I understand what BPDU accomplishes but I have a question about its initial configuration. If BPDU is configured on all switchports how does that affect your initial configuration and rollout? In other words, if you set up a new network and connect a downstream switch to a port on another switch what prevents that switch from shutting the port down due to the BPDUs received? Is there a specific command required on the Trunk Link or should it NOT be configured on Trunk Links?
Yes, BPDUS sent from all switches , however disabling spanning tree for a particular vlan would disable a BPDU to be sent for that VLAN.
I dont recommend setting it on a trunk link. This is a security feature prevents the Switch from recieving BPDU on a port by putting the port into errdisable state.
you should set it on edge ports where hosts are connected.
spanning-tree bpduguard enable