:10Z")

</div>

Hi,

Thanks for easy clarification . Is my below statement correct :

BPDU Guard is only useful when we have ports on a switch where computers/laptops/servers are connected OR may connect in future so that by any chance they don’t send any BPDU on our switch port.

thats it ! right ?

---

<div class="post-metadata">

### Author: ![andrew](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/andrew/32/645_2.png) [@andrew](https://forum.networklessons.com/u/andrew)
#### Post date: [July 28, 2016, 6:34pm UTC](https://forum.networklessons.com/t/spanning-tree-bpduguard/1142/11 "2016-07-28T18:34:45Z")

</div>

Abhishek,  
I would phrase is slightly differently:

> BPDUGuard is used on ports where BPDUs are not expected to be received, but if BPDUs are received, the port will be placed into an error state.

BPDUGuard does not prevent devices from sending BPDUs (BPDU Filtering does this). BPDUGuard simply listens for BPDUs and takes an action if it hears them.

---

<div class="post-metadata">

### Author: ![adave1103](https://cdn-forum.networklessons.com/letter_avatar_proxy/v4/letter/a/3ab097/32.png) [@adave1103](https://forum.networklessons.com/u/adave1103)
#### Post date: [July 29, 2016, 5:36am UTC](https://forum.networklessons.com/t/spanning-tree-bpduguard/1142/12 "2016-07-29T05:36:24Z")

</div>

thanks Andrew , it clears the doubt.

---

<div class="post-metadata">

### Author: ![said.alkhayyat](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/said.alkhayyat/32/825_2.png) [@said.alkhayyat](https://forum.networklessons.com/u/said.alkhayyat)
#### Post date: [December 10, 2017, 4:55am UTC](https://forum.networklessons.com/t/spanning-tree-bpduguard/1142/14 "2017-12-10T04:55:54Z")

</div>

Hi Rene,

Thank you for your great explanation on this, just got a question here.  
In ideal scenario, if we just configure all switch ports which are not connected to other switches to be In access mode (will they still receive BPDUs?) and will that eliminate the need of BPDU guard to be configured on these ports?  
Also if you can please explain a bit the difference between portfast and port mode access?

Thanks

---

<div class="post-metadata">

### Author: ![ReneMolenaar](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/renemolenaar/32/488_2.png) [@ReneMolenaar](https://forum.networklessons.com/u/ReneMolenaar)
#### Post date: [December 20, 2017, 2:03pm UTC](https://forum.networklessons.com/t/spanning-tree-bpduguard/1142/15 "2017-12-20T14:03:34Z")

</div>

Hi Said,

If you configure an interface in access mode then the interface only belongs to a single VLAN. The alternative is trunk mode, where multiple VLANs can cross the interfaces and they get tagged with the VLAN ID (using 802.1Q or ISL).

An interface in access mode still sends, receives, and processes BPDUs, this behavior doesn’t change. If your access mode interface connects to end devices then it’s a good idea to enable BPDU guard. You don’t want to process BPDUs from computers / laptops or anything like that.

Portfast is used to put interfaces in the forwarding state right away. It doesn’t go through the listening and learning states anymore. It also doesn’t trigger a TCN when the interface goes up/down. You can find a detailed explanation here:

> **[Cisco Portfast Configuration](https://networklessons.com/spanning-tree/cisco-portfast-configuration)**
>
> This lesson explains why we need Portfast and how to configure it on Cisco Catalyst Switches.

---

<div class="post-metadata">

### Author: ![rosna185](https://cdn-forum.networklessons.com/letter_avatar_proxy/v4/letter/r/e495f1/32.png) [@rosna185](https://forum.networklessons.com/u/rosna185)
#### Post date: [January 22, 2018, 9:46pm UTC](https://forum.networklessons.com/t/spanning-tree-bpduguard/1142/16 "2018-01-22T21:46:13Z")

</div>

In the Portfast tutorial, it was mentioned that once portfast is enabled on an access port it won’t send topology change notification. Will it still send BPDUs?  
Is that why we use BUDUGuard to stop BPDUs on Accessport?

---

<div class="post-metadata">

### Author: ![lagapidis](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/lagapidis/32/4949_2.png) [@lagapidis](https://forum.networklessons.com/u/lagapidis)
#### Post date: [January 28, 2018, 6:36am UTC](https://forum.networklessons.com/t/spanning-tree-bpduguard/1142/17 "2018-01-28T06:36:39Z")

</div>

Hello rosna

By default, all ports on a switch, including those configured with portfast **SEND** BPDUs. (It is possible to disable BPDU sending on these ports using BPDU filtering.) Portfast essentially skips the listening and learning states to enter the forwarding state immediately but does not disable STP. It also applies the global BPDUGuard feature (if it is enabled) to all ports configured using portfast.

In addition, as you mentioned, it won’t send any TC information on that port because by definition, there should be no switches connected to the specific port.

The reason we use BPDUGuard is because we don’t want any switches to be connected to a port configured with portfast. It is only for end devices. So if a BPDU is **RECEIVED** , the port goes into err-disabled state, essentially shutting down.

I hope this has been helpful!

Laz

---

<div class="post-metadata">

### Author: ![michael.mamabolo](https://cdn-forum.networklessons.com/letter_avatar_proxy/v4/letter/m/8e7dd6/32.png) [@michael.mamabolo](https://forum.networklessons.com/u/michael.mamabolo)
#### Post date: [February 15, 2018, 2:41am UTC](https://forum.networklessons.com/t/spanning-tree-bpduguard/1142/18 "2018-02-15T02:41:51Z")

</div>

Good explanation !!  
I really enjoy reading your topics and make me feel more comfortable and confident.

---

<div class="post-metadata">

### Author: ![mantena82](https://cdn-forum.networklessons.com/letter_avatar_proxy/v4/letter/m/f6c823/32.png) [@mantena82](https://forum.networklessons.com/u/mantena82)
#### Post date: [October 30, 2018, 4:54pm UTC](https://forum.networklessons.com/t/spanning-tree-bpduguard/1142/19 "2018-10-30T16:54:00Z")

</div>

Rene,

What do you recommend if want to make point to point Trunk connection,

Core sw (3850) -------\> Access switch (2960X) (single leg)  
If I configure my Core switch trunk interface with Bpduguard enable and root guuard, and the interface was going to error disable mode after sometime. I want to understand can we keep Bpduguard enable on trunk iterface or not ? could you please explain ?

Thanks  
Durga

---

<div class="post-metadata">

### Author: ![lagapidis](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/lagapidis/32/4949_2.png) [@lagapidis](https://forum.networklessons.com/u/lagapidis)
#### Post date: [October 30, 2018, 6:32pm UTC](https://forum.networklessons.com/t/spanning-tree-bpduguard/1142/20 "2018-10-30T18:32:31Z")

</div>

Hello Durga

BPDUguard should be enabled on interfaces to which you should never receive BPDUs such as those interfaces connected to end devices and hosts. BPDUGuard is often combined with portfast to protect these interfaces from creating an unwanted loop. You should never configure BPDUguard on interfaces where you expect BPDUs to arrive such as a link between switches. In your case, you should expect to receive BPDUs on the link between your core and access switch so BPDU guard should never be implemented there. BPDUs will be sent and the interface will go into errdisable state, something that is not desirable.

Rootguard on the other hand can be implemented on the interface on the core sw connecting to the access switch. This is because you want the core switch to always be the root and you should not accept any BPDUs that are incoming to change that.

I hope this has been helpful!

Laz

---

<div class="post-metadata">

### Author: ![pinkideb8](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/pinkideb8/32/1409_2.png) [@pinkideb8](https://forum.networklessons.com/u/pinkideb8)
#### Post date: [February 20, 2019, 3:58pm UTC](https://forum.networklessons.com/t/spanning-tree-bpduguard/1142/21 "2019-02-20T15:58:07Z")

</div>

why bpdu guard is not recommend on ports having uplink fast enabled?

[Next page](https://forum.networklessons.com/t/spanning-tree-bpduguard/1142.md?page=2)
