Link to home
Start Free TrialLog in
Avatar of jskfan
jskfanFlag for Cyprus

asked on

Is BPDUGUARD enough to avoid ROOTGUARD ?

Is BPDUGUARD enough to avoid ROOTGUARD ?

I have read in some articles where they stated that ROOTGUARD should be configured on the Core switches interfaces facing Distributed Switches and also configured on the Distributed Switches Interfaces facing Access Switches, this in order to prevent Bad Guy from connecting a new Switch configured with Lower Priority than existing switches or configured with Root Primary command then connected to Access Switches.

I thought when configuring BPDUGUARD on Access Switches will be enough, because no other Switch can be connected to Access Switches, and when connected the port will go in Shutdown (err-disabled)

Any clarification will be appreciated.

Thanks
ASKER CERTIFIED SOLUTION
Avatar of Don Johnston
Don Johnston
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of jskfan

ASKER

so to be in the safe side :
 ROOTGUARD should be configured on the Core switches interfaces facing Distributed Switches and also configured on the Distributed Switches Interfaces facing Access Switches
Yes.  

In that scenario, rootguard is to protect you from yourself. ;-)
Avatar of jskfan

ASKER

Thanks Don,

In Access Switch, BPDUGUARD should be enough , no need for Root Guard . Correct  ?
Yes.  That is correct.
Avatar of jskfan

ASKER

Thank you