Errdisable is a protective mechanism that automatically disables switch ports when specific error conditions or security violations are detected, preventing potential network disruptions and security breaches. It monitors various fault conditions including BPDU guard violations, port security breaches, link flapping, ARP inspection failures, and other Layer 2 protocol anomalies. The feature provides configurable detection thresholds, automatic recovery timers, and granular control over which error conditions trigger port shutdown, enabling administrators to balance network protection with operational continuity.
Name Type Constraint Mandatory Default Value errdisable Class [errdisable]No
Name Type Constraint Mandatory Default Value detect_cause Class [detect_cause]No flap_setting_cause Class [flap_setting_cause]No recovery_interval Integer min: 30, max: 86400 No recovery_cause Class [recovery_cause]No
Name Type Constraint Mandatory Default Value all Boolean true, falseNo arp_inspection Boolean true, falseNo bpduguard Boolean true, falseNo dhcp_rate_limit Boolean true, falseNo dtp_flap Boolean true, falseNo gbic_invalid Boolean true, falseNo inline_power Boolean true, falseNo l2ptguard Boolean true, falseNo link_flap Boolean true, falseNo loopback Boolean true, falseNo mlacp_minlink Boolean true, falseNo pagp_flap Boolean true, falseNo pppoe_ia_rate_limit Boolean true, falseNo security_violation_shutdown_vlan Boolean true, falseNo sfp_config_mismatch Boolean true, falseNo small_frame Boolean true, falseNo loopdetect Boolean true, falseNo
Name Type Constraint Mandatory Default Value dtp_flap_max_flaps Integer min: 1, max: 100 No dtp_flap_time Integer min: 1, max: 120 No link_flap_max_flaps Integer min: 1, max: 100 No link_flap_time Integer min: 1, max: 120 No pagp_flap_max_flaps Integer min: 1, max: 100 No pagp_flap_time Integer min: 1, max: 120 No
Name Type Constraint Mandatory Default Value all Boolean true, falseNo arp_inspection Boolean true, falseNo bpduguard Boolean true, falseNo channel_misconfig Boolean true, falseNo dhcp_rate_limit Boolean true, falseNo dtp_flap Boolean true, falseNo gbic_invalid Boolean true, falseNo inline_power Boolean true, falseNo l2ptguard Boolean true, falseNo link_flap Boolean true, falseNo link_monitor_failure Boolean true, falseNo loopback Boolean true, falseNo mac_limit Boolean true, falseNo mlacp_minlink Boolean true, falseNo mrp_miscabling Boolean true, falseNo oam_remote_failure Boolean true, falseNo pagp_flap Boolean true, falseNo port_mode_failure Boolean true, falseNo pppoe_ia_rate_limit Boolean true, falseNo psp Boolean true, falseNo psecure_violation Boolean true, falseNo security_violation Boolean true, falseNo sfp_config_mismatch Boolean true, falseNo small_frame Boolean true, falseNo storm_control Boolean true, falseNo udld Boolean true, falseNo unicast_flood Boolean true, falseNo vmps Boolean true, falseNo loopdetect Boolean true, falseNo
errdisable detect cause dhcp-rate-limit
errdisable detect cause loopdetect
errdisable detect cause security-violation shutdown vlan
errdisable recovery cause link-monitor-failure
errdisable recovery cause loopdetect
errdisable recovery cause psecure-violation
errdisable recovery interval 300
security_violation_shutdown_vlan : true
link_monitor_failure : true
Errdisable is a protective mechanism that automatically disables switch ports when specific error conditions or security violations are detected, preventing potential network disruptions and security breaches. It monitors various fault conditions including BPDU guard violations, port security breaches, link flapping, ARP inspection failures, and other Layer 2 protocol anomalies. The feature provides configurable detection thresholds, automatic recovery timers, and granular control over which error conditions trigger port shutdown, enabling administrators to balance network protection with operational continuity.
Name Type Constraint Mandatory Default Value errdisable Class [errdisable]No
Name Type Constraint Mandatory Default Value detect_cause Class [detect_cause]No flap_setting_cause Class [flap_setting_cause]No recovery_interval Integer min: 30, max: 86400 No recovery_cause Class [recovery_cause]No
Name Type Constraint Mandatory Default Value all Boolean true, falseNo arp_inspection Boolean true, falseNo bpduguard Boolean true, falseNo dhcp_rate_limit Boolean true, falseNo dtp_flap Boolean true, falseNo gbic_invalid Boolean true, falseNo inline_power Boolean true, falseNo l2ptguard Boolean true, falseNo link_flap Boolean true, falseNo loopback Boolean true, falseNo mlacp_minlink Boolean true, falseNo pagp_flap Boolean true, falseNo pppoe_ia_rate_limit Boolean true, falseNo security_violation_shutdown_vlan Boolean true, falseNo sfp_config_mismatch Boolean true, falseNo small_frame Boolean true, falseNo loopdetect Boolean true, falseNo
Name Type Constraint Mandatory Default Value dtp_flap_max_flaps Integer min: 1, max: 100 No dtp_flap_time Integer min: 1, max: 120 No link_flap_max_flaps Integer min: 1, max: 100 No link_flap_time Integer min: 1, max: 120 No pagp_flap_max_flaps Integer min: 1, max: 100 No pagp_flap_time Integer min: 1, max: 120 No
Name Type Constraint Mandatory Default Value all Boolean true, falseNo arp_inspection Boolean true, falseNo bpduguard Boolean true, falseNo channel_misconfig Boolean true, falseNo dhcp_rate_limit Boolean true, falseNo dtp_flap Boolean true, falseNo gbic_invalid Boolean true, falseNo inline_power Boolean true, falseNo l2ptguard Boolean true, falseNo link_flap Boolean true, falseNo link_monitor_failure Boolean true, falseNo loopback Boolean true, falseNo mac_limit Boolean true, falseNo mlacp_minlink Boolean true, falseNo mrp_miscabling Boolean true, falseNo oam_remote_failure Boolean true, falseNo pagp_flap Boolean true, falseNo port_mode_failure Boolean true, falseNo pppoe_ia_rate_limit Boolean true, falseNo psp Boolean true, falseNo psecure_violation Boolean true, falseNo security_violation Boolean true, falseNo sfp_config_mismatch Boolean true, falseNo small_frame Boolean true, falseNo storm_control Boolean true, falseNo udld Boolean true, falseNo unicast_flood Boolean true, falseNo vmps Boolean true, falseNo loopdetect Boolean true, falseNo