40.1k views
4 votes
Which of the following should be enabled on ports that have been enabled with PortFast so that it can prevent a rogue switch from modifying the STP topology?

a. Root guard
b. Loop guard
c. BPDU guard

User Idmitme
by
8.1k points

1 Answer

3 votes

Final answer:

BPDU guard should be enabled on ports with PortFast to prevent rogue switches from affecting the STP topology, shutting down ports if BPDUs are received.

Step-by-step explanation:

When PortFast is enabled on ports, the STP (Spanning Tree Protocol) feature BPDU guard should be enabled to prevent a rogue switch from modifying the STP topology. BPDU guard provides a security mechanism that shuts down PortFast-enabled ports if any BPDU (Bridge Protocol Data Unit) is received, thereby preventing the possibility of STP topology changes initiated by an unauthorized device. Root guard and loop guard also provide protection, but are mainly used for other specific scenarios in STP operation.

User Serenity
by
7.5k points