IntermediatePublished 2026-07-31
CCNA Foundations: PortFast & BPDU Guard
Today's daily lab
Harden the campus access edge by enabling PortFast and BPDU Guard only on host-facing access ports while keeping redundant switch-to-switch trunks loop-free with STP. Validate instant host link-up and demonstrate that a rogue BPDU errdisables the port instead of changing the topology.
Learning objectives
- Enable PortFast on user-facing access interfaces so hosts reach forwarding immediately.
- Enable BPDU Guard on those same access interfaces to protect against rogue switches.
- Ensure inter-switch trunk ports do not run PortFast or BPDU Guard.
- Verify STP state and errdisable behavior using show commands and host pings.
- Reason about redundant L2 topologies and why edge protection prevents topology reshaping.
Troubleshooting focus
- If a host link does not move to forwarding instantly, confirm PortFast is enabled on the access interface and not on trunks.
- If an access port goes down after connecting a device that emits BPDUs, check for BPDU Guard errdisable and confirm recovery settings.
- If hosts cannot ping each other, verify both are in the same VLAN and that VLAN is allowed across every trunk with a consistent native VLAN.
- If STP shows all trunk links forwarding, confirm STP is active and not administratively disabled; at least one redundant path should be blocked.
- If a trunk appears as an access port, re-check trunk configuration (mode, encapsulation dot1q, native VLAN) on both ends.
Topology
Subscribe to preview this lab's topology.
See plansFound a problem with this lab?
Please sign in to report a problem — tying it to your attempts lets us reproduce and fix it faster.
Grade your work
Create a free account to submit your completed lab for grading.
Create a free account