14.9.10 Packet Tracer - Implement STP Security Answers Version
Topology

Objectives
- Assign the Central switch as the root bridge.
- Secure spanning-tree parameters to prevent STP manipulation attacks.
Background / Scenario
There have been a number of attacks on the network recently. For this reason, the network administrator has assigned you the task of configuring Layer 2 security.
For optimum performance and security, the administrator would like to ensure that the root bridge is the 3560 Central switch. To prevent spanning-tree manipulation attacks, the administrator wants to ensure that the STP parameters are secure.
All switch devices have been preconfigured with the following:
- Enable password: ciscoenpa55
- Console password: ciscoconpa55
- SSH username and password: SSHadmin / ciscosshpa55
Instructions
Part 1: Configure Root Bridge
Step 1: Determine the current root bridge.
From Central, issue the show spanning-tree command to determine the current root bridge, to see the ports in use, and to see their status.
Question:
Which switch is the current root bridge?
Current root is SW-1.
Based on the current root bridge, what is the resulting spanning tree? (Draw the spanning-tree topology.)

Step 2: Assign Central as the primary root bridge.
Using the spanning-tree vlan 1 root primary command and assign Central as the root bridge.
Central(config)# spanning-tree vlan 1 root primary
Step 3: Assign SW-1 as a secondary root bridge.
Assign SW-1 as the secondary root bridge using the spanning-tree vlan 1 root secondary command.
SW-1(config)# spanning-tree vlan 1 root secondary
Step 4: Verify the spanning-tree configuration.
Issue the show spanning-tree command to verify that Central is the root bridge.
Central# show spanning-tree
VLAN0001
Spanning tree enabled protocol ieee
Root ID Priority 24577
Address 00D0.D31C.634C
This bridge is the root
Hello Time 2 sec Max Age 20 sec Forward Delay 15 secQuestions:
Which switch is the current root bridge?
Current root is Central.
Based on the new root-bridge, what is the resulting spanning tree? (Draw the spanning-tree topology.)

Part 2: Protect Against STP Attacks
Secure the STP parameters to prevent STP manipulation attacks.
Step 1: Enable PortFast on all access ports.
PortFast is configured on access ports that connect to a single workstation or server to enable them to become active more quickly. On the connected access ports of the SW-A and SW-B, use the spanning-tree portfast command.
SW-A(config)# interface range f0/1 - 4 SW-A(config-if-range)# spanning-tree portfast SW-B(config)# interface range f0/1 - 4 SW-B(config-if-range)# spanning-tree portfast
Step 2: Enable BPDU guard on all access ports.
BPDU guard is a feature that can help prevent rogue switches and spoofing on access ports. Enable BPDU guard on SW-A and SW-B access ports.
SW-A(config)# interface range f0/1 - 4 SW-A(config-if-range)# spanning-tree bpduguard enable SW-B(config)# interface range f0/1 - 4 SW-B(config-if-range)# spanning-tree bpduguard enable
Note: Spanning-tree BPDU guard can be enabled on each individual port using the spanning-tree bpduguard enable command in interface configuration mode or the spanning-tree portfast bpduguard default command in global configuration mode. For grading purposes in this activity, please use the spanning-tree bpduguard enable command.
Step 3: Enable root guard.
Root guard can be enabled on all ports on a switch that are not root ports. It is best deployed on ports that connect to other non-root switches. Use the show spanning-tree command to determine the location of the root port on each switch.
On SW-1, enable root guard on ports F0/23 and F0/24. On SW-2, enable root guard on ports F0/23 and F0/24.
SW-1(config)# interface range f0/23 - 24 SW-1(config-if-range)# spanning-tree guard root SW-2(config)# interface range f0/23 - 24 SW-2(config-if-range)# spanning-tree guard root
Device Configs - Final
SWITCH Central
! ============================================================== !--- 14.9.10 Packet Tracer - Implement STP Security !--- ANSWER SCRIPT FOR SWITCH Central !--- Usage: copy this whole file and paste it into the Central terminal (start at the Central> prompt). Every line beginning with "!" is a comment; IOS ignores it, so pasting a comment by accident is harmless. ! ============================================================== enable configure terminal ! -------------------------------------------------------------- !--- Part 1: Configure Central as the Primary Root Bridge. ! -------------------------------------------------------------- !--- Lower Central's bridge priority for VLAN 1 below every other switch's, making it the root bridge. spanning-tree vlan 1 root primary end ! -------------------------------------------------------------- !--- Save the configuration to NVRAM. (Press Enter when prompted for the destination filename.) ! -------------------------------------------------------------- copy running-config startup-config ! ============================================================== !--- Verification: !--- show spanning-tree vlan 1 -> confirms "This bridge is the root" and Priority 24577 (or lower) !--- Note: "root primary" is a macro — it reads the current lowest bridge priority in the VLAN and sets !--- Central's priority below it (24576 if none is below that already), rather than a fixed value; this is !--- why the verification output in the lab shows exactly Priority 24577 (24576 + VLAN 1 system ID extension). ! ==============================================================
SWITCH SW-1
! ============================================================== !--- 14.9.10 Packet Tracer - Implement STP Security !--- ANSWER SCRIPT FOR SWITCH SW-1 !--- Usage: copy this whole file and paste it into the SW-1 terminal (start at the SW-1> prompt). Every line beginning with "!" is a comment; IOS ignores it, so pasting a comment by accident is harmless. ! ============================================================== enable configure terminal ! -------------------------------------------------------------- !--- Part 1: Configure SW-1 as the Secondary Root Bridge. ! -------------------------------------------------------------- !--- Set a bridge priority that takes over as root for VLAN 1 only if Central goes down. spanning-tree vlan 1 root secondary ! -------------------------------------------------------------- !--- Part 2: Enable Root Guard on the Non-Root-Facing Trunk Ports. ! -------------------------------------------------------------- !--- Enable root guard on F0/23-24 — the ports connecting to other non-root switches (SW-A/SW-B side), !--- so no rogue or misconfigured switch attached there can be elected root. interface range fastethernet 0/23 - 24 spanning-tree guard root exit end ! -------------------------------------------------------------- !--- Save the configuration to NVRAM. (Press Enter when prompted for the destination filename.) ! -------------------------------------------------------------- copy running-config startup-config ! ============================================================== !--- Verification: !--- show spanning-tree vlan 1 -> confirms SW-1 is no longer "the root" but shows a priority just above !--- Central's (secondary root) !--- show spanning-tree summary | include Root guard -> confirms root guard is active on F0/23-24 !--- Note: if a port with root guard enabled receives a superior BPDU (one claiming to be a better root), !--- it goes into "root-inconsistent" state (traffic blocked) instead of allowing a re-election — this !--- protects Central's root-bridge role from STP manipulation attacks entering through SW-1. ! ==============================================================
SWITCH SW-2
! ============================================================== !--- 14.9.10 Packet Tracer - Implement STP Security !--- ANSWER SCRIPT FOR SWITCH SW-2 !--- Usage: copy this whole file and paste it into the SW-2 terminal (start at the SW-2> prompt). Every line beginning with "!" is a comment; IOS ignores it, so pasting a comment by accident is harmless. ! ============================================================== enable configure terminal ! -------------------------------------------------------------- !--- Part 1: Enable Root Guard on the Non-Root-Facing Trunk Ports. ! -------------------------------------------------------------- !--- Enable root guard on F0/23-24 — the ports connecting to other non-root switches (SW-A/SW-B side), !--- so no rogue or misconfigured switch attached there can be elected root. interface range fastethernet 0/23 - 24 spanning-tree guard root exit end ! -------------------------------------------------------------- !--- Save the configuration to NVRAM. (Press Enter when prompted for the destination filename.) ! -------------------------------------------------------------- copy running-config startup-config ! ============================================================== !--- Verification: !--- show spanning-tree summary | include Root guard -> confirms root guard is active on F0/23-24 !--- Note: unlike SW-1, SW-2 is not assigned as secondary root in this lab — only Central (primary) and !--- SW-1 (secondary) get explicit root-bridge priorities; SW-2 only gets the root-guard hardening. ! ==============================================================
SWITCH SW-A
! ============================================================== !--- 14.9.10 Packet Tracer - Implement STP Security !--- ANSWER SCRIPT FOR SWITCH SW-A !--- Usage: copy this whole file and paste it into the SW-A terminal (start at the SW-A> prompt). Every line beginning with "!" is a comment; IOS ignores it, so pasting a comment by accident is harmless. ! ============================================================== enable configure terminal ! -------------------------------------------------------------- !--- Part 1: Harden the Access Ports Connecting to PCs (F0/1-4). ! -------------------------------------------------------------- !--- Enable PortFast so these access ports skip listening/learning and go straight to forwarding when a PC connects. interface range fastethernet 0/1 - 4 spanning-tree portfast !--- Enable BPDU guard — if this access port ever receives a BPDU (e.g. a rogue switch plugged in), it is !--- immediately error-disabled instead of being allowed to participate in the spanning tree. spanning-tree bpduguard enable exit end ! -------------------------------------------------------------- !--- Save the configuration to NVRAM. (Press Enter when prompted for the destination filename.) ! -------------------------------------------------------------- copy running-config startup-config ! ============================================================== !--- Verification: !--- show running-config interface fastethernet 0/1 -> confirms "spanning-tree portfast" and !--- "spanning-tree bpduguard enable" on each of F0/1-4 !--- show spanning-tree summary | include BPDU -> confirms BPDU guard is active on these ports !--- Note: per the lab's own instructions, use "spanning-tree bpduguard enable" per interface (not the !--- global "spanning-tree portfast bpduguard default" command) — the activity is graded on this exact !--- per-interface command. ! ==============================================================
SWITCH SW-B
! ============================================================== !--- 14.9.10 Packet Tracer - Implement STP Security !--- ANSWER SCRIPT FOR SWITCH SW-B !--- Usage: copy this whole file and paste it into the SW-B terminal (start at the SW-B> prompt). Every line beginning with "!" is a comment; IOS ignores it, so pasting a comment by accident is harmless. ! ============================================================== enable configure terminal ! -------------------------------------------------------------- !--- Part 1: Harden the Access Ports Connecting to PCs (F0/1-4). ! -------------------------------------------------------------- !--- Enable PortFast so these access ports skip listening/learning and go straight to forwarding when a PC connects. interface range fastethernet 0/1 - 4 spanning-tree portfast !--- Enable BPDU guard — if this access port ever receives a BPDU (e.g. a rogue switch plugged in), it is !--- immediately error-disabled instead of being allowed to participate in the spanning tree. spanning-tree bpduguard enable exit end ! -------------------------------------------------------------- !--- Save the configuration to NVRAM. (Press Enter when prompted for the destination filename.) ! -------------------------------------------------------------- copy running-config startup-config ! ============================================================== !--- Verification: !--- show running-config interface fastethernet 0/1 -> confirms "spanning-tree portfast" and !--- "spanning-tree bpduguard enable" on each of F0/1-4 !--- show spanning-tree summary | include BPDU -> confirms BPDU guard is active on these ports !--- Note: per the lab's own instructions, use "spanning-tree bpduguard enable" per interface (not the !--- global "spanning-tree portfast bpduguard default" command) — the activity is graded on this exact !--- per-interface command. ! ==============================================================




