One misconfigured switch brought down an entire campus network. No failover triggered. No alert fired. Just silence.

The cause: Spanning Tree Protocol with no Root Bridge defined. STP saves you from broadcast storms. Wrong configuration makes it the source of one.
- WHAT STP DOES AND WHY IT BREAKS
Ethernet has no native loop prevention. A broadcast frame with no TTL circulates forever. STP blocks redundant paths and elects a Root Bridge to prevent this.
Misconfigure it and those redundant paths activate simultaneously. Broadcasts replicate. Switches forward them in a loop. Utilization hits 100%. The network stops.
- MISCONFIGURATION 1 ROOT BRIDGE NOT DEFINED
STP elects the Root Bridge based on the lowest Bridge ID. Without explicit priority settings, the election is unpredictable. An access switch with default priority can win over your core router.
Fix: Priority 4096 on primary core. 8192 on secondary. 32768 on access.
spanning-tree vlan [id] priority 4096
- MISCONFIGURATION 2 PORTFAST ON TRUNK PORTS
PortFast skips STP listening and learning phases. It is designed for access ports facing endpoints only.
On a trunk port, it is dangerous. The port goes directly to forwarding — loop detection delay disappears entirely.
Fix: PortFast on access ports only. Always pair with BPDU Guard. A BPDU arriving on a PortFast port shuts it down instantly.
spanning-tree portfast spanning-tree bpduguard enable
- MISCONFIGURATION 3 BPDU GUARD VS BPDU FILTER
These two are not interchangeable.
BPDU Guard: shuts the port down when a BPDU is received. BPDU Filter: silences BPDUs completely — sending and receiving.
BPDU Filter on an access port removes all STP protection. A rogue switch plugged in by an employee creates a loop. No safeguard stops it.
Rule: BPDU Guard on all access ports. BPDU Filter only on uplinks where Guard would cause false positives.
- BROADCAST STORM REAL-TIME TIMELINE
T+0s: Loop forms. One broadcast frame enters. T+3s: Frame count multiplies every millisecond. T+10s: Switch CPU hits 100%. Management plane unreachable. T+30s: All devices lose connectivity simultaneously. T+2min: Physical intervention required. Remote access is gone.
No link-down alert fires. Interfaces stay up. Monitoring shows high utilization — by then it is too late to act remotely.
Define the Root Bridge explicitly. Restrict PortFast to endpoint-facing ports. Deploy BPDU Guard, not BPDU Filter, on access ports.
STP is not a set-and-forget protocol. It breaks silently when no one owns the design decision.
Have you audited your STP topology recently? Do you know which switch holds your Root Bridge right now?