skip to content

Root Bridge Election

The lowest bridge ID wins, and bridge ID is priority then MAC, so the oldest switch wins unless priority is set. Interviewers ask because a badly placed root degrades the whole topology.

on this pageshow

questions

5

In spanning tree, which switch becomes the root bridge, and why does an untuned network often end up with an old switch as root?

level: juniorimportance: must knowfreq 50%

answer

  1. lowest wins, not highest
  2. priority first, then the address
  3. every switch ships the same default
  4. the tie falls to the MAC

basics

~20 s

The switch with the lowest bridge ID becomes root. The bridge ID is a priority followed by a MAC address, and every switch ships with the same default priority, so the lowest MAC decides, which is frequently an older device.

solid answer

~40 s

Spanning tree elects as root the bridge with the **lowest bridge ID**, an 8-octet value made of a 2-octet priority followed by the bridge's 6-octet MAC address (RFC 4188's `BridgeId`). Priority is compared first, so a deliberately low priority beats any MAC address. Untouched switches all carry the same IEEE default priority, 32,768, so the tie falls to the MAC address and the lowest one wins. Manufacturers tend to hand out addresses in rising order over the years, so that is often the oldest box in the building, a forgotten closet switch, although a manufacturer whose address block sorts lower can beat age. The cure is to set the priority on purpose on the switches you want as root and as backup root.

go deeper

for a junior

Recall the rule in one line: the lowest bridge ID wins, and the bridge ID is priority followed by MAC address, so with default priorities the lowest MAC becomes root.

for a middle

Explain why priority dominates: it sits in the bridge ID's most significant octets. Show that equal default priorities hand the decision to MAC addresses, and why that favours older hardware only as a tendency.

for a senior

Connect the accidental root to its effects on real traffic, idle fast links and a fragile closet switch, and say how you would verify and correct it with deliberate primary and backup priorities.

for a principal

Treat root placement as a design decision that belongs in a standard, not a default left to address order, and weigh how much of the network you want depending on one layer-2 tree at all.

## What the root bridge is Spanning tree turns a switched network that has redundant links into a single loop-free tree. Every tree needs a reference point, and in spanning tree that point is the **root bridge**: one switch that every other switch measures its distance to. Each non-root switch then keeps exactly one active path toward the root and blocks its other redundant paths; how those ports are chosen is a separate step of the protocol. The root's own ports normally all forward, and the shape of the whole tree, which links carry traffic and which sit idle, follows from where the root is. So the question "which switch is root?" is really "which switch does all forwarding radiate from?", and the protocol answers it with a single comparison. ## The bridge ID Every bridge has a **bridge ID** (RFC 4188 calls the type `BridgeId`): 8 octets, of which - the **first 2 octets** hold a **priority** value, the part an operator can configure, and - the **last 6 octets** hold a **MAC address** that identifies the bridge. RFC 4188 recommends the numerically smallest MAC among the bridge's ports but requires only that it be unique. The rule of the election is short: **the lowest bridge ID wins**. Because the priority sits in the most significant octets, priority is compared first and the MAC address only breaks a tie between equal priorities. Lower is better, which is the opposite of protocols such as the OSPF designated-router election, where the highest priority wins; mixing the two up is a classic interview slip. ## What happens when nobody configures anything IEEE 802.1D gives every bridge the same default priority, **32,768**. (On switches that run a separate tree per VLAN the displayed number also includes the VLAN, for example 32,769 in VLAN 1; that addition is identical on every switch in the same tree, so it never decides anything.) With every priority equal, the election is decided entirely by MAC address. | Switch | Where it sits | Priority | Bridge MAC | Result | |---|---|---|---|---| | DIST-1 | distribution, new | 32,768 | `00-00-5E-00-53-40` | loses | | DIST-2 | distribution, new | 32,768 | `00-00-5E-00-53-41` | loses | | ACC-7 | access closet, oldest | 32,768 | `00-00-5E-00-53-07` | **root**: lowest MAC | The two distribution switches, the ones a designer would want at the centre of the tree, lose to a closet switch purely because its address sorts lower. ## Why "oldest wins" is a tendency, not a rule The folklore says the oldest switch becomes root. The mechanism behind it: 1. MAC addresses are assigned by manufacturers from their own address blocks. 2. A manufacturer tends to allocate addresses in rising order as it ships hardware over the years. 3. So among one manufacturer's switches, older hardware tends to have lower addresses and wins the tie. It is only a tendency. A switch from a manufacturer whose block sorts lower can beat an older switch from another, and a replacement unit can carry any address. The only dependable statement is the rule itself: equal priorities, lowest MAC wins. ## Why it matters, and taking control An accidental root is rarely the right root. Typical consequences: - traffic between well-connected core or distribution switches detours through the accidental root's links; - the fastest links in the network can end up blocked while slow ones carry the load; - the reliability of the whole layer-2 domain now depends on a switch nobody chose. The fix is to stop leaving the outcome to MAC addresses. Configure the switch you want as root with a lower priority than the default, and a second switch with the next-lowest value as the backup root, for example 24,576 and 28,672. On current bridges the priority moves in steps of 4,096, which is why those numbers look odd. Once the priorities are set, the MAC address goes back to being what it should be: a tie-breaker that is never reached. ## Checking the result Every bridge reports the root it currently believes in (RFC 4188 exposes it as `dot1dStpDesignatedRoot`). Comparing that value across switches after a change confirms that the election landed where the design intended, and that every switch agrees on it.

  • Does the root bridge have to be the fastest or most central switch in the network?
    No. The election compares only bridge IDs, priority first and MAC second; link speed and position play no part. Speed matters later, through path cost, when non-root switches choose their path toward the root. That is exactly why an untuned network can elect a slow edge switch: the protocol knows nothing about the role a switch plays in your design.
  • Which MAC address does a switch use in its bridge ID when every port has its own address?
    One address for the whole bridge, its bridge address. RFC 4188 recommends the numerically smallest MAC among the bridge's ports but only requires it to be unique, and many switches use a base address assigned to the chassis. It is fixed for the box, which makes it a stable tie-breaker after priority.

saying these in an interview costs you the question

  • The switch with the highest bridge priority value becomes the root bridge.
  • The root bridge is the switch with the fastest links or the most ports.
  • The MAC address is compared before the priority in the bridge ID.
  • The newest switch wins because it has the most recent hardware.
  • An untuned network picks a random root each time the switches boot.
open as a page

How do 802.1D spanning-tree bridges agree on a single root bridge, and how is one bridge ID judged better than another?

level: middleimportance: must knowfreq 38%

basics

~20 s

Every bridge starts by claiming to be root and advertising its own bridge ID. A bridge that hears a lower root ID adopts it and relays it; bridge IDs compare as one number, priority first, MAC second, lowest winning.

open as a page

Why can a spanning-tree bridge priority be set only in multiples of 4,096, and what do the low 12 bits of the field carry?

level: middleimportance: should knowfreq 24%

basics

~20 s

Since IEEE 802.1t, the 16-bit priority field is split: only its top 4 bits are configurable, so priority moves in steps of 4,096, and the low 12 bits form a system ID extension carrying the VLAN or instance number.

open as a page

In a campus spanning tree where an old access switch won the root election, what happens to traffic between the distribution switches, and how do you fix it?

level: seniorimportance: should knowfreq 30%

basics

~20 s

Every forwarding path radiates from the root, so traffic between the distribution switches detours through the access switch's uplinks while their direct link blocks. Fix it by giving the distribution switches the two lowest bridge priorities, as primary and secondary root.

open as a page

What happens to an 802.1D spanning tree when someone plugs in a new switch whose bridge ID is lower than the current root's?

level: seniorimportance: should knowfreq 20%

basics

~20 s

The new switch's BPDUs announce a better root, every bridge accepts it, and the tree is rebuilt around the newcomer. Under 802.1D, ports that must start forwarding wait about 30 seconds and MAC entries age out early, so traffic drops and floods.

open as a page