Configuring Spanning Tree Protocol

Spanning Tree Protocol (STP) can be enabled globally, on a port-based VLAN, on an individual port, or a LAG port. STP port and bridge parameters can be configured on a port-based VLAN.
In the following task, all four methods for enabling STP are shown in Step 2. The subsequent steps also show four configuration choices. In the examples section, there is a separate example for each of the methods of configuring STP with some parameters.
Note: STP is enabled by default on devices running Layer 2 code. STP is disabled by default on devices running Layer 3 code.
  1. Enter global configuration mode.
    device# configure terminal
  2. Enable STP.
    • STP can be enabled globally.
    • STP can be enabled on a port-based VLAN.
    • STP can be enabled on an individual port.
    • STP can be enabled on a LAG port.
    device(config)# spanning-tree
    device(config)# vlan 10
    device(config-vlan-10)# spanning-tree
    
    device(config)# interface 1/1/1
    device(config-if-e1000-1/1/1)# spanning-tree
    device(config)# interface lag 1
    device(config-lag-if-lg1)# spanning-tree
    When configured on a port-based VLAN, the spanning-tree command enables a separate spanning tree in each VLAN, including the default VLAN.

    To enable STP on an individual port, you must be in the appropriate interface configuration mode.

  3. Change the STP bridge parameters by using the forward-delay, hello-time, max-age, and priority keywords of the spanning-tree command.
    device(config-vlan-10)# spanning-tree forward-delay 4 hello-time 3 max-age 10
    priority 0
    If you have configured a port-based VLAN on the device, you can configure the parameters only at the configuration level for individual VLANs.
  4. Change the STP port parameters by using the path-cost and priority keywords of the spanning-tree command.
    device(config-vlan-10)# spanning-tree ethernet 1/1/1 path-cost 15 priority 64
  5. Enable STP Protection.
    device(config-if-e1000-1/1/1)# stp-protect
    The stp-protect command causes the port to drop STP BPDUs received on this port.
  6. Clear the BPDU drop counters for all ports on the device or for a specific port with STP Protection enabled.
    device(config)# clear stp-protect-statistics
    device(config)# clear stp-protect-statistics ethernet 1/1/1
    device(config)# clear stp-protect-statistics lag 1 
    

    In the second example, the BPDU drop counters are cleared with STP Protection enabled for Ethernet and LAG ports respectively.

The following example shows how to enable STP globally.

device# configure terminal
device(config)# spanning-tree

The following example shows how to enable STP on a port-based VLAN, VLAN-10. Bridge and port parameters are configured.

device# configure terminal
device(config)# vlan 10
device(config-vlan-10)# spanning-tree
device(config-vlan-10)# spanning-tree priority 0 hello-time 3 max-age 10
device(config-vlan-10)# spanning-tree ethernet 1/1/5 path-cost 15 priority 64

The following example shows how to enable STP on an individual port, Ethernet interface 1/1/1.

device# configure terminal
device(config)# interface 1/1/1
device(config-if-e1000-1/1/1)# spanning-tree
device(config-if-e1000-1/1/1)# stp-protect

The following example shows how to enable STP on a LAG interface.

device# configure terminal
device(config)# interface lag 1
device(config-lag-if-lg1)# spanning-tree