AdvancedPublished 2026-07-02
Root Guard on Designated Ports
Bundle lab
Lab 9 of 10 in Spanning Tree Protocol (STP) · ← Previous · Next →
CCNA exam domain: Network Access
Advanced Rapid-PVST+ and Root Guard implementation on a three-switch triangle with a real loop. SW1 is the intentional root for VLAN 90 and protects its designated ports with Root Guard to prevent root re-parenting. Two Alpine hosts on VLAN 90 verify end-to-end forwarding remains stable even if a superior BPDU appears downstream.
Learning objectives
- Configure Rapid-PVST+ across all switches for VLAN 90
- Deterministically elect SW1 as the STP root for VLAN 90 using bridge priority 4096
- Enable Root Guard on SW1’s designated trunk ports toward SW2 and SW3
- Apply PortFast and BPDU Guard on host-facing access ports only
- Harden trunks with native VLAN 999, nonegotiate, and a restricted allow-list
- Verify STP state, root election, and Root Guard status using key show commands
- Confirm host-to-host reachability on VLAN 90 remains stable
Troubleshooting focus
- If SW1 is not root for VLAN 90, compare bridge priorities and MAC addresses with show spanning-tree vlan 90 on all switches.
- If a port shows root-inconsistent, check for superior BPDUs from the neighbor and verify the intended root’s priority is lowest.
- If hosts cannot ping, confirm both access ports are in VLAN 90 and trunks allow VLAN 90 end-to-end.
- If a trunk is up but no user traffic passes, verify native VLAN alignment and the allow-list includes VLAN 90 on both ends.
- If an access port err-disables due to BPDU Guard, identify the source of BPDUs (loop or unauthorized switch) before re-enabling.
Topology
Subscribe to preview this lab's topology.
See plansGrade your work
How this lab is graded
- Build it your way. Where a lab lets you choose a value — a VLAN name, an interface description — grading checks that you configured it, not which name you picked. Names that another line has to reference, like an ACL applied with
access-class, are stated in the guide and do have to match. - Addresses, modes and protocol keywords are exact. An IP address, a subnet mask,
switchport mode trunk, an encapsulation — these carry the meaning of the lab, so they are graded as written in the guide. - Grading reads your saved configuration. Export the lab from CML after you have configured it, and make sure anything you set is in the
running-config— a change that only exists in a terminal session never reaches the grader. - You can submit as many times as you like. Your best score stands, and each attempt tells you which checks passed so you can work the gaps.
- Scored something you believe is correct? Use Report an issue on this page — that is exactly how the grading fixes in the changelog got found.
Create a free account to submit your lab for grading.
Create a free accountFound a problem with this lab?
Please sign in to report a problem — tying it to your attempts lets us reproduce and fix it faster.