Professional Documents
Culture Documents
2
BAD Design
If any of our computers sends a broadcast what will our switches do?
They flood it!
A single broadcast frame will be flooded on this entire network
Our switches will forward traffic but how do they know to which
VLAN our traffic belongs?
There is not any filed that we can use to specify to which VLAN this Ethernet belongs
The use of trunking allows switches to pass frames from multiple VLANs over a single
physical connection by adding a small header to the Ethernet frame
7
VLANs & Trunks
• ISL:
8
VLANs & Trunks
802.1Q Tagging
In our tag you will find a “VLAN identifier” which is the VLAN to
which this Ethernet frame belongs
Every VLAN that goes across the trunk will be tagged using the 802.1Q
protocol
The native VLAN is the only VLAN that will not be tagged
9
VLANs & Trunks
10
VLAN ID
• VLAN ID 12 bits
• 0 - - ->> 4095
• 0 & 4095 = = >> reserved for system use only
• 1 - - - >> default VLAN & can not be deleted
• 1006 - - - >> 4095 = = >> extended range allowed only in VTP transparent
• 1006 - - - >> 1024 = = >> reserved for system use only
• 1025 - - - >> 4094 = = >normal range to create VLANs 11
VLANs & Trunks
13
VLANs & Trunks
VLAN 50 was created on SwitchA and you can see that it‟s active
14
VLANs & Trunks
Both computers are now in VLAN 50, so they can reach to each others
15
VLANs & Trunks
Verify our configuration
16
VLANs & Trunks
I will do the same on the switch A -- >> create vlan and add the
port to that vlan
17
VLANs & Trunks
Depending on the switch model you might see the same error as me
18
VLANs & Trunks
19
VLANs & Trunks
20
VLANs & Trunks
This is because the show vlan command only shows interfaces in access
mode and not trunk interfaces
21
VLANs & Trunks
show interface trunk command is very
useful
22
VLANs & Trunks
For security reasons you might want to limit the VLANs that are allowed
on the trunk
Now I removed VLAN 1-4094 from the trunk and only allows VLAN 1-50
23
VLANs & Trunks
DTP packets are exchanged between the two connected switches to determine
the link trunking status
1. Access
• Put interface into permanent non-trunking mode
2. Trunk
• Put interface into permanent trunking mode
3. Dynamic Auto
• Make interface able to convert to trunk mode
4. Dynamic desirable
• Make interface attempts to convert to be trunk mode
25
VLANs & Trunks
26
VLANs & Trunks
27
VLANs & Trunks
31
VLANs & Trunks
32
VLANs & Trunks
Switch A will send frame without tag as switch A see the port in access mode
Switch B will receive the frame untagged so will deal as a frame belongs
to its native VLAN 33
VLANs & Trunks
In real Network !!
34
VLANs & Trunks
35
VLANs & Trunks
The access ports that belong to that VLAN move into the in active state
37
VLANs & VTP
VTP will let you create VLANs on one switch and all the other switches
will synchronize themselves
38
VLANs & VTP
Besides the VTP server and VTP client there's also a VTP transparent
39
VLANs & VTP
VTP Modes
Server Transparent Client
create(add) create(add)
delete delete
modify modify
save save
forward forward forward
advertise
synchronize synchronize
40
VLANs & VTP
VTP Configuration
41
VLANs & VTP
❑ Configuration revision
❑ VTP V2 Mode:
42
VLANs & VTP
Switch B :
• The switch receives a VTP packet from domain “masrawy” and decides to
change its own domain-name from “NULL” (nothing) to “masrawy”
• The switch sees that the VTP packet has a higher revision number (1)
than what it currently has (0) and as a result it will synchronize itself
45
VLANs & VTP
46
VLANs & VTP
47
VLANs & VTP
Since all switches are in VTP Server mode I can create VLANs on any
switch and they should all synchronize
48
VLANs & VTP
49
VLANs & VTP
Each time I create another VLAN the revision number increases by one
Let's change the VTP mode on SwitchB
50
VLANs & VTP
I have disconnected the link between SwitchA and SwitchC so there
is no direct connection between them
51
VLANs & VTP
VTP Transparent
53
VLANs & VTP
A switch in VTP Transparent mode will not synchronize itself but it will
forward VTP advertisements to other switches so they can
synchronize
themselves
55
VLANs & VTP
56
VLANs & VTP
SwitchB will not advertise its VLANs
57
VLANs & VTP
VTP Server and Client mode store their information in the VLAN
database (vlan.dat on your flash memory) 58
VLANs & VTP
A VTP client can overwrite a VTP server if the revision number of the
VTP client is higher
First I change the domain-name and configure the correct VTP modes
59
VLANs & VTP
60
VLANs & VTP
61
VLANs & VTP
62
VLANs & VTP
I will change SwitchC from VTP Client mode to VTP Server mode
After adding the VLANs you can see that the VTP revision number has
increased
63
VLANs & VTP
After playing with my lab I'm going to erase the VLANs and change the
switch back to VTP Client mode so we can return it to the production
network
After deleting the VLANs the VTP revision number increased even more
64
VLANs & VTP
65
VLANs & VTP
OUCH!
66
VLANs & VTP
If you do want to use VTP Server / Client mode you need to make
sure you reset the revision number
❑ Deleting the vlan.dat file on your flash memory will reset the
revision number
67
VLANs & VTP
68