© 2006 Cisco Systems, Inc. All rights reserved.Cisco ConfidentialBCMSN 2 - 5 1 BCMSN v3.0—2-1 Correcting Common VLAN Configuration Errors BSMSN Module.

Slides:



Advertisements
Similar presentations
Virtual Trunk Protocol
Advertisements

© 2008 Cisco Systems, Inc. All rights reserved.Cisco ConfidentialPresentation_ID 1 Chapter 3: VLANs Routing & Switching.
Virtual LANs.
© 2008 Cisco Systems, Inc. All rights reserved.Cisco ConfidentialPresentation_ID 1 Chapter 3: VLANs Routing & Switching.
VLANs Module 2. 2 VLANs  VLANs  Trunking  VLAN Trunking Protocol (VTP)
© 2006 Cisco Systems, Inc. All rights reserved.Cisco PublicITE I Chapter 6 1 VLANs LAN Switching and Wireless – Chapter 3.
© 2006 Cisco Systems, Inc. All rights reserved.Cisco PublicITE I Chapter 6 1 VLANs LAN Switching and Wireless – Chapter 3.
© 2006 Cisco Systems, Inc. All rights reserved.Cisco Public 1 Version 4.0 Implement VTP LAN Switching and Wireless – Chapter 4.
Layer 2: Redundancy and High Availability Part 1: General Overview on Assignment 1.
© 2006 Cisco Systems, Inc. All rights reserved. ICND v2.3—2-1 Extending Switched Networks with Virtual LANs Configuring VLANs.
© 2009 Cisco Systems, Inc. All rights reserved. SWITCH v1.0—2-1 Implementing VLANs in Campus Networks Applying Best Practices for VLAN Topologies.
VLAN Trunking Protocol (VTP) W.lilakiatsakun. VLAN Management Challenge (1) It is not difficult to add new VLAN for a small network.
© 2008 Cisco Systems, Inc. All rights reserved.Cisco ConfidentialPresentation_ID 1 Chapter 3: Implementing VLAN Security Routing And Switching.
VTP VLAN Trunking Protocol
VLAN Trunking Protocol
Switching in an Enterprise Network
VLAN Trunking Protocol (VTP)
Building Cisco Multilayer Switched Networks (BCMSN)
VLAN Trunking Protocol (VTP)
Chapter 9 Virtual LANs (VLANs). Setup 1 Setup 2.
© 2006 Cisco Systems, Inc. All rights reserved.Cisco PublicITE I Chapter 6 1 Implementing: VTP VLAN Trunking Protocol LAN Switching and Wireless – Chapter.
VTP VTP or Virtual Trunking Protocol basically revises vlans on all the client switches once a change is made on server switch. It works over trunk links.
CCNA 3 Week 9 VLAN Trunking. Copyright © 2005 University of Bolton Origins Dates back to radio and telephone Trunk carries multiple channels over a single.
© 2002, Cisco Systems, Inc. All rights reserved..
Medium-Sized Switched Network Construction NetPro-ITI Implementing VLANs and Trunks.
© 2008 Cisco Systems, Inc. All rights reserved.Cisco ConfidentialPresentation_ID 1 Chapter 3: Implementing VLAN Security Routing And Switching.
VTP VLAN Trunking Protocol Create once and send to the other switches.
© 2008 Cisco Systems, Inc. All rights reserved.Cisco ConfidentialPresentation_ID 1 Chapter 3: Implementing VLAN Security Routing And Switching 3.0.
© 2006 Cisco Systems, Inc. All rights reserved.Cisco PublicITE I Chapter 6 1 LAN Switching and Wireless Implementing: VTP & VLAN Trunking Protocol Chapter.
1 © 2003, Cisco Systems, Inc. All rights reserved. CCNA 3 v3.0 Module 9 Virtual Trunking Protocol.
1 © 2003, Cisco Systems, Inc. All rights reserved. CCNA 3 v3.0 Module 8 Virtual LANs Cisco Networking Academy.
© 2006 Cisco Systems, Inc. All rights reserved.Cisco PublicITE I Chapter 6 1 VLANs LAN Switching and Wireless – Chapter 3.
Page 1 Switching Technologies Lecture 4C Hassan Shuja 03/28/2006.
Switching Topic 2 VLANs.
© 2006 Cisco Systems, Inc. All rights reserved.Cisco PublicITE I Chapter 6 1 Switching in an Enterprise Network Introducing Routing and Switching in the.
Virtual Local Area Networks (VLANs) Part II
Switching Topic 3 VTP. Agenda VTP basics Components Frames and advertisements Domains and revision numbers VTP operations VTP pruning VTP issues.
1 © 2003, Cisco Systems, Inc. All rights reserved. CCNA 3 v3.0 Module 9 VLAN Trunking Protocol Cisco Networking Academy.
Configuring VLAN Chapter 14 powered by DJ 1. Chapter Objectives At the end of this Chapter you will be able to:  Understand basic concept of VLAN  Configure.
CCNA3 v3 Module 9 v3 CCNA 3 Module 9 JEOPARDY K. Martin.
© 2006 Cisco Systems, Inc. All rights reserved.Cisco Public 1 Version 4.0 Implement VTP LAN Switching and Wireless – Chapter 4.
© 2006 Cisco Systems, Inc. All rights reserved.Cisco PublicITE I Chapter 6 1 Implement VTP LAN Switching and Wireless – Chapter 4.
© 2006 Cisco Systems, Inc. All rights reserved.Cisco Public 1 Version 4.0 VLANs LAN Switching and Wireless – Chapter 3.
VLAN Trunking Protocol
© 2008 Cisco Systems, Inc. All rights reserved.Cisco ConfidentialPresentation_ID 1 Chapter 3: VLANs Routing & Switching.
VLAN Trunking Protocol (VTP)
© 2006 Cisco Systems, Inc. All rights reserved.Cisco PublicITE I Chapter 6 1 VLANs LAN Switching and Wireless – Chapter 3.
VTP VLAN Trunking Protocol Create once and send to the other switches. VTP is a messaging protocol that uses Layer 2 trunk frames to manage the addition,
+ Lecture#8: VLAN Asma AlOsaimi Topics VLAN Segmentation VLAN Implementation VLAN Security and Design 3.0.
LAN Switching Virtual LANs. Virtual LAN Concepts A LAN includes all devices in the same broadcast domain. A broadcast domain includes the set of all LAN-connected.
Exploration 3 Chapter 4. What is VTP? VTP allows a network manager to configure a switch so that it will propagate VLAN configurations to other switches.
© 2006 Cisco Systems, Inc. All rights reserved.Cisco Public 1 VLANs.
Instructor Materials Chapter 2: Scaling VLANs
Chap 4 – Implement VTP Learning Objectives
Switching and VLANs.
© 2002, Cisco Systems, Inc. All rights reserved.
Switching and VLANs.
Extending Switched Networks with Virtual LANs
VLAN Trunking Protocol
Introduction to Networking
Chapter 2: Scaling VLANs
VLAN Trunking Protocol
Switching and VLANs.
Chapter 3: Implementing VLAN Security
CCNA 3 v3 JEOPARDY Module 9 CCNA3 v3 Module 9 K. Martin.
Chapter 2: Scaling VLANs
LAN Switching and Wireless – Chapter 4
LAN Switching and Wireless – Chapter 4
LAN Switching and Wireless – Chapter 4
Presentation transcript:

© 2006 Cisco Systems, Inc. All rights reserved.Cisco ConfidentialBCMSN BCMSN v3.0—2-1 Correcting Common VLAN Configuration Errors BSMSN Module 2 Lesson 5

© 2006 Cisco Systems, Inc. All rights reserved.Cisco ConfidentialBCMSN Objectives  Describe issues with 802.1Q Native VLANs and explain how to resolve those issues.  Describe trunk link problems and explain how to solve those.  Identify common problems with VTP configuration.  Describe best practices for using VTP in the Enterprise Composite Network Model.

© 2006 Cisco Systems, Inc. All rights reserved.Cisco ConfidentialBCMSN Purpose of this Lesson  What’s new in this module? Description of issues with 802.1Q Native VLANs and how to resolve those issues. Description of trunk link problems and how to solve those. Common problems with VTP configuration. Best practices for using VTP.  This lesson does not cover VLANs. The VLAN modules of BCMSN are largely unchanged.

© 2006 Cisco Systems, Inc. All rights reserved.Cisco ConfidentialBCMSN Different Native VLANs A native VLAN mismatch will merge traffic between VLANs.

© 2006 Cisco Systems, Inc. All rights reserved.Cisco ConfidentialBCMSN CDP and Unmatching Native VLANs  Instances where unmatching VLAN IDs are reported between two devices are displayed in the console in the following format: %NATIVE_VLAN_MISMATCH: native VLAN mismatch discovered on [local interface (local interface VLAN ID),] with [neighbor name neighbor interface (neighbor VLAN ID)]  In this example, a mismatch is reported on Ethernet 1/0 with native VLAN 5 and router1 Ethernet 2/3 with native VLAN 27: %NATIVE_VLAN_MISMATCH: native VLAN mismatch discovered on Ethernet1/0 (5), with router1 Ethernet2/3 (27)

© 2006 Cisco Systems, Inc. All rights reserved.Cisco ConfidentialBCMSN Untagged Frames Native VLAN frames are carried over the trunk link untagged.

© 2006 Cisco Systems, Inc. All rights reserved.Cisco ConfidentialBCMSN Q Native VLAN Considerations  Native VLAN must match at ends of trunk otherwise frames will ‘leak’ from one VLAN to another.  By default the native VLAN will be VLAN1. Avoid using VLAN 1 for management purposes.  Eliminate native VLANs from 802.1Q trunks by making the native VLAN an ‘unused’ VLAN.

© 2006 Cisco Systems, Inc. All rights reserved.Cisco ConfidentialBCMSN Explaining Trunk Link Problems  Trunks can be configured statically or autonegotiated with DTP.  For trunking to be autonegotiated, the switches must be in the same VTP domain.  Some trunk configuration combinations will successfully configure a trunk, some will not.  The following elements determine whether or not an operational trunk link is formed as well as the type of trunk the link becomes: Trunking mode Trunk encapsulation type VLAN Trunk Protocol (VTP) domain Hardware capabilities of two connected ports

© 2006 Cisco Systems, Inc. All rights reserved.Cisco ConfidentialBCMSN Dynamic Trunk Protocol (DTP)  What is DTP? Automates ISL/802.1Q trunk configuration Operates between switches Does not operate on routers Not supported on 2900XL or 3500XL  DTP synchronizes the trunking mode on link ends (i.e., native VLAN mismatch, VLAN range mismatch, encapsulation, etc.)  DTP states on ISL/dot1Q trunking port can be set to “auto” “on” “off” “desirable” “non-negotiate”

© 2006 Cisco Systems, Inc. All rights reserved.Cisco ConfidentialBCMSN Trunk—Solution Trunking Modes Uses DTP Forms Trunk with Off Forms Trunk with Auto Forms Trunk with Desirable Forms Trunk with On OffNo Forms Trunk with No Negotiate AutoYesNo Yes No DesirableYesNoYes No No NegotiateNo Yes OnYesNoYes

© 2006 Cisco Systems, Inc. All rights reserved.Cisco ConfidentialBCMSN Resolving Trunk Link Problems  When using DTP, ensure that both ends of the link are in the same VTP domain.  Ensure that the trunk encapsulation type configured on both ends of the link is valid.  DTP should be turned off on links where trunking is not required.  Best practice is to configure trunk and nonegotiate where trunks are required.

© 2006 Cisco Systems, Inc. All rights reserved.Cisco ConfidentialBCMSN  DTP negotiation tuning improves link up convergence time IOS(config-if)# switchport mode trunk IOS(config-if)# switchport nonegotiate Optimizing Convergence: Trunk Tuning Trunk Auto/Desirable Takes Some Time Two Seconds of Delay/Loss Tuned Away

© 2006 Cisco Systems, Inc. All rights reserved.Cisco ConfidentialBCMSN VTP Virtual Trunk Protocol  Centralized VLAN management  VTP server switch propagates VLAN database to VTP client switches  Runs only on trunks  Four modes: Server: updates clients and servers Client: receive updates— cannot make changes Transparent: let updates pass through Off: ignores VTP updates

© 2006 Cisco Systems, Inc. All rights reserved.Cisco ConfidentialBCMSN Common Problems with VTP Configuration  Check domain name  Check domain password  Check VTP version  Check trunk links  Check VTP modes At least 1 server?

© 2006 Cisco Systems, Inc. All rights reserved.Cisco ConfidentialBCMSN VLANs Disappear from Network VTP Bomb occurs when a VTP Server with a Higher Revision of the VTP Database (Albeit Loaded with Potentially Incorrect Information) Is Inserted into the Production VTP Domain Causing the Loss of VLAN Information on All Switches in That VTP Domain

© 2006 Cisco Systems, Inc. All rights reserved.Cisco ConfidentialBCMSN Example of New Switch Overwriting an Existing VTP Domain Switch#show vtp status VTP Version:2 Configuration Revision :2 Number of existing VLANs:7 VTP Operating Mode:Server VTP Domain Name:building1 New switch not connected: Existing switch: Switch#show vtp status VTP Version:2 Configuration Revision :1 Number of existing VLANs:6 VTP Operating Mode:Server VTP Domain Name:building1

© 2006 Cisco Systems, Inc. All rights reserved.Cisco ConfidentialBCMSN Example of New Switch Overwriting an Existing VTP Domain (cont.) New switch connected Switch#show vtp status VTP Version:2 Configuration Revision :2 Number of existing VLANs:7 VTP Operating Mode:Server VTP Domain Name:building1 New switch after connection: Existing switch after adding new: Switch#show vtp status VTP Version:2 Configuration Revision :2 Number of existing VLANs:7 VTP Operating Mode:Server VTP Domain Name:building1

© 2006 Cisco Systems, Inc. All rights reserved.Cisco ConfidentialBCMSN Resetting the VTP Revision Number 1.Use show vtp status command to check the VTP configuration revision number and the VTP domain name. If the revision number is 0, add the switch to the VTP domain. If the number is not 0, write down the domain name and proceed to Step 2. 2.Enter global configuration mode and use the vtp domain domain- name command to change the VTP domain name to something other than what was recorded in Step 1. 3.Issue the end command to exit configuration mode and save your changes 4.Use the show vtp status command to check the revision number. It should indicate 0. 5.Enter global configuration mode and use the vtp domain domain- name command to change the VTP domain name back to the name recorded in Step 1. 6.Issue the end command to exit configuration mode and save your changes 7.Use the show vtp status command to check the revision number. It should indicate 0.

© 2006 Cisco Systems, Inc. All rights reserved.Cisco ConfidentialBCMSN Check Revision Number, Record Domain

© 2006 Cisco Systems, Inc. All rights reserved.Cisco ConfidentialBCMSN Change Domain to Something New, Save Changes

© 2006 Cisco Systems, Inc. All rights reserved.Cisco ConfidentialBCMSN Change Domain Back to Original and Confirm

© 2006 Cisco Systems, Inc. All rights reserved.Cisco ConfidentialBCMSN Implementing VTP in the Enterprise Composite Network Model  Plan VTP domain boundaries.  Have only one or two VTP servers.  Configure a VTP password.  Manually configure the VTP domain name on all devices.  When setting up a new domain Configure VTP client switches first so that they participate passively  When cleaning up an existing VTP domain Configure passwords on servers first because clients may need to maintain current VLAN information until the server is verified as complete.

© 2006 Cisco Systems, Inc. All rights reserved.Cisco ConfidentialBCMSN Activity  You are tasked with adding a new switch to the existing network. The network is running VTP.  Describe the steps you would take to ensure that the new switch did not overwrite the existing configuration.

© 2006 Cisco Systems, Inc. All rights reserved.Cisco ConfidentialBCMSN Self Check 1.What is the danger of mismatched native VLANs? 2.What is the default native VLAN? 3.In a DTP configuration, what elements determine whether or not an operational trunk link is formed as well as the type of trunk the link becomes? 4.Name 4 VTP modes and describe their VTP roles. 5.What is a VTP Bomb?

© 2006 Cisco Systems, Inc. All rights reserved.Cisco ConfidentialBCMSN Summary  802.1Q native VLAN can cause security issues.  Configure the native VLAN to be an ‘unused’ VLAN.  Some trunk link configuration combinations can result in problems on the link.  Best practice is to configure trunks statically rather than with DTP.  Misconfiguration of VTP can give unexpected results.  Make only one or two VTP servers; keep the remainder as clients.

© 2006 Cisco Systems, Inc. All rights reserved.Cisco ConfidentialBCMSN Resources  DTP Messages: 111yj/2950smg/msg_desc.htm#xtocid3  Cisco Command Reference: ps6441/prod_command_ reference_list.html  TAC Case Collection (requires CCO login)

© 2006 Cisco Systems, Inc. All rights reserved.Cisco ConfidentialBCMSN Q and A

© 2006 Cisco Systems, Inc. All rights reserved.Cisco ConfidentialBCMSN