Huawei Switch RSTP Yapılandırması ve Güvenlik Ayarları

⚡ Huawei Switch’lerde RSTP Yapılandırması ve Güvenlik Önlemleri


🔄 1. Mevcut STP Ayarlarının Temizlenmesi

Önceki yapılandırmaların kaldırılmasıyla başlanır:

[Switch1]undo stp priority
[Switch1]interface GigabitEthernet 0/0/9
[Switch1-GigabitEthernet0/0/9]undo stp cost

[Switch2]undo stp priority

⚙️ 2. RSTP (Rapid Spanning Tree Protocol) Aktif Etme

Huawei switch’lerde STP modunu RSTP olarak seçiyoruz:

[Switch1]stp mode rstp
[Switch2]stp mode rstp

RSTP Bilgi Görüntüleme:

[Switch1]display stp
[Switch2]display stp

📌 RSTP, klasik STP’ye göre daha hızlı convergence (yakınsama) sağlar.
📌 Root Bridge bilgileri CIST Root satırında görülür.


🖥️ 3. Edge Port Yapılandırması

Edge port, switch’e doğrudan bağlı kullanıcı uçlarıdır. Bu portlar üzerinden loop oluşması beklenmez, bu nedenle RSTP hesaplamasına katılmaz.

[Switch1]interface GigabitEthernet 0/0/4
[Switch1-GigabitEthernet0/0/4]stp edged-port enable

[Switch2]interface GigabitEthernet 0/0/4
[Switch2-GigabitEthernet0/0/4]stp edged-port enable

🔐 4. BPDU Protection Aktif Etme

Edge portlar, BPDU mesajları alırsa loop oluşmaması için shutdown edilir. Bu korumayı etkinleştirelim:

[Switch1]stp bpdu-protection
[Switch2]stp bpdu-protection

Durum Kontrolü:

display stp brief

📌 Edge port’larda Protection: BPDU olarak görünmelidir.


🔄 5. Loop Protection Yapılandırması

Trafik yoğunluğu veya tek yönlü bağlantılarda switch, BPDU almazsa portlar yeniden yön seçer, bu durum loop’a neden olabilir. RSTP’de loop-protection, bu tür durumları engeller.

[Switch1]interface GigabitEthernet 0/0/9
[Switch1-GigabitEthernet0/0/9]stp loop-protection

[Switch1]interface GigabitEthernet 0/0/10
[Switch1-GigabitEthernet0/0/10]stp loop-protection

📌 Loop protection sadece root port ve alternate port üzerinde uygulanır.
📌 Root bridge üzerinde tüm portlar designated olduğundan uygulamaya gerek yoktur.

Kontrol:

display stp brief

✅ G0/0/9 → Role: ROOT | Protection: LOOP
✅ G0/0/10 → Role: ALTE | Protection: LOOP


📦 6. Son Konfigürasyon (Final)

✅ Switch1 Konfigürasyonu

sysname Switch1

stp mode rstp
stp bpdu-protection
stp enable

interface GigabitEthernet0/0/4
stp edged-port enable

interface GigabitEthernet0/0/9
stp loop-protection
bpdu enable

interface GigabitEthernet0/0/10
stp loop-protection
bpdu enable

✅ Switch2 Konfigürasyonu

sysname Switch2

stp mode rstp
stp bpdu-protection

interface GigabitEthernet0/0/4
stp edged-port enable

interface GigabitEthernet0/0/9
bpdu enable

interface GigabitEthernet0/0/10
bpdu enable

About Cem Kemal Erbaş

Check Also

Huawei NGFW Firewall VLAN, Zone ve NAT Konfigürasyon Rehberi

🔐 Huawei NGFW (Next Generation Firewall) – Ağ Yapılandırma ve Güvenlik Politikaları Bu senaryoda, Huawei …

Bir yanıt yazın