Cisco PortFast Configuration with BPDU Guard
Configure PortFast safely on host-facing switch ports, understand what changes, and protect the edge with BPDU Guard.

What does PortFast do?
Immediate forwarding
The endpoint gets network access without the classic two Forward Delay periods. This helps DHCP, PXE, authentication and other startup traffic.
Fewer topology changes
A normal endpoint disconnect does not need to trigger STP topology-change processing throughout the switched network.
Where PortFast belongs
Typical edge endpoints
Confirm the endpoint cannot bridge the port into another Layer 2 path.
Do not enable casually
A loop can begin forwarding immediately before STP has time to protect the topology.
PortFast disabled: normal classic STP transition
Without PortFast, a selected classic STP access port moves through listening and learning before forwarding.
Normal STP
15sLearning
15sForwarding
PortFast edge
SW1# debug spanning-tree events Spanning Tree event debugging is on STP: VLAN0001 Fa0/1 -> listening STP: VLAN0001 Fa0/1 -> learning STP: VLAN0001 Fa0/1 -> forwarding
When a normal non-edge interface changes state, STP can initiate topology-change processing. Inspect the counter and source interface with:
SW1# show spanning-tree detail
Number of topology changes 6 last change occurred 00:01:12 ago
from FastEthernet0/1undebug all.Enable PortFast on one access interface
Verify the interface is an endpoint-facing access port, assign its VLAN, then enable PortFast.
SW1(config)# interface FastEthernet0/1 SW1(config-if)# switchport mode access SW1(config-if)# switchport access vlan 10 SW1(config-if)# spanning-tree portfast
Newer Cisco platforms may display or accept the explicit edge syntax:
SW1(config-if)# spanning-tree portfast edge
At the next link-up, event output can show the direct transition:
SW1# STP: VLAN0010 Fa0/1 -> jump to forwarding from blocking
Enable PortFast globally on access ports
Global default configuration is useful when the access-layer policy is consistent. It applies PortFast to nontrunking access interfaces while allowing explicit per-interface overrides.
Classic syntax
SW1(config)# spanning-tree portfast default ! Disable the global default SW1(config)# no spanning-tree portfast default
Modern edge syntax
SW1(config)# spanning-tree portfast edge default ! Disable the edge default SW1(config)# no spanning-tree portfast edge default
Syntax varies by platform and software. Verify the command reference for the device and inspect the operational result instead of assuming every access port is safe.
spanning-tree portfast trunk exists for deliberate edge-trunk designs such as certain server or virtualization connections. It is not permission to use PortFast on ordinary switch-to-switch trunks.Protect PortFast ports with BPDU Guard
A valid endpoint-facing edge port should not receive STP BPDUs. BPDU Guard enforces that assumption by placing the interface into the err-disabled state when a BPDU arrives.
Per-interface protection
SW1(config)# interface FastEthernet0/1 SW1(config-if)# spanning-tree portfast SW1(config-if)# spanning-tree bpduguard enable
Global PortFast protection
SW1(config)# spanning-tree portfast bpduguard default ! Modern syntax on supported platforms SW1(config)# spanning-tree portfast edge bpduguard default
Verify PortFast and BPDU Guard
- Confirm the port is operationally an access/edge port.
- Verify PortFast in the interface detail output.
- Check the global PortFast and BPDU Guard defaults.
- Confirm no BPDUs are expected from the endpoint.
- Document the endpoint and access VLAN.
SW1# show spanning-tree interface FastEthernet0/1 detail SW1# show spanning-tree summary totals SW1# show running-config interface FastEthernet0/1 SW1# show interfaces status err-disabled
Recover from a BPDU Guard event
First remove or correct the device that sent the BPDU. Then recover the port under controlled conditions:
SW1(config)# interface FastEthernet0/1 SW1(config-if)# shutdown SW1(config-if)# no shutdown
Automatic errdisable recovery is available on supported platforms, but automatic recovery should not repeatedly re-enable an unresolved loop risk.
Common PortFast mistakes
- Enabling PortFast on a switch uplink: this can allow a loop to forward immediately.
- Thinking PortFast disables STP: STP remains active; only edge behavior changes.
- Skipping BPDU Guard: an unexpected downstream bridge can participate in STP or create a loop.
- Applying the global default without auditing ports: confirm which interfaces are nontrunking and endpoint-facing.
- Using PortFast trunk without a documented edge-trunk case: ordinary switch trunks must use normal STP behavior.
- Recovering err-disabled ports before removing the cause: fix the unexpected BPDU source first.
Cisco PortFast Frequently Asked Questions
Does PortFast skip listening and learning?
Yes. On link-up, an operational PortFast edge port moves directly to forwarding rather than waiting through the classic listening and learning delays.
Does PortFast disable Spanning Tree?
No. The interface remains part of the STP environment and can process BPDUs. PortFast changes edge-port transition behavior.
Should PortFast be enabled on every access port?
Only after confirming the port connects to a single endpoint and cannot create a Layer 2 loop. Global defaults require an access-port audit and suitable safeguards.
Can PortFast be used on a trunk?
Some Cisco platforms support PortFast trunk for deliberate edge-trunk use cases. Do not use it on ordinary switch-to-switch trunks.
What happens when a PortFast port receives a BPDU?
With BPDU Guard enabled, the port is placed into err-disabled state. Without BPDU Guard, behavior depends on platform and STP mode, so the safer edge design is PortFast plus BPDU Guard.
Does PortFast reduce topology-change notifications?
Yes. Edge-port link changes do not cause the ordinary STP topology-change behavior associated with non-edge forwarding ports.
Authoritative references
PortFast behavior, edge-port restrictions and BPDU Guard configuration were checked against Cisco’s PortFast and BPDU Guard guidance and Catalyst optional STP features guide.