Routelearn.net
Course menu

Course 6: Spanning Tree ProtocolLesson 4.5 (20 of 24 in this course)41 of 91 in the CCNA series

BPDU Filter

Suppressing BPDUs, the safe way and the dangerous way.

Advanced · 5 min read

BPDU Filter is a Cisco Spanning Tree feature that stops a port from sending BPDUs. Enabled globally, it applies only to PortFast ports, which stop sending after a short burst at link-up and return to normal STP as soon as a BPDU is received; enabled on an interface, the port neither sends nor processes BPDUs, which effectively disables STP there.

In simple terms: It tells a port to keep quiet and not send Spanning Tree messages to the device on the other end. Used carelessly on one port, it can switch off loop protection there.

What it's for

Edge ports still send a BPDU every 2 seconds to whatever is plugged in. BPDU Filter stops that. It can be turned on in two ways, and they work very differently. Mixing them up is a common way to create a loop.

Two situations that call for it

SituationThe concernMode used
A high-security office, where user ports keep sending BPDUsAnyone can capture the BPDUs on their laptop and read the root's bridge ID, priorities and costs. That helps an attacker make a fake BPDU.Global (for the whole switch, edge ports only)
Two organisations joining their Layer 2 networks with a linkTheir BPDUs would join two separate STP networks into one, with only one root. One company's settings could change the other company's network.Interface (on the link between them)

Way 1: global (the safer one)

spanning-tree portfast bpdufilter default

Applies to ports that are working as PortFast ports.

  • The port stops sending BPDUs (after sending a few when the link comes up).
  • If a BPDU is ever received, the port stops being PortFast and filtered, and runs normal STP. So a loop is still blocked.

In detail: when the port comes up, it sends 11 BPDUs: one at once, then one every 2 seconds, 10 more times (about 20 seconds in all). This gives a switch at the other end a chance to answer. If nothing answers, the port stops sending.

Example output · based on Cisco documentation; exact format varies by platform and software version
ACC1#show spanning-tree interface Gi1/0/5 detail
 Port 5 (GigabitEthernet1/0/5) of VLAN0010 is designated forwarding
   Port path cost 4, Port priority 128, Port Identifier 128.5.
   ...
   The port is in the portfast mode by default
   Link type is point-to-point by default
   Bpdu filter is enabled by default
   BPDU: sent 11, received 0
"by default" means the global command turned it on. The "sent" count stops at 11, so the filter is working.
A BPDU arrives on an edge port with…Result
portfast bpduguard defaultPort err-disabled
portfast bpdufilter defaultThe port stops being PortFast and runs normal STP
Both global commandsThey work fine together. The BPDU is received, so BPDU Guard shuts the port down.

Way 2: on one interface (the dangerous one)

interface GigabitEthernet1/0/12 spanning-tree bpdufilter enable

The port doesn't send BPDUs, and ignores BPDUs it receives. So STP is really turned off on this port.

DistributionAccess AGi1/0/12 · filterAccess BGi1/0/12 · filterDesk switchcabled to both
  1. 1. BPDUs are filtered. Someone connects a desk switch to two filtered ports. The access switches don't send BPDUs to it, and ignore any BPDUs coming from it.
  2. 2. STP can't see the loop. Every port in the circle keeps forwarding: Distribution → A → desk switch → B → Distribution.
  3. 3. Broadcast storm. One broadcast now goes round and round the loop, just like in the “Why is Spanning Tree needed?” lesson.

⚠️ If BPDU Guard and the interface BPDU Filter are both set on the same port, the filter wins: the port never processes the BPDU, so the guard never triggers.

When would you use it?

  • Global way: sometimes, to stop sending BPDUs to end devices or to a service provider's equipment, while keeping the safety net.
  • Interface way: only at a planned border that STP must not cross (for example, some links to a provider or a data centre). And only when loops are stopped in some other way.

For normal user ports, use PortFast with BPDU Guard, not BPDU Filter.

Verify

show spanning-tree interface GigabitEthernet1/0/12 detail

Look for 'Bpdu filter is enabled' and the BPDU counts. A port with the interface filter shows 'sent 0, received 0'.

Check yourself

Predict · scenario 1

A port has the global BPDU Filter (through PortFast) and receives a BPDU. What happens?

Predict · scenario 2

Why is interface-level BPDU Filter dangerous on an access port?