IntermediatePublished 2026-08-01
CCNA Foundations: Root Guard — Keep the Root Where You Put It
Today's daily lab
Harden a small campus Layer-2 triangle so a downstream access switch cannot become root. You will verify DSW1 is already the STP root for VLAN 20, then apply Root Guard on each distribution switch’s access-facing trunk to the access layer. Confirm steady-state reachability between users and that a superior BPDU would put those ports into root-inconsistent instead of re-rooting the campus.
Learning objectives
- Identify the intended STP root and verify the current root bridge per VLAN
- Apply Root Guard correctly on downstream-facing trunk ports at the distribution layer
- Validate steady state (no inconsistent ports) and end-to-end user VLAN reachability
- Demonstrate how a superior BPDU triggers root-inconsistent and auto-recovers when the threat is removed
- Avoid common misconfiguration: never apply Root Guard toward the core/root or on host access ports
Troubleshooting focus
- If hosts cannot ping each other, verify both access switch ports are in VLAN 20 and up/up with portfast
- Ensure all trunks match: native VLAN 999 and allowed VLANs 20,999 on both ends
- Confirm VLAN 20 exists on every switch in the path (vtp transparent requires local VLAN definition)
- Check the STP root: DSW1 should be root for VLAN 20; if not, examine priorities and BPDUs
- If an uplink shows root-inconsistent unexpectedly, ensure Root Guard is only on access-facing trunks
Topology
Subscribe to preview this lab's topology.
See plansFound a problem with this lab?
Please sign in to report a problem — tying it to your attempts lets us reproduce and fix it faster.
Grade your work
Create a free account to submit your completed lab for grading.
Create a free account