skip to content

In a looped Layer 2 access design, why should a VLAN's VRRP Active Router sit on the distribution switch that is that VLAN's spanning-tree root?

level: seniorimportance: should knowfreq 22%

answer

  1. one uplink is blocked
  2. forwarding path leads to the root
  3. traffic crosses the inter-switch link
  4. same switch, same VLAN
  5. alternate VLANs between switches

basics

~20 s

Spanning tree leaves each access switch forwarding toward the VLAN's root. If VRRP's Active Router is the other distribution switch, every upstream frame crosses the inter-distribution link; co-locating root and Active keeps the path one hop.

solid answer

~50 s

Picture access switch A1 dual-homed to distribution switches D1 and D2, which share a trunk and run VRRP for VLAN 10. That triangle is a loop, so spanning tree blocks one port: with D1 as root and typical priorities, A1's uplink to D2. If D2 is the VRRP Active Router, every host frame to the virtual MAC goes A1 to D1, across the D1-D2 link, and only then gets routed. That adds a hop, makes the inter-distribution link carry all upstream traffic for the VLAN, and leaves D1's routing idle. Making D1 both root and Active for VLAN 10 sends traffic straight up the forwarding uplink. To use both switches, alternate: D1 is root and Active for even VLANs, D2 for odd ones, with per-VLAN trees or MSTP instances. Keep them aligned after recovery too: spanning tree returns the root to D1 on its own, while VRRP returns only if D1 preempts.

go deeper

for a junior

Remember that in a looped access block one uplink is blocked, and the gateway should be on the switch the forwarding uplink leads to.

for a middle

Trace a frame to the virtual MAC when root and Active Router differ, and explain how alternating VLANs between two switches shares the load.

for a senior

Show how alignment survives failure and recovery: preemption with delay, tracking of uplinks, and the dual-Active risk when the gateways lose Layer 2 contact.

for a principal

Judge whether to keep a looped Layer 2 distribution block at all, weighing alignment discipline against routed access or multi-chassis bundles that remove the blocked uplink.

## The topology A classic campus distribution block looks like this: - two **distribution switches**, D1 and D2, each a Layer 3 switch that routes for the access VLANs; - a trunk between D1 and D2 carrying every VLAN; - several **access switches**, each with one uplink to D1 and one to D2, carrying the same VLANs. VLAN 10 uses `10.0.10.0/24`. D1 and D2 run VRRP VRID 10 with virtual IP `10.0.10.1` and virtual MAC `00-00-5E-00-01-0A`; the hosts use `10.0.10.1` as their default gateway. Each access switch, D1 and D2 form a **triangle**, which is a Layer 2 loop. Spanning tree breaks it by blocking one port. How the root is chosen and which port blocks belongs to spanning tree's own rules; what matters here is the result. With D1 as the VLAN's root and the usual distribution-over-access priorities, each access switch forwards on its uplink to D1 and blocks its uplink to D2. ## What goes wrong when root and gateway differ Suppose VRRP made **D2** the Active Router for VLAN 10 while D1 is the root. Trace a host's packet to the internet: 1. The host sends the frame to the virtual MAC `00-00-5E-00-01-0A`. 2. Its access switch has learned that MAC via its only forwarding uplink, the one to D1. 3. D1 is a VRRP Backup, so it must not route frames addressed to the virtual MAC; its switching side bridges the frame across the D1-D2 trunk toward D2. 4. D2, the Active Router, finally routes the packet upstream. Nothing breaks, which is why the mistake survives. But: - every upstream frame takes an **extra Layer 2 hop**; - the **D1-D2 trunk** carries the upstream traffic of every access switch in the VLAN and can become the block's bottleneck; - D1's routing capacity sits idle while its switching carries D2's load; - return traffic routed down via D2 also has to cross the trunk to reach the access switches, so both directions pay. ## Aligning them Make the spanning-tree root and the VRRP Active Router the **same switch for each VLAN**, and share the load by alternating VLANs: | VLAN | Spanning-tree root | VRRP Active (higher priority) | VRRP Backup | |---|---|---|---| | 10 | D1 | D1 | D2 | | 20 | D2 | D2 | D1 | | 30 | D1 | D1 | D2 | | 40 | D2 | D2 | D1 | Alternating needs a spanning tree per VLAN or per group of VLANs: a per-VLAN tree, or **MSTP instances** as defined by the IEEE in 802.1Q. With a single tree for every VLAN, only one switch can be root, so the alignment rule forces all VRRP Active roles onto it. ## Keeping them aligned through failure and recovery When D1 fails, both roles move to D2 together: spanning tree re-elects D2 as root and VRRP promotes D2 when advertisements stop. Recovery is where they drift apart: - spanning tree **always** returns the root to the best bridge, so D1 is root again as soon as it is back; - VRRP returns the Active role to D1 only if D1 has the higher priority **and preemption on**; with preemption off, D2 stays Active and the VLAN runs misaligned until the next failure. So the aligned design enables preemption on the intended Active, usually with an implementation's preemption delay so D1 does not reclaim the gateway before its upstream routing has converged. Priority tracking of D1's uplinks completes the picture: if D1 loses its uplinks, it gives up the gateway role even though it may remain the spanning-tree root. ## When the problem disappears The alignment problem exists because the design has a Layer 2 loop and a blocked uplink. Designs that remove the loop remove the problem with it: routing at the access layer, where each access switch is its own gateway, or a multi-chassis link bundle that lets both uplinks forward. Those are design choices of their own; in a looped design, alignment is the rule.

  • After D1 fails and recovers, why can VLAN 10's spanning-tree root and VRRP Active Router end up on different switches?
    Spanning tree always re-elects the best bridge, so the root returns to D1 as soon as it is back. VRRP moves the Active role back only if D1 has the higher priority and preemption on; with preemption off, D2 stays Active indefinitely and upstream traffic crosses the inter-distribution trunk until the next failover. Enable preemption on D1, usually with a delay so its routing converges first.
  • What happens if the two distribution switches stop hearing each other's VRRP advertisements?
    Each Backup's down timer expires and both become Active for the same virtual router, both answering ARP with the same virtual MAC. Switches then see that MAC arriving from two directions and keep moving their MAC table entry, so traffic splits unpredictably and some is lost. RFC 9568 notes that multiple Active Routers can disrupt as much as none, so keep a resilient Layer 2 path between the gateways and alert on dual-Active.

saying these in an interview costs you the question

  • Spanning tree and VRRP elect independently, so their placement never needs coordinating.
  • VRRP picks the Active Router by lowest bridge ID, so it follows the root automatically.
  • A gateway on the non-root switch breaks connectivity outright rather than adding a hop.
  • Making one switch root and Active for every VLAN is the best way to share load.
  • Turning off VRRP preemption keeps root and gateway aligned after a recovery.