10-20
Catalyst 3550 Multilayer Switch Software Configuration Guide
78-11194-03
Chapter10 Configuring STP
Understanding Advanced STP Features
Understanding Root Guard
The Layer 2 network of a service provider (SP) can incl ud e ma ny conn ec ti ons t o swi tc hes tha t a re n ot
owned by the SP. In such a topology, STP can reconfigure itself and select a customer switch as the STP
root switch, as shown in Figure 10-13. You can avoid this situation by configuring the root-guard feature
on interfaces that connect to switches outside of your customers network. If STP calculations cause an
interface in the customer network to be selected as the root port, root guard then places the interface in
the root-inconsistent (blocked) state to prevent the customers switch from becoming the root switch or
being in the path to the root.
If a switch outside the network becomes the root switch, the interface is blocked (root-inconsistent state),
and STP selects a new root switch. The customers switch does not become the root switch and is not in
the path to the root. For more information, see the Configuring Root Guard section on page 10-36.
Caution Misuse of the root-guard feature can cause a loss of connectivity.
Figure10-13 STP in a Service-Provider Network
Understanding EtherChannel Guard
EtherChannel guard detects a misconfigured EtherChannel when Ca talyst 3550 swi tch int erf ace s a re
configured as an EtherChannel while interfaces on the other device are not or not all the interfaces on
the other device are in the same EtherChannel. This feat ur e i s e nabl e d by de faul t.
In response to misconfiguration detected on the other devic e, E the rChann el gua rd pu ts Ca taly st 35 50
interfaces into the error-disabled (err-disabled) state to prevent a spanning-tree loop. For more
information, see the Enabling EtherChannel Guard section on page 10-37.
Customer network
Potential
STP root without
root guard enabled
Enable the root-guard feature
on these interfaces to prevent
switches in the customer
network from becoming
the root switch or being
in the path to the root.
Desired
root switch
Service-provider network
43578