Routelearn.net
Course menu

Course 6: Spanning Tree ProtocolLesson 4.3 (18 of 24 in this course)39 of 91 in the CCNA series

Root Guard

Stopping an unexpected switch from taking over as root.

Intermediate · 5 min read

Root Guard is a Cisco Spanning Tree protection feature that prevents a port from becoming a root port. If a superior BPDU arrives on that port, the port is put into the root-inconsistent (blocked) state, so the chosen root bridge keeps its role.

In simple terms: You decide which switch is the centre of the network. Root Guard stops a new or misconfigured switch from taking that place.

The problem

Situation: SW1 was carefully chosen as the root. Someone connects a test switch to SW2, and that test switch has priority 0. Its BPDUs are superior (better than SW1's). Without protection, every switch would accept it as the new root. Traffic would then go through a switch on someone's desk.

What Root Guard does

On a port with Root Guard, the switch won't let that port become a root port. If a better BPDU arrives there, the port goes into the root-inconsistent state, which means blocked. The root stays where it is.

DPRPDPSW1 (root)priority 24576SW2Gi1/0/24 · Root GuardLab switchpriority 0
  1. 1. Normal. SW2 receives SW1's BPDUs on its root port.
  2. 2. A better root appears. The test switch's BPDU arrives on Gi1/0/24, a designated port with Root Guard.
  3. 3. Port blocked: root-inconsistent. SW2 blocks Gi1/0/24 instead of changing the root. SW1 stays the root for the whole network.
  4. 4. Recovers by itself. When the better BPDUs stop (the test switch is removed or changed), the port goes back to forwarding by itself.

Why priority 0 alone isn't protection

STP has no security of its own. The switch with the lowest bridge ID always wins. You can set your core switch to priority 0, but anyone else can do the same. Then the lower MAC address wins, and you can't control that. Two common ways this happens:

  • By mistake: an old switch from a test lab, still set to a low priority, is connected as a new access switch.
  • On purpose: someone unplugs their PC and connects a switch set up to become root, so traffic passes through it.

Either way, the wrong switch becomes the root, and STP rebuilds the whole tree around it. Fast core links may get blocked. Traffic takes longer paths. Every affected VLAN has a short outage while STP settles.

Where to put it

  • On designated ports that should never lead to the root. For example, distribution ports facing the access switches, and ports facing other companies or customers.
  • Never on a root port or alternate port. Those ports are meant to receive the root's BPDUs.
RGRGRGRGRGRGBGBGCoreroot, priority 0Dist 1secondary rootDist 2Access 1Access 2PCsPCs
  1. 1. Core: the root is in the core, so every core port faces away from it. All of them get Root Guard.
  2. 2. Distribution: ports facing the access switches get Root Guard. A new access switch with a low priority is blocked instead of becoming the root.
  3. 3. Access: user ports get BPDU Guard instead. It reacts to any BPDU at all, not just better ones (next lesson).

Configure and verify

interface GigabitEthernet1/0/24 spanning-tree guard root
Example output · based on Cisco documentation; exact format varies by platform and software version
%SPANTREE-2-ROOTGUARD_BLOCK: Root guard blocking port GigabitEthernet1/0/24 on VLAN0010.
Example output · based on Cisco documentation; exact format varies by platform and software version
SW2#show spanning-tree vlan 10 | begin Interface
Interface           Role Sts Cost      Prio.Nbr Type
------------------- ---- --- --------- -------- --------------------------------
Gi1/0/1             Root FWD 4         128.1    P2p
Gi1/0/24            Desg BKN*4         128.24   P2p *ROOT_Inc
BKN* means broken, not blocked. *ROOT_Inc gives the reason. In show spanning-tree interface Gi1/0/24 detail, the port is called "broken (Root Inconsistent)". This often comes up in exams.
Example output · based on Cisco documentation; exact format varies by platform and software version
SW2#show spanning-tree inconsistentports
Name                 Interface                Inconsistency
-------------------- ------------------------ ------------------
VLAN0010             GigabitEthernet1/0/24    Root Inconsistent

Number of inconsistent ports (segments) in the system : 1
The port shows as Root Inconsistent while better BPDUs keep arriving. Unlike BPDU Guard, you don't need to reset anything. It recovers by itself.

Check yourself

Predict · scenario 1

A Root Guard port receives a superior BPDU. What happens?

Predict · scenario 2

Why must Root Guard never be configured on a switch's root port?