<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SpanGuard feature on Enterasys Products in FAQs</title>
    <link>https://community.extremenetworks.com/t5/faqs/spanguard-feature-on-enterasys-products/m-p/47271#M448</link>
    <description>Article ID: 5258 &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Products&lt;/B&gt;&lt;BR /&gt;
DFE&lt;BR /&gt;
Matrix C1&lt;BR /&gt;
Matrix E1&lt;BR /&gt;
SecureStack A2&lt;BR /&gt;
SecureStack B2&lt;BR /&gt;
SecureStack C2&lt;BR /&gt;
SmartSwitch 2000 2nd Generation&lt;BR /&gt;
SmartSwitch 6000 2nd Generation&lt;BR /&gt;
SmartSwitch 6000 3rd Generation &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Protocols/Features&lt;/B&gt;&lt;BR /&gt;
SpanGuard&lt;BR /&gt;
Spanning Tree &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Goals&lt;/B&gt;&lt;BR /&gt;
What is SpanGuard&lt;BR /&gt;
Which products support SpanGuard &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Solution&lt;/B&gt;&lt;BR /&gt;
SpanGuard (originally known as Secure Span) is a feature which shuts down a network port if it receives a BPDU. This feature may be activated on network edge ports, for the purpose of preventing "rogue" STA-aware devices from disrupting the existing Spanning Tree. &lt;BR /&gt;
&lt;BR /&gt;
When SpanGuard is enabled (this is a global option, disabled by default), reception of a BPDU (except loopback) by a port which has the STA adminEdge option enabled will cause the port to be locked and its state set to Blocking. By default, this condition will last for five minutes after reception of the last BPDU. &lt;BR /&gt;
&lt;BR /&gt;
Enterasys devices which support this feature: &lt;BR /&gt;
&lt;BR /&gt;
&lt;UL&gt; 
&lt;LI&gt;Matrix N-Series DFE, firmware 4.00.50 and higher 
&lt;/LI&gt;&lt;LI&gt;Matrix C1, firmware 2.00.14 and higher 
&lt;/LI&gt;&lt;LI&gt;Matrix E1, firmware 3.00.14 and higher 
&lt;/LI&gt;&lt;LI&gt;SecureStack A2, firmware 1.03.17 and higher 
&lt;/LI&gt;&lt;LI&gt;SecureStack B2, firmware 3.01.16 and higher 
&lt;/LI&gt;&lt;LI&gt;SecureStack C2, firmware 4.00.24 and higher 
&lt;/LI&gt;&lt;LI&gt;SmartSwitch 2000/6000 2nd/3rd Generation, firmware 5.06.04 and higher&lt;/LI&gt;&lt;/UL&gt;
For the DFE, C1, and E1 (see &lt;A href="http://bit.ly/1t5oi8k" target="_blank" rel="nofollow noreferrer noopener"&gt;5756&lt;/A&gt; for the SecureStack defaults); adminEdge is disabled (i.e. "adminedge false") by default, and must be enabled for individual User ports. If this is not done, SpanGuard will not function when enabled.&lt;BR /&gt;
For the other products, adminEdge is enabled by default (i.e. "adminedge true"), and must be disabled for individual Uplink ports. If this is not done, SpanGuard will &lt;I&gt;block uplink ports&lt;/I&gt; when enabled, as BPDUs are received. &lt;BR /&gt;
&lt;BR /&gt;
After adjusting adminEdge and enabling SpanGuard ('set spantree spanguard enable'), it is highly recommended to review the status of your ports ('show spantree spanguardlock *.*.*'). The resulting display should show all ports as unlocked. Otherwise, either an uplink port has been set as "adminEdge true" in error, or a BPDU-ingressing edge port warrants further investigation. &lt;BR /&gt;
&lt;BR /&gt;
Self-loopback-protection is already being handled as a separate function, possibly as a result of the action of 802.1w. The reception of foreign, unexpected BPDUs from beyond the edge of the defined Spanning Tree is truly a different issue, and is addressed by the SpanGuard feature.</description>
    <pubDate>Thu, 05 Sep 2013 06:03:00 GMT</pubDate>
    <dc:creator>FAQ_User</dc:creator>
    <dc:date>2013-09-05T06:03:00Z</dc:date>
    <item>
      <title>SpanGuard feature on Enterasys Products</title>
      <link>https://community.extremenetworks.com/t5/faqs/spanguard-feature-on-enterasys-products/m-p/47271#M448</link>
      <description>Article ID: 5258 &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Products&lt;/B&gt;&lt;BR /&gt;
DFE&lt;BR /&gt;
Matrix C1&lt;BR /&gt;
Matrix E1&lt;BR /&gt;
SecureStack A2&lt;BR /&gt;
SecureStack B2&lt;BR /&gt;
SecureStack C2&lt;BR /&gt;
SmartSwitch 2000 2nd Generation&lt;BR /&gt;
SmartSwitch 6000 2nd Generation&lt;BR /&gt;
SmartSwitch 6000 3rd Generation &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Protocols/Features&lt;/B&gt;&lt;BR /&gt;
SpanGuard&lt;BR /&gt;
Spanning Tree &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Goals&lt;/B&gt;&lt;BR /&gt;
What is SpanGuard&lt;BR /&gt;
Which products support SpanGuard &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Solution&lt;/B&gt;&lt;BR /&gt;
SpanGuard (originally known as Secure Span) is a feature which shuts down a network port if it receives a BPDU. This feature may be activated on network edge ports, for the purpose of preventing "rogue" STA-aware devices from disrupting the existing Spanning Tree. &lt;BR /&gt;
&lt;BR /&gt;
When SpanGuard is enabled (this is a global option, disabled by default), reception of a BPDU (except loopback) by a port which has the STA adminEdge option enabled will cause the port to be locked and its state set to Blocking. By default, this condition will last for five minutes after reception of the last BPDU. &lt;BR /&gt;
&lt;BR /&gt;
Enterasys devices which support this feature: &lt;BR /&gt;
&lt;BR /&gt;
&lt;UL&gt; 
&lt;LI&gt;Matrix N-Series DFE, firmware 4.00.50 and higher 
&lt;/LI&gt;&lt;LI&gt;Matrix C1, firmware 2.00.14 and higher 
&lt;/LI&gt;&lt;LI&gt;Matrix E1, firmware 3.00.14 and higher 
&lt;/LI&gt;&lt;LI&gt;SecureStack A2, firmware 1.03.17 and higher 
&lt;/LI&gt;&lt;LI&gt;SecureStack B2, firmware 3.01.16 and higher 
&lt;/LI&gt;&lt;LI&gt;SecureStack C2, firmware 4.00.24 and higher 
&lt;/LI&gt;&lt;LI&gt;SmartSwitch 2000/6000 2nd/3rd Generation, firmware 5.06.04 and higher&lt;/LI&gt;&lt;/UL&gt;
For the DFE, C1, and E1 (see &lt;A href="http://bit.ly/1t5oi8k" target="_blank" rel="nofollow noreferrer noopener"&gt;5756&lt;/A&gt; for the SecureStack defaults); adminEdge is disabled (i.e. "adminedge false") by default, and must be enabled for individual User ports. If this is not done, SpanGuard will not function when enabled.&lt;BR /&gt;
For the other products, adminEdge is enabled by default (i.e. "adminedge true"), and must be disabled for individual Uplink ports. If this is not done, SpanGuard will &lt;I&gt;block uplink ports&lt;/I&gt; when enabled, as BPDUs are received. &lt;BR /&gt;
&lt;BR /&gt;
After adjusting adminEdge and enabling SpanGuard ('set spantree spanguard enable'), it is highly recommended to review the status of your ports ('show spantree spanguardlock *.*.*'). The resulting display should show all ports as unlocked. Otherwise, either an uplink port has been set as "adminEdge true" in error, or a BPDU-ingressing edge port warrants further investigation. &lt;BR /&gt;
&lt;BR /&gt;
Self-loopback-protection is already being handled as a separate function, possibly as a result of the action of 802.1w. The reception of foreign, unexpected BPDUs from beyond the edge of the defined Spanning Tree is truly a different issue, and is addressed by the SpanGuard feature.</description>
      <pubDate>Thu, 05 Sep 2013 06:03:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/faqs/spanguard-feature-on-enterasys-products/m-p/47271#M448</guid>
      <dc:creator>FAQ_User</dc:creator>
      <dc:date>2013-09-05T06:03:00Z</dc:date>
    </item>
  </channel>
</rss>

