One tree per VLAN
With Common Spanning Tree (the “Introduction to Common Spanning Tree (CST)” lesson), all VLANs share one tree. So a blocked link is unused by every VLAN. Cisco's PVST+ (Per-VLAN Spanning Tree Plus) is different. It runs a separate spanning tree for every VLAN. Each VLAN has its own root bridge, its own port roles and its own blocked ports.
That's why the bridge ID includes the extended system ID (the VLAN number). The same switch has a different bridge ID in each VLAN. For example, 24586 in VLAN 10 and 32788 in VLAN 20.
What one shared tree really costs
Situation: a campus has two buildings, joined by two expensive fibre cables. It has a data VLAN and a voice VLAN. With one tree for everything:
- 1. Data uses fibre 1… the only fibre that STP leaves forwarding.
- 2. …and so does voice. Fibre 2 carries nothing, for any VLAN, until fibre 1 fails.
| Problem with one tree | What it means | How one tree per VLAN helps |
|---|---|---|
| Wasted capacity | You paid for two fibres but use one | Block fibre 2 for some VLANs and fibre 1 for others, so both carry traffic |
| One root for all traffic | A VLAN's traffic must go through the one root, even if its servers are somewhere else. The longer path adds delay, which is bad for voice and video. | Put each VLAN's root next to its main traffic |
| Everything fails together | A problem in the tree affects every VLAN at once | Each VLAN recovers on its own. The others keep working. |
Sharing the load with different roots
Situation: you make SW1 the root for VLAN 10, and SW2 the root for VLAN 20. Now each VLAN blocks a different link:
VLAN 10: root SW1
- 1. VLAN 10 uses SW1–SW3… …and blocks SW2–SW3 at SW3.
VLAN 20: root SW2
- 1. VLAN 20 uses SW2–SW3… …the link that VLAN 10 blocks. VLAN 20 blocks SW1–SW3 at SW3 instead.
Why it works: in VLAN 20, SW2 is the root. So SW3's cheapest path is its direct link to SW2. On the SW1–SW3 link, both ends are cost 4 from SW2. SW1 has the lower MAC, so it wins designated, and SW3's end is blocked. Now both of SW3's uplinks carry traffic, each for different VLANs. And each one is still a backup for the other.
PVST+ BPDUs
Each VLAN sends its own BPDUs. On trunks, they are tagged with the VLAN number and sent to Cisco's special address 0100.0ccc.cccd. For VLAN 1, PVST+ also sends standard IEEE BPDUs (to 0180.c200.0000). This lets it work with other vendors' switches that run a single Common Spanning Tree.
Pros and cons
| CST (802.1D) | PVST+ / Rapid PVST+ | MST (802.1s) | |
|---|---|---|---|
| Number of trees | 1 | 1 per VLAN | A few, each for many VLANs |
| Uses all links | No | Yes, per VLAN | Yes, per tree |
| Work for the switch | Lowest | Grows with every VLAN | Low |
| Standard | IEEE | Cisco | IEEE |
With hundreds of VLANs, PVST+ means hundreds of trees and lots of BPDUs. Each switch model has a limit on how many trees it can run. That's where MST helps. For most office networks, Rapid PVST+ is the usual choice.
PVST, PVST+ and the names you'll see
| Name | Trunking | Notes |
|---|---|---|
| PVST | Cisco ISL only | The first per-VLAN version. No longer used, like ISL. |
| PVST+ | 802.1Q (and ISL) | Adds 802.1Q support. Works with other vendors' single standard tree through VLAN 1. |
| Rapid PVST+ | 802.1Q | RSTP for each VLAN (the Rapid Spanning Tree lessons). The default on modern Cisco switches. |
💡 On Cisco switches, the command spanning-tree mode pvst really runs PVST+. show spanning-tree shows it as protocol ieee (classic 802.1D rules). Rapid PVST+ shows rstp, and MST shows mstp.
Check yourself
With PVST+, can the same switch be root for VLAN 10 but not for VLAN 20?
A switch with 300 VLANs runs PVST+. What's the main cost?