Routelearn.net
Course menu

Course 6: Spanning Tree ProtocolLesson 5.2 (24 of 24 in this course)45 of 91 in the CCNA series

Final troubleshooting lab

Six broken networks: read the symptoms and the output, find the cause, then check your answer.

Advanced · 30 min read

STP (Spanning Tree Protocol) is a Layer 2 protocol that lets switches with redundant links agree on a single loop-free path through the network. The switches exchange BPDUs, elect a root bridge and block the ports that would form a loop, unblocking them if an active link fails.

In simple terms: Spare cables between switches are useful, but they can make frames go round in circles forever. STP switches off just enough ports to stop the loops and turns them back on when a link breaks.

This uses the same network as the final configuration lab (DS1, DS2, AS1, AS2). Each ticket tells you the problem and shows some output. Work out the cause and the fix before you open the answer.

Ticket 1: everything is slow since Friday

Traffic between the two distribution switches now seems to go through an access switch.

Example output · based on Cisco documentation; exact format varies by platform and software version
DS1#show spanning-tree root
                                        Root    Hello Max Fwd
Vlan                   Root ID          Cost    Time  Age Dly  Root Port
---------------- -------------------- --------- ----- --- ---  ------------
VLAN0010          4106 0200.0000.00a2         4    2   20  15  Gi1/0/2
Show diagnosis

The VLAN 10 root has priority 4106 (4096 + 10) and MAC …00a2. That is AS2, not DS1. Someone set AS2's VLAN 10 priority to 4096. Fix: remove it on AS2 (no spanning-tree vlan 10 priority). To stop it happening again: Root Guard on the distribution ports facing the access switches would have blocked AS2, instead of letting it become the root.

Ticket 2: one desk is offline

A user plugged in "a small switch for my printer". Now nothing on their desk works.

Example output · based on Cisco documentation; exact format varies by platform and software version
AS1#show interfaces status err-disabled
Port      Name               Status       Reason               Err-disabled Vlans
Gi1/0/14                     err-disabled bpduguard
Show diagnosis

BPDU Guard shut down Gi1/0/14 when the small switch sent BPDUs. The feature is doing its job. Fix: remove the small switch (or give the user another port). Then do shutdown / no shutdown on Gi1/0/14, or let errdisable recovery cause bpduguard turn it back on.

Ticket 3: an entire access switch is cut off

All users on AS1 lost their connection after an engineer connected a test switch to AS1's spare uplink port.

Example output · based on Cisco documentation; exact format varies by platform and software version
DS1#show spanning-tree inconsistentports
Name                 Interface                Inconsistency
-------------------- ------------------------ ------------------
VLAN0010             GigabitEthernet1/0/1     Root Inconsistent
VLAN0020             GigabitEthernet1/0/1     Root Inconsistent
Show diagnosis

The test switch has a better bridge ID. Its better BPDUs go through AS1 (the spare uplink port has no BPDU Guard) to the distribution switches. Root Guard on DS1 Gi1/0/1 (and the same port on DS2) blocks these ports as root-inconsistent. This protects the root, but cuts AS1 off. Fix: disconnect the test switch. The ports recover by themselves. To stop it happening again: shut down or protect unused ports on access switches.

Ticket 4: an uplink is blocked for no obvious reason

Example output · based on Cisco documentation; exact format varies by platform and software version
AS2#show spanning-tree inconsistentports
Name                 Interface                Inconsistency
-------------------- ------------------------ ------------------
VLAN0020             GigabitEthernet1/1/1     Loop Inconsistent
Show diagnosis

Loop Guard blocked AS2's alternate uplink Gi1/1/1. BPDUs stopped arriving, but the link stayed up. This is a typical sign of a fibre that only works in one direction. Fix: check the fibre and optics on AS2 Gi1/1/1 ↔ DS1 Gi1/0/2. show udld neighbors often shows the problem too. When BPDUs come back, the port recovers.

Ticket 5: failovers take almost a minute

When an uplink fails, users on one access switch lose their connection for 30–50 seconds. On other switches, the backup takes over at once.

Example output · based on Cisco documentation; exact format varies by platform and software version
AS1#show spanning-tree summary
Switch is in pvst mode
Root bridge for: none
Extended system ID                      is enabled
Portfast Default                        is enabled
PortFast BPDU Guard Default             is enabled
Loopguard Default                       is enabled
...
Show diagnosis

AS1 runs classic PVST+, not Rapid PVST+. So its ports use the slow 802.1D timers (and the ports of its neighbours use them too). Fix: spanning-tree mode rapid-pvst on AS1.

Ticket 6: random short slowdowns all day

Every few minutes, traffic floods across the whole network for a short time.

Example output · based on Cisco documentation; exact format varies by platform and software version
DS1#show spanning-tree vlan 10 detail | include topology|occurred|from
  Number of topology changes 2381 last change occurred 00:00:09 ago
          from GigabitEthernet1/0/2
Show diagnosis

There are thousands of topology changes. The last one came in on Gi1/0/2 (toward AS2). Each change clears MAC tables, which causes short floods. Run the same command on AS2. It will point to a user port. The cause is a user port without PortFast (a device that keeps going up and down, or a port where PortFast was missed). Fix:

interface GigabitEthernet1/0/7 spanning-tree portfast spanning-tree bpduguard enable

Ticket 7: a distribution uplink won't forward

DS1 suddenly reaches the rest of the network through DS2, not its own direct uplink. The log shows STP errors. (For this ticket, a core switch above DS1 and DS2 is the root.)

Example output · based on Cisco documentation; exact format varies by platform and software version
DS1#show spanning-tree vlan 10 | begin Interface
Interface           Role Sts Cost      Prio.Nbr Type
------------------- ---- --- --------- -------- --------------------------------
Gi1/0/1             Desg FWD 4         128.1    P2p
Gi1/0/2             Desg FWD 4         128.2    P2p
Gi1/0/23            Desg BKN*4         128.23   P2p *TYPE_Inc
Gi1/0/24            Root FWD 4         128.24   P2p
Example output · based on Cisco documentation; exact format varies by platform and software version
DS1#show interfaces Gi1/0/23 switchport | include Mode
Administrative Mode: static access
Operational Mode: static access
Show diagnosis

TYPE_Inc means the port types don't match. DS1's end of the core link is an access port, but the core's end is a trunk. A trunk sends BPDUs tagged with their VLAN. An access port expects untagged BPDUs. If this were allowed, untagged VLAN 10 frames would end up in the core's native VLAN 1. Traffic would leak from one VLAN into another. So STP marks the port as broken. Fix: make both ends trunks.

interface GigabitEthernet1/0/23 switchport mode trunk switchport trunk allowed vlan 10,20

Ticket 8: a replaced access switch is isolated

AS2 was replaced with a new switch. Its uplinks are up, but no traffic passes. STP messages about VLANs appear in the log. AS2 also thinks it is the root.

Example output · based on Cisco documentation; exact format varies by platform and software version
AS2#show spanning-tree vlan 10 | begin Interface
Interface           Role Sts Cost      Prio.Nbr Type
------------------- ---- --- --------- -------- --------------------------------
Gi1/1/1             Desg BKN*4         128.49   P2p *PVID_Inc
Gi1/1/2             Desg BKN*4         128.50   P2p *PVID_Inc
Show diagnosis

PVID_Inc means the two ends of each trunk have different native VLANs. PVST+ BPDUs say which VLAN they belong to. So the switches notice that untagged frames would change VLAN when they cross the link, and they block it. Compare show interfaces trunk on both sides. Fix: set the same native VLAN as the distribution switches (whatever DS1 and DS2 use):

interface range GigabitEthernet1/1/1 - 2 switchport trunk native vlan 999

Use the same value as DS1 and DS2. The ports then recover by themselves ('Port consistency restored').

Ticket 9: the virtualisation host keeps going offline

A server running virtual machines, on AS1 Gi1/0/20 (a trunk with PortFast), lost its connection. Unplugging and replugging the cable doesn't help.

Example output · based on Cisco documentation; exact format varies by platform and software version
AS1#show interfaces status err-disabled
Port      Name               Status       Reason               Err-disabled Vlans
Gi1/0/20                     err-disabled bpduguard
Show diagnosis

The server's virtual switch (or a VM) sent BPDUs, and BPDU Guard did its job. If the server can't send traffic back in a loop, it is fine to use PortFast trunk without BPDU Guard. But keep a safety net: Root Guard, so a wrongly set virtual switch can never become the root. Then turn the port off and on again.

interface GigabitEthernet1/0/20 spanning-tree portfast trunk spanning-tree bpduguard disable spanning-tree guard root shutdown no shutdown
✅ Troubleshooting toolkit
  • show spanning-tree root: who the root is, and through which port.
  • show spanning-tree vlan X: every port's role and state.
  • show spanning-tree inconsistentports: ports blocked by Root Guard, Loop Guard, or a port-type or native-VLAN mismatch.
  • show interfaces trunk / switchport: trunk or access, and the native VLAN, on each end.
  • show interfaces status err-disabled: ports shut down by BPDU Guard or UDLD.
  • show spanning-tree summary: the mode and the global settings.
  • show spanning-tree vlan X detail: how many topology changes, and where they come from.