10-20
Catalyst 3550 Multilayer Switch Software Configuration Guide
78-11194-03
Chapter 10 Configuring STP
Understanding Advanced STP Features
Understanding Root Guard
The Layer 2 network of a service provider (SP) can include many connections to switches that are not
owned by the SP. In such a topology, STP can reconfigure itself and select a customer switch as the STP
root switch, as shown in
Figure 10-13
. You can avoid this situation by configuring the root-guard feature
on interfaces that connect to switches outside of your customer’s network. If STP calculations cause an
interface in the customer network to be selected as the root port, root guard then places the interface in
the root-inconsistent (blocked) state to prevent the customer’s switch from becoming the root switch or
being in the path to the root.
If a switch outside the network becomes the root switch, the interface is blocked (root-inconsistent state),
and STP selects a new root switch. The customer’s switch does not become the root switch and is not in
the path to the root. For more information, see the
“Configuring Root Guard” section on page 10-36
.
Caution
Misuse of the root-guard feature can cause a loss of connectivity.
Figure 10-13 STP in a Service-Provider Network
Understanding EtherChannel Guard
EtherChannel guard detects a misconfigured EtherChannel when Catalyst 3550 switch interfaces are
configured as an EtherChannel while interfaces on the other device are not or not all the interfaces on
the other device are in the same EtherChannel. This feature is enabled by default.
In response to misconfiguration detected on the other device, EtherChannel guard puts Catalyst 3550
interfaces into the error-disabled (err-disabled) state to prevent a spanning-tree loop. For more
information, see the
“Enabling EtherChannel Guard” section on page 10-37
.
Customer network
Potential
STP root without
root guard enabled
Enable the root-guard feature
on these interfaces to prevent
switches in the customer
network from becoming
the root switch or being
in the path to the root.
Desired
root switch
Service-provider network
43578