cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
822
Views
5
Helpful
3
Replies

VTP advertisements - can a VLAN be excluded ?

chris.smailes
Level 1
Level 1

We have a 6509 which is a VTP server for some edge switches which are VTP clients. The 6509 has had a number of VLANs created on it which are advertised out using VTP with VTP pruning enabled for all vlans. This works well. But, we have now created a new VLAN which will only ever have ports assigned to it which are physically on the 6509 itself (for security reasons). I have been trying to find a way of preventing this new VLAN from being advertised to the edge switches. VTP pruning will stop the broadcast traffic ok but the new 'secure' vlan is still advertised to the edge switches. Does anyone know if there is a way of excluding a new VLAN from the VTP advertisements ? Thanks for your time.

1 Accepted Solution

Accepted Solutions

andrew.prince
Level 10
Level 10

AFAIK - no, you cannot do this, using VLAN pruning is a good, but I would also recommend that you remove that VLAN from the allowed trunks list - just to make sure that no-one can configure a switch port by "mistake" on another switch to be in that VLAN.

You might also want to think about making that VLAN "Private" as well.

HTH>

View solution in original post

3 Replies 3

andrew.prince
Level 10
Level 10

AFAIK - no, you cannot do this, using VLAN pruning is a good, but I would also recommend that you remove that VLAN from the allowed trunks list - just to make sure that no-one can configure a switch port by "mistake" on another switch to be in that VLAN.

You might also want to think about making that VLAN "Private" as well.

HTH>

Thanks for the suggestions.

np - glad to help.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card