On (2012-05-24 10:56 +0200), Peter Rathlev wrote:

> connecting to anything that does not create a L2 loop, i.e. a bridge. We
> use Portfast and BPDU Guard on all links towards routers. That also

This is incredibly dangerous. Leak one BPDU from one customer EVPN
somewhere, and all customers are down in PE facing that metro.
PE<->Metro definitely should be BPDUfilter.

On customer ports, BPDUguard is apt, which you can enable per default for
edge/portfast ports, so you only need to configure porfast.

-- 
  ++ytti
_______________________________________________
cisco-nsp mailing list  [email protected]
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/

Reply via email to