Routelearn.net
Course menu

Course 6: Spanning Tree ProtocolLesson 2.5 (8 of 24 in this course)29 of 91 in the CCNA series

Topology changes (TCN)

How switches tell each other that the topology changed, and why MAC tables age faster afterwards.

Intermediate · 6 min read

TCN (Topology Change Notification) is a special BPDU that an 802.1D switch sends out of its root port when one of its ports starts forwarding or a forwarding port goes down. It is relayed hop by hop to the root bridge, which then sets the TC flag in its BPDUs so that every switch temporarily shortens its MAC address aging time from 300 seconds to the forward delay of 15 seconds.

In simple terms: After a link changes, switches may still remember old paths to some devices. A TCN warns the root, and the root tells every switch to forget unused addresses quickly so they are learned again on the new paths.

The last few lessons showed how STP builds a tree with no loops when nothing is changing. This lesson shows what happens when something changes. It also shows why STP needs an extra message, the topology change notification (TCN), as well as its normal BPDUs.

A stable network does two things all the time

  • The root sends BPDUs every 2 seconds. The other switches pass them on out of their designated ports.
  • Every switch learns MAC addresses from the frames it sees. It keeps each address for 300 seconds (5 minutes) after it last saw it.

Here is the network, working normally, with traffic between the two servers:

DPRPDPRPDPRPDPBLKSW-A (root)SW-BSW-CSW-DServer 1Server 2
  1. 1. Traffic follows the tree: C → A → B → D. The C–D link is blocked at D's end.
  2. 2. BPDUs every 2 seconds: the root sends them. B and C pass them on out of their designated ports. Root ports and the blocked port only receive them.
SwitchMAC table entry for Server 2 points to…
SW-CIts root port, toward SW-A
SW-AIts port toward SW-B
SW-BIts port toward SW-D

The A–C link fails: two problems

DPRP✕ link downDPRPDPRPDPBLKSW-A (root)SW-BSW-CSW-DServer 1Server 2
  1. 1. The link fails. Server 1 and Server 2 can't reach each other.
  2. 2. Problem 1: the backup path is blocked. D's port toward C must change from blocking to forwarding. With the classic timers, that takes 30 to 50 seconds.
  3. 3. Problem 2: old MAC entries. Even when that port forwards, B and A still think Server 1 is reached the old way. They send frames toward the broken link, and the frames are lost. This goes on until the old entries run out, which can take up to 5 minutes.

Problem 1 is fixed when STP works out the tree again (later in this lesson). Problem 2 is fixed by the topology change process. After a change, it tells every switch to remove MAC entries after 15 seconds (the forward delay) instead of 300. So the old, wrong entries disappear quickly, and the switches learn the correct paths again.

How the TCN process works

A topology change happens when a port starts forwarding, or when a forwarding port goes down. (PortFast ports don't count.) This is what happens next:

✕ link downRPDPRPDPRPDPAccessdetects changeDistributionCoreRootServer
  1. 1. A forwarding port goes down. The access switch's port to the server (no PortFast) fails.
  2. 2. TCN out the root port. It sends a TCN BPDU toward the root. It repeats it every 2 seconds until someone confirms they got it.
  3. 3. Acknowledged… The distribution switch replies with the TCA flag turned on in its next BPDU. TCA means "I got it"…
  4. 4. …and relays it. Each switch confirms to the switch below, then sends its own TCN out of its own root port. So the message climbs, switch by switch, up to the root.
  5. 5. The root tells everyone. The root doesn't send a TCN. Instead, it turns on the TC flag in its normal BPDUs for 35 seconds (max age + forward delay). Every switch passes these BPDUs on down the tree.
Message or flagSent byDirectionMeaning
TCN BPDUThe switch that saw the change, then each switch on the way upUp, out of root ports"Something changed" (it says nothing about what)
TCA flagThe next switch up, in a normal BPDUDown, one hop"Got it, stop repeating your TCN"
TC flagThe root, in its normal BPDUs, for 35 sDown, to every switch"Use short MAC aging now"

While switches see the TC flag, they remove any MAC entry that hasn't been used for 15 seconds. Devices that keep sending traffic stay in the table. Only quiet devices, or devices that moved, are removed and learned again. After 35 seconds, the time goes back to 300 seconds.

💡 What if the root itself sees the change? It has no root port and no switch above it. So it doesn't send a TCN at all. It just turns on the TC flag in its own BPDUs straight away. Many people get this wrong, but this is how the 802.1D standard works.

⚠️ The TCN process only shortens the MAC aging time. It doesn't choose root ports, change port roles or unblock anything. Those things are done separately, by the normal BPDUs.

Superior and inferior BPDUs

To follow what happens next, you need one more idea: each port remembers the best BPDU it has heard.

Superior BPDUInferior BPDU
MeansBetter information: a lower root ID, a lower cost, or a better senderWorse information than the port already has
ReactionKeep it. Work out the roles again if it changes the best path.Ignore it while the stored best BPDU is still valid

A stored BPDU stays valid for max age (20 s) after the last one arrived. If the root's BPDUs stop arriving on a port, the switch keeps the old information until max age runs out. Only then does it accept worse information. This waiting is why indirect failures are slow.

Walkthrough: the A–C failure, second by second

DPRP✕ link downDPRPDPRPDPBLKSW-A (root)SW-BSW-CSW-DServer 1Server 2
  1. 1. 0 s, SW-C (direct failure): its root port is down, so it throws away that BPDU. It hears no other BPDUs from the root (D's port toward it is blocked and silent). So C says it is the root and sends its own BPDUs.
  2. 2. 0 s, SW-A (the root, direct failure): its designated port went down, so it turns on the TC flag in its BPDUs. SW-B and SW-D shorten MAC aging to 15 s.
  3. 3. 0–20 s, SW-D (indirect failure): it hears C saying it is the root. But that is worse than the information D has stored for that port. D ignores it until max age runs out.
  4. 4. 20 s, SW-D: the old BPDU runs out. D's port toward C becomes designated and starts listening. It sends A's (better) BPDUs to C.
  5. 5. ~20 s, SW-C: the better BPDU arrives. C stops saying it is the root, and makes its port toward D its new root port.
  6. 6. ~50 s, converged: D's port finishes listening (15 s) and learning (15 s), and starts forwarding. The short MAC aging has already removed the old entries, so traffic flows again.
SwitchHow it learns of the failureWhat it doesTime
SW-A (root)Directly: its own port goes downSets the TC flagImmediately
SW-BThrough the TC flagShortens MAC aging. No role changes.Seconds
SW-CDirectly: its root port goes downSays it is root, then picks a new root port when better BPDUs arrive~20 s for the new root port
SW-DIndirectly: only via max ageBlocked port → designated → listening → learning → forwarding20 + 15 + 15 = ~50 s

The network has converged (settled) when every port is blocking or forwarding, and none is still listening or learning. SW-D's ~50 seconds is the usual time for an indirect failure (the “Port states and timers” lesson). This slowness is why Cisco added BackboneFast (the “UplinkFast and BackboneFast” lesson), and why RSTP was created (the Rapid Spanning Tree lessons).

How to verify

Example output · based on Cisco documentation; exact format varies by platform and software version
SW1#show spanning-tree vlan 10 detail | include topology|occurred|from
  Number of topology changes 14 last change occurred 00:00:47 ago
          from GigabitEthernet1/0/10
This shows how often the tree has changed, and which port the last change came from. Follow that port from switch to switch to find where it started. If the number keeps going up, the cause is usually a user port without PortFast, or a link that keeps going up and down.

RSTP does this differently

In Rapid Spanning Tree, the switch that sees a change sends TC BPDUs itself, and removes the affected MAC entries at once. It doesn't ask the root to do it. Also, only a port that starts forwarding counts as a change, not a port going down. See the “Introduction to Rapid PVST+” lesson.

Key takeaways

✅ The bottom line
  • Two separate things happen after a change. Normal BPDUs work out the roles and states again. The TCN process only removes old MAC entries faster.
  • The TCN goes up through root ports, one switch at a time. Each switch confirms it with TCA. Then the root turns on the TC flag for 35 s.
  • With TC on, MAC aging drops from 300 s to 15 s, so lost traffic recovers quickly.
  • A better BPDU on a port causes a role change. A worse one is ignored until max age runs out.
  • Direct failures recover in ~30 s. Indirect failures take ~50 s, because of max age.

Check yourself

Predict · scenario 1

What is the only thing the TCN process changes?

Predict · scenario 2

The root bridge's own designated port goes down. What does the root do?

Predict · scenario 3

A switch receives a BPDU on its blocked port claiming a worse root than the one it has stored. What does it do?

Predict · scenario 4

Why can traffic be blackholed even after the backup port is forwarding?