IntermediatePublished 2026-08-01
CCNA Foundations: Root Guard — Keep the Root Where You Put It
Archive lab
CCNA exam domain: Network Access
Harden a small campus Layer-2 triangle so a downstream access switch cannot become root. You will verify DSW1 is already the STP root for VLAN 20, then apply Root Guard on each distribution switch’s access-facing trunk to the access layer. Confirm steady-state reachability between users and that a superior BPDU would put those ports into root-inconsistent instead of re-rooting the campus.
Learning objectives
- Identify the intended STP root and verify the current root bridge per VLAN
- Apply Root Guard correctly on downstream-facing trunk ports at the distribution layer
- Validate steady state (no inconsistent ports) and end-to-end user VLAN reachability
- Demonstrate how a superior BPDU triggers root-inconsistent and auto-recovers when the threat is removed
- Avoid common misconfiguration: never apply Root Guard toward the core/root or on host access ports
Troubleshooting focus
- If hosts cannot ping each other, verify both access switch ports are in VLAN 20 and up/up with portfast
- Ensure all trunks match: native VLAN 999 and allowed VLANs 20,999 on both ends
- Confirm VLAN 20 exists on every switch in the path (vtp transparent requires local VLAN definition)
- Check the STP root: DSW1 should be root for VLAN 20; if not, examine priorities and BPDUs
- If an uplink shows root-inconsistent unexpectedly, ensure Root Guard is only on access-facing trunks
Topology
Subscribe to preview this lab's topology.
See plansGrade your work
How this lab is graded
- Build it your way. Where a lab lets you choose a value — a VLAN name, an interface description — grading checks that you configured it, not which name you picked. Names that another line has to reference, like an ACL applied with
access-class, are stated in the guide and do have to match. - Addresses, modes and protocol keywords are exact. An IP address, a subnet mask,
switchport mode trunk, an encapsulation — these carry the meaning of the lab, so they are graded as written in the guide. - Grading reads your saved configuration. Export the lab from CML after you have configured it, and make sure anything you set is in the
running-config— a change that only exists in a terminal session never reaches the grader. - You can submit as many times as you like. Your best score stands, and each attempt tells you which checks passed so you can work the gaps.
- Scored something you believe is correct? Use Report an issue on this page — that is exactly how the grading fixes in the changelog got found.
Create a free account to submit your lab for grading.
Create a free accountFound a problem with this lab?
Please sign in to report a problem — tying it to your attempts lets us reproduce and fix it faster.