All guided builds

Guided buildcore6 steps~16 min3 devices

Choose your root bridge

Close a loop of three switches, find the port spanning tree blocks on its own, then decide which switch is root — and which one takes over when it fails.

What you'll be able to do: A looped triangle of switches where the root bridge, the backup root and the blocked port are all decisions you made — and where losing the core hands the root to the switch you planned, then gives it back when the core returns.

Topics: Spanning Tree · Switching · Root bridge · Redundancy

What you'll build

Step by step

  1. 1. Two core switches, one cable

    Drag two switches onto the canvas, name them SW-Core1 and SW-Core2, and cable Gi0/2 to Gi0/2. Spanning tree is already running on both — nothing to switch on. One cable is no loop, so both ends forward: one switch's end is the designated port, the other's is its root port.

    • Cable SW-Core1 Gi0/2 ↔ SW-Core2 Gi0/2

    On SW-Core1 — Name the first core switch

    enable
    configure terminal
    hostname SW-Core1
    end

    On SW-Core2 — Name the second core switch

    enable
    configure terminal
    hostname SW-Core2
    end

    Check: run show spanning-tree on SW-Core1 and look for Bridge ID Priority 32769 (priority 32768 sys-id-ext 1).

    Why: Every switch speaks spanning tree out of the box — rapid PVST+ here, one instance per VLAN. Each advertises a bridge ID (priority plus VLAN, then its MAC address), and the lowest bridge ID in the network becomes the root bridge that every other switch measures its path against.

  2. 2. Close the loop — and find the port spanning tree blocks

    Add SW-Access and give it an uplink to each core: Gi0/1 to SW-Core1's Gi0/1, Gi0/2 to SW-Core2's Gi0/1. Three switches, three cables — a loop. Run `show spanning-tree` on all three: exactly one says "This bridge is the root", and exactly one port in the whole triangle reads BLK. Which ones? Every switch is tied at 32769, so the lowest MAC address breaks the tie — your canvas may well differ from your neighbour's, because nobody chose.

    • Cable SW-Access Gi0/1 ↔ SW-Core1 Gi0/1
    • Cable SW-Access Gi0/2 ↔ SW-Core2 Gi0/1

    On SW-Access — Name the access switch

    enable
    configure terminal
    hostname SW-Access
    end

    Check: run show spanning-tree on SW-Access and look for Root ID Priority 32769.

    Why: Spanning tree breaks a loop by electing one root, giving every other switch one root port (its cheapest path to the root), choosing one designated port on every link, and blocking whatever is left. A blocked port still listens to BPDUs — it is a spare waiting for a failure, not a dead cable.

  3. 3. Name a backup root — and watch it take over

    Plan the failover first: on SW-Core2, `spanning-tree vlan 1 root secondary`. That is shorthand for priority 28672, 4096 better than the default. It is meant for the backup, but nobody is primary yet, so 28672 beats every 32768 in the triangle and SW-Core2 becomes the root — whoever held it before. Spanning tree has never heard of "secondary"; it only compares numbers.

    On SW-Core2 — Lower SW-Core2's VLAN 1 priority with the secondary macro

    enable
    configure terminal
    spanning-tree vlan 1 root secondary
    end

    Check: run show spanning-tree on SW-Access and look for Root ID Priority 28673.

    Why: Root election is a pure comparison: lowest priority wins, and the MAC address only breaks ties. The root primary and root secondary keywords are macros that write a priority into the configuration, which is why the result depends entirely on what every other switch is set to.

  4. 4. Make SW-Core1 the root — and watch the blocked port move

    On SW-Core1, `spanning-tree vlan 1 root primary` writes priority 24576, which beats SW-Core2's 28672, and the tree re-forms around SW-Core1. Watch SW-Access: its root port swings to Gi0/1, straight up to the new root, and Gi0/2 drops to Altn BLK. Why that end of that link? SW-Core2 and SW-Access are both one hop from the root at cost 4, so the tie goes to the lower bridge ID — SW-Core2's 28673 beats SW-Access's 32769 — and SW-Access's end is the one that blocks.

    On SW-Core1 — Make SW-Core1 the root bridge for VLAN 1

    enable
    configure terminal
    spanning-tree vlan 1 root primary
    end

    Check: run show spanning-tree on SW-Access and look for Gi0/2 Altn BLK 4 128.Gi0/2 P2p.

    Why: Put the root where traffic converges — the core — so every access switch's best path runs straight up to it. Making the other core the second-best bridge pushes the blocked port down to the access layer, never onto the link between the cores.

  5. 5. Fail the root

    Simulate losing the core: shut both of SW-Core1's inter-switch ports. The survivors re-elect, and because you planned it, the answer is known in advance: SW-Core2 becomes root, and SW-Access's blocked Gi0/2 turns into its root port and starts forwarding. The spare link was waiting for exactly this.

    On SW-Core1 — Take both of the core's inter-switch links down at once

    enable
    configure terminal
    interface range Gi0/1 - 2
    shutdown
    end

    Check: run show spanning-tree on SW-Access and look for Gi0/2 Root FWD 4 128.Gi0/2 P2p.

    Why: Without the secondary, the replacement root would be whichever survivor has the lower MAC address — quite possibly the access switch. Configuring a secondary turns the failure plan into a decision instead of a coin toss.

  6. 6. Bring the core back

    Undo the failure with `no shutdown` on the same two ports. SW-Core1 still has the lowest bridge ID in the network, so the moment its BPDUs are heard again it takes the root straight back, SW-Access's root port returns to Gi0/1, and Gi0/2 goes back to blocking — the tree you designed, restored without a single command about spanning tree.

    On SW-Core1 — Bring both inter-switch links back up

    enable
    configure terminal
    interface range Gi0/1 - 2
    no shutdown
    end

    Check: run show spanning-tree on SW-Access and look for Port Gi0/1.

    Why: Spanning tree always converges on the best bridge ID: a better root announcing itself wins the election back immediately. The priorities you set are the design, and every failure and recovery re-derives the same answer from them.

The theory behind it

Build it for real

The lab walks you through these steps and ticks each one off as your network starts working.

Open in the lab
Choose your root bridge — step-by-step network lab · NetForge-AI