Routelearn.net
Course menu

Course 6: Spanning Tree ProtocolLesson 2.2 (5 of 24 in this course)26 of 91 in the CCNA series

The Spanning Tree Algorithm

Step by step: root bridge, root ports, designated ports, and the tie-breakers.

Intermediate · 9 min read

The Spanning Tree Algorithm (STA) is the procedure STP uses to turn a looped switched topology into a loop-free tree: elect the root bridge with the lowest bridge ID, pick each non-root switch’s root port by lowest root path cost, pick one designated port per segment, and block the rest, using bridge ID and port ID as tie-breakers.

In simple terms: It is the set of steps switches follow to agree on a single central switch and the shortest way to reach it, then block any extra links that would make a loop.

"Bridge" just means switch

Spanning Tree was invented before switches existed. Back then, LANs were joined by devices called bridges. That's why you'll see words like bridge ID, bridge priority and root bridge. Bridges are not used any more. When STP says "bridge", think "switch".

Why it's called a spanning tree

A tree grows out from its root. It splits into branches, and the branches never join up again. So nothing can go round in a circle. STP builds the same shape. It chooses one switch as the root. Then it makes exactly one path from the root to every other switch. Any link that would join two branches together is turned off for now. The result reaches ("spans") every switch, in the shape of a tree.

The five steps

  1. Choose the root bridge: the switch with the lowest bridge ID.
  2. Choose root ports: every other switch picks its cheapest port toward the root.
  3. Choose designated ports: one forwarding port on each link (also called a segment).
  4. Block the rest: every port that is not a root port or a designated port.
  5. Keep watching: if BPDUs stop or change, work it all out again and unblock a backup if needed.

This lesson covers step 1 and how path cost works. The “Spanning Tree port roles” lesson explains steps 2–4 in detail.

The bridge ID

Every switch has an 8-byte bridge ID (BID). The switch with the lowest BID becomes the root.

How two BIDs are compared: first the priority. The MAC address is only used if the priorities are the same.

Switch ASwitch BLower BIDWhy
32768 · 0200.0000.00114096 · 0200.0000.0022BLower priority, so the MAC is not checked
32768 · 0200.0000.001132768 · 0200.0000.0022ASame priority, lower MAC

You can set the priority in steps of 4096, from 0 to 61440 (the “Configuring PVST+” lesson). If you leave the default, the switch with the lowest MAC address wins. This is often just the oldest switch.

💡 On today's Cisco switches (PVST+, the PVST+ lessons) there is a separate tree for each VLAN. So the VLAN number is put inside the priority field. The 2 bytes are split into a 4-bit priority and a 12-bit extended system ID (the VLAN number). That's why the same switch shows 32769 in VLAN 1, 32778 in VLAN 10 and 32868 in VLAN 100 (32768 + the VLAN number). It's also why priorities go up in steps of 4096.

BPDUs: how switches share information

Switches send each other configuration BPDUs. People often call them "hello" BPDUs, because they are sent every hello time (2 seconds). These are the fields STP uses:

FieldUsed for
Root bridge IDWho the sender believes is root
Root path costThe sender's total cost to that root
Sender bridge IDWho sent this BPDU
Sender port IDWhich port it left from (port priority + number)
FlagsTopology change (TC) and acknowledgement (TCA), the “Topology changes (TCN)” lesson
Message age, max age, hello, forward delayTimers, the “Port states and timers” lesson

Step 1: electing the root bridge

When a switch starts up, it knows nothing about the other switches. So it thinks it is the root. It puts its own BID in the root field, with cost 0, and starts sending BPDUs. Then it compares the BPDUs it receives:

  • A BPDU with a lower root ID is superior (better). It means a better root exists. The switch stops claiming to be root and accepts the new one. From now on it puts the new root ID in its own BPDUs, so switches further away hear about it too.
  • A BPDU with a higher root ID is inferior (worse). The switch already knows a better root, so it ignores this BPDU.
SW1priority 24576SW2priority 32768SW3priority 32768PC APC B
  1. 1. Everyone starts as root. Each switch says its own BID is the root.
  2. 2. SW1's claim is the best. SW2 and SW3 receive SW1's BPDUs with a lower root ID (24576). These are superior, so both accept SW1 as root.
  3. 3. Worse claims are ignored. SW1 hears SW2's and SW3's first claims. They are worse than its own, so SW1 stays root.
  4. 4. Everyone agrees. SW2 and SW3 now name SW1 as root in their own BPDUs. In a bigger network, this is how switches far away hear about the root.

After the root is chosen, in classic 802.1D only the root creates new BPDUs, every 2 seconds. The other switches pass them on out of their designated ports. Before passing them on, they update the cost and sender fields.

Every switch now agrees on the root:

Example output · based on Cisco documentation; exact format varies by platform and software version
SW1#show spanning-tree vlan 1
VLAN0001
  Spanning tree enabled protocol ieee
  Root ID    Priority    24577
             Address     0200.0000.0001
             This bridge is the root
             Hello Time   2 sec  Max Age 20 sec  Forward Delay 15 sec

  Bridge ID  Priority    24577  (priority 24576 sys-id-ext 1)
             Address     0200.0000.0001
...
Interface           Role Sts Cost      Prio.Nbr Type
------------------- ---- --- --------- -------- --------------------------------
Gi1/0/1             Desg FWD 4         128.1    P2p
Gi1/0/2             Desg FWD 4         128.2    P2p
On the root, the Root ID and Bridge ID are the same, and it says This bridge is the root. All of its ports are designated.
Example output · based on Cisco documentation; exact format varies by platform and software version
SW2#show spanning-tree vlan 1
VLAN0001
  Spanning tree enabled protocol ieee
  Root ID    Priority    24577
             Address     0200.0000.0001
             Cost        4
             Port        1 (GigabitEthernet1/0/1)
...
  Bridge ID  Priority    32769  (priority 32768 sys-id-ext 1)
             Address     0200.0000.0002
On SW2, the Root ID is SW1's. It also shows SW2's cost to reach the root (4) and the port it uses (its root port). SW2's own Bridge ID is different.

Root path cost: how distance is measured

The root sends cost 0. Each switch adds the cost of the port where the BPDU came in, and sends out the new total:

SW1priority 24576SW2priority 32768SW3priority 32768PC APC B
  1. 1. Root advertises 0. SW1's BPDUs say: root = SW1, cost 0.
  2. 2. Each adds its port cost. SW2 and SW3 received cost 0 on a 1 Gbps port (cost 4). So each one is 4 away from the root, and that's the cost they send out.
  3. 3. Compare the options. Through SW2, SW3's cost would be 4 + 4 = 8. Directly, it is 4. The lowest wins, so the direct port becomes SW3's root port (the “Spanning Tree port roles” lesson).
Link speedShort cost (802.1D)Long cost (pathcost method long)
10 Mbps1002,000,000
100 Mbps19200,000
1 Gbps420,000
10 Gbps22,000
100 Gbps—200

Faster links cost less. The long method can tell apart very fast speeds that the short method can't. Use the same method on every switch.

The tie-breakers

Every STP comparison uses the same order. Go down the list until you find a difference:

  1. Lowest root bridge ID: the BPDU with the better root.
  2. Lowest root path cost.
  3. Lowest sender bridge ID.
  4. Lowest sender port ID: port priority (default 128), then port number.

Check yourself

Predict · scenario 1

A newly booted switch has heard no BPDUs yet. Who does it think the root is?

Predict · scenario 2

Which bridge ID wins: 32778 · 0200.0000.0001 or 28682 · 0200.0000.00FF?

Predict · scenario 3

A switch reaches the root via a 100 Mbps link directly (19), or via a neighbour over two 1 Gbps links (4 + 4). Which path wins?