IntermediatePublished 2026-07-31
CCNA Foundations: PortFast & BPDU Guard
Archive lab
CCNA exam domain: Network Access
Harden the campus access edge by enabling PortFast and BPDU Guard only on host-facing access ports while keeping redundant switch-to-switch trunks loop-free with STP. Validate instant host link-up and demonstrate that a rogue BPDU errdisables the port instead of changing the topology.
Learning objectives
- Enable PortFast on user-facing access interfaces so hosts reach forwarding immediately.
- Enable BPDU Guard on those same access interfaces to protect against rogue switches.
- Ensure inter-switch trunk ports do not run PortFast or BPDU Guard.
- Verify STP state and errdisable behavior using show commands and host pings.
- Reason about redundant L2 topologies and why edge protection prevents topology reshaping.
Troubleshooting focus
- If a host link does not move to forwarding instantly, confirm PortFast is enabled on the access interface and not on trunks.
- If an access port goes down after connecting a device that emits BPDUs, check for BPDU Guard errdisable and confirm recovery settings.
- If hosts cannot ping each other, verify both are in the same VLAN and that VLAN is allowed across every trunk with a consistent native VLAN.
- If STP shows all trunk links forwarding, confirm STP is active and not administratively disabled; at least one redundant path should be blocked.
- If a trunk appears as an access port, re-check trunk configuration (mode, encapsulation dot1q, native VLAN) on both ends.
Topology
Subscribe to preview this lab's topology.
See plansGrade your work
How this lab is graded
- Build it your way. Where a lab lets you choose a value — a VLAN name, an interface description — grading checks that you configured it, not which name you picked. Names that another line has to reference, like an ACL applied with
access-class, are stated in the guide and do have to match. - Addresses, modes and protocol keywords are exact. An IP address, a subnet mask,
switchport mode trunk, an encapsulation — these carry the meaning of the lab, so they are graded as written in the guide. - Grading reads your saved configuration. Export the lab from CML after you have configured it, and make sure anything you set is in the
running-config— a change that only exists in a terminal session never reaches the grader. - You can submit as many times as you like. Your best score stands, and each attempt tells you which checks passed so you can work the gaps.
- Scored something you believe is correct? Use Report an issue on this page — that is exactly how the grading fixes in the changelog got found.
Create a free account to submit your lab for grading.
Create a free accountFound a problem with this lab?
Please sign in to report a problem — tying it to your attempts lets us reproduce and fix it faster.