NetForge-AI
Networking CourseGuidedLessonsCommunityFeaturesProtocolsPricingPrivacyTerms
Sign inStart free
NetForge-AI
Networking CourseGuidedLessonsCommunityFeaturesProtocolsPricingPrivacyTerms
Sign inStart free
All lessons
Intermediate·15 minute read

Spanning Tree explained: root bridge and blocked ports

Short answer

Spanning Tree Protocol (STP) stops loops between switches by blocking just enough redundant ports to leave one loop-free path. The switches elect a root bridge — the lowest bridge ID, which is the priority followed by the MAC address — then every other switch keeps its best path toward the root forwarding and blocks the rest until a link fails.

Redundant switch links make a network survive a failure — and, without Spanning Tree, they make it melt down in a broadcast storm. This lesson explains how STP elects a root bridge, which ports it blocks, and how to choose the root yourself.

Open this lab

Why loops are fatal at Layer 2

An Ethernet frame has no time-to-live field. If two switches are connected by two links, a broadcast leaves one switch on both links, comes back on the other, and is flooded again — forever, multiplying each time. Within seconds the links are saturated and MAC tables flap. Spanning Tree exists so you can have the redundant cable without the loop.

Electing the root bridge

Every switch has a bridge ID: a priority (32768 by default, plus the VLAN number in per-VLAN STP) followed by its MAC address. The lowest bridge ID becomes the root bridge. With default priorities, the switch with the lowest MAC wins — often the oldest switch in the room, which is rarely the one you want.

SW-Core1(config)# spanning-tree vlan 1 root primary
SW-Core1(config)# end
SW-Access# show spanning-tree
Note: root primary lowers this switch's priority below the current root's; root secondary sets it just above, so it takes over only if the root fails.

Port roles

RoleWhereState
Root portOn each non-root switch: its best path toward the rootForwarding
Designated portOn each link: the port on the side closest to the rootForwarding
Alternate / blocked portAny other port that would create a loopBlocking

Watch it fail over

Build a triangle of three switches. One port goes to blocking (show spanning-tree lists it as Altn BLK). Shut the link to the root and run show spanning-tree again: the blocked port becomes the new root port and moves to forwarding, and traffic flows over the backup path.

Common questions

How is the STP root bridge chosen?
The switch with the lowest bridge ID wins: lowest priority first, and the lowest MAC address breaks a tie.
What is the default STP bridge priority?
32768. In per-VLAN spanning tree the VLAN number is added to it, so VLAN 1 shows 32769.
Why is one of my switch ports blocking?
That port would complete a loop, so Spanning Tree keeps it in blocking as a backup; it starts forwarding if the active path fails.
What is the difference between STP and RSTP?
RSTP (Rapid Spanning Tree) uses the same root election but converges much faster after a change, because switches negotiate port roles directly instead of waiting on timers.

Practise it

  • Guided build: choose your root bridge
  • Guided build: a redundant campus

Practice this in the lab

Reading helps. Wiring it up yourself and breaking it makes it stick.

Open the lab
NetForge-AI

A browser-native network lab and networking course, beginner to advanced. Free account opens Module 1 + a 5-device lab; the Course & Lab Pass or All-Access Max opens the full course.

Product

  • Lab
  • 3D Live
  • Networking Course
  • Lessons
  • Guided Builds
  • Network Challenges
  • For Teachers
  • Community
  • Features

Course modules

  • 1 · Fundamentals
  • 2 · Addressing
  • 3 · Access (L2)
  • 4 · Connectivity
  • Final Weighted Exam

Resources

  • Command Reference
  • Free Networking Tools
  • Subnet Calculator
  • MAC Address Lookup
  • Port Number Lookup
  • OSI Model Chart
  • Simulator Comparisons
  • FAQ
  • About
  • Contact
  • Privacy Policy
  • Terms of Service

NetForge-AI is an independent educational platform and is not affiliated with, endorsed by, or sponsored by any networking vendor or certification body. All product names, protocols, and standards referenced are the property of their respective owners and are used for descriptive, educational purposes only.

© 2026 NetForge-AI. All rights reserved.Built for networking learners worldwide.