On a campus with 200 VLANs, why choose MSTP over running one spanning tree per VLAN, and what does each approach cost?
answer
- topologies, not VLANs, need trees
- one BPDU per port
- VLAN groups mapped to instances
- a root per instance
- consistency is the price
basics
~20 sPer-VLAN trees run 200 independent trees, each sending its own BPDUs on every trunk; MSTP maps the 200 VLANs onto a few instances carried in one BPDU per port, at the price of an identical region configuration everywhere.
solid answer
~50 sOne common tree for all VLANs, plain 802.1Q-style RSTP, is cheap but wastes every blocked uplink. A **per-VLAN** design, one vendor family's PVST+ (802.1D-based) and Rapid PVST+ (802.1w-based), runs an independent tree per VLAN: each can have its own root, so load balancing is easy, but 200 VLANs mean 200 state machines per port and, on each trunk where the switch is designated, 200 BPDUs every Hello. **MSTP** (IEEE 802.1s, now in 802.1Q) recognises that a campus needs only a few distinct topologies, usually one per distribution switch. It maps VLAN groups to a handful of **instances**, each with its own root, and carries all of them in one BPDU per port. The cost is operational: every switch in a **region** must carry the same name, revision level and VLAN-to-instance map, or the design splits.
go deeper
Recall that a single spanning tree leaves the blocked uplink idle for every VLAN, and that per-VLAN trees and MSTP exist so that different VLANs can use different uplinks.
Explain how each design load-balances, a root per VLAN versus a root per instance, and where the BPDU and state-machine count comes from in each.
Size the control load for the real trunk and VLAN counts, and plan the MSTP region so that the map is identical everywhere and VLANs are pre-mapped before they are needed.
Weigh the per-VLAN tree's simplicity against MSTP's lower load and region discipline, and ask whether a layer-2 domain this large should survive at all.
## The problem a VLAN-rich campus poses A campus with **200 VLANs** has access switches dual-homed to two distribution switches, **D1** and **D2**, and every uplink is an 802.1Q trunk carrying all 200 VLANs. Spanning tree must block one uplink per access switch for loop freedom. The design question is *per what* it blocks: for every VLAN at once, for each VLAN separately, or for groups of VLANs. ## Option 1: one tree for every VLAN The original 802.1Q approach, and plain RSTP, run a **single common tree**. Every VLAN follows the same topology, so the blocked uplink of each access switch carries nothing until a failure. It is simple and light, but half of the uplink capacity sits idle. ## Option 2: one tree per VLAN **Per-VLAN spanning tree** is one vendor family's implementation, not an IEEE standard: **PVST+** runs an 802.1D instance per VLAN and **Rapid PVST+** an RSTP instance per VLAN. The bridge ID carries the VLAN number (the extended system ID), so each VLAN can elect its own root. - **Gain:** fine-grained load balancing. Make D1 root for VLANs 1-100 and D2 root for VLANs 101-200, and each access switch forwards half the VLANs on each uplink. - **Cost:** everything scales with VLANs times ports. A switch sends a BPDU **per VLAN** every Hello on each trunk where it is designated, and each port runs a state machine per VLAN. The arithmetic for D1, designated on its 20 downlink trunks (the usual case for a distribution switch), at the IEEE default Hello of 2 s: | Design | BPDUs per designated trunk per Hello | BPDUs per Hello, 20 trunks | Per second | |---|---|---|---| | per-VLAN trees, 200 VLANs | 200 | 4,000 | 2,000 | | MSTP, any number of instances | 1 | 20 | 10 | - **Interoperation** with standard bridges happens only through a single common tree at the boundary, and 200 independent topologies are 200 things to verify after any change. ## Option 3: MSTP instances **Multiple Spanning Tree Protocol (MSTP)** was published as IEEE 802.1s and is now part of **IEEE 802.1Q**. Its observation is that 200 VLANs on two distribution switches need only **two distinct topologies**. 1. Define a **region**: a set of switches with the same **region name**, **revision level** and **VLAN-to-instance map**. 2. Map VLANs 1-100 to **instance 1** and VLANs 101-200 to **instance 2**. Any VLAN not mapped stays in **instance 0**, the **internal spanning tree (IST)**. 3. Give D1 the lowest bridge priority for instance 1 and D2 the lowest for instance 2, so each instance blocks a different uplink. 4. Each port sends **one BPDU per Hello**. It carries the IST's information plus a record for every other instance, so adding instances adds bytes, not messages. Inside the region each instance has its own root, roles and states, run with the RSTP mechanisms (alternate ports, proposal and agreement, edge ports). ## What MSTP costs - **Configuration consistency.** The name, revision level and map must match on every switch of the region. The map is compared through a digest of the whole VLAN-to-instance table, so a difference even in an unused VLAN splits the region, and at a region boundary only the common tree survives. - **Change management.** Editing the map changes the digest; until every switch has the same edit, the edited switches form a separate region. Mapping planned VLAN ranges to instances in advance avoids most edits. - **Design effort.** Someone has to decide the grouping and place each instance's root, instead of accepting one tree per VLAN by default. ## Choosing | | One common tree | Per-VLAN trees | MSTP | |---|---|---|---| | Uplink use | one per switch | both, per VLAN | both, per instance | | Control load | lowest | grows with VLANs x ports | grows with ports | | Standard | IEEE | one vendor family's | IEEE 802.1Q | | Main risk | idle capacity | CPU and BPDU load at scale | region mismatch | For a few VLANs on one vendor's switches, per-VLAN trees are workable. At 200 VLANs, MSTP gives the same load balancing with a control load that no longer grows with the VLAN count.
- Why not give each of the 200 VLANs its own MSTP instance?The standard supports far fewer instances per region than there are VLAN IDs, and every instance still costs a state machine per port and a record in each BPDU. MSTP's design point is that the number of distinct topologies you need, usually one per distribution switch or uplink, is tiny compared with the number of VLANs, so a few instances do the work.
- When is a per-VLAN tree design still reasonable?With a modest number of VLANs, switches from one vendor family throughout, and a real need to place each VLAN's root individually. Its overhead grows with VLANs times trunk ports, so it is the VLAN count, not the protocol, that makes it expensive; few VLANs keep it cheap.
saying these in an interview costs you the question
- MSTP runs a separate spanning tree for every VLAN it carries.
- With one common tree, the two uplinks carry different VLANs.
- Per-VLAN spanning tree is an IEEE standard every switch implements.
- MSTP sends a separate BPDU for every instance on each port.
- Adding more instances always improves load balancing at no cost.