Spanning tree
How to check whether BPDU Guard is enabled on edge ports
BPDU Guard shuts a port down the moment a switch appears where only endpoints should be, which is what stops someone plugging a desk switch into a wall socket and rearranging your spanning tree. NacTrack does not read it from live state; it checks the running configuration against a benchmark rule, so the question is answered on the Compliance page rather than the STP one.
Before you start
What you need
- Module required: compliance.
- Permission required: view_audit.
- Aruba AOS-CX, Cisco NX-OS and Dell OS10 only
1. Open Security then Compliance

2. Switch to the Devices tab

3. Open a device result

The limits
What this view does not tell you
- Only three rules cover BPDU Guard, one each for Aruba AOS-CX, Cisco NX-OS and Dell OS10. A Cisco IOS or IOS-XE access switch is not checked for it at all, so a passing score does not mean the whole edge is protected.
- Compliance reads configuration text. It can tell you the command is present; it cannot tell you the port ever actually blocked anything.
- Root Guard is a different feature and NacTrack does not check it anywhere. Do not read a BPDU Guard pass as covering it.
