Understanding Root Guard - Cisco IE-3000-8TC Software Configuration Manual

Software configuration guide
Hide thumbs Also See for IE-3000-8TC:
Table of Contents

Advertisement

Understanding Optional Spanning-Tree Features

Understanding Root Guard

The Layer 2 network of a service provider (SP) can include many connections to switches that are not
owned by the SP. In such a topology, the spanning tree can reconfigure itself and select a customer
switch as the root switch, as shown in
on SP switch interfaces that connect to switches in your customer's network. If spanning-tree
calculations cause an interface in the customer network to be selected as the root port, root guard then
places the interface in the root-inconsistent (blocked) state to prevent the customer's switch from
becoming the root switch or being in the path to the root.
If a switch outside the SP network becomes the root switch, the interface is blocked (root-inconsistent
state), and spanning tree selects a new root switch. The customer's switch does not become the root
switch and is not in the path to the root.
If the switch is operating in multiple spanning-tree (MST) mode, root guard forces the interface to be a
designated port. If a boundary port is blocked in an internal spanning-tree (IST) instance because of root
guard, the interface also is blocked in all MST instances. A boundary port is an interface that connects
to a LAN, the designated switch of which is either an IEEE 802.1D switch or a switch with a different
MST region configuration.
Root guard enabled on an interface applies to all the VLANs to which the interface belongs. VLANs can
be grouped and mapped to an MST instance.
You can enable this feature by using the spanning-tree guard root interface configuration command.
Misuse of the root-guard feature can cause a loss of connectivity.
Caution
Figure 20-8
spanning-tree root without
root guard enabled
Cisco IE 3000 Switch Software Configuration Guide
20-8
Root Guard in a Service-Provider Network
Customer network
Potential
Chapter 20
Figure
20-8. You can avoid this situation by enabling root guard
Service-provider network
Enable the root-guard feature
on these interfaces to prevent
switches in the customer
network from becoming
the root switch or being
in the path to the root.
Configuring Optional Spanning-Tree Features
Desired
root switch
OL-13018-03

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Ie 3000

Table of Contents