Cisco PortFast Configuration with BPDU Guard

Configure PortFast safely on host-facing switch ports, understand what changes, and protect the edge with BPDU Guard.

PortFastBPDU GuardSTPCisco IOS
Cisco PortFast Configuration learning map
Learning map for Cisco PortFast Configuration showing the article's core concepts, workflow, practice topics, and troubleshooting path.

What does PortFast do?

PortFast treats a verified endpoint-facing interface as an STP edge port. When the link comes up, the port can move directly to forwarding instead of waiting through the classic listening and learning delays. Edge-port link changes also avoid ordinary topology-change notification behavior.

Immediate forwarding

The endpoint gets network access without the classic two Forward Delay periods. This helps DHCP, PXE, authentication and other startup traffic.

Fewer topology changes

A normal endpoint disconnect does not need to trigger STP topology-change processing throughout the switched network.

PortFast does not disable STP. The port can still process BPDUs. PortFast changes edge-port transition and topology-change behavior; it does not make a loop safe.

Where PortFast belongs

Single endpointPC, server or printer
SW1 access portFa0/1 · access VLANPORTFAST + BPDU GUARD
Upstream networkNormal STP uplink
Original visual: PortFast is applied only to the verified host-facing access port. The switch uplink continues normal spanning-tree operation.

Typical edge endpoints

WorkstationServerPrinterIP phoneSingle access point

Confirm the endpoint cannot bridge the port into another Layer 2 path.

Do not enable casually

SwitchHubBridgeUncontrolled trunkLoop-capable device

A loop can begin forwarding immediately before STP has time to protect the topology.

PortFast disabled: normal classic STP transition

Without PortFast, a selected classic STP access port moves through listening and learning before forwarding.

Normal STP

Listening
15s
Learning
15s
Forwarding
About 30 seconds with classic default timers

PortFast edge

Forwarding immediately
No listening or learning wait at link-up
SW1# debug spanning-tree events
Spanning Tree event debugging is on

STP: VLAN0001 Fa0/1 -> listening
STP: VLAN0001 Fa0/1 -> learning
STP: VLAN0001 Fa0/1 -> forwarding

When a normal non-edge interface changes state, STP can initiate topology-change processing. Inspect the counter and source interface with:

SW1# show spanning-tree detail
  Number of topology changes 6 last change occurred 00:01:12 ago
          from FastEthernet0/1
Debug caution: use debugging only in a lab or controlled maintenance window. Disable it afterward with undebug all.

Enable PortFast on one access interface

Verify the interface is an endpoint-facing access port, assign its VLAN, then enable PortFast.

SW1(config)# interface FastEthernet0/1
SW1(config-if)# switchport mode access
SW1(config-if)# switchport access vlan 10
SW1(config-if)# spanning-tree portfast

Newer Cisco platforms may display or accept the explicit edge syntax:

SW1(config-if)# spanning-tree portfast edge

At the next link-up, event output can show the direct transition:

SW1#
STP: VLAN0010 Fa0/1 -> jump to forwarding from blocking
Read the warning: Cisco IOS warns that PortFast should connect to a single host. Do not suppress that design rule merely because the command is accepted.

Enable PortFast globally on access ports

Global default configuration is useful when the access-layer policy is consistent. It applies PortFast to nontrunking access interfaces while allowing explicit per-interface overrides.

Classic syntax

SW1(config)# spanning-tree portfast default

! Disable the global default
SW1(config)# no spanning-tree portfast default

Modern edge syntax

SW1(config)# spanning-tree portfast edge default

! Disable the edge default
SW1(config)# no spanning-tree portfast edge default

Syntax varies by platform and software. Verify the command reference for the device and inspect the operational result instead of assuming every access port is safe.

About trunks: spanning-tree portfast trunk exists for deliberate edge-trunk designs such as certain server or virtualization connections. It is not permission to use PortFast on ordinary switch-to-switch trunks.

Protect PortFast ports with BPDU Guard

A valid endpoint-facing edge port should not receive STP BPDUs. BPDU Guard enforces that assumption by placing the interface into the err-disabled state when a BPDU arrives.

PortFast edge port
+
Unexpected BPDU received
→
Port becomes ERR-DISABLED

Per-interface protection

SW1(config)# interface FastEthernet0/1
SW1(config-if)# spanning-tree portfast
SW1(config-if)# spanning-tree bpduguard enable

Global PortFast protection

SW1(config)# spanning-tree portfast bpduguard default

! Modern syntax on supported platforms
SW1(config)# spanning-tree portfast edge bpduguard default
Do not substitute BPDU Filter casually. Suppressing BPDUs can hide a loop instead of safely shutting the unexpected connection. BPDU Guard is the clearer protection for ordinary host-facing edge ports.

Verify PortFast and BPDU Guard

  1. Confirm the port is operationally an access/edge port.
  2. Verify PortFast in the interface detail output.
  3. Check the global PortFast and BPDU Guard defaults.
  4. Confirm no BPDUs are expected from the endpoint.
  5. Document the endpoint and access VLAN.
SW1# show spanning-tree interface FastEthernet0/1 detail
SW1# show spanning-tree summary totals
SW1# show running-config interface FastEthernet0/1
SW1# show interfaces status err-disabled

Recover from a BPDU Guard event

First remove or correct the device that sent the BPDU. Then recover the port under controlled conditions:

SW1(config)# interface FastEthernet0/1
SW1(config-if)# shutdown
SW1(config-if)# no shutdown

Automatic errdisable recovery is available on supported platforms, but automatic recovery should not repeatedly re-enable an unresolved loop risk.

Common PortFast mistakes

  • Enabling PortFast on a switch uplink: this can allow a loop to forward immediately.
  • Thinking PortFast disables STP: STP remains active; only edge behavior changes.
  • Skipping BPDU Guard: an unexpected downstream bridge can participate in STP or create a loop.
  • Applying the global default without auditing ports: confirm which interfaces are nontrunking and endpoint-facing.
  • Using PortFast trunk without a documented edge-trunk case: ordinary switch trunks must use normal STP behavior.
  • Recovering err-disabled ports before removing the cause: fix the unexpected BPDU source first.

Cisco PortFast Frequently Asked Questions

Does PortFast skip listening and learning?

Yes. On link-up, an operational PortFast edge port moves directly to forwarding rather than waiting through the classic listening and learning delays.

Does PortFast disable Spanning Tree?

No. The interface remains part of the STP environment and can process BPDUs. PortFast changes edge-port transition behavior.

Should PortFast be enabled on every access port?

Only after confirming the port connects to a single endpoint and cannot create a Layer 2 loop. Global defaults require an access-port audit and suitable safeguards.

Can PortFast be used on a trunk?

Some Cisco platforms support PortFast trunk for deliberate edge-trunk use cases. Do not use it on ordinary switch-to-switch trunks.

What happens when a PortFast port receives a BPDU?

With BPDU Guard enabled, the port is placed into err-disabled state. Without BPDU Guard, behavior depends on platform and STP mode, so the safer edge design is PortFast plus BPDU Guard.

Does PortFast reduce topology-change notifications?

Yes. Edge-port link changes do not cause the ordinary STP topology-change behavior associated with non-edge forwarding ports.

Authoritative references

PortFast behavior, edge-port restrictions and BPDU Guard configuration were checked against Cisco’s PortFast and BPDU Guard guidance and Catalyst optional STP features guide.

Continue the STP lesson chain

Continue learning

Use these related resources to apply or verify the concepts on this page: