All language subtitles for 17 - Switching - Understanding VTP and 802.1q-eng

af Afrikaans
ak Akan
sq Albanian
am Amharic
ar Arabic
hy Armenian
az Azerbaijani
eu Basque
be Belarusian
bem Bemba
bn Bengali
bh Bihari
bs Bosnian
br Breton
bg Bulgarian
km Cambodian
ca Catalan
ceb Cebuano
chr Cherokee
ny Chichewa
zh-CN Chinese (Simplified)
zh-TW Chinese (Traditional)
co Corsican
hr Croatian
cs Czech
da Danish
nl Dutch
en English
eo Esperanto
et Estonian
ee Ewe
fo Faroese
tl Filipino
fi Finnish
fr French
fy Frisian
gaa Ga
gl Galician
ka Georgian
de German
el Greek
gn Guarani
gu Gujarati
ht Haitian Creole
ha Hausa
haw Hawaiian
iw Hebrew
hi Hindi
hmn Hmong
hu Hungarian
is Icelandic
ig Igbo
id Indonesian
ia Interlingua
ga Irish
it Italian
ja Japanese
jw Javanese
kn Kannada
kk Kazakh
rw Kinyarwanda
rn Kirundi
kg Kongo
ko Korean
kri Krio (Sierra Leone)
ku Kurdish
ckb Kurdish (Soranî)
ky Kyrgyz
lo Laothian
la Latin
lv Latvian
ln Lingala
lt Lithuanian
loz Lozi
lg Luganda
ach Luo
lb Luxembourgish
mk Macedonian
mg Malagasy
ms Malay
ml Malayalam
mt Maltese
mi Maori
mr Marathi
mfe Mauritian Creole
mo Moldavian
mn Mongolian
my Myanmar (Burmese)
sr-ME Montenegrin
ne Nepali
pcm Nigerian Pidgin
nso Northern Sotho
no Norwegian
nn Norwegian (Nynorsk)
oc Occitan
or Oriya
om Oromo
ps Pashto
fa Persian
pl Polish
pt-BR Portuguese (Brazil)
pt Portuguese (Portugal)
pa Punjabi
qu Quechua
ro Romanian Download
rm Romansh
nyn Runyakitara
ru Russian
sm Samoan
gd Scots Gaelic
sr Serbian
sh Serbo-Croatian
st Sesotho
tn Setswana
crs Seychellois Creole
sn Shona
sd Sindhi
si Sinhalese
sk Slovak
sl Slovenian
so Somali
es Spanish
es-419 Spanish (Latin American)
su Sundanese
sw Swahili
sv Swedish
tg Tajik
ta Tamil
tt Tatar
te Telugu
th Thai
ti Tigrinya
to Tonga
lua Tshiluba
tum Tumbuka
tr Turkish
tk Turkmen
tw Twi
ug Uighur
uk Ukrainian
ur Urdu
uz Uzbek
vi Vietnamese
cy Welsh
wo Wolof
xh Xhosa
yi Yiddish
yo Yoruba
zu Zulu

Original subtitles

>> Deeper down the rabbit hole we go with VLANs as we unpacked VTP and 802.1Q.

In the last Nugget, I gave you kind of the overview like this what VLANs are,

this is why they're great, this is some examples of how we can use them,

now I'd like to unpack the details of it.

So, how to look at trunks and how they really work

and that there's really a secret sauce behind them called 802.1Q.

We'll look at a concept of the Native VLAN and then finally, look at VTP,

how it can help or destroy your entire network.

Okay, let's pull a little review from the last Nugget.

Trunking, what is it?

Well, trunking is the ability to connect multiple switches together and allow your VLANs

to seamlessly go across your entire campus fabric.

Man, that statement was made for a marketing magazine or something like that.

That sounded so good, I can't even say it again if I try.

But, if I connect multiple switches together like let's add switch C and switch D together,

well, it gives me the ability to add computers, and devices, and wireless access points,

and printers and whatever else, whatever widgets I'd like to, all around the campus

and allow these VLANs to span that direction.

So, for instance, let's say VLAN 2, which I have there as that little orange-ish computer.

VLAN 2 might be the sales VLAN.

So all the sales people are a member of that.

So I can now add sales people down here and add them as well to VLAN 2 and maybe this--

this is-- this wireless access point is actually for VLAN 3

because only the executive team get wireless access, or whatever.

You get the point.

We can stretch our VLANs all around our company through this concept of trunking.

Now what trunking does is tag, remember I said in the last Nugget,

a better word for is tagging, tag each packet that sent across the wire, across those links

that connect the switches, with this special little 4-byte field.

Now, there are two forms of trunking, one is 802.1Q.

I'm hesitant even say this nowadays but you may see it.

You may encounter it somewhere sometime whether it be exam,

whether it be real world, you might run into it.

There is another one called ISL, Inter-Switch Link.

So these are two different languages that you can use for tagging packets.

Now, Cisco was first to the game with VLAN.

Long before there was a real standard or at least I should say a good standard,

Cisco came out with something called Inter-Switch Link.

Now that worked and it allowed you to tag your packets with specific VLAN information

and send it across, but anytime you say, Cisco made it,

that means it only works for Cisco switches.

802.1Q, which was the eventual standard, is the replacement for ISL.

Now, this is industry standard-- in-- in-- well, you get the point,

industry standard to where any vendor can create a switch and use 802.1Q.

So, I could-- you know, I've got switch A which might be a Cisco, might be a Cisco,

maybe bring in switch F over here with-- it's some hidden brand over here.

We don't know, but as long as it's a managed switch, it will support 802.1Q

and it will do VLANs and now be able to integrate and speak

that trunking language with my Cisco switches.

So let's dig a little bit deeper.

Inside of this little 4-byte tag is a-- is VLAN data and this is where it will be 1

of 4,096 different values so let it know which VLAN it belongs to.

And then next to that is something known as the priority, or if you dig a little bit deeper,

it's not part of this series but that is actually called class of service.

So switches can do quality of service as well.

So I can put in this header information.

I can put little tags that say, "Oh, these traffic is really important.

You're a level-5 traffic.

Whereas this traffic, eh, it's not that important

and you're a level 1 or a level 0 traffic."

So, these are all known as the CoS or Class of Service bits.

If you ever decided diving to CCNP, or get into Voice over IP

or one of the more advanced tracks, they'll totally explain that.

For now, we don't care.

[laughs] All eyes are on that VLAN tag which is sitting in the header and it passes all of that

between switches by embedding it into each frame.

Now, keep in mind, this is a trunking thing.

This is only on the links between your switches, VLAN tags are always removed

when we're sending data to the computer themselves.

Partnered with the concept of trunking is the idea of the Native VLAN.

Trunks send tagged information, right?

Let me go with the simple view here.

We got a couple of switches, let's say we've got three computers up here that are all--

you know, these guys are a member of VLAN 2, this guy is a member of VLAN 3,

and then down here I've got one computer that's a member of VLAN 2

and one computer member of VLAN 3.

So, if this is a trunk, it's going to send tagged information across.

So as VLAN 3 sends a broadcast, it will come down here and go, "Oh, let's put a little,

you know, shim on the header there.

We've got VLAN 3 tag, that's now we officially know, an 802.1Q tag on the header.

So when this guy gets it, he goes, "Oh, you belong to VLAN 3."

Strips off that little tag and then sends it to all the VLAN 3 devices.

That's what trunks do.

Now, the question of this Native VLAN comes in when we say, "Well,

what if I need to send something between these guys that is not tagged?"

And you might look at the picture and say, "Well, look at the picture what wouldn't be tag.

I mean, we've got two over here and two over here and three over here and three over here,

so you would have tags of two and tags of three [inaudible],

why would you send something that's not tagged?"

Well, there are management protocols that run behind the scenes on switches.

Well, like one of them we know is Telnet, another one might be SSH.

So, maybe I'm sitting here plugged in to the console port of the switch, this switch is,

you know, 300 feet down the hall and then like, well,

I don't want to go walk down the hall with my laptop.

That's a far walk.

I'm sitting in my chair, I'm kind of cozy.

I just want a Telnet from this switch down to this switch, right?

Well, if I'm Telnetting from this switch to this switch, what VLAN does that belong on?

None, really, I mean, it's whatever VLAN this switch management interface is

on which is probably VLAN 1.

So, it's going to send that across untagged,

or there's another protocol we haven't talk about yet called CDP.

It's a discovery protocol.

It's kind of neat because Cisco devices will send each other these little discovery messages

where they're like, "Oh, I see you my little friends, Cisco device.

I'm going to add you to a table."

So, an administrator at any point can type in a command called Show CDP Neighbors

and they can see all the Cisco devices around them, all of the devices

that are attached to whatever device they're on.

Well, in order for CDP to work, these guys have to send like little probes,

little hellos saying, "Hey, I'm running CDP.

This is me.

This is-- I'm a switch did you know who-- ."

All of that stuff is running on the Native VLAN.

It doesn't really belong to a VLAN so much as it's just traffic that needs

to pass from one switch to another.

It's considered untagged traffic.

This concept originally came about in long, long ago when switches were so expensive,

people were like, man, we can't afford many of these things.

Let's put hubs in the middle of our network so that we can kind of, you know, balance the cost.

So we would have some switches going through hubs to reach other switches.

Well, and to those hubs, we would plug in computers and these switches would have trunks

to each other, they'd be tagging packets,

so VLAN 15 ends up on VLAN 15 and all that kind of stuff.

But the question became, well, what happens when this computer comes in on that port and says,

"Hey, I want to talk to something.

What VLAN is it on?

The Native VLAN.

If a trunk receives data that does not have a tag on it,

it will automagically become part of the Native VLAN.

Nowadays-- I mean, nowadays, burn that model.

Nobody does that anymore, that's like-- you know, that's heresy.

Why would you put a hub in the middle of your network?

But nowadays, we use this concept for things like this.

For example, best practice says, "I want to put my IP phones on a VLAN."

Let's put them on VLAN 15 which is separate from the computer

that it's plugged into, maybe this guy is on VLAN 10.

Why is that a best practice?

Because it's scary.

If you have your computer and your phone on the same VLAN and somebody pulls out Wireshark,

Wireshark has the ability to capture voice packets and reassemble them into audio files.

[laugh]s So back in the day, you know, people would have those little butt sets

that they would have on their waist with the alligator clips.

You know, that they would clip on to the wires and be able to kind

of tap phone conversations and hear what's going on.

I mean phone text still have them today.

I shouldn't say back in the day, they're still around.

Now, you can do that without needing any alligator clips.

You can open Wireshark and I capture the data.

So Cisco is like, "Whoa, let's keep this guy on a separate VLAN than this guy.

But then we'll run in the problem, "Well, how do you that?

Because normal ports are only a member of one VLAN."

And then, you know, if this guy is sending traffic, I mean, how do I differentiate

between him sending traffic and him because they're coming in the same port.

Well, that was where that concept of the Native VLAN came in.

Now, what I'm about to tell you is if you were to tell this to Cisco, they'll be like,

"No, no, no, that's not how we do it.

It's not. It's not."

Because it's actually a security flaw, if you will, but it was the original way they do it

and it's still kind of the way they do it, but let me explain

and that we can unpack all of the politics behind it later.

The way that we can make this work is to configure this port as a type of trunk.

Now, a trunk will send tagged packets which IP phones understand.

So I can say, on this trunk, I'm going to have VLAN 15 be the tagged VLAN.

Now that's good because this phone understands tags.

Cisco IP phones, you pull them out of box, they're like, "I speak the language of 802.1Q.

I speak tags."

So, as I'm speaking on the phone, I'm saying, "Hello everybody" on the phone.

It's sending packets and it's automatically putting them with little tag of 15.

So the switch goes, "Okay, you're coming from a phone, I'm going to put you on VLAN 15."

Now the computer, no idea what a VLAN even is.

Computers do not know the concept of VLANs.

They know the concept of surfing the web.

They know the concept of transferring files.

So they just have an IP address, they're just sending data.

So they're coming in without any VLAN tags.

Hmm, that rings a bell.

If they don't have any VLAN tags, then what are they on?

The Native VLAN.

So what you would configure this for is it would be a trunk

and I would set it out for a Native VLAN of 10.

So when this computer starts sending data, it doesn't have a tag,

it says, "Well, you must be on VLAN 10."

So that's kind of how we apply that concept today.

Now, Cisco has new and improved ways of doing this kind of thing.

So the reason I emphasize that is because they really make a point of saying it's not a trunk.

It's a tagged access port, but it really is kind of the same thing.

So for now, just for the concept, that's what the Native VLAN is all about.

So, why am I talking about this?

You know, it's kind of like, okay, good I get it, what's the point?

Well, the point-- I found out-- so, this has been bugging me for so long.

You see how my circles are kind of like blobby, see that.

I found out that my little drawing program here converts my-- when I clear it like that,

when I clear-- it converts my pen to like a gel pen and I finally figured out, check this out.

Watch the blobby.

Watch it. Bam!

Isn't that so much cleaner?

Come on, the difference, gel pen, oh ugly.

Default, oh, much better.

So, I finally figured that out.

I was very excited.

But why am I telling you this concept of the Native VLAN?

The reason why is because it's dangerous if you mismatch them.

So, what I mean is this.

Let's say we've got two switches and by default, the Native VLAN is 1.

That's just how it is, but you can change that.

Let's say on one side, I make the Native VLAN 10 and on the other side,

I make the Native VLAN 20, right?

Well, that poses a problem.

It's going to break something, likely, if I do that.

The switches will start yelling at you.

They'll send you messages on the console port like mad being like, "Native VLAN mismatch.

Don't do this.

Something is very wrong."

But what ends up happening is devices that are on VLAN 10, maybe they're the accounting devices

and devices that are on VLAN 20, maybe they're the sales devices end

up merging together into this big blob VLAN.

So here's what happens.

This guy sends some data to the other side, the switches like, "Oh, okay,

you're trying to reach, we'll say, you know, device X over here," and he's in VLAN 20.

But as soon as it hits that trunk port, it goes, "Oh, wait a sec,

wait a sec, VLAN 20 is my Native VLAN.

That means VLAN 20 doesn't have any tags.

There're no tags in there."

So rather than doing what trunks normally do which is stick a little tag

on that packet saying VLAN 20 is-- you know, is tagged on here, so this switch gets in,

he's like, "Oh, you belong to VLAN 20."

He goes, "Oh, well that's my Native VLAN so I'm going to strip the tag off.

There's going to be no tag.

I'm just going to send it untagged 'cause remember, Native VLAN equals untagged."

So, on the other side, I've got a Native VLAN of 10.

So it comes in and it assumes that I'm on VLAN 10.

And so, so this untagged traffic went out on 20 came in it's like, "Oh,

well my Native VLAN is 10 so now I'm on 10."

Is it supposed to do that?

No, but it's how it's configured.

That's called the Native VLAN mismatch.

And what it does is undo a lot of your security boundaries to where this guy can now get

to this guy, and he's not supposed to.

Because-- and same thing happens on this side, if I've got computer and VLAN 10 over here.

When he sends it, he's going to be like, "Oh, VLAN 10,

that's my Native so I'll send it untagged and then it comes in on this guy as VLAN 20."

So, my point is, if you're configuring trunks which we're going to do in the next Nugget,

you want to make sure that the Native VLAN matches between both sides.

Now, let's get back to Cisco.

Cisco had a really good idea.

Remember I said, they were first to the game with VLANs,

they came out with this protocol called ISL.

We don't use it anymore nowadays, but it was great, great for its time.

Well, way back then, Cisco, you know, was kind of looking at the VLAN standard

as it was emerging and they're like, "We can do something really cool.

We're going to come up with this protocol called VTP."

Now, first of, the name will mess you up,

[laughs] it stands for the VLAN Trunking Protocol.

But, and I'm going to say it and I'm going to say it twice

because I want it to stick in your head.

It is not a trunking protocol, okay?

You get it?

The VLAN Trunking Protocol is not a trunking protocol.

There are only two trunking protocols out there.

One of them has gone away.

One is ISL, the other is 802.1Q.

Those are the two protocols that can tag traffic

so that switches know what VLAN it belongs to, that's it.

So the VLAN Trunking Protocol, what, is not a trunking protocol.

It should've been called the VLAN Replication Protocol, that's my humble opinion.

But nonetheless, here's what Cisco's goal was and it really was, it really was a good idea.

You know why I'm saying this, that I'm going to have this kicker at the end and I'm like, yeah,

and it's not a good idea anymore and you're right.

So, VTP was a great idea because what would happen is it would save you configuration work

and make your network totally consistent.

So, the way VTP works is you would link up all your switches with trunks.

So we've got 802.1Q running everywhere here.

This is our trunking, right?

8021Q Trunk, that bridge [inaudible] switch together

and I would go in and I would create a VLAN.

Let's say VLAN 10 and I name it, that's one of the things you can do.

We'll say name sales.

Now VTP immediately goes, "Oh, I'm going to update my database."

It looks like they made a change,

all the switches by the way start their database at Revision 0.

So it's Revision 0.

And now it goes, "Okay, they made a change.

They added VLAN 10.

We are at Rev 1."

He sends an announcement saying, "Rev 1," this guy is like, "Oh, sweet Rev 1.

I want Rev 1.

Rev 1, Rev 1."

So all these switches are getting this little revision and they go, "What's to be revised?"

My VLAN database.

So they now all have VLAN 10, VLAN 10.

So, it saves you the time, 'cause normally, I have to go switch by switch,

by switch and add in VLAN 10 and add in and name it and give it a name.

I mean, I know I'm making it sound like a lot of work, and it kind of is.

But VTP just makes it that much easier and then they go in there and say, "Well,

I'm going to add VLAN 20, maybe VLAN 20 is marketing."

And it goes, "Okay, Rev 2, Rev 2, Rev 2, Rev 2."

I mean, it's almost instantaneous.

It's like snap your fingers, bam!

VLAN 20 appears on all the switches.

And now, all you have to do is start assigning the ports to it, so it knows which ports belong

in which VLANS, but it saves you a big part of your configuration.

So that's really cool.

Here's where the problem comes in.

I'm talking about all these, right?

Let's say that you go out on eBay after this discussion like, "I got to do this.

I'm going to go on eBay, I'm going to buy a switch."

You look at the description and it says, you know, "Cisco 3550.

You know, the company went out of business, used it for eight years, still works great, you know,

their loss, your gain, buy it now 50 dollars."

And you're like, "Fifty dollars, that's great."

So you buy it now, bam!

You get the switch in the mail.

You go to log on and you find out it has the company's old configuration on it, that's cool.

Because it's very easy to do password recovery in a Cisco switch,

and I love when I get stuff off eBay where it has old configurations 'cause I

like seeing how people's network are setup.

I'm like, "Oh, oh."

You know, and I just like seeing that.

So, you kind of-- you look at it, you're like, "Man, this is really cool.

Oh well, okay let's erase it."

So, you erased the configuration on the switch.

You do, right erase is one of the ways to do it, quick way.

Reboot, okay, I'm back to a clean config.

Okay, I'm playing around at home doing my thing, right?

And all a sudden I'm like, "Ah, I got to go to work."

And then the thought hits your mind.

You know what, I have a lot of downtime at work.

Maybe I can bring my switch to work that I got off eBay and just do a little studying.

And so, you're like, "That's a great idea."

So you bring your switch to work and you configure, "You know, man, this is great",

and all of a sudden, it hits you again.

You're like, "You know what, I've got this home switch," poof, enter the picture.

"And I've been playing around but I want this to be real.

Here's what I want to do.

I want to take my cubicle here and I've got this little wall jack and I'm going

to unplug my computer that's plugged in.

I'm just going to-- I'm going to plug it into my home switch."

And you click in there and you-- if it were made for TV movie, you know, it would be slow motion.

There would be some guy jumping over the cubicle going, "Nooo!"

You know, there'll be some drama here but for now, you just click it in.

Light goes green and all of a sudden, poof!

First thing you notice you know-- first thing anybody notices, you'll see a head poke

up in the cubicle farms and, you know, Bob down the hall is like, "Hey, is your email up?"

You know, someone else is like, "No, my Facebook access isn't up either."

You know, like people immediately notice email and Facebook going down,

and you're kind of like, "Oh, yeah," and you kind of unplugged it

and shoved the switch in the drawer.

What happened?

Well, what happened was you got this switch from company X on eBay where they've been using it

for eight years and they've probably made bajillion VLAN changes.

You know, deleting VLANs, adding VLANs all that kind of stuff over the years.

Maybe they're up to VTP Rev 302, and maybe that switch on there had VLAN 100.

That's was the only VLAN, you know, at this point because you're playing with it in your lab

or whatever, that's the only VLAN that you had.

Well, as soon as you connected it to that wall jack, it goes through the ceiling

and eventually connects back here.

This guy is like, "Hey buddy, I've got VTP Rev 1302."

Your corporate switch is like, "Great, I'm at 2.

You know, it's like, you're way better."

So, the way VTP work is it's not like, "Let's talk, let's kind of merge our VLANs

to get"-- no, that's not how it works.

He's like, "1302 says there is no VLAN 20.

1302 says, there is no VLAN 10, 1302 has told me the only VLAN that there is, is VLAN 100."

And like I said, it's very fast, bam!

Bam! All your VLANs are gone in your entire enterprise, all replaced by VLAN 100.

You know what that looks like?

You walked in to the IT room and you see the switches and they've all turned amber.

Every light on them totally has gone from green and flicking and happy to this amber

like death-like state and usually, the IT person passes

out when they see it 'cause the entire network is not.

What has happened is it eliminated VLANs 10 and 20, but all the ports are assigned to those.

So it's not like the ports are like, "Oh, well, I guess our VLAN went away.

Let's all go over to VLAN 100 now."

They don't do that.

They're like, "No, I'm still in VLAN 20 and VLAN 20 doesn't exist so I'm going

to turn myself off, and I'm going to put myself in a disabled state."

So essentially, your entire network goes down.

Now, I know what you might be thinking.

You're like, but wait a sec, didn't you say I erased the switch, you know?

If you're speaking for my life, didn't you tell me

that I erased the switch before I bring it in?

Yes, I did.

Because VTP revisions survive configuration resets.

VLANs survive configuration resets.

So this little story could happen.

But now, let me add in a little reality to it.

Well, first of, it has happened a lot.

It completely takes on the network.

And the problem is, you know, people-- first of, it takes somebody some time to figure

out what time-- I mean, you walk in, the entire thing is down.

You're not thinking, "Oh, my VLANs must be gone."

You're thinking virus, worm, outbreak, failure.

You know, you're on the phone you're like, "What do I do?"

You're not even thinking straight when something like this occurs, I mean, everybody is yelling.

You know, company is like, "We're sending everybody home

for the day, losses," it's not good.

So, this is one of those not good days.

So by time you finally do figure out, you're like, "Oh man, my VLANs are gone."

A common fix is you take a switch off, you restore the configuration from backup,

you're like, "Okay, well let's put the old VLANs back on," and you reconnect it.

What happen as soon as you reconnect?

Bam! Revision 1302 comes in and destroys you and deletes your VLAN again.

The only way that you're going to get it back is to manually add your VLANs back in.

So you go, "Okay, VLAN 10 exists."

Now, we're up to Rev 1303 and now that replicates up, VLAN 20 exists,

1304 and we start getting our VTP Revs back up.

So, now let me add in now a little protection.

The way VTP works is through a common domain name.

A lot of companies make it their company name like Intel, they'll have the VTP domain Intel.

So, if this guy comes in and doesn't have the same VTP domain name as the rest

of the switches, then his revision will be ignored.

So, I know you're like kind of go, "Okay, that's a little better."

Well, here's where it usually happens.

This-- By the way VTP outages are-- they are common.

You know, if-- give me a group of, you know, 10 Cisco people that have worked for, you know,

10 to 15 years in the field and I guarantee you, probably two or three

of them have seen a complete network takedown from VTP.

So, where it usually happens is in the lab environment.

You got the company lab, right, where the company buys some stuff for people to play

with so that they can do testing.

They can do experiment without messing with the production environment.

Well, what ends up happening is, you know, there's a switch in the lab that seems

to be totally functional, totally fine that we've just been playing with for a long time.

In a crisis, the company is like, "Oh man, we're out of switches

and we just hired three more people.

Do we have any spares anywhere?"

You know, again, made for TV movie, slow motion music comes as somebody walks in the lab

and brings out this lab switch which has a higher VTP Rev than the corporate network

and happens to mirror the config in many ways as the corporate network

but maybe doesn't have the same VLAN numbers and click.

You know, that's where it wipes out the entire network.

So, that's VTP.

It's kind of like, "Yeah, that was a cool idea," but I will tell you Cisco now,

they have changed their recommendation.

Cisco will tell you in big bold red letters, "Don't use it."

Despite Cisco's recommendations, many people still do use VTP 'cause it is really handy.

And as long as you are very careful, it works well.

Now, like I said, for every 10 Cisco people, there'tr two or three of them

that have seen a complete network outage, but that means there are seven or eight of them

that are like, "Yeah, it's totally fine."

So, when you're using VTP, there are three modes that it can be in.

A Cisco switch can be a VTP server which is the default.

When you pull it out of the box, every Cisco switch has a VTP server.

And that means it has the power to create VLANs, to delete VLANs, to rename VLANs,

it can do all that stuff and then send the updates to all the other servers.

Now, you can have all your switches, be servers if you want to.

And that just means you can change your VLAN configuration from any switch.

Now, if you are going to use VTP, what Cisco recommends is saying, you have one server,

meaning one place that you can change VLANs from and all the rest

of them are configured as clients.

So the client switches you can't update VLANs.

They will only accept updates and send updates, you know, if, you know, for instance,

there's a server down here or something like that, he'll accept updates

and he'll send updates to the other switches.

But you can't go in there and change VLANs, delete VLANs.

If you try to, if you log on to that switch and you're like, "Okay, add VLAN 20."

It's going to be like, "Sorry, you're a VTP client.

You can't do that."

Now there-- you might be like, "Well, this seems safe.

How can I-- cause problem?"

Well, a lot of times, we are our own worst enemies, right?

Because you log in to that client switch and like, "Oh, man, I got to add VLAN 20,"

and you get the message, "I'm sorry, this is a VTP client."

And you're like, "Well buddy, it's one command."

"No you're not.

You're a server."

You type in-- it's a literally command, it's a VTP mode server and poof!

Now, I can add my VLAN without trying to figure out where in the network my VTP server is.

So, good intention but a lot of times, our own self-discipline gets away from us.

Transparent mode, now, the Cisco recommended mode.

VTP transparent mode essentially means I am not using VTP.

Truth be told, the way Cisco switches work is there is no way to--

you know, I'll put in quotes, turn off VTP.

Like you can go in there and say, "No VTP" and stop running it.

But you can go in and say, "I'm running VTP Transparent mode."

And what that means is, now, every single switch, if it's transparent,

every switch can change VLANs, it can modify VLANs, it can delete VLANs,

it can do whatever we want, but I'm not ever going to tell that VLAN information

to anybody else, meaning I'm not really participating.

Now, if somebody sends me a VTP update, if maybe somebody else is running VTP, I'll be like,

"Hey, thanks, I'll forward that on to any other switches that need it.

But you know what, I'm not looking at it.

I'm a transparent switch."

You know, think of the words, "I'm transparent.

I don't exist to you," or we can add some movie drama, "I'm dead to you."

You know, all the switches that are transparent totally ignore it, but it is worthwhile knowing

like if I have a VTP server here and a VTP server here and he's sending an update,

the transparent switch will ignore it and yet still pass it over that server.

One more neat feature associated with VTP.

It's the concept of VLAN pruning.

What this allows you to do is stop VLANs from crossing links where they don't belong.

So, let's say, you've got this environment and setup

with three switches, you create three VLANs.

We'll just for now call them VLAN green, VLAN blue, and VLAN red,

you know, which match up to some number.

So those are all created.

Those using VTP automatically replicate and now appear on all the switches.

However, on this bottom switch, you only assign computers to the red and blue VLAN.

You don't assign anything to the green VLAN.

Well, what VTP will do is have this switch report back and say, "Hey,

green VLAN, we don't need it here."

There're no ports that belong here.

So, the switch-- this switch automatically prunes green traffic from coming down here.

So if a green computer sends a broadcast that will come down here but then stop.

It doesn't continue on and like you see right here,

stops all the unnecessary broadcast traffic from crossing the links.

Well, that's great, but here's the funny thing, Cisco with their design and like, yeah,

you should have one server and then multiple clients.

Well, VTP pruning only works if you have all VTP servers.

Like if this guy is a VTP client, you won't participate in VTP pruning.

So, a little ironic with the design there.

Now some of you might be thinking, "Well, if we can't use VTP to do this, then how do we do it?"

Manually. You go back to this-- the manual model.

That's how everybody else does it.

You go to every switch that needs the VLAN, you manually create it,

you manually add it to the trunk and that's okay.

I mean, if everything was auto, we wouldn't really be paid for anything.

And I will tell you and this is kind of a rule in general.

With anything auto in network technology, mantra is you auto not use it

because it leaves too much to chance.

Anything that it's kind of like, "Oh, don't worry, it just kind of figures it out for you."

I'm always like, "Really?

All the time, every time, 100 percent at time it figures it out for me," I'd feel better.

I would just feel better if I could say, "Okay, that trunk has this, this, and this VLAN."

That would just make me feel better to manually type that in because again,

it's not that much work and it impacts so much.

So I would love for it to come back and say, "Okay,

if it's working, I look at them like that's good.

It's all me.

I know exactly"-- that sounded bad.

"It's all me, yeah."

But no, if it's working I'm like, you know, "I know exactly what that configures.

I have backups that config, I know what it looks like.

It's not just like, "Well, it just kind of happened.

They just kind of figured it out."

And then if something goes wrong, I'm like, "What's going wrong?

You know, what auto mechanism did this to me?"

So, that's the overview of why we don't use VTP anymore.

So, to summarize, we saw in this Nugget how the trunks really work and that's using

that 802.1Q protocol, industry standard protocol that works VLANs across the board.

We saw the VLAN lingo of Native VLAN so we know what that concept is.

It's essentially the untagged VLAN or the untagged I should say number when we're working

on trunks-- my little [inaudible] connecting it.

When we're working on trunks, if I send something without a tag it belongs

on that Native VLAN, and then of course we discuss VTP and all its glory.

I hope this has been informative for you and I'd like to thank you for viewing.

Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.