Have an example MSTP configuration below.
My questions is do I need to enable edge-safeguard and bpdu-restrict on each of the edge
ports in all the STP domains or just the CIST (S0) as per below, and would this make any difference if the edge device was for example an IP phone and therefor be carrying vlans that are in two different MSTI's?
configure mstp region Highgate
configure stpd s0 delete vlan default ports all
disable stpd s0 auto-bind vlan default
disable stpd s0
configure stpd s0 mode mstp cist
create stpd s1
configure stpd s1 mode mstp msti 1
enable stpd s1 auto-bind vlan Unused1-MSTI1
enable stpd s1 auto-bind vlan Unused2-MSTI1
create stpd s2
configure stpd s2 mode mstp msti 2
enable stpd s2 auto-bind vlan Unused1-MSTI2
enable stpd s2 auto-bind vlan Unused2-MSTI2
configure stpd s0 ports link-type edge 1:1-47 edge-safeguard enable bpdu-restrict
configure stpd s1 ports link-type edge 1:1-47 edge-safeguard enable bpdu-restrict
configure stpd s2 ports link-type edge 1:1-47 edge-safeguard enable bpdu-restrict
configure stpd s0 ports link-type point-to-point 1:48
configure stpd s1 ports link-type point-to-point 1:48
configure stpd s2 ports link-type point-to-point 1:48
Many thanks in advance.