Read-only commands #
Read-only commands
Cisco IOS XE · Authorized EXEC mode; context specified below
show spanning-tree summaryshow spanning-tree rootReplace these example values: 120.
show spanning-tree vlan 120Replace these example values: 120.
show spanning-tree vlan 120 detailReplace these example values: GigabitEthernet1/0/24.
show spanning-tree interface GigabitEthernet1/0/24 detailshow spanning-tree inconsistentportsMST-specific checks #
MST-specific checks
Cisco IOS XE · Authorized EXEC mode; context specified below
show spanning-tree mst configurationOutput may contain sensitive operational data.show spanning-tree mst 1Read the state in context #
The root ID identifies the elected root for the relevant instance. The root port on a non-root switch is its selected path toward that root. Port roles and forwarding states describe the resulting topology; they are not simply a good/bad classification for each cable.
Workflow #
- Select one affected VLAN. Confirm the running STP mode before interpreting per-VLAN output. Under MST, identify the instance containing that VLAN and use that instance throughout the investigation.
- Compare the observed root with the intended network design. An unexpected root is a useful finding, but it does not identify who changed the network or whether the election itself was incorrect.
- Trace the root-port direction across neighboring switches. Record the logical port-channel where one exists instead of treating every member as an independent STP path.
- Inspect details on the port associated with recent changes. Compare the timestamps with interface events and the reported service interruption.
- Check inconsistent ports separately. Record the exact inconsistency and inspect its cause on the neighboring device before proposing a recovery action.
Interpretation pitfalls #
Different VLANs can legitimately choose different roots and forwarding paths. One switchport may therefore forward one VLAN and block another. An MST region boundary adds another reason to avoid copying conclusions from a different instance.
A topology-change count without an observation period is weak evidence. A rising count during an incident is more informative than a large count collected across months. Even then, the port reporting a change is a place to investigate, not automatic proof that the attached device created the original fault.
Do not disable spanning tree, remove guard features or enable PortFast on an inter-switch link to make a blocked indicator disappear. First establish the intended loop-free path. Preserve the output that explains why the switch selected its current state.
Related cross-vendor guide #
- UniFi STP blocked-port guide: For a Cisco-to-UniFi connection, inspect the other vendor's STP state too. Use that device's own commands and interface labels.
Sources
Documentation reviewed: 8 October 2026