4.3 Spanning Tree Architecture: RSTP, MST, and STP Protection Mechanisms
Key Takeaways
Rapid Spanning Tree Protocol (RSTP / IEEE 802.1w) replaces legacy 802.1D 30–50 second timer-based convergence with an explicit Proposal/Agreement synchronization handshake on point-to-point links.
RSTP condenses Spanning Tree states into Discarding, Learning, and Forwarding, while establishing Alternate (backup path to Root Bridge) and Backup (redundant path to shared segment) port roles.
Multiple Spanning Tree (MST / IEEE 802.1s) maps multiple VLANs into discrete Spanning Tree Instances (MSTIs) within an MST Region, defined by matching Region Name, Revision Number, and VLAN-to-Instance mapping digest.
Root Guard enforces deterministic root bridge placement by placing designated ports into root-inconsistent state upon receiving superior BPDUs, while BPDU Guard err-disables PortFast edge ports upon receiving any BPDU.
Loop Guard prevents alternate and root ports from transitioning to forwarding during BPDU loss, while Unidirectional Link Detection (UDLD) aggressively identifies physical bidirectional fiber/copper continuity failures.
Spanning Tree Architecture: RSTP, MST, and STP Protection Mechanisms
In redundant Layer 2 switched networks, physical loops cause broadcast storms, frame duplication, and MAC address table instability. The original IEEE 802.1D Spanning Tree Protocol (STP) eliminated loops by blocking redundant links. However, legacy 802.1D was designed when bridge convergence measured in tens of seconds was acceptable. Modern enterprise infrastructures demand sub-second convergence and scalable VLAN handling, provided by Rapid Spanning Tree Protocol (RSTP) and Multiple Spanning Tree (MST), reinforced by specialized STP protection mechanisms.
Limitations of Legacy IEEE 802.1D STP
Legacy 802.1D relies on passive, timer-driven state transitions:
- Listening State (15s Forward Delay): Discards user data, transmits/receives Bridge Protocol Data Units (BPDUs), does not populate MAC address tables.
- Learning State (15s Forward Delay): Discards user data, populates MAC address tables from received frames.
- Max Age Timer (20s): The duration a switch stores BPDU information before declaring an indirect link failure.
When an indirect link failure occurs, an 802.1D switch waits for the Max Age timer to expire (20 seconds), then transitions an alternate port through Listening (15 seconds) and Learning (15 seconds) before reaching Forwarding—requiring 30 to 50 seconds of complete convergence outage. Furthermore, Common Spanning Tree (CST) maintains only a single STP instance across the entire network, preventing per-VLAN load balancing. Conversely, Cisco Per-VLAN Spanning Tree Plus (PVST+) instantiates an independent STP process for every configured VLAN, placing severe CPU and memory burdens on switches handling hundreds of VLANs.
Rapid Spanning Tree Protocol (RSTP / IEEE 802.1w)
IEEE 802.1w (implemented in Cisco networks as Rapid-PVST+) overcomes 802.1D limitations by replacing passive timer delays with active negotiation mechanisms, achieving convergence times under a few hundred milliseconds.
RSTP Port States and Roles
RSTP consolidates the five 802.1D port states into three operational states:
| 802.1D Port State | 802.1w (RSTP) State | Active in Topology? | Learns MACs? | Forwards Data? |
|---|---|---|---|---|
| Disabled | Discarding | No | No | No |
| Blocking | Discarding | No | No | No |
| Listening | Discarding | Yes | No | No |
| Learning | Learning | Yes | Yes | No |
| Forwarding | Forwarding | Yes | Yes | Yes |
RSTP redefines port roles to decouple forwarding responsibility from backup topologies:
- Root Port: Best path to the Root Bridge. Only one root port exists per non-root switch (Forwarding).
- Designated Port: Port on a given LAN segment that offers the lowest path cost back to the Root Bridge (Forwarding).
- Alternate Port: An alternate path to the Root Bridge receiving BPDUs from another switch. Acts as an immediate hot-standby for the Root Port (Discarding).
- Backup Port: A redundant link to the same shared collision domain (e.g., connected through an unmanaged hub) receiving BPDUs from the same local switch. Redundant to a designated port (Discarding).
Proposal/Agreement Handshake Mechanism
On point-to-point links (full-duplex connections), RSTP does not wait for Forward Delay timers. It executes an explicit two-way Proposal/Agreement handshake:
Switch A (Root) Switch B
| |
| -------- 1. Proposal BPDU (Desig) -------> |
| |
| [Sync Process: Sets non-edge
| ports to Discarding]
| |
| <------- 2. Agreement BPDU (Root) -------- |
| |
[Transitions Desig to [Transitions Root to
Forwarding immediately] Forwarding immediately]
- Proposal: Switch A (upstream designated switch) sends a configuration BPDU with the Proposal bit asserted out its point-to-point link.
- Synchronization (Sync): Switch B receives the proposal on its prospective Root Port. Switch B initiates a local Sync operation: it immediately places all its non-edge Designated ports into the Discarding state to prevent temporary loops.
- Agreement: Once its downstream ports are isolated, Switch B transmits an Agreement BPDU back to Switch A.
- Instant Forwarding: Switch A receives the Agreement and immediately transitions its designated port to Forwarding. Switch B transitions its root port to Forwarding. The entire process finishes in milliseconds.
- Propagation: Switch B then sends Proposal BPDUs out its own downstream designated links, cascading the synchronization process down the tree.
Edge Ports (PortFast)
Ports configured with PortFast are designated as edge ports (spanning-tree portfast). Edge ports connect directly to host devices (workstations, servers, routers) and immediately transition to Forwarding, bypassing listening and learning. Furthermore, when an edge port links up or down, it generates no Topology Change Notifications (TCNs). If an edge port receives a BPDU, it immediately strips its edge status and reverts to a standard non-edge RSTP port.
Multiple Spanning Tree Protocol (MST / IEEE 802.1s)
While Rapid-PVST+ provides fast convergence, running hundreds of spanning tree instances consumes massive CPU and control-plane bandwidth. Multiple Spanning Tree Protocol (MST) solves this scaling bottleneck by grouping multiple VLANs into a manageable number of Multiple Spanning Tree Instances (MSTIs).
MST Regions
Switches operating MST group themselves into MST Regions. Switches participate in the same MST Region only if their configuration parameters match identically:
- Configuration Name: Alphanumeric string up to 32 characters (case-sensitive).
- Revision Number: 16-bit integer (0 to 65535) administratively set to track configuration revisions.
- VLAN-to-Instance Mapping Table: A 4096-entry table mapping each VLAN ID to an MSTI. The switch computes a 16-byte MD5 signature digest of this table and advertises it in MST BPDUs.
If two adjacent switches have even a single VLAN mapped to a different instance, their MD5 digests will not match, causing them to treat each other as separate MST regions.
Internal and Common Spanning Tree Entities
- IST (Internal Spanning Tree / Instance 0): The default spanning tree instance running inside every MST region. It collects all regional topology information and interacts with external CST domains.
- CIST (Common and Internal Spanning Tree): Connects all separate MST regions, 802.1D CST bridges, and Rapid-PVST+ domains into a single unified global topology. Outside switches view an entire MST region as a single virtual bridge.
- MSTI (Multiple Spanning Tree Instances): Independent regional instances (IDs 1 through 4094) that run exclusively within the local MST region to optimize inter-VLAN traffic paths.
Spanning Tree Protection and Stability Mechanisms
To safeguard Layer 2 topologies against rogue switches, cabling errors, and hardware failures, network administrators deploy targeted STP stability features.
1. Root Guard (spanning-tree guard root)
- Purpose: Enforces root bridge placement. Prevents unauthorized or misconfigured switches from hijacking the Root Bridge role.
- Placement: Configured on designated ports pointing toward access switches, downstream distribution switches, or untrusted boundaries.
- Action: If a port receives a superior BPDU (advertising a lower bridge priority or superior path cost), Root Guard intercepts the packet and places the interface into a
root-inconsistentstate. The port stops forwarding traffic. - Recovery: Fully automatic. Once the rogue switch stops transmitting superior BPDUs, the interface transitions back through normal STP states to Forwarding.
2. BPDU Guard (spanning-tree bpduguard enable / spanning-tree portfast bpduguard default)
- Purpose: Protects edge ports where host devices connect. Endpoints should never transmit BPDUs.
- Placement: Applied to PortFast-enabled access ports.
- Action: If any BPDU (superior or inferior) is received on a BPDU Guard-enabled port, the switch immediately shuts the port down into the
err-disabledstate. - Recovery: Manual administrative recovery (
shutdownfollowed byno shutdown), or automated recovery via global timer:errdisable recovery cause bpduguard errdisable recovery interval 300
3. BPDU Filter (spanning-tree bpdufilter enable / spanning-tree portfast bpdufilter default)
- Purpose: Controls the transmission and reception of BPDUs on edge ports.
- Global Configuration: Configured via
spanning-tree portfast bpdufilter default. On link up, the port transmits 10–12 BPDUs, then stops transmitting. If the port receives any BPDU, it immediately disables BPDU Filter, strips its PortFast status, and behaves as a standard STP port. This is safe for enterprise deployment. - Interface Configuration: Configured via
spanning-tree bpdufilter enable. The port unconditionally stops sending BPDUs and drops all incoming BPDUs. Extreme Hazard: Disables loop detection entirely; creating a physical loop on this port causes immediate catastrophic network broadcast storms.
4. Loop Guard (spanning-tree guard loop / spanning-tree loopguard default)
- Purpose: Prevents Alternate and Root ports from erroneously transitioning to Designated Forwarding ports when BPDUs stop arriving due to unidirectional link failures or switch CPU software hangs.
- Action: If BPDUs cease on a non-designated port, Loop Guard places the interface into a
loop-inconsistentstate (blocking) rather than allowing it to transition to Forwarding. - Recovery: Automatic. The port restores to normal forwarding as soon as BPDUs resume.
5. Unidirectional Link Detection (UDLD - RFC 5171)
- Purpose: A Layer 2 protocol monitoring the physical continuity of fiber-optic (e.g., single-strand transmit fiber breaks) and twisted-pair cabling.
- Modes:
- Normal Mode: Flags the port as undetermined and generates syslog alerts if echo packets cease, but does not disable the interface.
- Aggressive Mode: Transmits 8 fast probe packets (1 per second) if echo packets stop. If no response arrives, UDLD immediately places the interface into the
err-disabledstate.
Loop Guard vs. UDLD Comparison
| Dimension | Loop Guard | UDLD |
|---|---|---|
| Operational Layer | Spanning Tree Protocol layer | Physical / Data Link layer (RFC 5171) |
| Failure Cause | Software hangs, BPDU generation failure | Physical wiring breaks, faulty optical transceivers |
| Port Applicability | Root and Alternate ports | All point-to-point links (Designated, Root, Alternate) |
| Neighbor Protocol | Requires no neighbor protocol support | Both link partners must run UDLD |
| Failure Reaction | Transitions to loop-inconsistent (blocking) | Aggressive mode err-disables port |
STP Protection Features Matrix
| Feature | CLI Configuration | Target Interfaces | Trigger Condition | Reaction | Recovery Method |
|---|---|---|---|---|---|
| Root Guard | Interface: spanning-tree guard root | Designated ports | Superior BPDU received | root-inconsistent state | Automatic when BPDUs cease |
| BPDU Guard | Global / Interface: spanning-tree bpduguard enable | PortFast edge ports | Any BPDU received | err-disabled state | Manual bounce or errdisable recovery |
| BPDU Filter | Global / Interface: spanning-tree bpdufilter enable | PortFast edge ports | Global: BPDU received; Interface: Unconditional | Global: drops filter; Interface: ignores BPDUs | Global: automatic; Interface: N/A |
| Loop Guard | Global / Interface: spanning-tree guard loop | Root & Alternate ports | BPDUs cease arriving | loop-inconsistent state | Automatic when BPDUs resume |
| UDLD Aggressive | Global / Interface: udld port aggressive | Fiber / Point-to-point | Loss of bidirectional echo | err-disabled state | Manual bounce or errdisable recovery |
Configuring Rapid-PVST+ and MST
Topic 3.1.c says configure and verify, so practise the configuration, not just the theory.
Rapid-PVST+ and root bridge placement
spanning-tree mode rapid-pvst
spanning-tree vlan 10,20 root primary
spanning-tree vlan 30,40 priority 24576
!
interface GigabitEthernet1/0/10
spanning-tree portfast
spanning-tree bpduguard enable
root primary is a macro: it sets the bridge priority to 24576, or lower if needed to beat the current root. Manually configured priorities must be multiples of 4096, because the extended system ID (the VLAN number) occupies the low 12 bits of the 16-bit bridge priority field.
MST region configuration
spanning-tree mode mst
spanning-tree mst configuration
name CAMPUS
revision 1
instance 1 vlan 10-19
instance 2 vlan 20-29
!
spanning-tree mst 1 priority 24576
spanning-tree mst 2 priority 28672
VLANs that are not mapped to an instance stay in instance 0 (the IST). Every switch in the region must use the same name, revision number, and VLAN-to-instance mapping. Using different root priorities per instance, as above, lets two distribution switches share the load.
| Verification command | What it shows |
|---|---|
show spanning-tree vlan 10 | Root bridge ID, local bridge ID, and each port's role, state, and cost for VLAN 10 |
show spanning-tree mst configuration | Region name, revision, and VLAN-to-instance mapping (compare across switches) |
show spanning-tree mst 1 | Root, priority, and port roles for MST instance 1 |
show spanning-tree interface GigabitEthernet1/0/10 detail | PortFast, BPDU Guard, and BPDU counters for one port |
CLI Verification and Troubleshooting Inconsistent States
Switch# show spanning-tree summary
Switch is in rapid-pvst mode
Root bridge for: VLAN0001, VLAN0010, VLAN0020
PortFast Default is disabled
PortFast BPDU Guard Default is enabled
PortFast BPDU Filter Default is disabled
Loopguard Default is enabled
EtherChannel misconfig guard is enabled
UplinkFast is disabled
BackboneFast is disabled
Switch# show spanning-tree inconsistentports
Name Interface Inconsistency
-------------------- ---------------------- ------------------
VLAN0010 GigabitEthernet0/1 Root Inconsistent
VLAN0020 GigabitEthernet0/2 Loop Inconsistent
Number of inconsistent ports (segments) in the system : 2
show spanning-tree summary: Reports the active STP operating mode (PVST+, Rapid-PVST+, or MST) and global protection defaults.show spanning-tree inconsistentports: Identifies interfaces blocked by Root Guard (Root Inconsistent) or Loop Guard (Loop Inconsistent).show udld <interface>: Validates bidirectional link status, neighbor echo exchange, and operational mode.
During a Rapid Spanning Tree Protocol (RSTP / 802.1w) convergence event on a point-to-point full-duplex link, what critical action does a downstream switch perform immediately upon receiving a Proposal BPDU on its prospective Root Port?
It starts its Max Age timer and pauses all MAC address learning for 20 seconds
It forwards the Proposal BPDU out all of its access ports that connect to host workstations and IP phones
It places the port into an err-disabled state until an administrator manually approves the new spanning-tree topology
It runs a sync, moving its non-edge designated ports to Discarding, and then returns an Agreement BPDU
Which three configuration parameters must match identically across switches for them to participate within the same Multiple Spanning Tree (MST) region?
Configuration Name, Revision Number, and the VLAN-to-Instance mapping MD5 digest signature
Root Bridge Priority, Hello Timer interval, and VTP Domain Name
System ID, Port Priority list, and BFD multiplier interval
Autonomous System Number, CIST root MAC address, and IST instance number configured on each switch
An administrator connects an unmanaged switch to an access port configured with PortFast and Root Guard. What will occur if a rogue device connected to the unmanaged switch transmits a BPDU with a priority of 4096 (which is superior to the current root bridge)?
The port will immediately transition to err-disabled and require manual administrative intervention
The port will ignore the BPDU and continue forwarding traffic normally without generating syslog alerts
Root Guard will place the interface into a root-inconsistent state, blocking all traffic until superior BPDUs cease
The switch will accept the new root bridge and propagate topology change notifications across the campus core
Sections you finish are checked off in the contents.