Routelearn.net
Course menu

Course 6: Spanning Tree ProtocolLesson 4.4 (19 of 24 in this course)40 of 91 in the CCNA series

BPDU Guard

Shutting down an edge port the moment a switch appears on it.

Intermediate · 5 min read

BPDU Guard is a Cisco Spanning Tree protection feature that puts a port into the err-disabled state as soon as it receives a BPDU. It is used on PortFast edge ports, where only end devices should be connected and a BPDU means a switch has appeared.

In simple terms: Ports for PCs should never hear from another switch. If one does, BPDU Guard shuts the port down straight away before a loop can start.

Why PortFast needs a partner

PortFast (the “PortFast” lesson) expects an end device on the port. But someone might plug a switch into it, or connect a cable back into another port. A PortFast port forwards at once, so a loop can form before STP reacts. BPDU Guard removes this risk. End devices never send BPDUs. So any BPDU on that port means something is wrong, and the port is shut down.

Access switchPCGi1/0/10Desk switchGi1/0/11
  1. 1. End devices are fine. PCs never send BPDUs, so BPDU Guard never acts on them.
  2. 2. A switch is plugged in. The desk switch sends BPDUs into Gi1/0/11.
  3. 3. Port err-disabled. The access switch shuts Gi1/0/11 down at once. There is no loop, and no change to the root.

A rogue (unwanted) switch doesn't even need to become the root to cause damage. It can send topology-change BPDUs again and again. Then every switch keeps clearing its MAC table, and traffic is flooded everywhere. BPDU Guard stops all of this, because it reacts to any BPDU, good or bad.

The border of your STP domain

Think of PortFast + BPDU Guard ports as the border of your STP network. Inside the border, switches send each other BPDUs. At the border, no BPDU is allowed in.

PortPortFastBPDU GuardRoot Guard
Access port to a PC, printer, phoneYesYes—
Access switch uplinkNoNever: it must receive BPDUs, even when blockedNo
Distribution port facing accessNoNoYes

💡 Why the two always go together: BPDU Guard makes sure no switch can be on the port. So there is no reason for the port to wait through listening and learning, and it should have PortFast too. Also, PortFast doesn't turn STP off. Without BPDU Guard, a switch plugged into that port would still take part in STP.

Configure

interface GigabitEthernet1/0/11 spanning-tree portfast spanning-tree bpduguard enable

On one port. It works with or without PortFast.

spanning-tree portfast default spanning-tree portfast bpduguard default

For the whole switch: turns on BPDU Guard on every PortFast port (IOS XE also accepts 'spanning-tree portfast edge bpduguard default').

What you'll see

Example output · based on Cisco documentation; exact format varies by platform and software version
%SPANTREE-2-BLOCK_BPDUGUARD: Received BPDU on port Gi1/0/11 with BPDU Guard enabled. Disabling port.
%PM-4-ERR_DISABLE: bpduguard error detected on Gi1/0/11, putting Gi1/0/11 in err-disable state
Example output · based on Cisco documentation; exact format varies by platform and software version
SW1#show interfaces status err-disabled
Port      Name               Status       Reason               Err-disabled Vlans
Gi1/0/11                     err-disabled bpduguard

Recovering the port

First remove the cause (unplug the switch). Then turn the port back on by hand…

interface GigabitEthernet1/0/11 shutdown no shutdown

…or let the switch try again by itself after a set time:

errdisable recovery cause bpduguard errdisable recovery interval 300

Turns the port back on after 300 s (you can choose 30–86400). If the unwanted switch is still there, the port is shut down again.

Example output · based on Cisco documentation; exact format varies by platform and software version
SW1#show errdisable recovery
ErrDisable Reason            Timer Status
-----------------            --------------
bpduguard                    Enabled
...
Timer interval: 300 seconds

Interfaces that will be enabled at the next timeout:

Interface       Errdisable reason       Time left(sec)
---------       -----------------       --------------
Gi1/0/11        bpduguard                  214

Note: show interfaces only says err-disabled. To see the reason, use show interfaces status err-disabled. Automatic recovery is useful at remote sites where nobody can go and fix it. Where security matters more, leave it off, so someone checks the problem first.

Best-practice template

! access switch, global spanning-tree portfast default spanning-tree portfast bpduguard default ! ! any access port that really does lead to a switch interface GigabitEthernet1/0/48 description Link to lab switch spanning-tree portfast disable spanning-tree bpduguard disable

Trunks are left out automatically, because 'portfast default' only applies to access ports.

⚠️ Limits: BPDU Guard can't detect a hub, or a cheap switch that doesn't send BPDUs. A loop through one of those still needs STP (or storm control) to stop it.

Check yourself

Predict · scenario 1

How does BPDU Guard differ from Root Guard when triggered?

Predict · scenario 2

With 'spanning-tree portfast bpduguard default', which ports are protected?