Under RSTP, how does an alternate port differ from a backup port, and which one can replace a failed root port?
answer
- who sent the better BPDU
- another bridge versus this bridge
- path to root versus path to segment
- shared media or a looped cable
basics
~20 sAn RSTP alternate port hears a better BPDU from another bridge, a standby root path that replaces a failed root port at once; a backup port hears its own bridge on a shared segment and never becomes root port.
solid answer
~50 sBoth are RSTP roles for a port that sits in `discarding`; they differ in **who sent the better BPDU** the port hears. An **alternate** port receives a better BPDU from **another bridge**: it is a second path toward the root that lost to the root port. When the root port fails, the best alternate port takes the root role and forwards immediately. A **backup** port receives a better BPDU from **its own bridge**, meaning two of the switch's ports sit on the same segment and the other one is designated there. It backs up that designated port's connection to the segment, so it can never become the root port; its path leads back to its own switch. Backup ports appear only on shared media, such as a hub, or with a cable looped between two ports of one switch; on point-to-point uplinks redundancy shows up as alternate ports.
go deeper
Recall that both roles are standby ports in the discarding state, and that only the alternate port offers another way to reach the root bridge.
Explain the test that tells them apart: whether the superior BPDU on the port came from another bridge or from the same bridge, and what each one can be promoted to.
Use the roles diagnostically: a missing alternate port means no fast uplink failover, and a backup port on a switch-to-switch link points to shared media or a looped cable.
Treat alternate ports as standby capacity that carries nothing, and weigh it against designs that use every uplink, such as per-instance trees or link bundles across two chassis.
## The setting Take an access switch, **S3**, with two uplinks: one to distribution switch **D1**, which is the root bridge, and one to distribution switch **D2**. D1 and D2 are also linked to each other. Every link is full duplex and every switch runs **RSTP** (IEEE 802.1w, now part of 802.1D-2004). S3's uplink to D1 offers the lowest root path cost, so it becomes S3's **root port**. On the S3-D2 link, D2 advertises a path to the root that beats anything S3 would send on that link, so D2's port is **designated** for the segment. S3's port there is not needed for forwarding, and classic 802.1D would simply call it blocked. RSTP gives it a more useful name. ## Two roles, one difference RSTP defines two discarding roles. The difference is the **source of the superior BPDU** the port keeps hearing: | | Alternate port | Backup port | |---|---|---| | Better BPDU comes from | another bridge | the same bridge (another of its own ports) | | What it offers | a second path toward the root | a second connection to one segment | | Typical place | the second uplink of a dual-homed switch | shared media, or a cable looped between two ports of one switch | | Can become root port? | yes | no | | Can become designated? | if the topology changes | yes, if its sibling designated port fails | | State while standing by | `discarding` | `discarding` | - S3's port toward D2 is an **alternate** port: the better information it hears comes from D2, a different bridge, and that information describes a working path to the root. - Suppose S3 also had two ports connected to the same unmanaged hub. One of them would be designated for the hub segment; the other would hear S3's own designated port's BPDUs, which beat what it would send itself. That second port is a **backup** port. ## What happens when the root port fails 1. S3's link to D1 goes down, so S3 loses its root port. 2. S3 already holds D2's information on its alternate port, describing a path to the root via D2 and the D2-D1 link. 3. The alternate port takes the **root** role and moves to `forwarding` immediately; RSTP allows a new root port to forward without the timed learning walk once the old root port is no longer forwarding, because moving the root role from one port to another cannot then open a loop through S3. 4. S3 announces the change so that other bridges flush the MAC addresses they learned through the old path. A **backup** port cannot do step 3. Its better BPDU came from its own switch, so the only thing it knows is a route back into S3 — no path to the root at all. If S3's designated port on the hub fails, the backup port can take over as designated for that segment; because the segment is shared, it cannot use the proposal/agreement handshake and reaches forwarding on Forward Delay timers. ## Why the distinction matters in practice - **Fast failover needs an alternate port.** A switch with a single uplink, or with its redundancy hidden behind shared media, has nothing pre-computed to fail over to. - **A backup port is a warning sign** in a modern switched network. Switch-to-switch links are point-to-point, so seeing a backup port usually means a hub, a media converter shared by several devices, or a patch cable looped back into the same switch. - **Both roles are invisible to traffic.** Neither forwards frames nor learns MAC addresses while standing by, so their existence shows only in the protocol's view of each port, which is where to look when checking redundancy. - **Several alternate ports** are possible on a switch with more than two uplinks; the best one is chosen by the ordinary comparison that picks a root port (root path cost, then sender bridge ID, then sender port ID). ## The 802.1D comparison Classic 802.1D-1998 knew only root, designated and non-designated (blocked) ports. A blocked port could not be promoted at once, because the protocol did not record whether its information described a valid path to the root. RSTP's alternate role is precisely that record, and it is what lets a dual-homed switch lose its uplink without walking listening and learning first.
- Why do backup ports almost never appear in a modern switched network?A backup port needs two ports of one switch on the same segment, which means shared media such as a hub, or a cable looped between two ports of the same switch. Full-duplex point-to-point links give every pair of ports its own segment, so redundancy shows up as alternate ports instead, and a backup port usually points to a cabling mistake.
- If a switch has three uplinks, which alternate port becomes root port when the root port fails?The one whose received information is best by the same comparison that chose the original root port: lowest root path cost, then lowest sender bridge ID, then lowest sender port ID. Every alternate port already holds that information, so the choice is immediate and needs no new BPDU exchange.
saying these in an interview costs you the question
- Alternate and backup ports are the same role under two different names.
- A backup port can take over as root port when the uplink fails.
- Alternate ports forward traffic to share load until a failure occurs.
- Classic 802.1D-1998 already defined alternate and backup port roles.
- Every redundant point-to-point uplink ends up as a backup port.