Two facts about Ethernet that make loops deadly
- Switches copy broadcasts everywhere. A broadcast is for every device in the VLAN. So a switch sends a copy out of every port, except the port it came in on.
- Ethernet frames never expire. They have no TTL (time to live) like IP packets do. So nothing stops a frame that keeps travelling.
Put these two facts together in a network with a loop. One broadcast is copied again and again, forever. This is a broadcast storm. It only ends when a device crashes or someone pulls a cable. So a switched network must never have a loop.
From no redundancy to too much
Early Ethernet networks were simple chains of switches with no backup links, so they had no loops. But as companies came to depend on the network, having no backup became a problem.
- 1. One link between buildings: it works. But if that cable is cut, users can't reach any server.
- 2. So a second link is added… …and now the two switches form a loop. A broadcast from SW1 goes over both cables, comes back over the other one, and goes round forever.
Engineers needed a way to keep the backup cable connected without creating a loop. The answer was the Spanning Tree Protocol. It became the standard IEEE 802.1D in 1990. It made large switched networks with backup links possible.
Common looped shapes
Many people think a loop needs three or more switches. But two cables between the same two switches already make a loop. Bigger networks are made of these shapes:
| Shape | Loop formed by | Ports STP blocks |
|---|---|---|
| Pair with two links | Two parallel cables | 1 |
| Triangle | Three switches, three links | 1 |
| Square | Four switches, four links | 1 |
| Square with a diagonal | Two overlapping loops | 2 |
The rule: STP blocks one port for every extra path. This leaves exactly one working path between any two switches.
How STP fixes it, in one picture
- 1. One active path. STP blocks one end of the second cable, so there is no loop.
- 2. The backup waits. If the active cable fails, STP unblocks the second one.
Why "Common" Spanning Tree?
The original standard builds one tree for the whole network. Every VLAN shares that one tree. So if a port is blocked, it is blocked for all VLANs at once:
- 1. VLAN 10 uses the tree… Employee traffic goes up to the root, SW1.
- 2. …and so does VLAN 20. Guest traffic takes the same tree.
- 3. The backup link sits idle. SW2–SW3 is blocked for every VLAN. Its bandwidth is wasted until something fails.
| Advantage | Limitation |
|---|---|
| Simple: one tree to understand | No load balancing: blocked links are idle for every VLAN |
| Little work for the switch: one set of BPDUs | One root for all VLANs, so some VLANs take long paths |
| Standard: every vendor supports it | Slow convergence: 30–50 seconds |
CST is old now. It has been replaced by Per-VLAN Spanning Tree (PVST+), Rapid Spanning Tree (RSTP) and MST. Modern Cisco switches don't run plain CST at all. They run PVST+ or Rapid PVST+. But all of these use the same basic steps, roles and timers. That's why the rest of the Common Spanning Tree lessons studies the original in detail. (When Cisco PVST+ switches connect to switches that run only one standard tree, they use VLAN 1 to work together.)
Check yourself
Two switches are connected by two cables and nothing else. Is that a loop?
With Common Spanning Tree, a link is blocked for VLAN 10. What about VLAN 20 on the same link?