The campus
- 1. VLAN 10 (target state): DS1 is the root. Each access switch uses its uplink to DS1, and keeps its uplink to DS2 as a backup (alternate).
- 2. Across the access layer. In VLAN 10, traffic between the access switches goes through DS1. VLAN 20 is the opposite: DS2 is the root, and the uplinks to DS1 are the backups.
| Link | Ports |
|---|---|
| DS1 – DS2 | Gi1/0/24 ↔ Gi1/0/24 |
| AS1 – DS1 / DS2 | AS1 Gi1/1/1 ↔ DS1 Gi1/0/1 · AS1 Gi1/1/2 ↔ DS2 Gi1/0/1 (fibre) |
| AS2 – DS1 / DS2 | AS2 Gi1/1/1 ↔ DS1 Gi1/0/2 · AS2 Gi1/1/2 ↔ DS2 Gi1/0/2 (fibre) |
| User ports | Gi1/0/1–24 on AS1 (VLAN 10) and AS2 (VLAN 20) |
Requirements
- Rapid PVST+ on every switch.
- VLANs 10 and 20 on every switch. All links between switches are trunks that allow only VLANs 10 and 20.
- DS1: root for VLAN 10, and backup root for VLAN 20. DS2: the opposite.
- User ports: access ports with PortFast and BPDU Guard.
- No access switch may ever become the root. Protect the distribution ports that face the access switches.
- Protect the access uplinks against one-way link failures. Use one STP feature and one link feature.
⚠️ The solution is based on Cisco IOS / IOS XE documentation. It has not been run in a lab here. Change the interface names to match your switches. Some switch models also need switchport trunk encapsulation dot1q.
Solution
All switches (requirements 1–2)
spanning-tree mode rapid-pvst
vlan 10
name USERS-10
vlan 20
name USERS-20! Trunks: DS1/DS2 Gi1/0/1, Gi1/0/2, Gi1/0/24 and AS1/AS2 Gi1/1/1-2
interface range GigabitEthernet1/0/1 - 2 , GigabitEthernet1/0/24
switchport mode trunk
switchport trunk allowed vlan 10,20On DS1 and DS2. On AS1 and AS2 use 'interface range GigabitEthernet1/1/1 - 2'.
DS1 and DS2 (requirements 3 and 5)
! DS1
spanning-tree vlan 10 priority 24576
spanning-tree vlan 20 priority 28672
interface range GigabitEthernet1/0/1 - 2
spanning-tree guard root
udld port aggressive! DS2
spanning-tree vlan 20 priority 24576
spanning-tree vlan 10 priority 28672
interface range GigabitEthernet1/0/1 - 2
spanning-tree guard root
udld port aggressiveRoot Guard only goes on the ports that face the access switches. Those ports are designated in every VLAN. It must not go on Gi1/0/24, because that is a root port on whichever distribution switch is not the root.
AS1 and AS2 (requirements 4 and 6)
spanning-tree portfast default
spanning-tree portfast bpduguard default
spanning-tree loopguard default
interface range GigabitEthernet1/0/1 - 24
switchport mode access
switchport access vlan 10
interface range GigabitEthernet1/1/1 - 2
udld port aggressiveOn AS2, use 'switchport access vlan 20'. The global Loop Guard command covers the uplinks (root and alternate ports). UDLD checks the fibre itself.
Part 2: tuning and traffic engineering
The customer adds four more requirements, written in business words. Work out which feature each one needs:
- AS1 Gi1/0/48 connects a wireless access point on a trunk (one VLAN per Wi-Fi network). After a restart, it must forward at once.
- VLAN 10 must use hello 1 s, forward delay 7 s and max age 10 s.
- On AS2, VLAN 10 traffic must use uplink Gi1/1/2 (to DS2). VLAN 20 must not change.
- DS2 must use the second cable to DS1 for VLAN 10 (assume a second DS1–DS2 link, Gi1/0/25 ↔ Gi1/0/25), without changing anything on DS2.
Requirement 7: PortFast on a trunk
portfast default only covers access ports. So the access point's trunk needs the interface command. The access point connects wireless users to VLANs, but it never sends traffic back in a loop. So this is safe.
! AS1
interface GigabitEthernet1/0/48
switchport mode trunk
spanning-tree portfast trunkRequirement 8: timers, on the root only
! DS1 (VLAN 10 root)
spanning-tree vlan 10 hello-time 1
spanning-tree vlan 10 forward-time 7
spanning-tree vlan 10 max-age 10Check: 2 × (1 + 1) = 4 ≤ 10 ≤ 2 × (7 − 1) = 12. On a switch that is not the root, these commands would do nothing. Note: if DS2 becomes the root for VLAN 10 later, its own timers are used, so set them on DS2 too.
Requirement 9: per-VLAN port cost
AS2's two VLAN 10 paths cost 4 (direct to DS1) and 4 + 4 = 8 (through DS2 and the DS1–DS2 link). So the direct path wins. Raise the cost of the DS1 uplink for VLAN 10 only. This moves the root port without changing VLAN 20:
! AS2
interface GigabitEthernet1/1/1
spanning-tree vlan 10 cost 20VLAN 10 through DS1 = 20, through DS2 = 8. So Gi1/1/2 becomes the root port. Check with 'show spanning-tree vlan 10 root' (cost 8, port Gi1/1/2) and 'show spanning-tree vlan 20' (no change).
Requirement 10: sender port priority
DS2 sees two links to the same neighbour with the same cost. So the tie is decided by the sender's port ID. That means the change goes on DS1, the sender:
! DS1
interface GigabitEthernet1/0/25
spanning-tree vlan 10 port-priority 0DS1's Gi1/0/25 now sends port ID 0.25. That is lower than Gi1/0/24's 128.24. So DS2's Gi1/0/25 becomes its VLAN 10 root port.
Verification checklist
These are the results you should see. They are not copied from a real switch:
| Check | Command | Expected |
|---|---|---|
| Mode | show spanning-tree summary | rapid-pvst on all four switches |
| Roots | show spanning-tree root | VLAN 10 root = DS1, VLAN 20 root = DS2 |
| AS1, VLAN 10 | show spanning-tree vlan 10 | Gi1/1/1 Root FWD, Gi1/1/2 Altn BLK, user ports Desg FWD Edge |
| AS1, VLAN 20 | show spanning-tree vlan 20 | Gi1/1/2 Root FWD, Gi1/1/1 Altn BLK |
| Guards | show spanning-tree inconsistentports | No inconsistent ports |
| UDLD | show udld neighbors | Each uplink Bidirectional |
Test it
- Shut down AS1 Gi1/1/1. VLAN 10 users on AS1 should only lose a moment, while Gi1/1/2 becomes the root port.
- Connect a spare switch to an AS1 user port. The port should be shut down (err-disabled) by BPDU Guard.
- Set AS2's VLAN 10 priority to 0. DS1 and DS2 should block their ports to AS2 as root-inconsistent, and DS1 should stay the root. Remove the change afterwards.