STP Root Bridge Configuration: Primary, Secondary and Priority

Learn how to choose the STP root per VLAN with Cisco IOS root primary, root secondary and manual bridge-priority commands.

STPRoot BridgePVSTCisco IOS
Spanning Tree Root Bridge Configuration learning map
Learning map for Spanning Tree Root Bridge Configuration showing the article's core concepts, workflow, practice topics, and troubleshooting path.

STP root bridge configuration: key takeaways

Two configuration methods: use spanning-tree vlan X root primary|secondary to let Cisco IOS select a lower priority, or use spanning-tree vlan X priority VALUE to set the bridge priority explicitly.
  • The switch with the lowest Bridge ID becomes root.
  • Bridge priority wins first; the MAC address breaks an exact priority tie.
  • Manual priority values range from 0 through 61440 in increments of 4096.
  • With the extended system ID, the displayed priority equals the configured priority plus the VLAN ID.
  • PVST can use a different root bridge for each VLAN.
  • Place the primary and secondary roots on appropriate distribution or backbone switches—not randomly on access switches.

What the root bridge controls

Every spanning-tree instance builds its loop-free topology around one root bridge. Non-root switches select their lowest-cost path toward that root, which influences root ports, designated ports, blocked redundant paths and therefore the Layer 2 forwarding pattern.

SW1Priority 24576
SW2Priority 32768
SW3Priority 32768
Original diagram: SW1 has the lowest Bridge ID, becomes root and anchors the two green forwarding branches. One redundant port blocks on the orange link.
Design meaning: choosing the root is a path-control decision. Put it where you want Layer 2 traffic to converge, normally in the distribution or backbone layer.

How STP elects the root bridge

Switches compare Bridge IDs carried in BPDUs. The numerically lowest Bridge ID wins.

SW1
32768 + MAC 00AA
Candidate
SW2
24576 + MAC 00FF
ROOT: lowest priority
SW3
32768 + MAC 0001
Candidate

SW2 wins even though another switch might have a lower MAC address, because bridge priority is compared before MAC address. MAC address is only the tie-breaker when effective priorities match.

Extended system ID calculation

Configured priority+VLAN ID=Displayed Bridge ID priority

For VLAN 10, configured priority 24576 appears as 24586. For VLAN 20, configured priority 0 appears as 20. The VLAN ID is the extended system ID; it does not mean the configured base priority changed.

Prerequisites and lab topology

Before configuring the root bridge, understand PVST, root election, Bridge ID components, VLAN creation and 802.1Q trunks. The examples use three switches connected in a redundant triangle with VLANs 10, 20 and 30 carried across trunks.

SW1, SW2, SW3(config)# vlan 10
SW1, SW2, SW3(config)# vlan 20
SW1, SW2, SW3(config)# vlan 30

SW1, SW2, SW3(config)# interface range GigabitEthernet0/0 - 1
SW1, SW2, SW3(config-if-range)# switchport mode trunk
Platform note: some switch platforms support or require a separate trunk-encapsulation command; others support only 802.1Q and do not expose that command. Check the model’s command reference.

Step 1: verify the current root bridge

Never change STP priority blindly. First identify the current root and each switch’s own Bridge ID.

SW1# show spanning-tree vlan 10

VLAN0010
  Root ID    Priority    32778
             Address     5254.0015.bc74
             Cost        4
             Port        1 (GigabitEthernet0/0)

  Bridge ID  Priority    32778  (priority 32768 sys-id-ext 10)
             Address     5254.001a.935a

If the output says This bridge is the root, the local switch owns the Root ID. Otherwise, compare Root ID with Bridge ID and note the root-facing port.

SW1# show spanning-tree bridge detail
SW1# show spanning-tree root
SW1# show spanning-tree vlan 10 summary

Step 2: choose a configuration method

Method A: root primary / secondary

Use Cisco IOS convenience commands when you want the software to choose an appropriate priority relative to the current topology.

SW1(config)# spanning-tree vlan 10 root primary
SW2(config)# spanning-tree vlan 10 root secondary

root primary attempts to make SW1 the current VLAN 10 root. root secondary lowers SW2’s priority so it is a strong backup candidate.

Method B: manual priority

Set an explicit, documented value when deterministic priority planning matters.

SW1(config)# spanning-tree vlan 10 priority 4096
SW2(config)# spanning-tree vlan 10 priority 8192

The lower number wins. Values must be multiples of 4096 from 0 through 61440.

Important: “secondary root” is not an STP protocol role. It is a Cisco configuration convenience. Another switch with a lower Bridge ID can still become root, so verify the result.

Common priority values

0
Strongest
409681922457632768
Default
61440

The automatic value selected by root primary can depend on software, platform and current root priority. Many classic Catalyst PVST examples from a default topology produce 24576 for primary and 28672 for secondary, but you should confirm the actual running configuration instead of assuming those numbers universally.

Configure different roots per VLAN

PVST runs a separate spanning-tree instance for each VLAN. That means root placement can be divided across distribution switches to align the active Layer 2 paths with gateway placement and uplink capacity.

VLAN 10 · UsersPrimary root: SW1

Secondary: SW2

VLAN 20 · VoicePrimary root: SW2

Secondary: SW1

VLAN 30 · ServersPrimary root: SW1

Secondary: SW2

SW1(config)# spanning-tree vlan 10,30 root primary
SW1(config)# spanning-tree vlan 20 root secondary

SW2(config)# spanning-tree vlan 20 root primary
SW2(config)# spanning-tree vlan 10,30 root secondary
Keep the design intentional: align the STP root with the active default gateway where practical. Randomly spreading VLAN roots among access switches can create inefficient paths and harder troubleshooting.

Step 3: verify the new root and backup

  1. Run show spanning-tree vlan 10 on the intended primary and confirm This bridge is the root.
  2. Confirm Root ID priority and address match the intended switch.
  3. On non-root switches, verify the root port and expected path cost.
  4. Check the running configuration for the effective priority.
  5. Repeat for every VLAN in the design.
SW1# show spanning-tree vlan 10
VLAN0010
  Root ID    Priority    24586
             Address     5254.001a.935a
             This bridge is the root

  Bridge ID  Priority    24586  (priority 24576 sys-id-ext 10)

SW1# show running-config | include spanning-tree

Common root bridge configuration mistakes

  • Leaving the election to MAC addresses: the oldest or least suitable switch can become root when all priorities remain default.
  • Configuring an access switch as root: this can pull Layer 2 paths away from the intended distribution design.
  • Assuming “secondary” is guaranteed: election still follows the lowest Bridge ID.
  • Forgetting the VLAN ID in displayed priority: 24586 represents base priority 24576 plus VLAN 10.
  • Using an invalid priority: extended-system-ID environments require increments of 4096.
  • Changing timers casually: prefer validated defaults or documented platform guidance.
  • Skipping post-change verification: always confirm the root, port roles and blocked path per VLAN.

Spanning Tree Root Bridge Frequently Asked Questions

How do I make a Cisco switch the STP root?

Use spanning-tree vlan VLAN-ID root primary, or configure a lower explicit value with spanning-tree vlan VLAN-ID priority VALUE. Verify the result afterward.

What is the default STP priority?

The default configurable priority is 32768. With the extended system ID, Cisco output displays the base priority plus the VLAN ID.

Is priority 0 always the root?

Priority 0 is the lowest configurable base priority, but if multiple switches use it for the same VLAN, the lowest MAC address breaks the tie.

What does root secondary actually do?

It configures a lower bridge priority intended to make the switch a strong backup root candidate. STP itself does not define a “secondary root” role.

Can a VLAN range use the same root command?

Yes. Cisco IOS accepts VLAN lists and ranges, subject to platform syntax—for example, spanning-tree vlan 10,20,30 root primary.

Should the STP root match the default gateway?

In many campus designs, aligning the STP root with the active first-hop gateway reduces unnecessary Layer 2 path stretch. The correct choice still depends on the topology and redundancy design.

Authoritative references

This lesson’s command behavior and design cautions were checked against Cisco’s official Spanning Tree Protocol guide and current Catalyst STP configuration guidance.

Continue the STP lesson chain

Continue learning

Use these related resources to apply or verify the concepts on this page: