07-16-2010 08:11 AM - edited 03-06-2019 12:03 PM
Hi,
We have 6509 CatOS switch where port from module 5 connects to firewall .
we have enabled portfast and bpduguard on that module 5.
is this good practice to enable both on port going to fw.
also recently that port received bpdu from fw and went into errdisabled,
anyone know why this happended
thanks
mahesh
07-16-2010 08:44 AM
I don’t know if I understand your comment correctly
if you enable portfast (port connected to user port or router port), you need some features to help you
so portfast = direct to forward state
for example port 1 connected to user PC , and you don’t want the user wait 30 sec to come in forward state
you will enable portfast (because no loop will come from user port)
but if the user connect switch in port 1 , the switch will send bpdu and come to forward state
the bpdu guard and bpdu filter will help if the port receive bpdu
in bpdu gurd the port will be in errdisable
in bpdu filter the port will be auto disable portfast
,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,
About port connected to firewall you I don’t recommended to enable portfast and bpdu gaurd
07-16-2010 12:08 PM
Hi,
We have 6509 CatOS switch where port from module 5 connects to firewall .
we have enabled portfast and bpduguard on that module 5.
is this good practice to enable both on port going to fw.
also recently that port received bpdu from fw and went into errdisabled,
anyone know why this happended
thanks
mahesh
Hi Mahesh,
07-18-2010 07:45 PM
hi Ganesh,
But we open cisco tac c ase they told us to turn off the port fast on the switch port that connects to fw not bpdu guard.
any comments or ideas?
thanks for help
mahesh
07-18-2010 09:00 PM
Hello,
You can turn-on the port-fast and not worry about the BPDU-Guard on an
interface that is connected to a routed device (routed devices will not
participate in Spanning-tree calculations). So, in your case, you can
turn-on port-fast on the interface connecting to the firewall without any
issues (as long as it is not participating in Spanning-tree).
Note: If your firewall is ASA 5505 (or similar) that has a switch module,
then what TAC said is correct. You should turn-off port-fast and turn-on
BPDU-guard.
Hope this helps.
Regards,
NT
07-19-2010 07:08 AM
Hi,
thnaks for reply fw is juniper fw.
mahesh
07-18-2010 10:51 PM
hi Ganesh,
But we open cisco tac c ase they told us to turn off the port fast on the switch port that connects to fw not bpdu guard.
any comments or ideas?
thanks for help
mahesh
Hi Mahesh,
As NT pointed out if ASA as switch modules the recommendation from cisco TAC is right.
Hope to Help !!
Ganesh.H
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: