Specifications
14-13
Catalyst 2950 and Catalyst 2955 Switch Software Configuration Guide
78-11380-07
Chapter 14 Configuring Optional Spanning-Tree Features
Understanding Optional Spanning-Tree Features
If the switch is operating in multiple spanning-tree (MST) mode, root guard forces the port to be a
designated port. If a boundary port is blocked in an internal spanning-tree (IST) instance because of root
guard, the port also is blocked in all MST instances. A boundary port is a port that connects to a LAN,
the designated switch of which is either an 802.1D switch or a switch with a different MST region
configuration.
Root guard enabled on an interface applies to all the VLANs to which the interface belongs. VLANs can
be grouped and mapped to an MST instance.
If your switch is running PVST, PVRST, or MSTP, you can enable this feature by using the
spanning-tree guard root interface configuration command. The PVRST and MSTP are available only
if you have the EI installed on your switch.
Caution Misuse of the root-guard feature can cause a loss of connectivity.
Figure 14-10 Root Guard in a Service-Provider Network
Understanding Loop Guard
You can use loop guard to prevent alternate or root ports from becoming designated ports because of a
failure that leads to a unidirectional link. This feature is most effective when it is configured on the entire
switched network.
If your switch is running PVST, PVRST, or MSTP, you can enable this feature by using the
spanning-tree loopguard default global configuration command. The PVRST and MSTP are available
only if you have the EI installed on your switch.
When the switch is operating in PVST mode, loop guard prevents alternate and root ports from becoming
designated ports, and spanning tree does not send BPDUs on root or alternate ports.
When the switch is operating in MST mode, BPDUs are not sent on nonboundary ports only if the port
is blocked by loop guard in all MST instances. On a boundary port, loop guard blocks the port in all MST
instances.
Customer network
Potential
spanning-tree root without
root guard enabled
Enable the root-guard feature
on these interfaces to prevent
switches in the customer
network from becoming
the root switch or being
in the path to the root.
Desired
root switch
Service-provider network
43578