The problem
Situation: SW1 was carefully chosen as the root. Someone connects a test switch to SW2, and that test switch has priority 0. Its BPDUs are superior (better than SW1's). Without protection, every switch would accept it as the new root. Traffic would then go through a switch on someone's desk.
What Root Guard does
On a port with Root Guard, the switch won't let that port become a root port. If a better BPDU arrives there, the port goes into the root-inconsistent state, which means blocked. The root stays where it is.
- 1. Normal. SW2 receives SW1's BPDUs on its root port.
- 2. A better root appears. The test switch's BPDU arrives on Gi1/0/24, a designated port with Root Guard.
- 3. Port blocked: root-inconsistent. SW2 blocks Gi1/0/24 instead of changing the root. SW1 stays the root for the whole network.
- 4. Recovers by itself. When the better BPDUs stop (the test switch is removed or changed), the port goes back to forwarding by itself.
Why priority 0 alone isn't protection
STP has no security of its own. The switch with the lowest bridge ID always wins. You can set your core switch to priority 0, but anyone else can do the same. Then the lower MAC address wins, and you can't control that. Two common ways this happens:
- By mistake: an old switch from a test lab, still set to a low priority, is connected as a new access switch.
- On purpose: someone unplugs their PC and connects a switch set up to become root, so traffic passes through it.
Either way, the wrong switch becomes the root, and STP rebuilds the whole tree around it. Fast core links may get blocked. Traffic takes longer paths. Every affected VLAN has a short outage while STP settles.
Where to put it
- On designated ports that should never lead to the root. For example, distribution ports facing the access switches, and ports facing other companies or customers.
- Never on a root port or alternate port. Those ports are meant to receive the root's BPDUs.
- 1. Core: the root is in the core, so every core port faces away from it. All of them get Root Guard.
- 2. Distribution: ports facing the access switches get Root Guard. A new access switch with a low priority is blocked instead of becoming the root.
- 3. Access: user ports get BPDU Guard instead. It reacts to any BPDU at all, not just better ones (next lesson).
Configure and verify
interface GigabitEthernet1/0/24
spanning-tree guard root%SPANTREE-2-ROOTGUARD_BLOCK: Root guard blocking port GigabitEthernet1/0/24 on VLAN0010.
SW2#show spanning-tree vlan 10 | begin Interface Interface Role Sts Cost Prio.Nbr Type ------------------- ---- --- --------- -------- -------------------------------- Gi1/0/1 Root FWD 4 128.1 P2p Gi1/0/24 Desg BKN*4 128.24 P2p *ROOT_Inc
show spanning-tree interface Gi1/0/24 detail, the port is called "broken (Root Inconsistent)". This often comes up in exams.SW2#show spanning-tree inconsistentports Name Interface Inconsistency -------------------- ------------------------ ------------------ VLAN0010 GigabitEthernet1/0/24 Root Inconsistent Number of inconsistent ports (segments) in the system : 1
Check yourself
A Root Guard port receives a superior BPDU. What happens?
Why must Root Guard never be configured on a switch's root port?