Spanning Tree Protocol stops a switched network from destroying itself when there is more than one path between two switches.
Ethernet frames have no time to live field, so a broadcast caught in a loop circulates forever and multiplies at every switch. Spanning tree elects a root, blocks the redundant ports, and brings them back into service when a link fails.
- An Ethernet frame has no hop counter, so a loop never ends by itself
- The lowest bridge ID wins, which is usually the oldest switch
- Portfast and BPDU guard belong together on every access port
- RSTP converges in under a second, the original takes 30 to 50
- A blocking port is the protocol working, not a fault
On this page
The problemWhy a loop is fatal at layer 2
This is worth understanding properly, because it explains why the spanning tree protocol is worth its complexity.
An IP packet carries a time to live field. Every router decrements it, and a packet caught in a routing loop dies after a few dozen hops. A layer 2 network has no such field. An Ethernet frame has a source, a destination and no counter at all.
Now consider a switch receiving a broadcast frame, which it must flood out of every port except the one it arrived on. If two switches are connected by two cables, the frame goes out both ports, comes back on both, and each copy is flooded again.
The traffic doubles on every pass. Within seconds the switches are saturated forwarding copies of one frame, the processors reach one hundred percent, and the network carries no useful data.
That is a broadcast storm, and a second effect makes it worse. The same source address keeps arriving on different ports, so every switch rewrites its MAC address table continuously. Even unicast traffic stops being delivered correctly, because no switch on the network knows where anything is any more.
Both effects together take a network from working to dead in under a minute, and they do not clear until somebody physically removes a cable. That is the failure the spanning tree protocol exists to prevent.
The algorithmHow spanning tree decides which link to block
The spanning tree algorithm sounds elaborate and comes down to four elections, in order.
Elect the root bridge. Every switch announces a bridge ID, which is a configurable priority value followed by its MAC address. The lowest bridge ID wins and becomes the root. Every other decision in the process is measured relative to that one device.
Each other switch picks a root port. That is the port with the lowest cost path back to the root, where cost is derived from link speed: faster links have lower costs. This port is always in the forwarding state.
Each network segment picks a designated port. For every link between two devices, whichever end has the better path to the root becomes the designated port for that segment and forwards traffic.
Every other port blocks. Any port that is neither a root port nor a designated port is put into the blocking state. It receives BPDUs and forwards no data at all. That is the redundant path, held ready.
The switches keep announcing themselves with BPDUs every two seconds. If those stop arriving on a blocking port, the network topology has changed, and STP recalculates and moves that port to forwarding.
The port states, which is what a switch shows you against every interface.
| State | Forwards data | Learns MAC addresses | Listens to BPDUs | In RSTP |
|---|---|---|---|---|
| Blocking | No | No | Yes | Called discarding |
| Listening | No | No | Yes | Gone, merged into discarding |
| Learning | No | Yes | Yes | Kept |
| Forwarding | Yes | Yes | Yes | Kept |
| Disabled | No | No | No | Kept |
Under the original protocol a port walks blocking, listening, learning, forwarding, with a timer at each step, which is where the 30 to 50 seconds comes from. Rapid spanning tree collapses the first two into one discarding state and negotiates rather than waiting, so a port that should forward does so almost immediately.
The versionsThe spanning tree versions, and which one you are running
Three protocol names come up and the differences matter.
STP, 802.1D, the original, converges in 30 to 50 seconds because it moves each port through the listening and learning states on timers before forwarding. That delay was acceptable in 1990 and is not now.
RSTP, 802.1w, is rapid STP and is what any switch made in the last fifteen years actually runs, even when the menu still says spanning tree. It converges in under a second in most network topologies by having switches negotiate directly rather than waiting out timers.
MSTP, 802.1s, runs several STP instances so different VLANs can use different paths, which stops the redundant link from carrying no traffic at all. It is worth the configuration on a network with many VLANs and a real second path.
Cisco devices add their own spanning tree variants, PVST+ and Rapid PVST+, which run an instance per VLAN. They interoperate with the standards, and mixing them without care produces a network where different vendors have elected different roots.
The practical point: check which STP version your switches are running before changing anything, because the convergence times and the failure modes are different.
ConfigurationConfiguring spanning tree so it behaves
Spanning tree is enabled by default on managed switches, and by default it makes bad choices. Three settings turn the protocol from a hazard into a feature.
Set the root bridge deliberately. By default the lowest MAC address wins, which usually means the oldest switch in the building becomes the root of the network. Set the priority manually on the switch that should be root, normally a core switch, and set the second lowest priority on its neighbor so failover is predictable.
Turn on portfast, or edge port, on every access port. A port with a desktop on it does not need to move through the listening and learning states, and portfast puts it straight into forwarding.
Without it, a machine boots faster than the port changes state, which is the classic cause of a workstation that gets no address on a cold start.
Turn on BPDU guard everywhere portfast is enabled. Portfast tells the switch there is no switch on that port. BPDU guard enforces it: if a BPDU arrives on a portfast port, that port shuts down immediately.
It is what stops somebody plugging a small switch under a desk from becoming the root bridge for the entire network, which is a real event that happens regularly.
Those three settings together are the whole STP configuration for most networks. Root guard and loop guard are worth adding at the edges of a network you do not fully control.
PitfallsWhere people go wrong
Leaving the root bridge election to chance. The oldest device usually has the lowest MAC address and therefore wins. Every path in the network is then calculated toward a switch in a cupboard, and traffic takes links nobody designed it to take.
Portfast without BPDU guard. Portfast on its own says trust this port. BPDU guard is what makes that safe. One without the other is an invitation.
Disabling STP to fix a problem. It is the protocol that stops one mistake from taking down the building. Networks where it was turned off to solve something work fine until the day somebody patches a cable into the wrong port.
Assuming a blocking port means a broken cable. A port in the blocking state is STP working correctly. It looks like a fault in monitoring and it is a redundant link standing by.
Ignoring topology change notifications. One flapping link causes a spanning tree recalculation across the whole network and flushes the MAC address tables, which shows up as brief traffic loss everywhere. Frequent topology changes almost always trace back to a single unstable port, and finding it is what the counters are for.
Mixing vendors without checking the spanning tree mode. Cisco per VLAN instances and standard MSTP do interoperate and need deliberate configuration. Left to defaults, two vendors elect different roots and the forwarding paths make no sense.
Trusting that RSTP is enabled. Many switches ship with the older STP version enabled for compatibility. Check, because 30 seconds of outage on a link failure is a very different service than one second.
ComparisonThe three spanning tree versions, on convergence and what they do with the spare link
| Criterion | STP, 802.1D | RSTP, 802.1w | MSTP, 802.1s |
|---|---|---|---|
| Convergence after a failure | 30 to 50 s | Under a second | Under a second |
| Uses the redundant links normally | No | No | Yes, per VLAN |
| Configuration effort | Minimal | Minimal | Real |
| Right for a small flat network | Replace it | Yes | Overkill |
| Right for many VLANs and real redundancy | No | Workable | Yes |
| Backward compatible | Yes | Yes | Yes |
| What most switches run today | Rarely | Usually | Where configured |
The second row is the argument for MSTP. Under RSTP the redundant links forward nothing at all until something breaks, which on expensive links is a large amount of idle capacity.
FAQFrequently asked questions
What does Spanning Tree Protocol do?
STP finds loops in a switched network and blocks redundant ports so exactly one forwarding path exists between any two points, bringing them back when a link fails.
Why are layer 2 looping frames so damaging?
Ethernet frames have no time to live field, so a broadcast caught in a loop circulates forever and multiplies at every device. The network saturates within seconds.
What is a root bridge?
The switch every spanning tree path is measured from. It is elected by the lowest bridge ID, a priority value followed by a MAC address, and it should always be set deliberately rather than left to the election process.
What is a BPDU?
A bridge protocol data unit, the message switches exchange every two seconds to build and maintain the network topology. Their absence on a blocking port is what triggers a recalculation.
What is the difference between STP and RSTP?
Convergence speed. The original STP takes 30 to 50 seconds after a failure. Rapid STP negotiates directly and usually recovers in under a second.
What is portfast?
A setting that puts an access port straight into the forwarding state instead of moving through listening and learning. It belongs on every port with an end device and never on a port with a switch.
What is BPDU guard?
A control that shuts a port down if a BPDU arrives on it. Paired with portfast, it stops an unauthorized switch from participating in the election and becoming the root.
Should I disable STP?
No. It is what prevents one wrong cable from taking the network down. If STP is causing problems, the configuration is wrong rather than the protocol.
Why is one of my ports in the blocking state?
Because it is a redundant path and STP is doing exactly what it should. That port moves to forwarding if the active path fails.
How do I choose the root bridge?
Set a low priority value on the switch that should be root, and the next lowest on its neighbor, so both the primary and the backup are decided rather than inherited.
What is a broadcast storm?
The result of a looping frame: broadcasts multiplying until switches spend all their capacity forwarding copies and no other traffic gets through.
Does STP work across VLANs?
It depends on the version. Standard RSTP runs one instance for the whole network. MSTP and the Cisco per VLAN variants run several, which is what lets different VLANs take different paths.
What is the RSTP protocol?
RSTP is Rapid Spanning Tree Protocol, defined in IEEE 802.1w and now part of 802.1D. It does the same job as the original spanning tree, preventing loops, but converges in a few seconds instead of 30 to 50 by using handshakes between switches. Current switches run RSTP or a variant by default.
What is spanning tree PortFast?
PortFast is a setting for ports that connect to end devices. It skips the listening and learning states so the port forwards immediately, which stops computers timing out on DHCP at startup. It belongs only on access ports, and is normally paired with BPDU guard so a switch plugged in by mistake shuts the port.
Keep readingRelated concepts
Read next · Addressing What Is a Subnet? Spanning tree operates below the addressing, on the switches that carry the frames inside one subnet. Open this next15 min- Cabling and connectivity · 10 min Cat6 vs Cat6a The physical links spanning tree is deciding between, and how far each one reaches.
- Diagnostics · 11 min Ping and Traceroute A spanning tree recalculation shows up as brief loss everywhere, which is what these commands will catch.
- Design · 11 min Ring Topology, and the Networks Where It Never Went Away What keeps an Ethernet loop from destroying itself.
- Design · 9 min Hybrid Topology, and Why You Already Have One What holds the joints together.
- Routing · 12 min OSPF Explained The routing layer above the switches, once the loops have been dealt with.
- Protocols · 9 min What IGMP Is, and Why Multicast Floods Without It The neighboring switch feature.
- Cabling and connectivity · 11 min T568A vs T568B, and Why the Answer Is Almost Never Both What keeps the network standing when a cable ends up somewhere it should not.
- Switching · 14 min What Is a VLAN? What keeps a switched network standing once the trunks multiply.
- Switching · 12 min What Is VXLAN? What the underlay design was built to stop needing.
- Design · 12 min Star Topology, and Why the Building Decided It What has to be running before the second uplink goes in.
- Switching · 10 min Top of Rack Switching, and the Number Nobody Puts on the Datasheet Why the fabric moved away from a switched design.
- Switching · 9 min The MAC Address Table, and How to Find Which Port a Device Is On What keeps the table stable when there is more than one path.
- Switching · 9 min EtherChannel, Bundling Several Links Into One The protocol that would block a second parallel link without a bundle.