From: "Bastien Roucariès" <roucaries.bastien@gmail.com>
To: netdev@vger.kernel.org
Cc: "Bastien Roucariès" <rouca@debian.org>
Subject: [PATCH iproute2 4/6] Better documentation of BDPU guard
Date: Sun, 5 Apr 2020 15:48:56 +0200 [thread overview]
Message-ID: <20200405134859.57232-5-rouca@debian.org> (raw)
In-Reply-To: <20200405134859.57232-1-rouca@debian.org>
Document that guard disable the port and how to reenable it
Signed-off-by: Bastien Roucariès <rouca@debian.org>
---
man/man8/bridge.8 | 13 ++++++++++++-
1 file changed, 12 insertions(+), 1 deletion(-)
diff --git a/man/man8/bridge.8 b/man/man8/bridge.8
index c8e15416..53aebb60 100644
--- a/man/man8/bridge.8
+++ b/man/man8/bridge.8
@@ -340,7 +340,18 @@ STP BPDUs.
.BR "guard on " or " guard off "
Controls whether STP BPDUs will be processed by the bridge port. By default,
the flag is turned off allowed BPDU processing. Turning this flag on will
-cause the port to stop processing STP BPDUs.
+disables
+the bridge port if a STP BPDU packet is received.
+
+If running Spanning Tree on bridge, hostile devices on the network
+may send BPDU on a port and cause network failure. Setting
+.B guard on
+will detect and stop this by disabling the port.
+The port will be restarted if link is brought down, or
+removed and reattached. For example if guard is enable on
+eth0:
+
+.B ip link set dev eth0 down; ip link set dev eth0 up
.TP
.BR "hairpin on " or " hairpin off "
--
2.25.1
next prev parent reply other threads:[~2020-04-05 13:50 UTC|newest]
Thread overview: 18+ messages / expand[flat|nested] mbox.gz Atom feed top
2020-04-05 13:48 Improve documentation of bridge Bastien Roucariès
2020-04-05 13:48 ` [PATCH iproute2 1/6] Better documentation of mcast_to_unicast option Bastien Roucariès
2020-04-05 13:48 ` [PATCH iproute2 2/6] Improve hairpin mode description Bastien Roucariès
2020-04-05 13:48 ` [PATCH iproute2 3/6] Document BPDU filter option Bastien Roucariès
2020-04-05 13:48 ` Bastien Roucariès [this message]
2020-04-05 13:48 ` [PATCH iproute2 5/6] Document root_block option Bastien Roucariès
2020-04-06 9:54 ` Sergei Shtylyov
2020-04-05 13:48 ` [PATCH iproute2 6/6] State of bridge STP port are now case insensitive Bastien Roucariès
2020-04-12 23:50 ` [V2][PATH 0/6] iproute improve documentation of bridge roucaries.bastien
2020-04-12 23:50 ` [PATCH 1/6] Better documentation of mcast_to_unicast option roucaries.bastien
2020-04-20 16:43 ` Stephen Hemminger
2020-04-12 23:50 ` [PATCH 2/6] Improve hairpin mode description roucaries.bastien
2020-04-12 23:50 ` [PATCH 3/6] Document BPDU filter option roucaries.bastien
2020-04-12 23:50 ` [PATCH 4/6] Better documentation of BDPU guard roucaries.bastien
2020-04-13 9:28 ` Sergei Shtylyov
2020-04-12 23:50 ` [PATCH 5/6] Document root_block option roucaries.bastien
2020-04-12 23:50 ` [PATCH 6/6] State of bridge STP port are now case insensitive roucaries.bastien
2020-04-20 16:51 ` [V2][PATH 0/6] iproute improve documentation of bridge Stephen Hemminger
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20200405134859.57232-5-rouca@debian.org \
--to=roucaries.bastien@gmail.com \
--cc=netdev@vger.kernel.org \
--cc=rouca@debian.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.