skip to content

STP

Ethernet frames have no TTL, so a Layer 2 loop is fatal; STP builds a loop-free tree by electing a root and blocking redundant links. Any question about redundancy in a switched network starts here.

on this pageshow

explore

questions

30

Why do switched Ethernet networks need spanning tree, and why is a Layer 2 loop more destructive than a Layer 3 routing loop?

level: juniorimportance: must knowfreq 65%

answer

  1. redundant cables close a path
  2. what the Ethernet header lacks
  3. flooding out every other port
  4. IPv4 TTL, IPv6 Hop Limit
  5. block ports, keep one path

basics

~20 s

Ethernet frames carry no TTL or hop count, so a broadcast that enters a loop of switches circulates indefinitely and keeps reaching every host. Spanning tree blocks redundant ports so one active path remains, and reopens one if that path fails.

solid answer

~50 s

Switches are cabled redundantly so one failed link does not cut a site off, but redundant links form loops. An Ethernet header (destination MAC, source MAC, EtherType) has no hop count or `TTL`, and a switch floods broadcasts and unknown-destination frames out every port except the one they arrived on. Nothing expires a frame that enters a loop: it circulates and keeps reaching every host until a link in the loop is cut. A routing loop is bounded: each IPv4 router decrements `TTL` (RFC 791, RFC 1812) and each IPv6 node `Hop Limit` (RFC 8200), discarding the packet at zero, and routers must not forward limited broadcasts (RFC 1812). Spanning tree has the switches exchange BPDUs and block just enough ports that exactly one active path joins any two segments, keeping the blocked links as standby.

go deeper

for a junior

Recall the one-line cause: Ethernet has no TTL, so a flooded frame in a loop never dies. Then say what spanning tree does about it: block redundant ports, keep one path, reopen on failure.

for a middle

Explain why flooding plus the missing hop count makes copies circulate, and contrast IP's TTL and Hop Limit, which bound a routing loop. Name the four symptoms: storm, duplicates, MAC flapping and CPU load.

for a senior

Show you know the blast radius: a switching loop takes down a whole broadcast domain while a routing loop degrades only the looping prefixes. Mention that VLANs limit the reach but never remove the loop.

for a principal

Discuss the price of blocking: idle links and non-shortest paths. Be ready to argue when link aggregation, routed access or an overlay fabric is worth more than a spanning-tree design.

## Why switched networks contain loops at all A **switch** (the IEEE standards call it a *bridge*) relays Ethernet frames between its ports. Network designers deliberately connect switches with **more than one path**: two uplinks from an access switch, a ring of switches, a mesh between distribution switches. The reason is resilience: if one cable, optic or switch fails, traffic still has a way through. But any redundant path closes a **loop**, a cycle in the physical topology, and Ethernet cannot tolerate one on its own. ## What the Ethernet header lacks An Ethernet frame header holds three things a switch looks at: the **destination MAC address**, the **source MAC address** and the **EtherType** (an 802.1Q tag adds a VLAN ID and priority, nothing more). There is **no hop count and no time-to-live field**. RFC 6325, the IETF's TRILL specification, states the problem directly in its introduction: the Ethernet header contains no hop count or TTL, which is dangerous whenever a temporary loop forms. Two switch behaviours turn that missing field into an outage: - **Flooding.** A switch sends a broadcast frame, and any frame whose destination it has not learned, out of **every port except the one it arrived on**. In a loop, "every other port" includes the way back round. - **No memory of frames.** A switch keeps a table of *addresses*, not of *frames it has already relayed*. A copy that comes back round looks like a brand-new frame and is flooded again. Put together, a single ARP request (which RFC 826 has a host broadcast to every station on the segment) enters the loop and nothing ever expires it. Each pass re-delivers it to every host port, and every further broadcast adds more copies that also never leave. ## Why a Layer 3 loop is bounded Routing loops happen too, for example while routers disagree about a failed link. They hurt, but they burn out: | Property | Ethernet (Layer 2) | IP routing (Layer 3) | |---|---|---| | Lifetime field | none | IPv4 `TTL`, IPv6 `Hop Limit`, 8 bits each | | What a hop does | relays the frame unchanged | decrements the field, discards at zero | | Broadcasts | flooded across every switch in the VLAN | routers must not forward limited broadcasts (RFC 1812) | | Outcome of a loop | copies circulate until the loop is cut | each packet dies after at most 255 hops | RFC 791 says a datagram whose TTL reaches zero must be destroyed, and RFC 8200 says an IPv6 packet is discarded when its `Hop Limit` is zero or decremented to zero. So a routing loop wastes some bandwidth and drops the affected traffic; a switching loop can take down **the whole broadcast domain**, because every host on it receives the storm. ## What a loop does to a network The symptoms always come together: - **Broadcast storm**: looping broadcasts saturate the inter-switch links and every access port in the VLAN. - **Duplicate frames**: a frame flooded down two paths arrives at its destination twice. - **MAC address flapping**: a switch sees the same source address arriving on different ports and keeps moving its table entry, so traffic for that host is sent the wrong way. - **CPU exhaustion**: hosts and the switches' own management processors are interrupted by every broadcast copy. ## How spanning tree fixes it **Spanning tree** (IEEE 802.1D; its rapid successor RSTP was folded into 802.1D-2004) keeps the physical redundancy but makes the *logical* topology a tree: 1. The switches exchange **BPDUs** (bridge protocol data units), the control messages that let them discover one another and the shape of the network. 2. One switch becomes the **root**, and every other switch keeps its best path towards it. 3. Every port that would close a loop is put into a **blocking** condition: it discards data frames but keeps listening for BPDUs. 4. When an active link fails, the BPDUs stop or change, and a blocked port moves to forwarding so connectivity returns. The result is exactly **one active path between any two segments**, so a flooded frame reaches every host once and then stops at the edge. ## What it costs Blocking is not free. RFC 7348 (VXLAN, an Informational RFC) notes that with spanning tree, operators pay for links they cannot use, and RFC 6325 points out that forwarding follows whatever path survives the blocking rather than the shortest path between two switches. Link aggregation, routed access and overlay fabrics are the designs that recover that capacity, and each still depends on keeping whatever Layer 2 remains loop-free.

  • Doesn't an Ethernet broadcast storm eventually die out once links congest and frames are dropped?
    No. Congestion drops some copies, but the survivors keep circulating and every new broadcast or flooded multicast (ARP, DHCP and the like) adds more. Where a switch has three or more ports in the looped topology, each copy also multiplies on every pass. Nothing in the frame expires, so the storm lasts until a link in the loop is cut or blocked.
  • Does splitting a switched network into VLANs prevent Layer 2 loops?
    It limits a storm's reach, because a broadcast floods only within its own VLAN, which is its own broadcast domain. It does not remove the loop: a cabling loop that carries a VLAN still loops that VLAN, and a loop between two trunks carries every VLAN on them. VLANs shrink the blast radius; spanning tree or a loop-free design must still cover every VLAN.
  • Why don't switches simply add a hop count to Ethernet frames?
    Transparent bridging was designed to relay hosts' frames unchanged, so there is no field a classic switch can decrement. Protocols that need one add their own header: TRILL (RFC 6325, Standards Track) wraps frames between routing bridges in a header with a 6-bit hop count. Plain 802.1D bridging keeps the frame as it is, so it must avoid loops entirely.

saying these in an interview costs you the question

  • Ethernet frames carry a TTL that each switch decrements, just like IP packets.
  • A broadcast storm burns itself out once the links are congested.
  • Spanning tree load-balances traffic across all of the redundant links.
  • Spanning tree shuts redundant links down until someone re-enables them.
  • A routing loop is just as unbounded as a switching loop.
open as a page

In spanning tree, which switch becomes the root bridge, and why does an untuned network often end up with an old switch as root?

level: juniorimportance: must knowfreq 50%

basics

~20 s

The switch with the lowest bridge ID becomes root. The bridge ID is a priority followed by a MAC address, and every switch ships with the same default priority, so the lowest MAC decides, which is frequently an older device.

open as a page

What does Rapid Spanning Tree Protocol (RSTP, IEEE 802.1w) change compared with classic 802.1D spanning tree?

level: juniorimportance: must knowfreq 45%

basics

~20 s

RSTP keeps 802.1D's root election and path costs but adds alternate and backup port roles, merges disabled, blocking and listening into one discarding state, and moves ports to forwarding by an explicit neighbour handshake instead of waiting out timers.

open as a page

In 802.1D spanning tree, what do the Hello, Max Age and Forward Delay timers control, and whose values do bridges actually use?

level: middleimportance: must knowfreq 40%

basics

~20 s

Hello Time (IEEE default 2 s) paces the root's Configuration BPDUs, Max Age (20 s) is how long stored BPDU information lives, and Forward Delay (15 s) is each listening and learning period. Every bridge uses the root's values, carried in its BPDUs.

open as a page

Under 802.1D spanning tree, why does a direct uplink failure take about 30 seconds to recover while an indirect failure takes about 50?

level: middleimportance: must knowfreq 40%

basics

~20 s

A direct failure shows up at once as link loss, leaving only listening and learning: about 30 s at IEEE defaults. An indirect failure is learned through BPDUs, so stored information must first reach Max Age (20 s): about 50 s.

open as a page

Why should a spanning-tree edge port, which one vendor calls PortFast, be paired with BPDU Guard on access ports?

level: middleimportance: must knowfreq 45%

basics

~20 s

An edge port forwards at once on an unchecked promise that no bridge is attached. BPDU Guard enforces the promise by shutting the port on the first BPDU, so a user's switch or a looped cable costs one port, not the tree.

open as a page

With spanning tree disabled, a second patch cable joins two access switches; what does one ARP broadcast do, and why does the storm never stop?

level: middleimportance: must knowfreq 48%

basics

~20 s

Each switch floods the broadcast out the other cable, so two copies circle the loop indefinitely, reaching every host on each pass. Hosts receive duplicates, both switches keep relearning the sender's MAC on the looped ports, and links and CPUs saturate.

open as a page

In an 802.1D ring S1-S2-S3-S4-S1 of equal-cost links with S1 as root, which ports become root, designated and blocked?

level: middleimportance: must knowfreq 32%

basics

~20 s

S2 and S4 use their S1-facing ports as root ports; S3, two hops either way, picks the neighbour with the lower bridge ID; each link's designated port sits on the bridge nearer the root, leaving one S3 port blocking.

open as a page

Under 802.1D spanning tree, why does a newly connected switch port take about 30 seconds before it forwards a host's frames?

level: middleimportance: must knowfreq 50%

basics

~20 s

802.1D holds the port in listening and then learning, each for one Forward Delay (15 s by the IEEE default), before forwarding: listening lets the tree settle so no temporary loop forms, and learning fills the MAC table first.

open as a page

How do 802.1D spanning-tree bridges agree on a single root bridge, and how is one bridge ID judged better than another?

level: middleimportance: must knowfreq 38%

basics

~20 s

Every bridge starts by claiming to be root and advertising its own bridge ID. A bridge that hears a lower root ID adopts it and relays it; bridge IDs compare as one number, priority first, MAC second, lowest winning.

open as a page

Under 802.1D spanning tree, how does a topology change travel through TCN BPDUs and the TC flag, and why do MAC tables then age faster?

level: seniorimportance: must knowfreq 30%

basics

~20 s

A detecting bridge sends a TCN out its root port; each upstream bridge acknowledges with TCA and relays it. The root then sets TC for 35 s at IEEE defaults, and bridges age MAC entries after Forward Delay so stale ones clear.

open as a page

Under RSTP, how does the proposal/agreement handshake bring a designated port to forwarding without timers, and what does the sync step do?

level: seniorimportance: must knowfreq 22%

basics

~20 s

An RSTP designated port on a point-to-point link proposes; the neighbour syncs by putting its other non-edge designated ports into discarding, then agrees, and the proposing port forwards at once because no loop can pass through the neighbour.

open as a page

In 802.1D spanning tree, what is a BPDU, and how do Configuration BPDUs and Topology Change Notification BPDUs differ?

level: juniorimportance: should knowfreq 38%

basics

~20 s

A BPDU (bridge protocol data unit) is the spanning-tree control frame bridges exchange on the reserved address 01-80-C2-00-00-00. Configuration BPDUs flow outward from the root carrying the tree's state; TCN BPDUs climb toward the root to report a change.

open as a page

Under 802.1D spanning tree, what are the root port, the designated port and the blocked port, and how many of each exist?

level: juniorimportance: should knowfreq 42%

basics

~20 s

Each non-root bridge has exactly one root port, its lowest-cost path to the root bridge; each segment has exactly one designated port, the one nearest the root; every other port is non-designated and held in blocking.

open as a page

Decoding an 802.1D Configuration BPDU field by field, what does each field mean, and which fields does a relaying bridge rewrite?

level: middleimportance: should knowfreq 24%

basics

~20 s

A Configuration BPDU carries the root ID, the sender's root path cost, bridge ID and port ID, message age, the root's three timers and the TC/TCA flags. Relaying bridges copy the root ID and timers but rewrite cost, sender IDs and age.

open as a page

How does spanning tree turn a redundant mesh of switch links into a loop-free tree, and what does a blocked port still do?

level: middleimportance: should knowfreq 35%

basics

~20 s

Switches exchange BPDUs, elect a root, and keep only each switch's least-cost path to it plus one designated port per segment; every other port blocks. A blocked port drops data frames but keeps receiving BPDUs, ready to take over.

open as a page

Why can a spanning-tree bridge priority be set only in multiples of 4,096, and what do the low 12 bits of the field carry?

level: middleimportance: should knowfreq 24%

basics

~20 s

Since IEEE 802.1t, the 16-bit priority field is split: only its top 4 bits are configurable, so priority moves in steps of 4,096, and the low 12 bits form a system ID extension carrying the VLAN or instance number.

open as a page

Under RSTP, how does an alternate port differ from a backup port, and which one can replace a failed root port?

level: middleimportance: should knowfreq 28%

basics

~20 s

An RSTP alternate port hears a better BPDU from another bridge, a standby root path that replaces a failed root port at once; a backup port hears its own bridge on a shared segment and never becomes root port.

open as a page

On a campus with 200 VLANs, why choose MSTP over running one spanning tree per VLAN, and what does each approach cost?

level: middleimportance: should knowfreq 25%

basics

~20 s

Per-VLAN trees run 200 independent trees, each sending its own BPDUs on every trunk; MSTP maps the 200 VLANs onto a few instances carried in one BPDU per port, at the price of an identical region configuration everywhere.

open as a page

A spanning-tree network shows its topology-change counter climbing all day and constant unicast flooding; how do you find the source and stop it?

level: seniorimportance: should knowfreq 20%

basics

~20 s

Recurring topology changes keep every bridge on 15-second MAC ageing, flooding frames to silent hosts. Trace the reports hop by hop to the bridge whose own port keeps changing, then fix it: a flapping link, or a host port that should be edge.

open as a page

In a spanning-tree campus, where do Root Guard and Loop Guard belong, and what failure does each one stop?

level: seniorimportance: should knowfreq 28%

basics

~20 s

Root Guard goes on designated ports facing switches that must never become root and blocks on a superior BPDU. Loop Guard goes on root and alternate ports between switches and holds them blocked when BPDUs stop, as on one-way links.

open as a page

After a spanning-tree reconvergence, why do some silent hosts stay unreachable for a while, and why does the switched network flood unicast traffic?

level: seniorimportance: should knowfreq 15%

basics

~20 s

Switches still map MAC addresses to the old path. Hosts that transmit are relearned at once; frames to silent hosts go the wrong way until entries are aged out or flushed, and after a flush unlearned destinations are flooded.

open as a page

How does RSTP restore forwarding in well under a second after an uplink fails, and when does it fall back to 802.1D-like timers?

level: seniorimportance: should knowfreq 25%

basics

~20 s

RSTP promotes a precomputed alternate port at once, accepts bad news from its designated bridge immediately, and confirms forwarding by handshake on point-to-point links. Shared links, 802.1D neighbours and non-edge host ports fall back to timers.

open as a page

In a switched Ethernet LAN, a whole floor loses connectivity with line-rate broadcast on the uplinks, pegged switch CPUs and one MAC flapping between two ports; how do you confirm a Layer 2 loop and stop it?

level: seniorimportance: should knowfreq 22%

basics

~20 s

Line-rate broadcast plus a flapping MAC means a Layer 2 loop. Confirm it from flap logs and identical repeated frames, cut a link on the loop to stop it at once, then find why spanning tree did not block it.

open as a page

Under 802.1D spanning tree, how do the short and long port path cost tables differ, and what breaks when bridges mix them?

level: seniorimportance: should knowfreq 15%

basics

~20 s

802.1D-1998's short table gives 16-bit costs (19 for 100 Mb/s, 4 for 1 Gb/s) that bottom out near 10 Gb/s; 802.1t's long table (200,000, 20,000) scales further. Mixed on one network, root path costs stop being comparable.

open as a page

In a campus spanning tree where an old access switch won the root election, what happens to traffic between the distribution switches, and how do you fix it?

level: seniorimportance: should knowfreq 30%

basics

~20 s

Every forwarding path radiates from the root, so traffic between the distribution switches detours through the access switch's uplinks while their direct link blocks. Fix it by giving the distribution switches the two lowest bridge priorities, as primary and secondary root.

open as a page

What happens to an 802.1D spanning tree when someone plugs in a new switch whose bridge ID is lower than the current root's?

level: seniorimportance: should knowfreq 20%

basics

~20 s

The new switch's BPDUs announce a better root, every bridge accepts it, and the tree is rebuilt around the newcomer. Under 802.1D, ports that must start forwarding wait about 30 seconds and MAC entries age out early, so traffic drops and floods.

open as a page

Why is lowering just one 802.1D spanning-tree timer, such as Max Age or Forward Delay, to speed up convergence risky?

level: seniorimportance: nice to knowfreq 12%

basics

~20 s

The 802.1D timers are coupled: the IEEE requires 2 x (Hello + 1 s) <= Max Age <= 2 x (Forward Delay - 1 s). Changing one alone can expire information too early or let ports forward before the tree settles, causing loops.

open as a page

Two MSTP switches share the same region name and VLAN-to-instance map yet act as separate regions; what is wrong, and what does the boundary do?

level: seniorimportance: nice to knowfreq 12%

basics

~20 s

An MSTP region needs a matching name, revision level and VLAN-to-instance digest, so a differing revision level is the usual culprit; at the boundary only the CIST crosses, and boundary ports forward or discard every VLAN together.

open as a page