Information
A feature that can be deployed to prevent an attacker from spoofing his or her system as the root bridge by sending announcements with a lower bridge priority and so becoming the root. The 'root-guard' feature allows an operator to block certain interfaces from becoming the root. This could be enabled, for example, on customer facing (untrusted) SAPs.
Solution
Run the following command on the device to configure root-guard: configure service vpls sap stp root-guard