This uses the same network as the final configuration lab (DS1, DS2, AS1, AS2). Each ticket tells you the problem and shows some output. Work out the cause and the fix before you open the answer.
Ticket 1: everything is slow since Friday
Traffic between the two distribution switches now seems to go through an access switch.
DS1#show spanning-tree root Root Hello Max Fwd Vlan Root ID Cost Time Age Dly Root Port ---------------- -------------------- --------- ----- --- --- ------------ VLAN0010 4106 0200.0000.00a2 4 2 20 15 Gi1/0/2
Show diagnosis
The VLAN 10 root has priority 4106 (4096 + 10) and MAC …00a2. That is AS2, not DS1. Someone set AS2's VLAN 10 priority to 4096. Fix: remove it on AS2 (no spanning-tree vlan 10 priority). To stop it happening again: Root Guard on the distribution ports facing the access switches would have blocked AS2, instead of letting it become the root.
Ticket 2: one desk is offline
A user plugged in "a small switch for my printer". Now nothing on their desk works.
AS1#show interfaces status err-disabled Port Name Status Reason Err-disabled Vlans Gi1/0/14 err-disabled bpduguard
Show diagnosis
BPDU Guard shut down Gi1/0/14 when the small switch sent BPDUs. The feature is doing its job. Fix: remove the small switch (or give the user another port). Then do shutdown / no shutdown on Gi1/0/14, or let errdisable recovery cause bpduguard turn it back on.
Ticket 3: an entire access switch is cut off
All users on AS1 lost their connection after an engineer connected a test switch to AS1's spare uplink port.
DS1#show spanning-tree inconsistentports Name Interface Inconsistency -------------------- ------------------------ ------------------ VLAN0010 GigabitEthernet1/0/1 Root Inconsistent VLAN0020 GigabitEthernet1/0/1 Root Inconsistent
Show diagnosis
The test switch has a better bridge ID. Its better BPDUs go through AS1 (the spare uplink port has no BPDU Guard) to the distribution switches. Root Guard on DS1 Gi1/0/1 (and the same port on DS2) blocks these ports as root-inconsistent. This protects the root, but cuts AS1 off. Fix: disconnect the test switch. The ports recover by themselves. To stop it happening again: shut down or protect unused ports on access switches.
Ticket 4: an uplink is blocked for no obvious reason
AS2#show spanning-tree inconsistentports Name Interface Inconsistency -------------------- ------------------------ ------------------ VLAN0020 GigabitEthernet1/1/1 Loop Inconsistent
Show diagnosis
Loop Guard blocked AS2's alternate uplink Gi1/1/1. BPDUs stopped arriving, but the link stayed up. This is a typical sign of a fibre that only works in one direction. Fix: check the fibre and optics on AS2 Gi1/1/1 ↔ DS1 Gi1/0/2. show udld neighbors often shows the problem too. When BPDUs come back, the port recovers.
Ticket 5: failovers take almost a minute
When an uplink fails, users on one access switch lose their connection for 30–50 seconds. On other switches, the backup takes over at once.
AS1#show spanning-tree summary Switch is in pvst mode Root bridge for: none Extended system ID is enabled Portfast Default is enabled PortFast BPDU Guard Default is enabled Loopguard Default is enabled ...
Show diagnosis
AS1 runs classic PVST+, not Rapid PVST+. So its ports use the slow 802.1D timers (and the ports of its neighbours use them too). Fix: spanning-tree mode rapid-pvst on AS1.
Ticket 6: random short slowdowns all day
Every few minutes, traffic floods across the whole network for a short time.
DS1#show spanning-tree vlan 10 detail | include topology|occurred|from Number of topology changes 2381 last change occurred 00:00:09 ago from GigabitEthernet1/0/2
Show diagnosis
There are thousands of topology changes. The last one came in on Gi1/0/2 (toward AS2). Each change clears MAC tables, which causes short floods. Run the same command on AS2. It will point to a user port. The cause is a user port without PortFast (a device that keeps going up and down, or a port where PortFast was missed). Fix:
interface GigabitEthernet1/0/7
spanning-tree portfast
spanning-tree bpduguard enableTicket 7: a distribution uplink won't forward
DS1 suddenly reaches the rest of the network through DS2, not its own direct uplink. The log shows STP errors. (For this ticket, a core switch above DS1 and DS2 is the root.)
DS1#show spanning-tree vlan 10 | begin Interface Interface Role Sts Cost Prio.Nbr Type ------------------- ---- --- --------- -------- -------------------------------- Gi1/0/1 Desg FWD 4 128.1 P2p Gi1/0/2 Desg FWD 4 128.2 P2p Gi1/0/23 Desg BKN*4 128.23 P2p *TYPE_Inc Gi1/0/24 Root FWD 4 128.24 P2p
DS1#show interfaces Gi1/0/23 switchport | include Mode Administrative Mode: static access Operational Mode: static access
Show diagnosis
TYPE_Inc means the port types don't match. DS1's end of the core link is an access port, but the core's end is a trunk. A trunk sends BPDUs tagged with their VLAN. An access port expects untagged BPDUs. If this were allowed, untagged VLAN 10 frames would end up in the core's native VLAN 1. Traffic would leak from one VLAN into another. So STP marks the port as broken. Fix: make both ends trunks.
interface GigabitEthernet1/0/23
switchport mode trunk
switchport trunk allowed vlan 10,20Ticket 8: a replaced access switch is isolated
AS2 was replaced with a new switch. Its uplinks are up, but no traffic passes. STP messages about VLANs appear in the log. AS2 also thinks it is the root.
AS2#show spanning-tree vlan 10 | begin Interface Interface Role Sts Cost Prio.Nbr Type ------------------- ---- --- --------- -------- -------------------------------- Gi1/1/1 Desg BKN*4 128.49 P2p *PVID_Inc Gi1/1/2 Desg BKN*4 128.50 P2p *PVID_Inc
Show diagnosis
PVID_Inc means the two ends of each trunk have different native VLANs. PVST+ BPDUs say which VLAN they belong to. So the switches notice that untagged frames would change VLAN when they cross the link, and they block it. Compare show interfaces trunk on both sides. Fix: set the same native VLAN as the distribution switches (whatever DS1 and DS2 use):
interface range GigabitEthernet1/1/1 - 2
switchport trunk native vlan 999Use the same value as DS1 and DS2. The ports then recover by themselves ('Port consistency restored').
Ticket 9: the virtualisation host keeps going offline
A server running virtual machines, on AS1 Gi1/0/20 (a trunk with PortFast), lost its connection. Unplugging and replugging the cable doesn't help.
AS1#show interfaces status err-disabled Port Name Status Reason Err-disabled Vlans Gi1/0/20 err-disabled bpduguard
Show diagnosis
The server's virtual switch (or a VM) sent BPDUs, and BPDU Guard did its job. If the server can't send traffic back in a loop, it is fine to use PortFast trunk without BPDU Guard. But keep a safety net: Root Guard, so a wrongly set virtual switch can never become the root. Then turn the port off and on again.
interface GigabitEthernet1/0/20
spanning-tree portfast trunk
spanning-tree bpduguard disable
spanning-tree guard root
shutdown
no shutdownshow spanning-tree root: who the root is, and through which port.show spanning-tree vlan X: every port's role and state.show spanning-tree inconsistentports: ports blocked by Root Guard, Loop Guard, or a port-type or native-VLAN mismatch.show interfaces trunk/switchport: trunk or access, and the native VLAN, on each end.show interfaces status err-disabled: ports shut down by BPDU Guard or UDLD.show spanning-tree summary: the mode and the global settings.show spanning-tree vlan X detail: how many topology changes, and where they come from.