Broadcast Storms and Layer 2 Loops: Fast Containment and Safe Recovery
Recognize a Layer 2 loop, contain the blast radius, and restore service without creating a second outage.
Recognize the pattern quickly
A Layer 2 loop can produce high broadcast or multicast rates, MAC movement, switch CPU pressure, interface saturation, and unstable access across a VLAN. The network may look broken everywhere even though one physical connection created the loop.
Look for sudden traffic growth and repeated MAC moves around the same timestamp. That correlation is often stronger than a generic high-CPU alarm.
Contain the smallest possible area
When customer impact is severe, isolating the suspected access port, trunk, or recently changed segment may be safer than analyzing every switch while the storm continues. Preserve management access and follow your change authority.
Avoid taking broad parts of the network down unless the evidence justifies it. The goal is to break the loop with the smallest blast radius.
Find why loop prevention did not stop it
After stabilization, review spanning-tree state, edge/portfast settings, BPDU protections, unmanaged switches, accidental patching, virtual switching, and any service carrying Layer 2 over a wider domain.
Restore the isolated segment only after the loop path is understood, while watching MAC learning, CPU, and broadcast rate. Fix both the physical mistake and the missing safeguard that allowed it.