STP Path Cost Tuning and Root Bridge Diameter - 夜莺博客

STP Path Cost Tuning and Root Bridge Diameter

Most spanning tree problems in a campus are not bugs — they are default choices nobody revisited. The root bridge is whichever switch happens to have the lowest MAC address, path costs are derived from link speed alone, and the network diameter is assumed to be seven. This article covers the three knobs that actually shape an STP topology: who is root, how much each link costs, and how large the network is allowed to be.

Choosing the root bridge deliberately

! explicit priority - lowest wins, granularity is 4096
spanning-tree vlan 10 priority 4096
!
! or let the switch do the arithmetic
spanning-tree vlan 10 root primary
spanning-tree vlan 10 root secondary

! verify what you actually got
show spanning-tree vlan 10 root
show spanning-tree root

root primary sets a priority of 24576, or 4096 less than the current root if that switch already has a lower value. root secondary sets 28672. Both are convenience macros over priority, and both are evaluated once at command time — so in a ring where two switches are both configured as primary, the outcome depends on the order they booted. The explicit priority 4096 is more predictable, and 4096 versus 8192 on a pair of distribution switches gives you a deterministic primary/secondary pair.

The root should be a distribution or core switch, never an access switch. If the root sits on an access switch, every flow from the access layer has to traverse the weakest link in the topology to reach the rest of the network.

Path cost: the short and long methods

! global cost method - long is the default on modern platforms
spanning-tree pathcost method long

! per-VLAN cost on an interface
interface GigabitEthernet1/0/1
 spanning-tree vlan 10 cost 1000

Costs scale inversely with bandwidth, and the two methods disagree about how far:

  • Short (16-bit): 1 Gb/s = 4, 100 Mb/s = 19, 10 Mb/s = 100. Ranges only to 65,535, which is why 10G and 40G links are indistinguishable — both collapse to cost 1 or 2.
  • Long (32-bit): 10 Mb/s = 2,000,000, 100 Mb/s = 200,000, 1 Gb/s = 20,000, 10 Gb/s = 2,000, 100 Gb/s = 200. This is what MST always uses, and it is the only sane choice if you have mixed 1G/10G/25G links.

Tuning cost has one purpose: to break a tie in a way that matches your intended traffic flow. Because lower cost wins, raising the cost on a link you do not want used is usually safer than lowering costs everywhere else — one change instead of many.

The network diameter and timers

spanning-tree vlan 10 root primary diameter 4
spanning-tree vlan 10 hello-time 2

Declaring a diameter tells the root to size max-age and forward-delay for a topology of that size, instead of assuming seven hops. Getting this wrong hurts convergence after a failure: a diameter that is too large produces conservative timers and slow reconvergence, while one that is too small risks a topology change propagating past max-age. The count is the maximum number of switches between any two end stations — not the number of switches you own.

Verification and diagnosis

show spanning-tree vlan 10
! VLAN0010
!   Root ID  Priority 4096, Address 0011.2233.4455, Cost 0
!     This bridge is the root
!   Interface        Role Sts Cost      Prio.Nbr Type
!   Gi1/0/1          Desg FWD 2000      128.1   P2p

show spanning-tree vlan 10 detail | include Number of topology changes
show spanning-tree interface GigabitEthernet1/0/1

Three things to look for: the Root ID priority should be the value you configured; the Cost column on each interface should match your design; and a rising topology-change counter points at a flapping access port rather than a design problem.

MST and Nexus variations

! IOS MST
spanning-tree mode mst
spanning-tree mst configuration
 name CAMPUS revision 1
 instance 1 vlan 10-20
 exit
spanning-tree mst 0 root primary
interface GigabitEthernet1/0/1
 spanning-tree mst 1 cost 1000

! Nexus
spanning-tree mst 0 root primary
spanning-tree mst 0-1 cost 1000

MST is where cost tuning pays off most: with a single instance per VLAN group you choose per-instance costs to build two different active topologies, so half your VLANs use one uplink and half use the other. Verifying that design is a matter of checking show spanning-tree mst on both switches and confirming the root ports differ per instance.

Protecting the topology you have built is the other half of the job: BPDU guard, root guard and loop guard explain which guard applies to which port role, and for a non-Cisco view of the same problem see ArubaOS-CX MSTP configuration.

原文链接:https://www.cisco.com/c/en/us/td/docs/switches/lan/csbms/CBS_250_350/CLI/cbs-250-cli/spanning-tree-commands.pdf