Qtech QSW-2870 Руководство пользователя онлайн [199/230] 481606

Qtech QSW-2870 Руководство пользователя онлайн [199/230] 481606
Chapter8 Reliability Configuration
8-17
Loop protection
The root port and other blocked ports state maintains by receiving BPDU from
upstream Switch continuously. When it causes that these ports cannot receive
BPDU from upstream Switch because of link congestion or link failure, Switch will
select the root port over again. The original root port will change to the
designated port and the original blocked port will migrate to the forwarding state.
This will lead to loop of switching network.
Loop protection function will inhibit loop. After enabling loop protection function, if
the root port cannot receive BPDU from upstream, it will be configured to be
blocked state. And the blocked port will maintain blocked state and not forward
message so there will not be any loop in the network.
Root protection
The root protection function can be used to prevent the unknown source or origin
BPDU from changing network topology.
Due to the mistaken configuration of maintainer or malicious network attack, the
legal root bridge may receive configuration message with higher priority in the
network. So the current root bridge will lose the root bridge position and lead to
error change of network topology. Assuming that the original flow is forwarded
through the high-rate link, the illegal change will cause that the flow of high-rate
link is pulled into low-rate link and make network congestion. Root protection
function can prevent this condition from happening.
For these ports configured root protection function, the role of port only maintains
to be designated port. Once this kind of ports receive configuration message with
higher priority, the state of these ports will be configured as listening state and not
forward message (equivalent to the link which the port connected disconnecting).
During long enough time, if not receiving better configuration message, the port
will restore the original state.
TC protection
After Switch receiving TC-BPDU message, it will delete MAC table item and ARP
table item. If someone forges TC-BPDU packet to attack Switch maliciously, the
Switch will receive a lot of TC-BPDU messages in a short time. And frequent

Содержание

Скачать
Случайные обсуждения