For a Loop Protection shutdown, remove the accidental loop and then set the affected port back to State → Active. For BPDU Guard on an intentional switch uplink, correct that port’s edge/guard role. A normal RSTP alternate port should remain blocked; it needs no repair.
Identify the protection mechanism
Open Ports and select the affected switch port; STP-blocked ports have a blocked symbol. Read the corresponding System Log event to distinguish STP from Loop Protection or BPDU Guarding. Open UniFi Devices → switch → Port Manager → port → Spanning Tree Protocol to inspect the port’s STP setting; Loop Protection is under the port’s advanced settings. Available controls depend on the switch model.
Remove the loop or correct the BPDU Guard role
For an accidental loop, disconnect the verified redundant cable/bridge. If every AP uses wired backhaul and no AP depends on mesh, disable Settings → WiFi → Wireless Meshing.
For BPDU Guard on an intentional switch uplink, open that port’s Spanning Tree Protocol controls, keep STP/RSTP enabled, set STP Edge to Auto or Disabled and remove BPDU Guarding from that uplink. Keep BPDU Guarding on client-facing ports where a downstream bridge is unauthorized.
For parallel cables that were meant to be aggregated, leave one path disconnected until the aggregate is configured at both ends.
After removing the triggering path, open Devices → switch → Ports → Port Manager → port and set State → Active to re-enable it. Loop Protection and BPDU Guard shutdowns require this manual intervention; a normal RSTP alternate port does not. Avoid disabling protection across all ports to clear one alert. Gateway ports should not be assumed to have the same STP behavior as switch ports.
Trace all Layer 2 paths
Check switch uplinks, parallel cables, downstream switches and AP wireless uplinks/mesh. A path can return over wireless even when the cabling diagram contains no obvious loop. Verify any intended parallel links are configured as the supported aggregate rather than independent forwarding paths.
For an unintended root choice, open UniFi Devices → switch → Settings → Priority on each switch and compare priorities. Lower wins; equal values are resolved by bridge identity. If the intended core should win, set it to 0 and downstream switches to higher supported values such as 4096 and 8192, provided no other bridge has an equal/lower priority. This triggers convergence; check the blocked/forwarding ports again. A correctly blocked alternate path needs no change.
Check convergence
Confirm a stable root and forwarding path, then test the affected VLANs. If a priority/role change produces the wrong path, restore that setting. Repeated offline events without a protection event need the separate link/power investigation.