Why do switched Ethernet networks need spanning tree, and why is a Layer 2 loop more destructive than a Layer 3 routing loop?
answer
- redundant cables close a path
- what the Ethernet header lacks
- flooding out every other port
- IPv4 TTL, IPv6 Hop Limit
- block ports, keep one path
basics
~20 sEthernet frames carry no TTL or hop count, so a broadcast that enters a loop of switches circulates indefinitely and keeps reaching every host. Spanning tree blocks redundant ports so one active path remains, and reopens one if that path fails.
solid answer
~50 sSwitches are cabled redundantly so one failed link does not cut a site off, but redundant links form loops. An Ethernet header (destination MAC, source MAC, EtherType) has no hop count or `TTL`, and a switch floods broadcasts and unknown-destination frames out every port except the one they arrived on. Nothing expires a frame that enters a loop: it circulates and keeps reaching every host until a link in the loop is cut. A routing loop is bounded: each IPv4 router decrements `TTL` (RFC 791, RFC 1812) and each IPv6 node `Hop Limit` (RFC 8200), discarding the packet at zero, and routers must not forward limited broadcasts (RFC 1812). Spanning tree has the switches exchange BPDUs and block just enough ports that exactly one active path joins any two segments, keeping the blocked links as standby.
go deeper
Recall the one-line cause: Ethernet has no TTL, so a flooded frame in a loop never dies. Then say what spanning tree does about it: block redundant ports, keep one path, reopen on failure.
Explain why flooding plus the missing hop count makes copies circulate, and contrast IP's TTL and Hop Limit, which bound a routing loop. Name the four symptoms: storm, duplicates, MAC flapping and CPU load.
Show you know the blast radius: a switching loop takes down a whole broadcast domain while a routing loop degrades only the looping prefixes. Mention that VLANs limit the reach but never remove the loop.
Discuss the price of blocking: idle links and non-shortest paths. Be ready to argue when link aggregation, routed access or an overlay fabric is worth more than a spanning-tree design.
## Why switched networks contain loops at all A **switch** (the IEEE standards call it a *bridge*) relays Ethernet frames between its ports. Network designers deliberately connect switches with **more than one path**: two uplinks from an access switch, a ring of switches, a mesh between distribution switches. The reason is resilience: if one cable, optic or switch fails, traffic still has a way through. But any redundant path closes a **loop**, a cycle in the physical topology, and Ethernet cannot tolerate one on its own. ## What the Ethernet header lacks An Ethernet frame header holds three things a switch looks at: the **destination MAC address**, the **source MAC address** and the **EtherType** (an 802.1Q tag adds a VLAN ID and priority, nothing more). There is **no hop count and no time-to-live field**. RFC 6325, the IETF's TRILL specification, states the problem directly in its introduction: the Ethernet header contains no hop count or TTL, which is dangerous whenever a temporary loop forms. Two switch behaviours turn that missing field into an outage: - **Flooding.** A switch sends a broadcast frame, and any frame whose destination it has not learned, out of **every port except the one it arrived on**. In a loop, "every other port" includes the way back round. - **No memory of frames.** A switch keeps a table of *addresses*, not of *frames it has already relayed*. A copy that comes back round looks like a brand-new frame and is flooded again. Put together, a single ARP request (which RFC 826 has a host broadcast to every station on the segment) enters the loop and nothing ever expires it. Each pass re-delivers it to every host port, and every further broadcast adds more copies that also never leave. ## Why a Layer 3 loop is bounded Routing loops happen too, for example while routers disagree about a failed link. They hurt, but they burn out: | Property | Ethernet (Layer 2) | IP routing (Layer 3) | |---|---|---| | Lifetime field | none | IPv4 `TTL`, IPv6 `Hop Limit`, 8 bits each | | What a hop does | relays the frame unchanged | decrements the field, discards at zero | | Broadcasts | flooded across every switch in the VLAN | routers must not forward limited broadcasts (RFC 1812) | | Outcome of a loop | copies circulate until the loop is cut | each packet dies after at most 255 hops | RFC 791 says a datagram whose TTL reaches zero must be destroyed, and RFC 8200 says an IPv6 packet is discarded when its `Hop Limit` is zero or decremented to zero. So a routing loop wastes some bandwidth and drops the affected traffic; a switching loop can take down **the whole broadcast domain**, because every host on it receives the storm. ## What a loop does to a network The symptoms always come together: - **Broadcast storm**: looping broadcasts saturate the inter-switch links and every access port in the VLAN. - **Duplicate frames**: a frame flooded down two paths arrives at its destination twice. - **MAC address flapping**: a switch sees the same source address arriving on different ports and keeps moving its table entry, so traffic for that host is sent the wrong way. - **CPU exhaustion**: hosts and the switches' own management processors are interrupted by every broadcast copy. ## How spanning tree fixes it **Spanning tree** (IEEE 802.1D; its rapid successor RSTP was folded into 802.1D-2004) keeps the physical redundancy but makes the *logical* topology a tree: 1. The switches exchange **BPDUs** (bridge protocol data units), the control messages that let them discover one another and the shape of the network. 2. One switch becomes the **root**, and every other switch keeps its best path towards it. 3. Every port that would close a loop is put into a **blocking** condition: it discards data frames but keeps listening for BPDUs. 4. When an active link fails, the BPDUs stop or change, and a blocked port moves to forwarding so connectivity returns. The result is exactly **one active path between any two segments**, so a flooded frame reaches every host once and then stops at the edge. ## What it costs Blocking is not free. RFC 7348 (VXLAN, an Informational RFC) notes that with spanning tree, operators pay for links they cannot use, and RFC 6325 points out that forwarding follows whatever path survives the blocking rather than the shortest path between two switches. Link aggregation, routed access and overlay fabrics are the designs that recover that capacity, and each still depends on keeping whatever Layer 2 remains loop-free.
- Doesn't an Ethernet broadcast storm eventually die out once links congest and frames are dropped?No. Congestion drops some copies, but the survivors keep circulating and every new broadcast or flooded multicast (ARP, DHCP and the like) adds more. Where a switch has three or more ports in the looped topology, each copy also multiplies on every pass. Nothing in the frame expires, so the storm lasts until a link in the loop is cut or blocked.
- Does splitting a switched network into VLANs prevent Layer 2 loops?It limits a storm's reach, because a broadcast floods only within its own VLAN, which is its own broadcast domain. It does not remove the loop: a cabling loop that carries a VLAN still loops that VLAN, and a loop between two trunks carries every VLAN on them. VLANs shrink the blast radius; spanning tree or a loop-free design must still cover every VLAN.
- Why don't switches simply add a hop count to Ethernet frames?Transparent bridging was designed to relay hosts' frames unchanged, so there is no field a classic switch can decrement. Protocols that need one add their own header: TRILL (RFC 6325, Standards Track) wraps frames between routing bridges in a header with a 6-bit hop count. Plain 802.1D bridging keeps the frame as it is, so it must avoid loops entirely.
saying these in an interview costs you the question
- Ethernet frames carry a TTL that each switch decrements, just like IP packets.
- A broadcast storm burns itself out once the links are congested.
- Spanning tree load-balances traffic across all of the redundant links.
- Spanning tree shuts redundant links down until someone re-enables them.
- A routing loop is just as unbounded as a switching loop.