Options

Port security(shutdown mode) vs bpduguard?

StonedHitmanStonedHitman Member Posts: 120
I was reading up on bpduguard and I immediately thought of port security. My question is this, If my goal was to shutdown a port on a switch as soon as a device was connected to it, would port security "shutdown" suffice, or would I need to use bpduguard, or both? from what I understand bpduguard is only used in conjunction with portfast on edge ports. So, if I'm using portfast then I need bpduguard and if I'm not using portfast I should use port security?
Currently reading Network Warrior

Comments

  • Options
    elderkaielderkai Member Posts: 279
    bpduguard only acts when the switchport receives a bpdu, so something running STP(a switch).
  • Options
    Adam BAdam B Member Posts: 108 ■■□□□□□□□□
    Yeah as elder said, bpduguard would be used in a situation where you don't want other switches connecting but you're fine with lets just say other hosts connecting. That way bpdu's are never transmitted causing internal loops between the switches. It's used in synch with Portfast generally, as it will allow hosts to come up on those switches quicker than the usual convergence time, and not allow other switches to go up on them thanks to bpduguard
    2015 Goals: CCNP SWITCH [] SEC+ [ ] CCNP ROUTE [ ] CCNP TSHOOT [ ]

  • Options
    OfWolfAndManOfWolfAndMan Member Posts: 923 ■■■■□□□□□□
    The purpose of bpduguard is to prevent someone from inserting a switch into your topology (Especially preventing someone from becoming a root bridge, as they could steal all your trafficz). Port security, by default, will shut an interface down after a second device with a different MAC address is attached to the switchport, unless you configure the port with #switchport port-security maximum [number of max mac addresses]. What is your purpose of trying to shut a port down?
    :study:Reading: Lab Books, Ansible Documentation, Python Cookbook 2018 Goals: More Ansible/Python work for Automation, IPSpace Automation Course [X], Build Jenkins Framework for Network Automation []
  • Options
    HeeroHeero Member Posts: 486
    Maybe he is trying to do a ghetto man's wire trace by plugging into wall jacks and seeing what port goes down on the switch?
  • Options
    Dieg0MDieg0M Member Posts: 861
    BPDU Guard will not shut down the port, it will put it in Err-disable mode. You can use both BPDU Guard and port-security on the same switch port but for different purposes.
    Follow my CCDE journey at www.routingnull0.com
Sign In or Register to comment.