IntermediatePublished 2026-07-02
STP Lab 6: BPDU Guard — Protecting the Edge
Bundle lab
Continue the STP series on a three-switch triangle with a real loop. SW1 is the deterministic root for VLAN 60, and access ports already use PortFast. In this lab you will harden the edge by enabling BPDU Guard on the two host-facing access ports on SW2 and SW3, while leaving the inter-switch trunks untouched. Verify with show commands that BPDU Guard is active only on the edge and that hosts still communicate normally.
Learning objectives
- Explain why PortFast needs BPDU Guard on access ports
- Enable BPDU Guard on PortFast-enabled access ports
- Verify BPDU Guard status on specific interfaces
- Confirm trunks do not have BPDU Guard enabled
- Validate root bridge election for VLAN 60 remains on SW1
Troubleshooting focus
- If a host port is err-disabled, check for unexpected BPDUs: show spanning-tree interface <if> detail and show errdisable recovery
- If inter-switch links go down unexpectedly, confirm BPDU Guard was not applied on trunks: show running-config interface <trunk-if>
- If hosts cannot ping each other, confirm both are in VLAN 60 on access ports and VLAN 60 is allowed across all trunks
- If STP does not block the expected loop link, verify root priority on SW1 and consistent Rapid-PVST operation on all switches
Topology
Subscribe to preview this lab's topology.
See plansGrade your work
How this lab is graded
- Build it your way. Where a lab lets you choose a value — a VLAN name, an interface description — grading checks that you configured it, not which name you picked. Names that another line has to reference, like an ACL applied with
access-class, are stated in the guide and do have to match. - Addresses, modes and protocol keywords are exact. An IP address, a subnet mask,
switchport mode trunk, an encapsulation — these carry the meaning of the lab, so they are graded as written in the guide. - Grading reads your saved configuration. Export the lab from CML after you have configured it, and make sure anything you set is in the running-config — a change that only exists in a terminal session never reaches the grader.
- You can submit as many times as you like. Your best score stands, and each attempt tells you which checks passed so you can work the gaps.
- Scored something you believe is correct? Use Report an issue on this page — that is exactly how the grading fixes in the changelog got found.
Create a free account to submit your lab for grading.
Create a free accountFound a problem with this lab?
Please sign in to report a problem — tying it to your attempts lets us reproduce and fix it faster.