Networking · Concept · 11 min read

Spanning Tree Protocol: Why a Redundant Cable Can Take a Network Down

An Ethernet frame has no hop counter, so a loop at layer 2 is permanent until somebody pulls a cable. Here is what spanning tree does about that, the three settings that make it behave, and why a blocking port is good news.

Written by Marko Ristic, Editor Updated Sep 17, 2026
0Hop counters in an Ethernet frame, which is the whole problem
2 sHow often switches announce themselves with a BPDU
3Settings that turn spanning tree from a hazard into a feature
<1 sRSTP convergence, against 30 to 50 for the original
Short answer

Spanning Tree Protocol stops a switched network from destroying itself when there is more than one path between two switches.

Ethernet frames have no time to live field, so a broadcast caught in a loop circulates forever and multiplies at every switch. Spanning tree elects a root, blocks the redundant ports, and brings them back into service when a link fails.

  • An Ethernet frame has no hop counter, so a loop never ends by itself
  • The lowest bridge ID wins, which is usually the oldest switch
  • Portfast and BPDU guard belong together on every access port
  • RSTP converges in under a second, the original takes 30 to 50
  • A blocking port is the protocol working, not a fault
On this page

The problemWhy a loop is fatal at layer 2

This is worth understanding properly, because it explains why the spanning tree protocol is worth its complexity.

An IP packet carries a time to live field. Every router decrements it, and a packet caught in a routing loop dies after a few dozen hops. A layer 2 network has no such field. An Ethernet frame has a source, a destination and no counter at all.

Now consider a switch receiving a broadcast frame, which it must flood out of every port except the one it arrived on. If two switches are connected by two cables, the frame goes out both ports, comes back on both, and each copy is flooded again.

The traffic doubles on every pass. Within seconds the switches are saturated forwarding copies of one frame, the processors reach one hundred percent, and the network carries no useful data.

That is a broadcast storm, and a second effect makes it worse. The same source address keeps arriving on different ports, so every switch rewrites its MAC address table continuously. Even unicast traffic stops being delivered correctly, because no switch on the network knows where anything is any more.

Both effects together take a network from working to dead in under a minute, and they do not clear until somebody physically removes a cable. That is the failure the spanning tree protocol exists to prevent.

The algorithmHow spanning tree decides which link to block

The spanning tree algorithm sounds elaborate and comes down to four elections, in order.

Elect the root bridge. Every switch announces a bridge ID, which is a configurable priority value followed by its MAC address. The lowest bridge ID wins and becomes the root. Every other decision in the process is measured relative to that one device.

Each other switch picks a root port. That is the port with the lowest cost path back to the root, where cost is derived from link speed: faster links have lower costs. This port is always in the forwarding state.

Each network segment picks a designated port. For every link between two devices, whichever end has the better path to the root becomes the designated port for that segment and forwards traffic.

Every other port blocks. Any port that is neither a root port nor a designated port is put into the blocking state. It receives BPDUs and forwards no data at all. That is the redundant path, held ready.

The switches keep announcing themselves with BPDUs every two seconds. If those stop arriving on a blocking port, the network topology has changed, and STP recalculates and moves that port to forwarding.

The port states, which is what a switch shows you against every interface.

StateForwards dataLearns MAC addressesListens to BPDUsIn RSTP
BlockingNoNoYesCalled discarding
ListeningNoNoYesGone, merged into discarding
LearningNoYesYesKept
ForwardingYesYesYesKept
DisabledNoNoNoKept

Under the original protocol a port walks blocking, listening, learning, forwarding, with a timer at each step, which is where the 30 to 50 seconds comes from. Rapid spanning tree collapses the first two into one discarding state and negotiates rather than waiting, so a port that should forward does so almost immediately.

The versionsThe spanning tree versions, and which one you are running

Three protocol names come up and the differences matter.

STP, 802.1D, the original, converges in 30 to 50 seconds because it moves each port through the listening and learning states on timers before forwarding. That delay was acceptable in 1990 and is not now.

RSTP, 802.1w, is rapid STP and is what any switch made in the last fifteen years actually runs, even when the menu still says spanning tree. It converges in under a second in most network topologies by having switches negotiate directly rather than waiting out timers.

MSTP, 802.1s, runs several STP instances so different VLANs can use different paths, which stops the redundant link from carrying no traffic at all. It is worth the configuration on a network with many VLANs and a real second path.

Cisco devices add their own spanning tree variants, PVST+ and Rapid PVST+, which run an instance per VLAN. They interoperate with the standards, and mixing them without care produces a network where different vendors have elected different roots.

The practical point: check which STP version your switches are running before changing anything, because the convergence times and the failure modes are different.

ConfigurationConfiguring spanning tree so it behaves

Spanning tree is enabled by default on managed switches, and by default it makes bad choices. Three settings turn the protocol from a hazard into a feature.

Set the root bridge deliberately. By default the lowest MAC address wins, which usually means the oldest switch in the building becomes the root of the network. Set the priority manually on the switch that should be root, normally a core switch, and set the second lowest priority on its neighbor so failover is predictable.

Turn on portfast, or edge port, on every access port. A port with a desktop on it does not need to move through the listening and learning states, and portfast puts it straight into forwarding.

Without it, a machine boots faster than the port changes state, which is the classic cause of a workstation that gets no address on a cold start.

Turn on BPDU guard everywhere portfast is enabled. Portfast tells the switch there is no switch on that port. BPDU guard enforces it: if a BPDU arrives on a portfast port, that port shuts down immediately.

It is what stops somebody plugging a small switch under a desk from becoming the root bridge for the entire network, which is a real event that happens regularly.

Those three settings together are the whole STP configuration for most networks. Root guard and loop guard are worth adding at the edges of a network you do not fully control.

PitfallsWhere people go wrong

Leaving the root bridge election to chance. The oldest device usually has the lowest MAC address and therefore wins. Every path in the network is then calculated toward a switch in a cupboard, and traffic takes links nobody designed it to take.

Portfast without BPDU guard. Portfast on its own says trust this port. BPDU guard is what makes that safe. One without the other is an invitation.

Disabling STP to fix a problem. It is the protocol that stops one mistake from taking down the building. Networks where it was turned off to solve something work fine until the day somebody patches a cable into the wrong port.

Assuming a blocking port means a broken cable. A port in the blocking state is STP working correctly. It looks like a fault in monitoring and it is a redundant link standing by.

Ignoring topology change notifications. One flapping link causes a spanning tree recalculation across the whole network and flushes the MAC address tables, which shows up as brief traffic loss everywhere. Frequent topology changes almost always trace back to a single unstable port, and finding it is what the counters are for.

Mixing vendors without checking the spanning tree mode. Cisco per VLAN instances and standard MSTP do interoperate and need deliberate configuration. Left to defaults, two vendors elect different roots and the forwarding paths make no sense.

Trusting that RSTP is enabled. Many switches ship with the older STP version enabled for compatibility. Check, because 30 seconds of outage on a link failure is a very different service than one second.

THREE SWITCHES, ONE LOOP, ONE BLOCKED PORTSWITCH Athe root bridgeSWITCH Broot port to ASWITCH Croot port to ABLOCKINGWITHOUT SPANNING TREEOne broadcast frame goes round thetriangle forever, doubling at everyswitch. The network dies in seconds.WITH SPANNING TREEOne port blocks, so exactly one pathexists between any two switches. Ifa live link fails, the blocked portstarts forwarding within a second.The dashed link is not broken and not unplugged. It is a redundant path being held ready,which is why a blocking port in a monitoring dashboard is usually correct rather than a fault.
The smallest topology with a loop in it, and the one port spanning tree blocks to break it.

ComparisonThe three spanning tree versions, on convergence and what they do with the spare link

CriterionSTP, 802.1DRSTP, 802.1wMSTP, 802.1s
Convergence after a failure30 to 50 sUnder a secondUnder a second
Uses the redundant links normallyNoNoYes, per VLAN
Configuration effortMinimalMinimalReal
Right for a small flat networkReplace itYesOverkill
Right for many VLANs and real redundancyNoWorkableYes
Backward compatibleYesYesYes
What most switches run todayRarelyUsuallyWhere configured

The second row is the argument for MSTP. Under RSTP the redundant links forward nothing at all until something breaks, which on expensive links is a large amount of idle capacity.

FAQFrequently asked questions

What does Spanning Tree Protocol do?

STP finds loops in a switched network and blocks redundant ports so exactly one forwarding path exists between any two points, bringing them back when a link fails.

Why are layer 2 looping frames so damaging?

Ethernet frames have no time to live field, so a broadcast caught in a loop circulates forever and multiplies at every device. The network saturates within seconds.

What is a root bridge?

The switch every spanning tree path is measured from. It is elected by the lowest bridge ID, a priority value followed by a MAC address, and it should always be set deliberately rather than left to the election process.

What is a BPDU?

A bridge protocol data unit, the message switches exchange every two seconds to build and maintain the network topology. Their absence on a blocking port is what triggers a recalculation.

What is the difference between STP and RSTP?

Convergence speed. The original STP takes 30 to 50 seconds after a failure. Rapid STP negotiates directly and usually recovers in under a second.

What is portfast?

A setting that puts an access port straight into the forwarding state instead of moving through listening and learning. It belongs on every port with an end device and never on a port with a switch.

What is BPDU guard?

A control that shuts a port down if a BPDU arrives on it. Paired with portfast, it stops an unauthorized switch from participating in the election and becoming the root.

Should I disable STP?

No. It is what prevents one wrong cable from taking the network down. If STP is causing problems, the configuration is wrong rather than the protocol.

Why is one of my ports in the blocking state?

Because it is a redundant path and STP is doing exactly what it should. That port moves to forwarding if the active path fails.

How do I choose the root bridge?

Set a low priority value on the switch that should be root, and the next lowest on its neighbor, so both the primary and the backup are decided rather than inherited.

What is a broadcast storm?

The result of a looping frame: broadcasts multiplying until switches spend all their capacity forwarding copies and no other traffic gets through.

Does STP work across VLANs?

It depends on the version. Standard RSTP runs one instance for the whole network. MSTP and the Cisco per VLAN variants run several, which is what lets different VLANs take different paths.

What is the RSTP protocol?

RSTP is Rapid Spanning Tree Protocol, defined in IEEE 802.1w and now part of 802.1D. It does the same job as the original spanning tree, preventing loops, but converges in a few seconds instead of 30 to 50 by using handshakes between switches. Current switches run RSTP or a variant by default.

What is spanning tree PortFast?

PortFast is a setting for ports that connect to end devices. It skips the listening and learning states so the port forwards immediately, which stops computers timing out on DHCP at startup. It belongs only on access ports, and is normally paired with BPDU guard so a switch plugged in by mistake shuts the port.

Read next · Addressing What Is a Subnet? Spanning tree operates below the addressing, on the switches that carry the frames inside one subnet. Open this next15 min
Also worth reading
One packet a weekA short, illustrated explainer every Tuesday. No vendor pitches, unsubscribe in one click.