The problem
Situation: a user turns on their PC. Without PortFast, the port spends 15 s listening and 15 s learning (the “Port states and timers” lesson). But the PC has already sent its DHCP request, and the switch dropped it. So the PC may get a 169.254 address (no real IP), or start without its network drives. Also, every time the port goes up or down, it causes a topology change in the whole network (the “Topology changes (TCN)” lesson).
What PortFast does
PortFast makes the port an edge port. An edge port connects to an end device, such as a PC, so it can't be part of a loop. When the link comes up, it starts forwarding straight away. It also doesn't cause topology changes.
- 1. Both PCs boot. Both send a DHCP request as soon as their cable is connected.
- 2. PC 2 is online immediately. Its PortFast port is forwarding already.
- 3. PC 1 waits. Its port is still listening, then learning. It only forwards after about 30 s.
Configuration
interface GigabitEthernet1/0/11
switchport mode access
spanning-tree portfastOn one access port. Newer IOS XE versions also accept 'spanning-tree portfast edge'.
spanning-tree portfast defaultFor the whole switch: turns on PortFast on every access port (not trunks).
interface GigabitEthernet1/0/20
switchport mode trunk
spanning-tree portfast trunkFor a trunk to one server or hypervisor that is not a switch (IOS XE: 'spanning-tree portfast edge trunk'). Never use it on a link to another switch.
⚠️ The risk: if someone plugs a switch into a PortFast port (or connects a cable in a loop), the port forwards at once. A loop can form before STP reacts. So always use PortFast together with BPDU Guard (the “BPDU Guard” lesson). If a PortFast port receives a BPDU, it stops being an edge port and works like a normal STP port.
Verify
SW1#show spanning-tree interface GigabitEthernet1/0/11 portfast VLAN0010 enabled
In show spanning-tree vlan 10, the Type column for the port shows Edge (for example P2p Edge).
Watch it in the log
Situation: a server on SW3 Gi1/0/10 restarts. You turn on debug spanning-tree events and compare the port coming up without PortFast, and then with PortFast:
SW3#! without PortFast 10:00:00.100: STP: VLAN0010 Gi1/0/10 -> listening 10:00:15.100: STP: VLAN0010 Gi1/0/10 -> learning 10:00:30.100: STP: VLAN0010 sent Topology Change Notice on Gi1/0/1 10:00:30.100: STP: VLAN0010 Gi1/0/10 -> forwarding
SW3#! with PortFast 10:05:00.100: STP: VLAN0010 Gi1/0/10 ->jump to forwarding from blocking
PortFast doesn't turn STP off
Many people think it does, but it doesn't. A PortFast port is still a designated port. It keeps sending BPDUs every 2 seconds, and keeps listening for them. Only two things change: how fast it starts, and that it doesn't cause topology changes.
| Something plugged in | What the PortFast port does |
|---|---|
| PC, printer, server | Stays an edge port: forwards at once, no TCNs |
| A switch sending BPDUs | Stops being an edge port (but the setting stays in the config). It runs normal STP (listening, learning, TCNs) and takes whatever role the BPDUs decide, even blocked. |
| The port becomes an 802.1Q trunk | Normal PortFast doesn't work on trunks (unless portfast trunk is set) |
So there are two states. The administrative state is what you configured. The operational state is what is really happening:
SW3#show spanning-tree interface Gi1/0/10 portfast VLAN0010 disabled
spanning-tree portfast is still in the config. But a switch was connected, so PortFast is really off. The Type column no longer shows Edge.Three ways to enable it
| Command | Applies to | When to use it |
|---|---|---|
spanning-tree portfast default | Every access (non-trunk) port | Best for access switches. Turn it off on single ports where needed with spanning-tree portfast disable. |
spanning-tree portfast | One interface | When only a few ports need it |
switchport host | One interface | A shortcut. In one command it sets access mode, turns on PortFast and removes the port from any EtherChannel. |
SW3#show spanning-tree summary | include Portfast Portfast Default is enabled PortFast BPDU Guard Default is disabled Portfast BPDU Filter Default is disabled
Where to use it (and the trunk exception)
- 1. End devices: PCs, printers, phones and single-VLAN servers get normal PortFast.
- 2. Trunks to devices that don't bridge: an access point (one VLAN per Wi-Fi network), or a firewall or router with VLAN sub-interfaces, needs a trunk. But it can't send traffic back in a loop. Use 'spanning-tree portfast trunk'.
- 3. A hypervisor's virtual switch: it connects virtual machines to VLANs. It doesn't pass traffic between its uplinks, and it doesn't run STP. So PortFast trunk avoids the 30 s wait while the VMs start.
- 4. Never between switches: skipping listening and learning there can cause short loops.
Check yourself
Where should PortFast be configured?
Besides faster startup, what else does PortFast prevent?