What it's for
Edge ports still send a BPDU every 2 seconds to whatever is plugged in. BPDU Filter stops that. It can be turned on in two ways, and they work very differently. Mixing them up is a common way to create a loop.
Two situations that call for it
| Situation | The concern | Mode used |
|---|---|---|
| A high-security office, where user ports keep sending BPDUs | Anyone can capture the BPDUs on their laptop and read the root's bridge ID, priorities and costs. That helps an attacker make a fake BPDU. | Global (for the whole switch, edge ports only) |
| Two organisations joining their Layer 2 networks with a link | Their BPDUs would join two separate STP networks into one, with only one root. One company's settings could change the other company's network. | Interface (on the link between them) |
Way 1: global (the safer one)
spanning-tree portfast bpdufilter defaultApplies to ports that are working as PortFast ports.
- The port stops sending BPDUs (after sending a few when the link comes up).
- If a BPDU is ever received, the port stops being PortFast and filtered, and runs normal STP. So a loop is still blocked.
In detail: when the port comes up, it sends 11 BPDUs: one at once, then one every 2 seconds, 10 more times (about 20 seconds in all). This gives a switch at the other end a chance to answer. If nothing answers, the port stops sending.
ACC1#show spanning-tree interface Gi1/0/5 detail Port 5 (GigabitEthernet1/0/5) of VLAN0010 is designated forwarding Port path cost 4, Port priority 128, Port Identifier 128.5. ... The port is in the portfast mode by default Link type is point-to-point by default Bpdu filter is enabled by default BPDU: sent 11, received 0
| A BPDU arrives on an edge port with… | Result |
|---|---|
portfast bpduguard default | Port err-disabled |
portfast bpdufilter default | The port stops being PortFast and runs normal STP |
| Both global commands | They work fine together. The BPDU is received, so BPDU Guard shuts the port down. |
Way 2: on one interface (the dangerous one)
interface GigabitEthernet1/0/12
spanning-tree bpdufilter enableThe port doesn't send BPDUs, and ignores BPDUs it receives. So STP is really turned off on this port.
- 1. BPDUs are filtered. Someone connects a desk switch to two filtered ports. The access switches don't send BPDUs to it, and ignore any BPDUs coming from it.
- 2. STP can't see the loop. Every port in the circle keeps forwarding: Distribution → A → desk switch → B → Distribution.
- 3. Broadcast storm. One broadcast now goes round and round the loop, just like in the “Why is Spanning Tree needed?” lesson.
⚠️ If BPDU Guard and the interface BPDU Filter are both set on the same port, the filter wins: the port never processes the BPDU, so the guard never triggers.
When would you use it?
- Global way: sometimes, to stop sending BPDUs to end devices or to a service provider's equipment, while keeping the safety net.
- Interface way: only at a planned border that STP must not cross (for example, some links to a provider or a data centre). And only when loops are stopped in some other way.
For normal user ports, use PortFast with BPDU Guard, not BPDU Filter.
Verify
show spanning-tree interface GigabitEthernet1/0/12 detailLook for 'Bpdu filter is enabled' and the BPDU counts. A port with the interface filter shows 'sent 0, received 0'.
Check yourself
A port has the global BPDU Filter (through PortFast) and receives a BPDU. What happens?
Why is interface-level BPDU Filter dangerous on an access port?