Guided buildcore6 steps~16 min3 devices
Choose your root bridge
Close a loop of three switches, find the port spanning tree blocks on its own, then decide which switch is root — and which one takes over when it fails.
What you'll be able to do: A looped triangle of switches where the root bridge, the backup root and the blocked port are all decisions you made — and where losing the core hands the root to the switch you planned, then gives it back when the core returns.
Topics: Spanning Tree · Switching · Root bridge · Redundancy
What you'll build
- SW-Core1 — a switch, the core switch that should be the root bridge
- SW-Core2 — a switch, the second core switch, planned as the backup root
- SW-Access — a switch, the access switch with one uplink to each core
Step by step
1. Two core switches, one cable
Drag two switches onto the canvas, name them SW-Core1 and SW-Core2, and cable Gi0/2 to Gi0/2. Spanning tree is already running on both — nothing to switch on. One cable is no loop, so both ends forward: one switch's end is the designated port, the other's is its root port.
- Cable SW-Core1 Gi0/2 ↔ SW-Core2 Gi0/2
On SW-Core1 — Name the first core switch
enable configure terminal hostname SW-Core1 endOn SW-Core2 — Name the second core switch
enable configure terminal hostname SW-Core2 endCheck: run
show spanning-treeon SW-Core1 and look forBridge ID Priority 32769 (priority 32768 sys-id-ext 1).Why: Every switch speaks spanning tree out of the box — rapid PVST+ here, one instance per VLAN. Each advertises a bridge ID (priority plus VLAN, then its MAC address), and the lowest bridge ID in the network becomes the root bridge that every other switch measures its path against.
2. Close the loop — and find the port spanning tree blocks
Add SW-Access and give it an uplink to each core: Gi0/1 to SW-Core1's Gi0/1, Gi0/2 to SW-Core2's Gi0/1. Three switches, three cables — a loop. Run `show spanning-tree` on all three: exactly one says "This bridge is the root", and exactly one port in the whole triangle reads BLK. Which ones? Every switch is tied at 32769, so the lowest MAC address breaks the tie — your canvas may well differ from your neighbour's, because nobody chose.
- Cable SW-Access Gi0/1 ↔ SW-Core1 Gi0/1
- Cable SW-Access Gi0/2 ↔ SW-Core2 Gi0/1
On SW-Access — Name the access switch
enable configure terminal hostname SW-Access endCheck: run
show spanning-treeon SW-Access and look forRoot ID Priority 32769.Why: Spanning tree breaks a loop by electing one root, giving every other switch one root port (its cheapest path to the root), choosing one designated port on every link, and blocking whatever is left. A blocked port still listens to BPDUs — it is a spare waiting for a failure, not a dead cable.
3. Name a backup root — and watch it take over
Plan the failover first: on SW-Core2, `spanning-tree vlan 1 root secondary`. That is shorthand for priority 28672, 4096 better than the default. It is meant for the backup, but nobody is primary yet, so 28672 beats every 32768 in the triangle and SW-Core2 becomes the root — whoever held it before. Spanning tree has never heard of "secondary"; it only compares numbers.
On SW-Core2 — Lower SW-Core2's VLAN 1 priority with the secondary macro
enable configure terminal spanning-tree vlan 1 root secondary endCheck: run
show spanning-treeon SW-Access and look forRoot ID Priority 28673.Why: Root election is a pure comparison: lowest priority wins, and the MAC address only breaks ties. The root primary and root secondary keywords are macros that write a priority into the configuration, which is why the result depends entirely on what every other switch is set to.
4. Make SW-Core1 the root — and watch the blocked port move
On SW-Core1, `spanning-tree vlan 1 root primary` writes priority 24576, which beats SW-Core2's 28672, and the tree re-forms around SW-Core1. Watch SW-Access: its root port swings to Gi0/1, straight up to the new root, and Gi0/2 drops to Altn BLK. Why that end of that link? SW-Core2 and SW-Access are both one hop from the root at cost 4, so the tie goes to the lower bridge ID — SW-Core2's 28673 beats SW-Access's 32769 — and SW-Access's end is the one that blocks.
On SW-Core1 — Make SW-Core1 the root bridge for VLAN 1
enable configure terminal spanning-tree vlan 1 root primary endCheck: run
show spanning-treeon SW-Access and look forGi0/2 Altn BLK 4 128.Gi0/2 P2p.Why: Put the root where traffic converges — the core — so every access switch's best path runs straight up to it. Making the other core the second-best bridge pushes the blocked port down to the access layer, never onto the link between the cores.
5. Fail the root
Simulate losing the core: shut both of SW-Core1's inter-switch ports. The survivors re-elect, and because you planned it, the answer is known in advance: SW-Core2 becomes root, and SW-Access's blocked Gi0/2 turns into its root port and starts forwarding. The spare link was waiting for exactly this.
On SW-Core1 — Take both of the core's inter-switch links down at once
enable configure terminal interface range Gi0/1 - 2 shutdown endCheck: run
show spanning-treeon SW-Access and look forGi0/2 Root FWD 4 128.Gi0/2 P2p.Why: Without the secondary, the replacement root would be whichever survivor has the lower MAC address — quite possibly the access switch. Configuring a secondary turns the failure plan into a decision instead of a coin toss.
6. Bring the core back
Undo the failure with `no shutdown` on the same two ports. SW-Core1 still has the lowest bridge ID in the network, so the moment its BPDUs are heard again it takes the root straight back, SW-Access's root port returns to Gi0/1, and Gi0/2 goes back to blocking — the tree you designed, restored without a single command about spanning tree.
On SW-Core1 — Bring both inter-switch links back up
enable configure terminal interface range Gi0/1 - 2 no shutdown endCheck: run
show spanning-treeon SW-Access and look forPort Gi0/1.Why: Spanning tree always converges on the best bridge ID: a better root announcing itself wins the election back immediately. The priorities you set are the design, and every failure and recovery re-derives the same answer from them.
The theory behind it
More in Switching & wireless
- Map the network with CDP and LLDP — Let two switches and a router discover each other, find the router's address from a switch that was never told it, add LLDP, then stop the router announcing itself toward the internet.
- Two departments, one switch — Split a single switch into Sales and Ops with VLANs, and watch the pings between them stop.
- One VLAN across two switches — Split four PCs into two VLANs across two switches, then carry both VLANs between the switches over a single tagged trunk.
- Router on a stick — Split one switch into two VLANs and route between them over a single router port.
- Route between VLANs on the switch — Give one switch an SVI in each VLAN, find out why the VLANs still can't talk, then turn on ip routing — inter-VLAN routing with no router at all.
- Two cables, one logical link — Add a second uplink between two switches, watch spanning tree block it, then bundle both into an LACP EtherChannel so they carry traffic together.
Build it for real
The lab walks you through these steps and ticks each one off as your network starts working.
Open in the lab