Under 802.1D spanning tree, what are the root port, the designated port and the blocked port, and how many of each exist?
answer
- one per bridge, one per segment
- nearest to the root wins
- the root bridge owns no root port
- blocked ports still hear BPDUs
basics
~20 sEach non-root bridge has exactly one root port, its lowest-cost path to the root bridge; each segment has exactly one designated port, the one nearest the root; every other port is non-designated and held in blocking.
solid answer
~40 sUnder IEEE 802.1D the roles fall out of the tree. The **root port** is the one port on each non-root bridge with the lowest root path cost to the root bridge; the root bridge has none. The **designated port** is the one port per segment that offers the lowest root path cost onto that segment: it sends configuration BPDUs there and carries the segment's traffic toward the root. A port that is neither is **non-designated** and sits in `blocking`: it discards data frames but still receives BPDUs, so it can take over if the designated side goes quiet. Counting only point-to-point links between bridges, *B* bridges and *L* links end with *B − 1* root ports, *L* designated ports and *L − (B − 1)* blocked ports — one blocked port per redundant link.
go deeper
Recall the counts: one root port per non-root bridge, one designated port per segment, and everything else blocks. Say that the root bridge has no root port.
Explain how each role is chosen — root path cost first, then sender bridge ID and port ID — and what a blocked port still does with BPDUs.
Show you can predict where the blocked port lands before looking at a switch, and name the edge cases: a root bridge with two ports on one segment, host ports as designated ports.
Connect the counting rule to design: every redundant layer-2 link costs one idle port, which is the bandwidth argument for routed or aggregated designs over a large spanning tree.
## The three roles IEEE 802.1D builds a loop-free tree over a meshed layer-2 network by giving every port one of a small number of jobs. Three matter in the classic protocol: - **Root port** — on every bridge except the root bridge, the single port with the lowest **root path cost**: the sum of port path costs from this bridge to the root. It is the bridge's one way "up" the tree. - **Designated port** — on every **segment** (a link, or a shared medium with several bridges on it), the single port that offers that segment the lowest root path cost. It transmits configuration BPDUs onto the segment and forwards the segment's frames toward the root. A host-facing port is normally designated too: no other bridge competes for that segment. - **Non-designated (blocked) port** — any port that is neither. The protocol puts it in the `blocking` state, so it neither forwards data frames nor learns MAC addresses. 802.1D-1998 names only the root and designated roles; "blocked port" is the working name for the rest. The rapid protocol later split those leftovers into **alternate** and **backup** roles, which are RSTP's vocabulary, not 802.1D's. ## How each role is chosen The root bridge is elected first (lowest bridge ID). Then: 1. **Root port.** Each non-root bridge compares, for every port that hears BPDUs: the root path cost through that port (the advertised cost plus the receiving port's own path cost), then the sender's bridge ID, then the sender's port ID, then the receiving port's own port ID. Lowest wins at every step. 2. **Designated port.** On each segment, the bridge advertising the lowest root path cost owns it; ties go to the lower bridge ID, then the lower port ID. The root bridge advertises a cost of 0, so on ordinary links all its ports are designated. 3. **Everything else blocks.** ## What each role does to traffic | Role | State when stable | Data frames | Learns MACs | BPDUs | |---|---|---|---|---| | Root port | `forwarding` | forwarded | yes | receives the designated side's BPDUs | | Designated port | `forwarding` | forwarded | yes | transmits them onto the segment | | Non-designated | `blocking` | discarded | no | receives and processes, does not transmit | The last column is why blocking is not "off". A blocked port keeps listening to the designated bridge on its segment. If those BPDUs stop, or better information arrives, the port can be re-selected as a root or designated port and start its walk toward forwarding. ## Counting the roles On a network whose bridges are joined only by point-to-point links, the counts follow from the definitions: - **Root ports:** one per non-root bridge, so *B − 1*. - **Designated ports:** one per link, so *L*. - **Blocked ports:** what is left of the *2L* inter-switch ports: *2L − L − (B − 1) = L − (B − 1)*. A four-switch ring has *B = 4*, *L = 4*: three root ports, four designated ports, one blocked port — eight ports in all. A tree needs exactly *B − 1* links, so every link beyond that is redundant and costs exactly one blocked port. The arithmetic changes on shared segments, where one segment can hold several bridges' ports. ## Edge cases worth knowing - **The root bridge can block.** If two of its ports land on the same segment (a hub, or a cable looping two of its own ports together), only the one with the lower port ID is designated and the other blocks. - **A disabled port has no role.** An administratively disabled or link-down port is in the `disabled` state and takes no part in the protocol. - **One root port, even with equal paths.** Two equal-cost paths to the root do not share load; the tie-breakers pick one, and the other port blocks or is designated elsewhere. ## Common slips - Saying each switch has one designated port: designation is per **segment**, and the root bridge usually has several. - Saying the designated port "points toward the root": that is the root port; a designated port faces away from the root, onto its segment. - Treating a blocked port as deaf: it discards data, not BPDUs.
- Why does a blocked 802.1D port keep receiving BPDUs if it never forwards data?Because it is the standby path. It keeps hearing the designated bridge's configuration BPDUs on its segment. If they stop long enough for the stored information to age out, or a BPDU with better information arrives, the bridge re-runs the role selection, and the port can become root or designated and walk toward forwarding. A port that ignored BPDUs could never notice that the active path had failed.
- Can the 802.1D root bridge itself have a blocked port?Yes, in one case: two of its ports on the same segment, such as both cabled to one hub or looped to each other. Each port hears the other's BPDU with the same root, cost and bridge ID, so the lower port ID wins and the other port is non-designated and blocks. On ordinary point-to-point links every port of the root bridge is designated.
Every town keeps exactly one road it uses to reach the capital (its root port). On every stretch of road, the town nearer the capital is responsible for it (the designated port). A road that is nobody's route to the capital and nobody's responsibility is barricaded — but a town behind a barricade still hears the messengers on the other side, so it knows when it must reopen.
saying these in an interview costs you the question
- Every switch has a root port, including the root bridge.
- Each switch has exactly one designated port.
- A blocked port ignores everything, BPDUs included.
- The designated port is the one that points toward the root.
- Alternate and backup are 802.1D's names for the blocked ports.