Routelearn.net
Course menu

Course 6: Spanning Tree ProtocolLesson 3.3 (13 of 24 in this course)34 of 91 in the CCNA series

Lab: Spanning Tree customization

Make different switches root for different VLANs and steer traffic onto the links you choose.

Intermediate · 25 min read

STP customization means changing Spanning Tree parameters, such as per-VLAN bridge priority, port cost, port priority and timers, so that the root bridge and forwarding paths for each VLAN are the ones the network designer chose rather than the result of default values.

In simple terms: Left alone, switches pick the root and the paths by themselves. Customizing STP lets you choose which switch is in charge and which cables each VLAN uses.

Most real networks only choose where the root is. They leave everything else at the default settings. But exams, and some special cases, ask you to fine-tune the tree. This lab practises the three other settings you can change: port cost, port priority and timers.

⚠️ Based on Cisco IOS / IOS XE documentation, not run in a lab here. Change the interface names to match your switches. All links are 1 Gbps trunks (cost 4) carrying VLANs 10 and 20. The switches run PVST+.

Topology

Gi1/0/1 ↔ Gi1/0/1Gi1/0/3 ↔ Gi1/0/1Gi1/0/3 ↔ Gi1/0/2SW1VLAN 10 rootSW2VLAN 20 rootSW4access
  1. 1. Two cables between SW1 and SW2: SW1 Gi1/0/1 ↔ SW2 Gi1/0/1, and SW1 Gi1/0/2 ↔ SW2 Gi1/0/2. SW4 is connected to both. SW1 is already the root for VLAN 10, and SW2 for VLAN 20.
VLANRootDefault result
10SW1SW4 uses its direct link to SW1 (cost 4). Its port to SW2 is blocked.
20SW2SW1's root port is Gi1/0/1 (facing SW2's Gi1/0/1). SW1 Gi1/0/2 is blocked.

Requirements

  1. VLAN 10: SW4's traffic to SW1 must go via SW2.
  2. VLAN 20: SW1 must reach SW2 over the second cable (its Gi1/0/2), without changing any cost on SW1.
  3. VLAN 20: the root must send BPDUs every second. If the root goes silent, switches must stop waiting for it after 10 seconds.

Try it yourself first. Then compare with the solutions.

Remember the decision order

A switch chooses its root port by going down this list until it finds a difference (the “Spanning Tree port roles” lesson):

  1. Lowest root bridge ID
  2. Lowest total root path cost
  3. Lowest sender bridge ID
  4. Lowest sender port ID

You already used rule 1 when you chose the roots. Requirement 1 uses rule 2, and requirement 2 uses rule 4.

Requirement 1: VLAN 10 via SW2 (port cost)

Plan first. The cost adds up from switch to switch. So a change on one port can also change things for switches further down. Write down the paths before you change anything:

SW4's path to SW1Cost nowCost if SW4 Gi1/0/1 is set to 20
Direct (Gi1/0/1)420
Via SW2 (Gi1/0/2)4 + 4 = 88 ✓ lowest

You have two choices: lower the cost of the path you want, or raise the cost of the path you don't want. Here, the simplest is to raise the cost of the direct port. It only affects SW4, because no switch is connected below SW4.

Show solution
! SW4 interface GigabitEthernet1/0/1 spanning-tree vlan 10 cost 20
Example output · based on Cisco documentation; exact format varies by platform and software version
SW4#show spanning-tree vlan 10 root
                                        Root    Hello Max Fwd
Vlan                   Root ID          Cost    Time  Age Dly  Root Port
---------------- -------------------- --------- ----- --- ---  ------------
VLAN0010         24586 0200.0000.0001         8    2   20  15  Gi1/0/2
The root port is now Gi1/0/2 (toward SW2), with a total cost of 8. On SW4, show spanning-tree vlan 10 would show Gi1/0/1 as Altn BLK, because SW1's end of that link (cost 0) is designated.
DPRPDPALTcost 20 on SW4DPRPSW1VLAN 10 rootSW2VLAN 20 rootSW4access
  1. 1. Requirement met: SW4 reaches SW1 through SW2.

Requirement 2: VLAN 20 over the second cable (port priority)

SW1 sees two equal paths to SW2: the same root, the same cost (4) and the same sender switch (SW2). So rule 4 decides: the sender port ID. This is the port ID of SW2's port at the other end of each cable.

Port ID partMeaningConfigurable?
Port priorityDefault 128. On Cisco switches, 0–240 in steps of 16. Lower wins.Yes
Port numberA number fixed by the hardware. Gi1/0/1 is usually 1. Stacked switches, modules and EtherChannels use higher numbers.No

The two parts are shown together as Prio.Nbr, for example 128.1. You are not allowed to change SW1's costs, and the rule looks at the sender's port ID. So the change goes on SW2.

Show solution
! SW2 interface GigabitEthernet1/0/2 spanning-tree vlan 20 port-priority 64

SW2 Gi1/0/2 becomes 64.2. That is lower than Gi1/0/1's 128.1, so SW1 now prefers the cable connected to Gi1/0/2.

Example output · based on Cisco documentation; exact format varies by platform and software version
SW1#show spanning-tree vlan 20
...
Interface           Role Sts Cost      Prio.Nbr Type
------------------- ---- --- --------- -------- --------------------------------
Gi1/0/1             Altn BLK 4         128.1    P2p
Gi1/0/2             Root FWD 4         128.2    P2p
Gi1/0/3             Desg FWD 4         128.3    P2p
SW1's root port has moved to Gi1/0/2. But SW1's own port priorities have not changed (the Prio.Nbr column shows SW1's own ports). On SW2, show spanning-tree vlan 20 would show Gi1/0/2 as 64.2.

Requirement 3: VLAN 20 timers

The timers are sent in the root's BPDUs. So you change them only on the root for that VLAN, and every other switch follows. The allowed values are:

TimerDefaultRangeCommand (on the root)
Hello2 s1–10 sspanning-tree vlan 20 hello-time 1
Max age20 s6–40 sspanning-tree vlan 20 max-age 10
Forward delay15 s4–30 sspanning-tree vlan 20 forward-time …

⚠️ The timers must fit together. Max age must be at least 2 × (hello + 1), and at most 2 × (forward delay − 1). Hello 1, max age 10 and forward delay 15 fit (4 ≤ 10 ≤ 28). If timers are too short, ports can start forwarding before the tree is ready, and cause loops.

Show solution
! SW2 (the VLAN 20 root) spanning-tree vlan 20 hello-time 1 spanning-tree vlan 20 max-age 10
Example output · based on Cisco documentation; exact format varies by platform and software version
SW2#show spanning-tree vlan 20
VLAN0020
  Spanning tree enabled protocol ieee
  Root ID    Priority    24596
             Address     0200.0000.0002
             This bridge is the root
             Hello Time   1 sec  Max Age 10 sec  Forward Delay 15 sec
The new values appear in the Root ID section. The same line on SW1 and SW4 shows that they have received them.

💡 Shortcut: spanning-tree vlan 20 root primary diameter 3 hello-time 1 makes the switch the root. It also works out matching timers for a network up to 3 switches across, so you don't have to choose each value.

Wrap-up questions

Why did requirement 2 have to be configured on SW2, not SW1?

Rule 4 compares the sender's port ID, which is inside the BPDUs that SW2 sends. Changing SW1's own port priority would only affect switches that receive BPDUs from SW1.

Would SW4's cost change affect any other switch?

No. No switch is connected below SW4 in VLAN 10. If another switch were connected to SW4, its total cost would change too. That's why you plan the whole tree first.