Arista EOS Spanning Tree (MSTP) Configuration Guide - 夜莺博客

Arista EOS Spanning Tree (MSTP) Configuration Guide

Arista EOS runs a single spanning tree implementation (MSTP by default, RSTP compatible) that covers both PVST-style per-VLAN behaviour and instance-based mapping. Most production problems come from three places: an unintended root bridge elected because priorities were never set, edge ports that are still waiting for the listening/learning timers, and BPDUs leaking into the data center fabric where the overlay assumes a loop-free topology. This guide covers the configuration that avoids all three and the show commands that confirm it.

Enable MSTP and Define Instances

switch(config)# spanning-tree mode mstp
switch(config)# spanning-tree mst configuration
switch(config-mst)# name CAMPUS-CORE
switch(config-mst)# revision 1
switch(config-mst)# instance 1 vlan 10,20,30
switch(config-mst)# instance 2 vlan 100-150
switch(config-mst)# exit

Instances let you load-share: instance 1 can root on the primary distribution switch while instance 2 roots on the secondary. The MST name and revision must match on every switch in the region, otherwise each switch builds its own region and every inter-switch link is treated as a region boundary.

Root Bridge Selection

switch(config)# spanning-tree mst 1 priority 4096
switch(config)# spanning-tree mst 2 priority 8192
switch(config)# spanning-tree vlan 10-150 priority 4096
switch(config)# show spanning-tree root

Set an explicit primary and secondary root per instance. Leaving the default 32768 lets any newly installed switch with a lower MAC become root - a very common cause of a sudden topology change after a hardware refresh.

Edge Ports, Portfast and BPDU Guard

switch(config)# interface Ethernet1-24
switch(config-if-Et1-24)# switchport mode access
switch(config-if-Et1-24)# spanning-tree portfast
switch(config-if-Et1-24)# spanning-tree bpduguard enable
switch(config-if-Et1-24)# exit

spanning-tree portfast moves access ports straight to forwarding; BPDU guard shuts the port (errdisable) the moment a BPDU arrives, which stops someone from plugging an unmanaged switch into the wall. Recovery is automatic when the port is configured with errdisable recovery, or manual via shutdown / no shutdown.

Trunks Between Switches

switch(config)# interface Ethernet49
switch(config-if-Et49)# switchport mode trunk
switch(config-if-Et49)# switchport trunk allowed vlan 10,20,30
switch(config-if-Et49)# spanning-tree guard loop
switch(config-if-Et49)# exit

spanning-tree guard loop protects the uplink against a one-way link failure that would otherwise create a forwarding loop. On VXLAN leaf-spine links, most operators disable spanning tree on the fabric ports entirely and rely on the underlay being loop free - see the loop-free assumptions in Arista EOS VLAN and native VLAN troubleshooting before doing that.

Verification and Troubleshooting

show spanning-tree
show spanning-tree mst configuration
show spanning-tree instance 1
show spanning-tree interface Ethernet49 detail
show spanning-tree topology
show interfaces Ethernet1 status
  • Port stuck in discarding on an access port: portfast missing, or a BPDU was received from downstream.
  • Constant topology changes: flapping link, or a downstream device sending BPDUs on an edge port.
  • Traffic black-holed after cabling work: the new link became root because priorities were never configured.
  • Errdisabled ports: check show interfaces status errdisabled and clear with shut / no shut.

Apply your changes through a config session so a mistake cannot be committed to the running configuration - see Arista EOS configuration sessions - and keep the edge-port policy consistent with portfast and BPDU guard configuration.

Region Design and Load Sharing

Everything inside one MST region shares a topology per instance, so keep the region boundaries deliberate. Two rules keep it manageable: put the access layer in its own region when it has a different change cadence, and never let the same VLAN map to different instances on switches that share a trunk.

switch# show spanning-tree mst configuration digest
switch# show spanning-tree instance 1 detail | include Root
switch# show spanning-tree instance 2 detail | include Root

Compare the configuration digest on all switches of the region before a maintenance window. A single character difference in the name, revision or VLAN mapping makes a switch its own region, which usually shows up as unexpected discarding on an uplink.

原文链接:https://www.arista.com/en/um-eos/eos-layer-2-configuration