1-37[Sysname] stp interface GigabitEthernet 1/0/1 root-protection2) Perform this configuration in Ethernet port view system-view[Sysname] interface GigabitEthernet 1/0/1[Sysname-GigabitEthernet1/0/1] stp root-protectionConfiguring Loop GuardConfiguration procedureFollow these steps to configure loop guard:To do... Use the command... RemarksEnter system view system-view —Enter Ethernet port view interface interface-typeinterface-number —Enable the loop guard function onthe current port stp loop-protectionRequiredThe loop guard function isdisabled by default.Configuration example# Enable the loop guard function on GigabitEthernet 1/0/1. system-view[Sysname] interface GigabitEthernet 1/0/1[Sysname-GigabitEthernet1/0/1] stp loop-protectionConfiguring TC-BPDU Attack GuardConfiguration prerequisitesMSTP runs normally on the switch.Configuration procedureFollow these steps to configure the TC-BPDU attack guard function:To do... Use the command... RemarksEnter system view system-view —Enable the TC-BPDU attackguard function stp tc-protection enableRequiredThe TC-BPDU attack guardfunction is disabled by default.Set the maximum times that aswitch can remove the MACaddress table and ARP entrieswithin each 10 secondsstp tc-protection thresholdnumber OptionalConfiguration example# Enable the TC-BPDU attack guard function