How does vtp use the vtp password




















If you do configure a domain password, all domain switches must share the same password and you must configure the password on each switch in the management domain. Switches without a password or with the wrong password reject VTP advertisements.

If you configure a VTP password for a domain, a switch that is booted without a VTP configuration does not accept VTP advertisements until you configure it with the correct password. After the configuration, the switch accepts the next VTP advertisement that uses the same password and domain name in the advertisement.

If you are adding a new switch to an existing network with VTP capability, the new switch learns the domain name only after the applicable password has been configured on it. When you enable version 2 on a switch, all of the versioncapable switches in the domain enable version 2. If there is a version 1-only switch, it does not exchange VTP information with switches that have version 2 enabled. You must configure these VLANs manually on each device. When you configure VTP, you must configure a trunk port so that the switch can send and receive VTP advertisements to and from other switches in the domain.

For more information about the command, see the command reference for this release. You receive an error message, and the configuration is not allowed. You must manually configure these VLANs on each device. Save this configuration to the startup configuration so that the switch starts in VTP transparent mode.

If the switch is then powered off, it resets the VTP configuration to the default. Configure the VTP administrative-domain name. The name can be 1 to 32 characters. All switches operating in VTP server or client mode under the same administrative responsibility must be configured with the same domain name.

This command is optional for modes other than server mode. VTP server mode requires a domain name. If the switch has a trunk connection to a VTP domain, the switch learns the domain name from the VTP server in the domain. Optional Set the password for the VTP domain. The password can be 8 to 64 characters. If you configure a VTP password, the VTP domain does not function properly if you do not assign the same password to each switch in the domain.

Note Only VTP mode and domain name are saved in the switch running configuration and can be copied to the startup configuration file. When you configure a domain name, it cannot be removed; you can only reassign a switch to a different domain.

To return a switch in another mode to VTP server mode, use the no vtp mode global configuration command. To return the switch to a no-password state, use the no vtp password global configuration command. If you configure a takeover by configuring a VTP primary server, you are prompted to reenter the password. The secret password must contain 32 hexadecimal characters.

To clear the password, enter the no vtp password global configuration command. Change the operational state of a switch from a secondary server the default to a primary server and advertise the configuration to the domain. If the switch password is configured as hidden , you are prompted to reenter the password.

This is the default. If you do not enter force , you are prompted for confirmation before the takeover. This example shows how to configure a switch as the primary server for the VLAN database the default when a hidden or secret password was configured:. To enable VTP version 3, you must manually configure it on each switch.

To return to the default VTP version 1, use the no vtp version global configuration command. Pruning increases available bandwidth by restricting flooded traffic to those trunk links that the traffic must use to access the destination devices. By default, pruning is disabled. You need to enable pruning on only one switch in VTP server mode.

To disable VTP pruning, use the no vtp pruning global configuration command. In VTP version 3, you must manually enable pruning on each switch in the domain. By default, VLANs 2 through are pruning-eligible on trunk ports. You can enable VTP only on ports that are in trunk mode. Incoming and outgoing VTP traffic are blocked, not forwarded. To disable VTP on the interface, use the no vtp interface configuration command. Write down the domain name. Write down the configuration revision number.

Continue with the next steps to reset the switch configuration revision number. Change the domain name from the original one displayed in Step 1 to a new name. The VLAN information on the switch is updated and the configuration revision number is reset to 0. You return to privileged EXEC mode. Optional Verify that the domain name is the same as in Step 1 and that the configuration revision number is 0.

After resetting the configuration revision number, add the switch to the VTP domain. You can also display statistics about the advertisements sent and received by the switch. Display information about all VTP version 3 devices in the domain. Conflicts are VTP version 3 devices with conflicting primary servers. The show vtp devices command does not display information when the switch is in transparent or off mode. Display VTP status and configuration for all interfaces or the specified interface.

Display the VTP password. While the use of VTP is restricted to Cisco devices, is has been configured on many networks since its creation. Many modern networks are moving away from the use of global VLANs on the network in exchange for routing at the access layer verus switching. Knowing the VTP concepts are still quite important as it has been deployed in a number of networks and should be familiar to any good Cisco network engineer.

I would like to receive exclusive offers and hear about products from Pearson IT Certification and its family of brands. I can unsubscribe at any time. Pearson Education, Inc.

This privacy notice provides an overview of our commitment to privacy and describes how we collect, protect, use and share personal information collected through this site. Please note that other Pearson websites and online products and services have their own separate privacy policies. To conduct business and deliver products and services, Pearson collects and uses personal information in several ways in connection with this site, including:.

For inquiries and questions, we collect the inquiry or question, together with name, contact details email address, phone number and mailing address and any other additional information voluntarily submitted to us through a Contact Us form or an email. We use this information to address the inquiry and respond to the question. We use this information to complete transactions, fulfill orders, communicate with individuals placing orders or visiting the online store, and for related purposes.

Pearson may offer opportunities to provide feedback or participate in surveys, including surveys evaluating Pearson products, services or sites. Participation is voluntary. Pearson collects information requested in the survey questions and uses the information to evaluate, support, maintain and improve products, services or sites; develop new products and services; conduct educational research; and for other purposes specified in the survey.

Occasionally, we may sponsor a contest or drawing. Participation is optional. Pearson collects name, contact information and other information specified on the entry form for the contest or drawing to conduct the contest or drawing. Pearson may collect additional personal information from the winners of a contest or drawing in order to award the prize and for tax reporting purposes, as required by law.

If you have elected to receive email newsletters or promotional mailings and special offers but want to unsubscribe, simply email information informit. On rare occasions it is necessary to send out a strictly service related announcement. For instance, if our service is temporarily suspended for maintenance we might send users an email. Generally, users may not opt-out of these communications, though they can deactivate their account information.

However, these communications are not promotional in nature. We communicate with users on a regular basis to provide requested services and in regard to issues relating to their account we reply via email or phone in accordance with the users' wishes when a user submits their information through our Contact Us form. Pearson automatically collects log data to help ensure the delivery, availability and security of this site.

We use this information for support purposes and to monitor the health of the site, identify problems, improve service, detect unauthorized access and fraudulent activity, prevent and respond to security incidents and appropriately scale computing resources.

Pearson may use third party web trend analytical services, including Google Analytics, to collect visitor information, such as IP addresses, browser types, referring pages, pages visited and time spent on a particular site.

While these analytical services collect and report information on an anonymous basis, they may use cookies to gather web trend information. The information gathered may enable Pearson but not the third party web trend services to link information with application and system log data. Pearson uses this information for system administration and to identify problems, improve service, detect unauthorized access and fraudulent activity, prevent and respond to security incidents, appropriately scale computing resources and otherwise support and deliver this site and its services.

After everything is configured, the new setup should be verified to ensure that the connections work properly. Version 1 is the default VTP version on all switches and is typically used. No VTP version configuration is needed if you will be running version 1. Version 1 and version 2 are not compatible, so it is an all-or-nothing configuration for your switches. However, if all your switches are VTP version 2 compatible, changing one switch changes all of them.

Be careful if you are not sure whether all your switches are version 2 compatible. This means that all switches must be capable of running version 2. If a VTP advertisement is received and has an unrecognized type-length-value, the version 2 VTP switches will still propagate the changes through their trunk links.

Transparent mode Switches can run in transparent mode, which means that they only forward messages and advertisements, not add them to their own database.

In version 1, the switch checks the domain name and version before forwarding, but in version 2, the switches forward VTP messages without checking the version. Consistency checks Consistency checks are run when an administrator enters new information in the switches, either with the CLI or other management software.

A switch checks the digest on a VTP message, and if it is correct, no consistency check is made. To configure VTP version 2 on a series, use the set vtp v2 enable command:. Both versions are supported, as shown next:. VLAN database editing buffer manipulation commands: abort Exit mode without applying the changes apply Apply current changes and bump revision number exit Apply changes, bump revision number, and exit mode no Negate a command or set its defaults reset Abandon current changes and reread current database show Show database information vlan Add, delete, or modify values associated with a single VLAN vtp Perform VTP administrative functions.

Configuring the Domain After you decide which version to run, set the VTP domain name and password on the first switch. The VTP name can be up to 32 characters long. The password is a minimum of 8 characters and a maximum of 64 on the , and although truncated to 64 characters on the IOS-based switches, it has no minimum value. Configuring the VTP Mode Create your first switch as a server, and then create the connected switches as clients, or whatever you decided to configure them as.

The show vtp domain command shows you the domain name, mode, and pruning information:. It also shows configuration errors if detected:. If a switch is inserted into the domain and has incorrect VLAN information, the result could be a VTP database propagated throughout the internetwork with false information. Perform a clear config all to remove any existing VLAN configuration on a set-based switch.

If it has, you should erase the startup-config after saving it to a TFTP server or as a text file. Configure the switch to perform the mode of VTP that it will participate in.

VTP Pruning To preserve bandwidth, you can configure the VTP to reduce the number of broadcasts, multicasts, and other unicast packets. This is called VTP pruning. VTP restricts broadcasts to only trunk links that must have the information. If a trunk link does not need the broadcasts, the information is not sent.

VTP pruning is disabled by default on all switches. VLAN 1 can never prune. Use the following command to clear the unwanted VLANs:.



0コメント

  • 1000 / 1000