Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

How can I filter the VTP frames ?

Hi,

i have 2 6509 (CatOS and IOS) connected together with 1 Gigabit Ethernet port configured as trunk 802.1q for the VLANs 1 and 2.

The 1st swtiches is configured as VTP server (version 1) and the 2nd is not configured.

How can i block the transport of the VTP protocol frames on the port (only on this ports!) ?

Is there a command in the IOS and/or in the CatOS for filter the VTP protocol only on the port ?

CCO:

"By default, the Catalyst 6000 family switch is in VTP server mode and is in the no-management domain

state until the switch receives an advertisement for a domain over a trunk link or you configure a

management domain.

If the switch receives a VTP advertisement over a trunk link, it inherits the management domain name

and the VTP configuration revision number. The switch ignores advertisements with a different

management domain name or an earlier configuration revision number.

"

Correct me please:

the vtp frames are transported only on trunk ports: if i remove the trunk configuration on the port the VTP frames are not tranpsoterd.

Thanks in advance.

1 REPLY
Cisco Employee

Re: How can I filter the VTP frames ?

You want to use vtp transparent on both switches. This will stop vtp adv. over the trunks. Vtp transparent is the suggested way to go according to Cisco's best practices. Always try to use best practices.

http://www.cisco.com/warp/public/473/103.html

There are pros and cons to VTP's ability to make changes easily on a network, and many enterprises prefer a cautious approach of using VTP transparent mode for the following reasons:

It encourages good change control practice, as the requirement to modify a VLAN on a switch or trunk port has to be considered one switch at a time.

It limits the risk of an administrator error, such as deleting a VLAN accidentally and thus impacting the entire domain.

There is no risk from a new switch being introduced into the network with a higher VTP revision number and overwriting the entire domain's VLAN configuration.

It encourages VLANs to be pruned from trunks running to switches that do not have ports in that VLAN, thus making frame flooding more bandwidth-efficient. Manual pruning also has the benefit of reducing the spanning tree diameter (see DTP section).

The extended VLAN range in CatOS 6.x, numbers 1025-4094, can only be configured in this way.

VTP Transparent mode is supported in Campus Manager 3.1, part of Cisco Works 2000. The old restriction of needing at least one server in a VTP domain has been removed

117
Views
0
Helpful
1
Replies
CreatePlease login to create content