The last few lessons showed how STP builds a tree with no loops when nothing is changing. This lesson shows what happens when something changes. It also shows why STP needs an extra message, the topology change notification (TCN), as well as its normal BPDUs.
A stable network does two things all the time
- The root sends BPDUs every 2 seconds. The other switches pass them on out of their designated ports.
- Every switch learns MAC addresses from the frames it sees. It keeps each address for 300 seconds (5 minutes) after it last saw it.
Here is the network, working normally, with traffic between the two servers:
- 1. Traffic follows the tree: C → A → B → D. The C–D link is blocked at D's end.
- 2. BPDUs every 2 seconds: the root sends them. B and C pass them on out of their designated ports. Root ports and the blocked port only receive them.
| Switch | MAC table entry for Server 2 points to… |
|---|---|
| SW-C | Its root port, toward SW-A |
| SW-A | Its port toward SW-B |
| SW-B | Its port toward SW-D |
The A–C link fails: two problems
- 1. The link fails. Server 1 and Server 2 can't reach each other.
- 2. Problem 1: the backup path is blocked. D's port toward C must change from blocking to forwarding. With the classic timers, that takes 30 to 50 seconds.
- 3. Problem 2: old MAC entries. Even when that port forwards, B and A still think Server 1 is reached the old way. They send frames toward the broken link, and the frames are lost. This goes on until the old entries run out, which can take up to 5 minutes.
Problem 1 is fixed when STP works out the tree again (later in this lesson). Problem 2 is fixed by the topology change process. After a change, it tells every switch to remove MAC entries after 15 seconds (the forward delay) instead of 300. So the old, wrong entries disappear quickly, and the switches learn the correct paths again.
How the TCN process works
A topology change happens when a port starts forwarding, or when a forwarding port goes down. (PortFast ports don't count.) This is what happens next:
- 1. A forwarding port goes down. The access switch's port to the server (no PortFast) fails.
- 2. TCN out the root port. It sends a TCN BPDU toward the root. It repeats it every 2 seconds until someone confirms they got it.
- 3. Acknowledged… The distribution switch replies with the TCA flag turned on in its next BPDU. TCA means "I got it"…
- 4. …and relays it. Each switch confirms to the switch below, then sends its own TCN out of its own root port. So the message climbs, switch by switch, up to the root.
- 5. The root tells everyone. The root doesn't send a TCN. Instead, it turns on the TC flag in its normal BPDUs for 35 seconds (max age + forward delay). Every switch passes these BPDUs on down the tree.
| Message or flag | Sent by | Direction | Meaning |
|---|---|---|---|
| TCN BPDU | The switch that saw the change, then each switch on the way up | Up, out of root ports | "Something changed" (it says nothing about what) |
| TCA flag | The next switch up, in a normal BPDU | Down, one hop | "Got it, stop repeating your TCN" |
| TC flag | The root, in its normal BPDUs, for 35 s | Down, to every switch | "Use short MAC aging now" |
While switches see the TC flag, they remove any MAC entry that hasn't been used for 15 seconds. Devices that keep sending traffic stay in the table. Only quiet devices, or devices that moved, are removed and learned again. After 35 seconds, the time goes back to 300 seconds.
💡 What if the root itself sees the change? It has no root port and no switch above it. So it doesn't send a TCN at all. It just turns on the TC flag in its own BPDUs straight away. Many people get this wrong, but this is how the 802.1D standard works.
⚠️ The TCN process only shortens the MAC aging time. It doesn't choose root ports, change port roles or unblock anything. Those things are done separately, by the normal BPDUs.
Superior and inferior BPDUs
To follow what happens next, you need one more idea: each port remembers the best BPDU it has heard.
| Superior BPDU | Inferior BPDU | |
|---|---|---|
| Means | Better information: a lower root ID, a lower cost, or a better sender | Worse information than the port already has |
| Reaction | Keep it. Work out the roles again if it changes the best path. | Ignore it while the stored best BPDU is still valid |
A stored BPDU stays valid for max age (20 s) after the last one arrived. If the root's BPDUs stop arriving on a port, the switch keeps the old information until max age runs out. Only then does it accept worse information. This waiting is why indirect failures are slow.
Walkthrough: the A–C failure, second by second
- 1. 0 s, SW-C (direct failure): its root port is down, so it throws away that BPDU. It hears no other BPDUs from the root (D's port toward it is blocked and silent). So C says it is the root and sends its own BPDUs.
- 2. 0 s, SW-A (the root, direct failure): its designated port went down, so it turns on the TC flag in its BPDUs. SW-B and SW-D shorten MAC aging to 15 s.
- 3. 0–20 s, SW-D (indirect failure): it hears C saying it is the root. But that is worse than the information D has stored for that port. D ignores it until max age runs out.
- 4. 20 s, SW-D: the old BPDU runs out. D's port toward C becomes designated and starts listening. It sends A's (better) BPDUs to C.
- 5. ~20 s, SW-C: the better BPDU arrives. C stops saying it is the root, and makes its port toward D its new root port.
- 6. ~50 s, converged: D's port finishes listening (15 s) and learning (15 s), and starts forwarding. The short MAC aging has already removed the old entries, so traffic flows again.
| Switch | How it learns of the failure | What it does | Time |
|---|---|---|---|
| SW-A (root) | Directly: its own port goes down | Sets the TC flag | Immediately |
| SW-B | Through the TC flag | Shortens MAC aging. No role changes. | Seconds |
| SW-C | Directly: its root port goes down | Says it is root, then picks a new root port when better BPDUs arrive | ~20 s for the new root port |
| SW-D | Indirectly: only via max age | Blocked port → designated → listening → learning → forwarding | 20 + 15 + 15 = ~50 s |
The network has converged (settled) when every port is blocking or forwarding, and none is still listening or learning. SW-D's ~50 seconds is the usual time for an indirect failure (the “Port states and timers” lesson). This slowness is why Cisco added BackboneFast (the “UplinkFast and BackboneFast” lesson), and why RSTP was created (the Rapid Spanning Tree lessons).
How to verify
SW1#show spanning-tree vlan 10 detail | include topology|occurred|from Number of topology changes 14 last change occurred 00:00:47 ago from GigabitEthernet1/0/10
RSTP does this differently
In Rapid Spanning Tree, the switch that sees a change sends TC BPDUs itself, and removes the affected MAC entries at once. It doesn't ask the root to do it. Also, only a port that starts forwarding counts as a change, not a port going down. See the “Introduction to Rapid PVST+” lesson.
Key takeaways
- Two separate things happen after a change. Normal BPDUs work out the roles and states again. The TCN process only removes old MAC entries faster.
- The TCN goes up through root ports, one switch at a time. Each switch confirms it with TCA. Then the root turns on the TC flag for 35 s.
- With TC on, MAC aging drops from 300 s to 15 s, so lost traffic recovers quickly.
- A better BPDU on a port causes a role change. A worse one is ignored until max age runs out.
- Direct failures recover in ~30 s. Indirect failures take ~50 s, because of max age.
Check yourself
What is the only thing the TCN process changes?
The root bridge's own designated port goes down. What does the root do?
A switch receives a BPDU on its blocked port claiming a worse root than the one it has stored. What does it do?
Why can traffic be blackholed even after the backup port is forwarding?