cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
4572
Views
26
Helpful
6
Replies

parking vlan

cisco steps
Level 1
Level 1

how do I Place all unused ports in a parking vlan,wich is dedicated to grouping unused ports until they are proactively placed into service .

This is part of Switch security .. I know I can execute the shut command and that should do it , but I needed to learn more

Thanks

6 Replies 6

n.nandrekar
Level 4
Level 4

Hi!

All switchports are by default members of the native vlan (vlan 1 in cisco). You can call that as a parking vlan if you want :).

If you want a seperate vlan you can create it and then tnter into the interface configs to make all the ports as access of that vlan. You could use the "interface range xxxx" command to configure multiple interfaces at the same time.

Regards,

Niranjan

I think there is more to it then that for security. I know they all members of vlan1 .. on my notes it says other way to secure port is to place them to parking vlan " if parking vlan= vlan1 then why they mentioned that you can place them there if the are members by default" hehe :-)

Thanks Niranjan

ocporbust,

As Niranjan mentioned,Seems you want to put the unused ports into the vlan,Called Parking vlan. It should be fine to do that way. Just make that vlan and no need to make the vlan interface for routing. Then shutting those ports down. I wouldn't use vlan 1 for parking or management devices(Vlan management).

HTH

Thot

foxbatreco
Level 3
Level 3

This type of unused vlans lot are to be placed in a random far off vlan.

Create a vlan which is different from ur current group of vlans.Say Vlan 905 and assign all unused interfaces onto this vlan.

By default Vlan 1 ( native vlan) accomodates all unused interfaces.But its always better from security perspective to assign different vlan to unused ports.

Pls rate if this helps!!!

glen.grant
VIP Alumni
VIP Alumni

Put all unused ports into a dummy or parking vlan that is not used for anything . then put that vlan into suspend mode and it will not pass data. I think any ports in that vlan will show inactive then if you look at it via show interface status". .

hey Thanks alot for making things clear to me. now it makes more since on how to do it and why to do it... again Thanks to all of you//

karim

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card