cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
245
Views
0
Helpful
1
Replies

Vlan 1 question

david-flores
Level 1
Level 1

We have recently migrated our management vlan off vlan 1, to a new dedicated vlan. Our network consists of 2 6500 at the core, and the rest 3560, snd 3548 all running L2. Some of the switches have vlan 1 admin down, and some admin up, is it necessary to still have vlan 1 up or down on all switches?

Thanks.

1 Accepted Solution

Accepted Solutions

Giuseppe Larosa
Hall of Fame
Hall of Fame

Hello David,

L2 only devices like a 2950 can have only one active vlan so on those platforms you will see only the new management vlan SVI up/up and the SVI for Vlan1 will be admin down.

Some switches that actually have some L3 capabilities can have both SVI up/up.

My suggestion is to shut down the SVI of Vlan1 manually on devices that have it still up/up.

The main reason for moving away from vlan1 as management vlan are security reasons: leaving an alive L3 interface in vlan1 would expose the switches to some threats as it was before the migration.

Hope to help

Giuseppe

View solution in original post

1 Reply 1

Giuseppe Larosa
Hall of Fame
Hall of Fame

Hello David,

L2 only devices like a 2950 can have only one active vlan so on those platforms you will see only the new management vlan SVI up/up and the SVI for Vlan1 will be admin down.

Some switches that actually have some L3 capabilities can have both SVI up/up.

My suggestion is to shut down the SVI of Vlan1 manually on devices that have it still up/up.

The main reason for moving away from vlan1 as management vlan are security reasons: leaving an alive L3 interface in vlan1 would expose the switches to some threats as it was before the migration.

Hope to help

Giuseppe

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card