Why PortFast needs a partner
PortFast (the “PortFast” lesson) expects an end device on the port. But someone might plug a switch into it, or connect a cable back into another port. A PortFast port forwards at once, so a loop can form before STP reacts. BPDU Guard removes this risk. End devices never send BPDUs. So any BPDU on that port means something is wrong, and the port is shut down.
- 1. End devices are fine. PCs never send BPDUs, so BPDU Guard never acts on them.
- 2. A switch is plugged in. The desk switch sends BPDUs into Gi1/0/11.
- 3. Port err-disabled. The access switch shuts Gi1/0/11 down at once. There is no loop, and no change to the root.
A rogue (unwanted) switch doesn't even need to become the root to cause damage. It can send topology-change BPDUs again and again. Then every switch keeps clearing its MAC table, and traffic is flooded everywhere. BPDU Guard stops all of this, because it reacts to any BPDU, good or bad.
The border of your STP domain
Think of PortFast + BPDU Guard ports as the border of your STP network. Inside the border, switches send each other BPDUs. At the border, no BPDU is allowed in.
| Port | PortFast | BPDU Guard | Root Guard |
|---|---|---|---|
| Access port to a PC, printer, phone | Yes | Yes | — |
| Access switch uplink | No | Never: it must receive BPDUs, even when blocked | No |
| Distribution port facing access | No | No | Yes |
💡 Why the two always go together: BPDU Guard makes sure no switch can be on the port. So there is no reason for the port to wait through listening and learning, and it should have PortFast too. Also, PortFast doesn't turn STP off. Without BPDU Guard, a switch plugged into that port would still take part in STP.
Configure
interface GigabitEthernet1/0/11
spanning-tree portfast
spanning-tree bpduguard enableOn one port. It works with or without PortFast.
spanning-tree portfast default
spanning-tree portfast bpduguard defaultFor the whole switch: turns on BPDU Guard on every PortFast port (IOS XE also accepts 'spanning-tree portfast edge bpduguard default').
What you'll see
%SPANTREE-2-BLOCK_BPDUGUARD: Received BPDU on port Gi1/0/11 with BPDU Guard enabled. Disabling port. %PM-4-ERR_DISABLE: bpduguard error detected on Gi1/0/11, putting Gi1/0/11 in err-disable state
SW1#show interfaces status err-disabled Port Name Status Reason Err-disabled Vlans Gi1/0/11 err-disabled bpduguard
Recovering the port
First remove the cause (unplug the switch). Then turn the port back on by hand…
interface GigabitEthernet1/0/11
shutdown
no shutdown…or let the switch try again by itself after a set time:
errdisable recovery cause bpduguard
errdisable recovery interval 300Turns the port back on after 300 s (you can choose 30–86400). If the unwanted switch is still there, the port is shut down again.
SW1#show errdisable recovery ErrDisable Reason Timer Status ----------------- -------------- bpduguard Enabled ... Timer interval: 300 seconds Interfaces that will be enabled at the next timeout: Interface Errdisable reason Time left(sec) --------- ----------------- -------------- Gi1/0/11 bpduguard 214
Note: show interfaces only says err-disabled. To see the reason, use show interfaces status err-disabled. Automatic recovery is useful at remote sites where nobody can go and fix it. Where security matters more, leave it off, so someone checks the problem first.
Best-practice template
! access switch, global
spanning-tree portfast default
spanning-tree portfast bpduguard default
!
! any access port that really does lead to a switch
interface GigabitEthernet1/0/48
description Link to lab switch
spanning-tree portfast disable
spanning-tree bpduguard disableTrunks are left out automatically, because 'portfast default' only applies to access ports.
⚠️ Limits: BPDU Guard can't detect a hub, or a cheap switch that doesn't send BPDUs. A loop through one of those still needs STP (or storm control) to stop it.
Check yourself
How does BPDU Guard differ from Root Guard when triggered?
With 'spanning-tree portfast bpduguard default', which ports are protected?