Presentation is loading. Please wait.

Presentation is loading. Please wait.

VLAN Trunking Protocol

Similar presentations


Presentation on theme: "VLAN Trunking Protocol"— Presentation transcript:

1 VLAN Trunking Protocol
Configure VLAN Trunking Protocol (VTP) VTP vulnerabilities and security Slide 1 of 1 Purpose: Emphasize:

2 VLAN Trunking Protocol (VTP)
A messaging system that advertises VLAN configuration information Maintains VLAN configuration consistency throughout a common administrative domain VTP sends advertisements on trunk ports only Support mixed media trunks (Fast Ethernet, FDDI, ATM) VTP Domain “ICND” 3.Sync to the latest vlan information Slide 1 of 1 Purpose: Emphasize: Notes: VTP is a Cisco proprietray feature. VTP is a Layer 2 messaging protocol that maintains VLAN configuration consistency by managing the addition, deletion, and renaming of VLANs on a network-wide basis. VTP minimizes misconfigurations and configuration inconsistencies that can cause several problems, such as duplicate VLAN names, incorrect VLAN-type specifications, and security violations. A VTP domain (also called a VLAN management domain) is one switch or several interconnected switches sharing the same VTP domain. A switch is configured to be in only one VTP domain. You make global VLAN configuration changes for the domain by using the Cisco IOS command-line interface (CLI), Cisco Visual Switch Manager Software, or Simple Network Management Protocol (SNMP). By default, a 1900 switch is in the no-management-domain state until it receives an advertisement for a domain over a trunk link or you configure a management domain. The default VTP mode is server mode, but VLANs are not propagated over the network until a management domain name is specified or learned. If the switch receives a VTP advertisement over a trunk link, it inherits the management domain name and configuration revision number. The switch then ignores advertisements with a different management domain name or an earlier configuration revision number. When you make a change to the VLAN configuration on a VTP server, the change is propagated to all switches in the VTP domain. VTP advertisements are transmitted out all trunk connections, including Inter-Switch Link (ISL), IEEE Q, IEEE , and ATM LAN Emulation (LANE). If you configure a switch from VTP transparent mode, you can create and modify VLANs, but the changes are not transmitted to other switches in the domain, and they affect only the individual switch. 2 1.“new vlan added”

3 VTP Modes Server Client Transparent Create vlans Modify vlans
Delete vlans Sends/forwards advertisements Synchronize Saved in NVRAM Server Sends/forwards advertisements Synchronize Not saved in NVRAM Slide 1 of 1 Purpose: Emphasize: Default VTP mode on the Catalyst switches is Server. Be careful when adding new switches into an existing network. This is covered in more detail later. Create vlans Modify vlans Delete vlans Forwards advertisements Does not synchronize Saved in NVRAM Client Transparent

4 How VTP Works VTP advertisements are sent as multicast frames across trunk links VTP servers and clients synchronized to latest revision number VTP advertisement are sent every five minutes or when there is a change Slide 1 of 2 Purpose: Emphasize: Notes: VTP advertisements are sent on factory-default VLAN based on the media type. Each advertisement starts as configuration revision number 0. When changes are made, the configuration revision number increments (n+1). Routers ignore VTP packets. There are two types of advertisements; requests from clients that want to learn at boot up and response from servers. There are three types of messages; summary advertisements sent every 300 seconds on VLAN 1, subset advertisements with information about VLANs, and advertisement requests from clients where the server responds with summary and subset advertisements

5 How VTP Works VTP advertisements are sent as multicast frames
VTP servers and clients synchronized to latest revision number VTP advertisement are sent every five minutes or when there is a change 1. Add new VLAN 2. Rev 3 --> Rev 4 Slide 2 of 2 Purpose: Emphasize: The latest revision number is what the switches will synchronize to. 4 Server 4 3. Advertise Rev 4 4.Sync new vlan info 3. Advertise Rev 4 4.Sync new vlan info Client Client

6 VTP Pruning Reduces unnecessary flooded (broadcast/unknown address) traffic Example: Station A sends broadcast. Broadcast is only flooded toward any switch with ports assigned to the green VLAN Port 2 B Switch 4 Flooded traffic is pruned Switch 2 Slide 1 of 1 Purpose: Emphasize: VTP prunning provides optimized flooding. Without VTP prunning, station A’s broadcast will be flooded to all switches whether they have any port in the red vlan or not. Note: VLAN 1 can’t be prunned. STP, CDP, VTP updates are sent on VLAN1. All switches in the switched network must support prunning or prunning will be disabled. Each trunk port maintains a state variable per vlan indicating if the switch has any port assigned to a particular vlan or not. Green VLAN Switch 5 Port 1 A Switch 6 Switch 3 Switch 1

7 VTP Configuration Guidelines
VTP domain name VTP mode (server/client/transparent)—VTP server mode is the default VTP pruning VTP password Slide 1 of 1 Purpose: Emphasize: Notes: All switches in a VTP domain must run the same VTP version. The password entered with a domain name should be the same for all switches in the domain. If you configure a VTP password, the management domain will not function properly if you do not assign the management domain password to each switch in the domain. A VTP version 2-capable switch can operate in the same VTP domain as a switch running VTP version 1 provided version 2 is disabled on the version 2-capable switch (version 2 is disabled by default). Do not enable VTP version 2 on a switch unless all of the switches in the same VTP domain are version 2-capable. When you enable version 2 on a switch, all of the version 2-capable switches in the domain must have version 2 enabled. If there is a version 1-only switch, it will not exchange VTP information with switches with version 2 enabled. If there are token ring networks in your environment, you must enable VTP version 2 for Token Ring VLAN switching to function properly. Enabling or disabling VTP pruning on a VTP server enables or disables VTP pruning for the entire management domain. In the lab, all the switches are set to VTP transparent mode.

8 Creating a VTP Domain switch1(config)# vtp domain domain1
vtp password 123 vtp mode client show vtp status Slide 1 of 2 Purpose: Emphasize:


Download ppt "VLAN Trunking Protocol"

Similar presentations


Ads by Google