Routelearn.net
Course menu

Course 6: Spanning Tree ProtocolLesson 5.1 (23 of 24 in this course)44 of 91 in the CCNA series

Final configuration lab

Design and configure Spanning Tree for a two-tier campus, including every protection feature.

Advanced · 40 min read

STP (Spanning Tree Protocol) is a Layer 2 protocol that lets switches with redundant links agree on a single loop-free path through the network. The switches exchange BPDUs, elect a root bridge and block the ports that would form a loop, unblocking them if an active link fails.

In simple terms: Spare cables between switches are useful, but they can make frames go round in circles forever. STP switches off just enough ports to stop the loops and turns them back on when a link breaks.

The campus

DPRPGi1/0/24 ↔ Gi1/0/24DPRPDPRPDPALTDPALTDS1VLAN 10 rootDS2VLAN 20 rootAS1users: VLAN 10AS2users: VLAN 20
  1. 1. VLAN 10 (target state): DS1 is the root. Each access switch uses its uplink to DS1, and keeps its uplink to DS2 as a backup (alternate).
  2. 2. Across the access layer. In VLAN 10, traffic between the access switches goes through DS1. VLAN 20 is the opposite: DS2 is the root, and the uplinks to DS1 are the backups.
LinkPorts
DS1 – DS2Gi1/0/24 ↔ Gi1/0/24
AS1 – DS1 / DS2AS1 Gi1/1/1 ↔ DS1 Gi1/0/1 · AS1 Gi1/1/2 ↔ DS2 Gi1/0/1 (fibre)
AS2 – DS1 / DS2AS2 Gi1/1/1 ↔ DS1 Gi1/0/2 · AS2 Gi1/1/2 ↔ DS2 Gi1/0/2 (fibre)
User portsGi1/0/1–24 on AS1 (VLAN 10) and AS2 (VLAN 20)

Requirements

  1. Rapid PVST+ on every switch.
  2. VLANs 10 and 20 on every switch. All links between switches are trunks that allow only VLANs 10 and 20.
  3. DS1: root for VLAN 10, and backup root for VLAN 20. DS2: the opposite.
  4. User ports: access ports with PortFast and BPDU Guard.
  5. No access switch may ever become the root. Protect the distribution ports that face the access switches.
  6. Protect the access uplinks against one-way link failures. Use one STP feature and one link feature.

⚠️ The solution is based on Cisco IOS / IOS XE documentation. It has not been run in a lab here. Change the interface names to match your switches. Some switch models also need switchport trunk encapsulation dot1q.

Solution

All switches (requirements 1–2)
spanning-tree mode rapid-pvst vlan 10 name USERS-10 vlan 20 name USERS-20
! Trunks: DS1/DS2 Gi1/0/1, Gi1/0/2, Gi1/0/24 and AS1/AS2 Gi1/1/1-2 interface range GigabitEthernet1/0/1 - 2 , GigabitEthernet1/0/24 switchport mode trunk switchport trunk allowed vlan 10,20

On DS1 and DS2. On AS1 and AS2 use 'interface range GigabitEthernet1/1/1 - 2'.

DS1 and DS2 (requirements 3 and 5)
! DS1 spanning-tree vlan 10 priority 24576 spanning-tree vlan 20 priority 28672 interface range GigabitEthernet1/0/1 - 2 spanning-tree guard root udld port aggressive
! DS2 spanning-tree vlan 20 priority 24576 spanning-tree vlan 10 priority 28672 interface range GigabitEthernet1/0/1 - 2 spanning-tree guard root udld port aggressive

Root Guard only goes on the ports that face the access switches. Those ports are designated in every VLAN. It must not go on Gi1/0/24, because that is a root port on whichever distribution switch is not the root.

AS1 and AS2 (requirements 4 and 6)
spanning-tree portfast default spanning-tree portfast bpduguard default spanning-tree loopguard default interface range GigabitEthernet1/0/1 - 24 switchport mode access switchport access vlan 10 interface range GigabitEthernet1/1/1 - 2 udld port aggressive

On AS2, use 'switchport access vlan 20'. The global Loop Guard command covers the uplinks (root and alternate ports). UDLD checks the fibre itself.

Part 2: tuning and traffic engineering

The customer adds four more requirements, written in business words. Work out which feature each one needs:

  1. AS1 Gi1/0/48 connects a wireless access point on a trunk (one VLAN per Wi-Fi network). After a restart, it must forward at once.
  2. VLAN 10 must use hello 1 s, forward delay 7 s and max age 10 s.
  3. On AS2, VLAN 10 traffic must use uplink Gi1/1/2 (to DS2). VLAN 20 must not change.
  4. DS2 must use the second cable to DS1 for VLAN 10 (assume a second DS1–DS2 link, Gi1/0/25 ↔ Gi1/0/25), without changing anything on DS2.
Requirement 7: PortFast on a trunk

portfast default only covers access ports. So the access point's trunk needs the interface command. The access point connects wireless users to VLANs, but it never sends traffic back in a loop. So this is safe.

! AS1 interface GigabitEthernet1/0/48 switchport mode trunk spanning-tree portfast trunk
Requirement 8: timers, on the root only
! DS1 (VLAN 10 root) spanning-tree vlan 10 hello-time 1 spanning-tree vlan 10 forward-time 7 spanning-tree vlan 10 max-age 10

Check: 2 × (1 + 1) = 4 ≤ 10 ≤ 2 × (7 − 1) = 12. On a switch that is not the root, these commands would do nothing. Note: if DS2 becomes the root for VLAN 10 later, its own timers are used, so set them on DS2 too.

Requirement 9: per-VLAN port cost

AS2's two VLAN 10 paths cost 4 (direct to DS1) and 4 + 4 = 8 (through DS2 and the DS1–DS2 link). So the direct path wins. Raise the cost of the DS1 uplink for VLAN 10 only. This moves the root port without changing VLAN 20:

! AS2 interface GigabitEthernet1/1/1 spanning-tree vlan 10 cost 20

VLAN 10 through DS1 = 20, through DS2 = 8. So Gi1/1/2 becomes the root port. Check with 'show spanning-tree vlan 10 root' (cost 8, port Gi1/1/2) and 'show spanning-tree vlan 20' (no change).

Requirement 10: sender port priority

DS2 sees two links to the same neighbour with the same cost. So the tie is decided by the sender's port ID. That means the change goes on DS1, the sender:

! DS1 interface GigabitEthernet1/0/25 spanning-tree vlan 10 port-priority 0

DS1's Gi1/0/25 now sends port ID 0.25. That is lower than Gi1/0/24's 128.24. So DS2's Gi1/0/25 becomes its VLAN 10 root port.

Verification checklist

These are the results you should see. They are not copied from a real switch:

CheckCommandExpected
Modeshow spanning-tree summaryrapid-pvst on all four switches
Rootsshow spanning-tree rootVLAN 10 root = DS1, VLAN 20 root = DS2
AS1, VLAN 10show spanning-tree vlan 10Gi1/1/1 Root FWD, Gi1/1/2 Altn BLK, user ports Desg FWD Edge
AS1, VLAN 20show spanning-tree vlan 20Gi1/1/2 Root FWD, Gi1/1/1 Altn BLK
Guardsshow spanning-tree inconsistentportsNo inconsistent ports
UDLDshow udld neighborsEach uplink Bidirectional

Test it

  1. Shut down AS1 Gi1/1/1. VLAN 10 users on AS1 should only lose a moment, while Gi1/1/2 becomes the root port.
  2. Connect a spare switch to an AS1 user port. The port should be shut down (err-disabled) by BPDU Guard.
  3. Set AS2's VLAN 10 priority to 0. DS1 and DS2 should block their ports to AS2 as root-inconsistent, and DS1 should stay the root. Remove the change afterwards.