How does spanning tree turn a redundant mesh of switch links into a loop-free tree, and what does a blocked port still do?
answer
- logical tree over a physical mesh
- BPDUs reveal the topology
- one root, best path towards it
- one forwarding port per segment
- blocked ends still hear BPDUs
basics
~20 sSwitches exchange BPDUs, elect a root, and keep only each switch's least-cost path to it plus one designated port per segment; every other port blocks. A blocked port drops data frames but keeps receiving BPDUs, ready to take over.
solid answer
~50 sSpanning tree keeps the physical redundancy but forwards on a **logical tree**. Switches discover each other through BPDUs, sent to a reserved multicast address that bridges consume rather than relay. One switch becomes the root; every other switch keeps one **root port**, its least-cost path towards the root, and every segment keeps one **designated port** that forwards onto it. Every remaining port blocks, so exactly one active path joins any two segments: with N switches on point-to-point links, N-1 links forward. On a point-to-point link only one end blocks, so the other end keeps sending BPDUs onto it. The blocked port discards data frames and learns no addresses, but it keeps receiving those BPDUs; when they stop or show a better path, it moves towards forwarding. The tree is a set of least-cost paths to the root, not a minimum spanning tree, so some switch pairs take a longer route.
go deeper
Know the picture: a redundant physical mesh, a loop-free logical tree, one root, and ports that block to break each loop while staying ready as backups.
Explain root ports, designated ports and blocked ports, why N switches on point-to-point links forward exactly N-1 links, and what a blocked port still does with BPDUs.
Point out what the tree is not: not a minimum spanning tree and not pair-wise shortest paths. Say why a device that drops BPDUs, or a one-way link, defeats the protection.
Weigh the cost of idle links and root-centred paths against simplicity, and know when that cost justifies aggregation, routed access or a fabric instead of a larger spanning-tree domain.
## Physical mesh, logical tree A **spanning tree** of a graph is a subset of its links that connects every node with **no cycle**. Spanning tree protocols (IEEE 802.1D, and its rapid version RSTP) apply that idea to switches. The **physical topology** keeps every redundant cable, while the **logical topology** (the links that actually carry frames) is a tree. Because a tree has exactly one path between any two points, a flooded frame reaches every segment once and then stops. For switches joined by point-to-point links, a tree over **N** switches uses exactly **N-1** links. Every link beyond that closes one independent loop and must be blocked at one end. ## How the switches discover the topology No switch is configured with a map. They learn it from **BPDUs** (bridge protocol data units), the control messages of the protocol: - BPDUs go to the reserved multicast address `01-80-C2-00-00-00`, the address RFC 6325 lists for BPDUs. Under the IEEE standard, a bridge **consumes** frames sent to that reserved block and does not relay them, so each switch hears only the switches on its own links and sends BPDUs of its own. - Each BPDU says, in effect, which switch the sender believes is the root and how far the sender is from it. - From what arrives on each port, a switch works out which port is its best way towards the root and which ports lead to switches that are better placed than it is. The details (BPDU fields, timers, how the root wins) are their own topics. Here, the point is that **BPDUs are the discovery signal**: a redundant cable is noticed because BPDUs arrive across it. ## Which ports forward and which block 1. **One root switch** is elected for the whole tree. 2. Every other switch picks one **root port**, the port with the lowest total path cost towards the root. 3. On every segment, one port becomes the **designated port**, the one that forwards onto that segment towards the leaves. On the root, every port is normally designated. 4. Every port that is neither root nor designated **blocks**. A worked example: four switches fully meshed by point-to-point links of equal cost, with S1 as root. | Link | Result | |---|---| | S1-S2, S1-S3, S1-S4 | forward (each is the root port of S2, S3 or S4) | | S2-S3 | one end designated, other end blocks | | S2-S4 | one end designated, other end blocks | | S3-S4 | one end designated, other end blocks | Six links exist and 4 - 1 = 3 forward, so three links each have one blocked end. The tie-breaks that decide *which* end of a link blocks are covered separately. Note that traffic from S3 to S4 now goes through S1, two hops instead of one. ## What a blocked port still does Blocking is a **filter on data**, not a disconnection: - It **discards** every data frame it receives, including broadcasts, and sends none. - It **does not learn** source addresses, so the switch's table never points through it. - It **keeps receiving and processing BPDUs** from the designated port at the other end of the link, which is how it knows the active path is still healthy. - The cable, optics and link stay **up**, so the port can move to forwarding when the BPDUs stop arriving or start advertising a better path. The intermediate states it walks through, and how long that takes, are separate subjects. A blocked port is therefore **standby capacity under supervision**, and that is how spanning tree gives redundancy without loops. ## What kind of tree it is Spanning tree builds a **tree of least-cost paths towards the root**. It is **not** a minimum spanning tree in the graph-theory sense (the cheapest total set of links), and it does **not** give every pair of switches its shortest path. RFC 6325 makes the same point: forwarding is whatever path remains after spanning tree removes the redundant ones. Two consequences follow: - **Idle capacity**: blocked links carry no data. RFC 7348 (VXLAN, Informational) notes that operators pay for links they cannot use. - **Root placement matters**: since every path runs through the tree towards the root, a badly placed root drags traffic across the wrong switches. ## What the design needs to stay safe - Every switch in the domain must run the protocol and exchange BPDUs; a device that silently drops them hides a loop. - A link that fails in one direction can stop BPDUs reaching a blocked port, which then starts forwarding; guard features exist for that case. - Any loop formed where BPDUs cannot travel is invisible to spanning tree.
- Why does spanning tree block only one end of a redundant switch link rather than both?One blocked end is enough to stop data crossing the link in either direction, because frames sent to the blocked end are discarded and it sends none. Keeping the other end designated means it goes on sending BPDUs onto the link, so the blocked end keeps hearing whether the active path is healthy and can take over when it is not.
- Why can a loop that BPDUs never cross escape spanning tree entirely?Spanning tree only knows about paths it sees BPDUs on. If a device in the loop does not pass BPDUs, or a port has BPDU processing disabled or filtered, the switches never learn that the redundant path exists, so no port blocks. RFC 6325 lists lost spanning tree messages as a cause of loops.
saying these in an interview costs you the question
- Spanning tree builds a minimum spanning tree with the lowest total link cost.
- Spanning tree gives every pair of switches its shortest path.
- A blocked port is administratively shut down and its link goes down.
- A blocked port stops listening to BPDUs until the network changes.
- Both ends of a redundant link have to block to break the loop.