Spanning Tree Protocol (STP) is used in networks to prevent Layer 2 loops on the access network. STP may be leveraged by an attacker for a variety of security attacks. To reduce the risk of STP attacks, iOS supports the following security features for STP.
BPDU Guard:
STP uses Bridge Packet Data Units (BPDUs) to exchange information across switches to discover the topology and put the ports in forwarding or blocking modes. The BPDUs are exchanged only between devices that participate in the STP domain. An attacker may try to send STP BPDUs from an access port of the switch and try to mislead the network devices by blocking some ports or putting some other ports in a forwarding mode, creating broadcast loops. The BPDUs also influence ...