AdvancedPublished 2026-07-02
Root Guard on Designated Ports
Bundle lab · $29.99
Advanced Rapid-PVST+ and Root Guard implementation on a three-switch triangle with a real loop. SW1 is the intentional root for VLAN 90 and protects its designated ports with Root Guard to prevent root re-parenting. Two Alpine hosts on VLAN 90 verify end-to-end forwarding remains stable even if a superior BPDU appears downstream.
✓ 1 learner has completed this lab.
Learning objectives
- Configure Rapid-PVST+ across all switches for VLAN 90
- Deterministically elect SW1 as the STP root for VLAN 90 using bridge priority 4096
- Enable Root Guard on SW1’s designated trunk ports toward SW2 and SW3
- Apply PortFast and BPDU Guard on host-facing access ports only
- Harden trunks with native VLAN 999, nonegotiate, and a restricted allow-list
- Verify STP state, root election, and Root Guard status using key show commands
- Confirm host-to-host reachability on VLAN 90 remains stable
Troubleshooting focus
- If SW1 is not root for VLAN 90, compare bridge priorities and MAC addresses with show spanning-tree vlan 90 on all switches.
- If a port shows root-inconsistent, check for superior BPDUs from the neighbor and verify the intended root’s priority is lowest.
- If hosts cannot ping, confirm both access ports are in VLAN 90 and trunks allow VLAN 90 end-to-end.
- If a trunk is up but no user traffic passes, verify native VLAN alignment and the allow-list includes VLAN 90 on both ends.
- If an access port err-disables due to BPDU Guard, identify the source of BPDUs (loop or unauthorized switch) before re-enabling.
Topology
Own this lab's topology — and every lab — in Spanning Tree Protocol (STP).
Unlock with Spanning Tree Protocol (STP)Found a problem with this lab?
Please sign in to report a problem — tying it to your attempts lets us reproduce and fix it faster.
Grade your work
Create a free account to submit your completed lab for grading.
Create a free account