STP Attack Explained: Spanning Tree Vulnerabilities and How to Prevent Them
Learn what an STP Attack is, how attackers exploit Spanning Tree Protocol vulnerabilities, and the best ways to secure your network. Simple terms, real examples, and expert prevention tips.
Quick answer: An STP attack abuses Spanning Tree Protocol's trust in BPDU messages. An attacker sends a superior BPDU to become the root bridge, which reroutes traffic, or floods BPDUs to force constant recalculation and outages. Prevent it with PortFast plus BPDU Guard on user ports, Root Guard on uplinks, access-mode ports, port security and log monitoring.
Key takeaways
- STP trusts any BPDU, so a device on an access port can try to win the root election.
- BPDU Guard shuts a user port that receives a BPDU; Root Guard blocks a port that receives a superior BPDU.
- Set your root bridge priority deliberately instead of leaving it to the lowest MAC address.
- Detect with switch logs, show spanning-tree root and topology change counts; firewalls will not see this.
What is Spanning Tree Protocol, and why can it be attacked?
Switches in a LAN are often connected in loops on purpose, so that if one link fails another carries traffic. Loops are dangerous in Ethernet, because broadcast frames circle forever and bring the network down within seconds. Spanning Tree Protocol (STP) prevents this. Switches elect one root bridge, work out the best path to it, and block the other links.
The weakness is that STP is built on trust. Switches exchange BPDUs (Bridge Protocol Data Units) and believe what they hear. A switch that advertises a better bridge ID wins the root election, and nothing in the protocol checks whether that switch is meant to be there.
STP terms in plain language
| Term | Meaning |
|---|---|
| Root bridge | The reference switch for the whole spanning tree. All paths are calculated towards it. |
| BPDU | The message switches send to share bridge IDs and path costs. |
| Bridge ID | A priority value plus the switch MAC address (and VLAN ID in per-VLAN versions). The lowest bridge ID becomes root. |
| Port roles and states | Root, designated and alternate/blocked ports decide which links forward traffic. |
| PortFast | Lets an access port start forwarding immediately. Intended only for end devices. |
How do STP attacks work?
These are the two main patterns. They are described so you can recognise and prevent them. Test them only on your own lab switches, in Packet Tracer or GNS3, or on equipment you are authorised in writing to assess. Doing it on a network you do not own is an offence under India's IT Act, 2000.
1. Root bridge takeover
An attacker connects a device to an access port that accepts BPDUs and sends BPDUs with a very low bridge priority. If that value beats the current root, the switches recalculate and the attacker's device becomes the root. Paths change, and traffic that used to stay on local links may now travel through the attacker's connection point. Two points that older write-ups skip:
- To actually see other users' traffic, the attacker's device must be placed on the new path, for example by connecting to two switches or by negotiating a trunk. Becoming root on its own does not copy frames to the attacker.
- Even when no data is read, a changed root can send traffic over slow links and cause outages.
2. BPDU flood or constant topology changes
Repeated crafted BPDUs can force frequent recalculations. Switches flush their MAC tables, traffic floods while they relearn, performance drops and CPU use rises. This is a denial-of-service condition.
Where did the earlier example go?
How to protect a network from STP attacks
The principle: access ports should never take part in STP decisions, and uplinks should never accept a better root from the wrong direction.
| Control | Where | What it does |
|---|---|---|
switchport mode access | User ports | Stops the port becoming a trunk, so the device cannot join as a switch |
spanning-tree portfast with bpduguard | User ports | If any BPDU arrives, the port is put in err-disabled state (shut down) |
spanning-tree guard root | Ports facing switches that must never become root | If a superior BPDU arrives, the port goes into root-inconsistent state (blocked) until it stops |
| Port security | User ports | Limits MAC addresses per port, reducing rogue switch and flooding risk |
| Set root priority manually | Core switches | Makes your intended root clear: spanning-tree vlan 1-4094 root primary or set priority |
| Disable unused ports | All | Shut them and place them in an unused VLAN |
| Native VLAN not VLAN 1 | Trunks | Reduces VLAN hopping risk |
! access ports (example range)
interface range g0/1 - 24
switchport mode access
spanning-tree portfast
spanning-tree bpduguard enable
switchport port-security
switchport port-security maximum 2
! uplink to a distribution switch that must never be root
interface g0/48
spanning-tree guard root
! optional: auto-recover err-disabled ports after 5 minutes
errdisable recovery cause bpduguard
errdisable recovery interval 300
You can also enable BPDU Guard on all PortFast ports at once with spanning-tree portfast bpduguard default. Think carefully before enabling auto-recovery in sensitive areas, because a repeated attack will keep flapping the port. Avoid BPDU Filter on user ports unless you understand it: it can hide loops and defeat the protection above.
Use switchport nonegotiate on trunk ports to stop DTP, and set trunks manually with switchport mode trunk. It is rejected on ports set to access mode, where DTP is already off.
How to detect an STP attack
- Logs. Cisco switches log messages such as
%SPANTREE-2-BLOCK_BPDUGUARD,%PM-4-ERR_DISABLEwith "bpduguard error detected", and%SPANTREE-2-ROOTGUARD_BLOCK. Send these to a central log server or SIEM and alert on them. - Check the root.
show spanning-tree rootshould always name your intended switch. If a different bridge ID appears, investigate. - Look at topology changes.
show spanning-tree detailshows the number and time of topology changes and which port they came from. Frequent changes from one port point to the source. - Symptoms. Sudden slow performance, broadcast spikes, high switch CPU, or a MAC table that keeps flushing.
- Response. Shut the port, find the device physically, and check the port-security log.
Firewalls do not see this, because STP runs at Layer 2 inside the switched network. Switch logs and monitoring are your detection.
Do newer protocols fix it?
RSTP and MSTP make STP faster and more scalable, but they are still trust-based, so BPDU Guard and Root Guard still apply. Data centres often use routed designs and EVPN-VXLAN overlays, which reduce reliance on STP. Campus networks can use routed access, where Layer 3 starts at the access switch and loops are not an issue on that edge. Whichever is used, protect the edge ports, since the edge is where untrusted devices connect.
Common mistakes
- Enabling PortFast without BPDU Guard.
- Leaving the root election to chance: if you do not set a priority, the oldest switch (lowest MAC) may become root.
- Applying Root Guard on the wrong side of a link and blocking legitimate paths.
- Forgetting to monitor logs, so a shut port goes unnoticed for days.
- Treating Layer 2 as trusted just because the cabling is inside the building.
Career relevance
STP and Layer 2 security are core CCNA material and routinely come up in network engineer and security analyst interviews. Being able to configure BPDU Guard and Root Guard and explain what each does, from memory, is a good signal.
Next steps
Build this in Packet Tracer: three switches in a triangle, set a root, enable the controls above, then simulate a rogue BPDU and read the logs. For guided training, see WebAsha's CCNA 200-301 course. Related reading: CCNA interview questions on STP, VLAN hopping attack explained and switch configuration interview questions.
Frequently Asked Questions
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Wow
0
Sad
0
Angry
0