Jeremy’s IT Lab lecture video:

Day 19 - DTP & VTP


Commands


DTP and VTP are not on the CCNA exam topics anymore, but basic questions about them could be present on the exam.


DTP & VTP Info

Dynamic Trunking Protocol (DTP)

DTP is a Cisco proprietary protocol that allows Cisco switches to dynamically change their interface mode (access or trunk) without manual configuration.

  • DTP is enabled by default on all Cisco switch interfaces.
  • For security, it’s recommended to disable DTP and to manually configure switches.

Dynamic Trunking Protocol Modes

1. Dynamic Desirable

  • A switchport in dynamic desirable mode will actively try to form a trunk with other Cisco switches.
  • It will form a trunk if connected to another switchport in the following modes:
    1. switchport mode trunk
    2. switchport mode dynamic desirable
    3. switchport mode dynamic auto
  • Otherwise, it’ll be a static access port.

2. Dynamic Auto

  • A switchport in dynamic auto mode won’t actively try to form a trunk with other Cisco switches, however, it will form a trunk if the switch connected to it is actively trying to form a trunk.
  • It will form a trunk if connected to a switchport in the following modes:
    1. switchport mode trunk
    2. switchport mode dynamic desirable
  • Otherwise, it’ll be a static access port.

What are static access ports?

Static access port means an access port that belongs to a single VLAN that doesn’t change (unless you configure a different VLAN).

DTP when connected to hosts

DTP will not form a trunk with end hosts (PCs, routers, and etc.), the switchport will be in access mode.

Administrative ModeTrunkDynamic DesirableAccessDynamic Auto
TrunkTrunkTrunkN/ATrunk
Dynamic DesirableTrunkTrunkAccessTrunk
AccessN/AAccessAccessAccess
Dynamic AutoTrunkTrunkAccessAccess

DTP - Default Settings

On older switches, switchport mode dynamic desirable is the default administrative mode.

On newer switches, switchport mode dynamic auto is the default administrative mode.

  • Switches that support 802.1Q and ISL trunk encapsulations can also use DTP to negotiate the encapsulation method they will use.
    • This negotiation is enabled by default, as the default trunk encapsulation mode is: switchport trunk encapsulation negotiate
    • ISL is favored over 802.1Q, so if both switches support ISL it’ll be automatically selected.
    • DTP frames are sent in the VLAN1 when using ISL, and they’re sent in the native VLAN when using 802.1Q (the default native VLAN is VLAN1 on switches).

DTP negotiation can be disabled through:

  1. The switchport nonegotiate command
  2. Configuring an access port with switchport mode access

VLAN Trunking Protocol (VTP)

VLAN Trunking Protocol (VTP) is a protocol that allows you to configure VLANs on a central VTP server switch, and other switches (VTP clients) will synchronize their VLAN database to the server.

  • For security, it’s recommended to disable VTP and to manually configure switches.
  • Switches operate in VTP server mode by default.
  • There are three VTP versions: 1, 2, 3.
  • There are three VTP modes:
    1. Server
      • Can add/modify/delete VLANs.
      • Stores the VLAN database in non-volatile RAM (NVRAM).
      • Will increase the revision number every time a VLAN is added/modified/deleted.
      • Will advertise the latest version of the VLAN database on trunk interfaces, and the VTP clients will sync their VLAN database to it.
      • VTP servers also function as VTP clients, where a VTP server will sync to another VTP server with a higher revision number.
    2. Client
      • Cannot add/modify/delete VLANs.
      • Does not store the VLAN database in NVRAM. (In VTP3, it does).
      • Will sync their VLAN database to the server with the highest revision number in their VTP domain.
      • Will advertise their VLAN database, and forward VTP advertisements over their trunk ports.
    3. Transparent
      • Does not participate in the VTP domain.
      • Can add/modify/delete VLANs, but they won’t be advertised.
      • Stores the VLAN database in non-volatile RAM (NVRAM).
      • Will forward VTP advertisements in the same domain as it.

Higher revision number

If a switch receives a VTP advertisement in the same VTP domain with a higher revision number, it will update its VLAN database to match.

Resetting the VTP Revision Number

Resetting the revision number to zero can be done in two ways:

  1. Changing the VTP domain to an unused domain.
  2. Changing the VTP mode to transparent.

VTP domain null & Automatic VTP domain joining

If a switch with no VTP domain (domain null) receives a VTP advertisement with a VTP domain name, it’ll automatically join that VTP domain.

Jeremy’s IT Lab előadásvideó:

19. Nap - DTP & VTP


Parancsok


A DTP és a VTP már nem szerepel a CCNA vizsgakövetelmények között, de alapvető kérdések még előfordulhatnak velük kapcsolatban a vizsgán.


DTP & VTP Információk

Dynamic Trunking Protocol (DTP)

A DTP egy Cisco saját fejlesztésű protokoll, amely lehetővé teszi a Cisco switchek számára, hogy dinamikusan váltsák interfész módjukat (access vagy trunk) manuális konfiguráció nélkül.

  • A DTP alapértelmezés szerint engedélyezve van minden Cisco switch interfészen.
  • Biztonsági okokból ajánlott letiltani a DTP-t, és manuálisan konfigurálni a switcheket.

Dynamic Trunking Protocol Módok

1. Dynamic Desirable

  • A dynamic desirable módban lévő switchport aktívan próbál trunk kapcsolatot létrehozni más Cisco switchekkel.
  • Trunk kapcsolatot létesít, ha az alábbi módokban lévő switchporthoz csatlakozik:
    1. switchport mode trunk
    2. switchport mode dynamic desirable
    3. switchport mode dynamic auto
  • Egyébként statikus access portként működik.

2. Dynamic Auto

  • A dynamic auto módban lévő switchport nem próbál aktívan trunk kapcsolatot kiépíteni, de trunkot létesít, ha a csatlakozó switch aktívan próbál trunk kapcsolatot kialakítani.
  • Trunk kapcsolatot létesít, ha az alábbi módokban lévő switchporthoz csatlakozik:
    1. switchport mode trunk
    2. switchport mode dynamic desirable
  • Egyébként statikus access portként működik.

Mik azok a statikus access portok?

A statikus access port olyan access portot jelent, amely egyetlen VLAN-hoz tartozik, és ez nem változik (hacsak manuálisan nem konfigurál egy másik VLAN-t).

DTP gazdagépekhez (hostokhoz) kapcsolódva

A DTP nem hoz létre trunk kapcsolatot a végfelhasználói hostokkal (PC-k, routerek stb.), a switchport access módban marad.

Adminisztratív módTrunkDynamic DesirableAccessDynamic Auto
TrunkTrunkTrunkN/ATrunk
Dynamic DesirableTrunkTrunkAccessTrunk
AccessN/AAccessAccessAccess
Dynamic AutoTrunkTrunkAccessAccess

DTP - Alapértelmezett Beállítások

A régebbi switcheken a switchport mode dynamic desirable az alapértelmezett adminisztratív mód.

Az újabb switcheken a switchport mode dynamic auto az alapértelmezett adminisztratív mód.

  • A 802.1Q és ISL trunk enkapszulációkat támogató switchek a DTP segítségével is egyeztethetik a használni kívánt enkapszulációs eljárást.
    • Ez az egyeztetés alapértelmezés szerint engedélyezve van, mivel az alapértelmezett trunk enkapszulációs mód a következő: switchport trunk encapsulation negotiate
    • Az ISL előnyben részesül a 802.1Q-val szemben, így ha mindkét switch támogatja az ISL-t, az automatikusan kiválasztásra kerül.
    • A DTP frame-ek ISL esetén a VLAN 1-ben, míg 802.1Q esetén a native VLAN-ban kerülnek elküldésre (az alapértelmezett native VLAN a VLAN 1 a switcheken).

A DTP egyeztetés letiltható:

  1. A switchport nonegotiate paranccsal
  2. Egy access port konfigurálásával a switchport mode access paranccsal

VLAN Trunking Protocol (VTP)

A VLAN Trunking Protocol (VTP) egy olyan protokoll, amely lehetővé teszi a VLAN-ok konfigurálását egy központi VTP szerver switchen, és a többi switch (VTP kliens) szinkronizálja VLAN adatbázisát a szerverrel.

  • Biztonsági okokból ajánlott letiltani a VTP-t, és manuálisan konfigurálni a switcheket.
  • A switchek alapértelmezés szerint VTP szerver módban működnek.
  • Három VTP verzió létezik: 1, 2, 3.
  • Három VTP mód létezik:
    1. Server
      • Képes VLAN-okat hozzáadni / módosítani / törölni.
      • A VLAN adatbázist nem-felejtő memóriában (NVRAM) tárolja.
      • Minden alkalommal növeli a revíziós számot (revision number), amikor egy VLAN hozzáadásra / módosításra / törlésre kerül.
      • A trunk interfészeken hirdeti a VLAN adatbázis legújabb verzióját, és a VTP kliensek ehhez szinkronizálják VLAN adatbázisukat.
      • A VTP szerverek VTP kliensként is funkcionálnak, vagyis egy VTP szerver szinkronizál egy másik VTP szerverhez, ha annak magasabb a revíziós száma.
    2. Client
      • Nem képes VLAN-okat hozzáadni / módosítani / törölni.
      • Nem tárolja a VLAN adatbázist az NVRAM-ban (a VTP3-ban viszont igen).
      • Szinkronizálja a VLAN adatbázisát a VTP domainjében lévő legmagasabb revíziós számmal rendelkező szerverhez.
      • Hirdeti a saját VLAN adatbázisát, és továbbítja a VTP hirdetéseket a trunk portjain keresztül.
    3. Transparent
      • Nem vesz részt a VTP domainben.
      • Hozzáadhat / módosíthat / törölhet helyi VLAN-okat, de ezek nem kerülnek hirdetésre.
      • A VLAN adatbázist az NVRAM-ban tárolja.
      • Továbbítja a VTP hirdetéseket a vele azonos domainben lévő eszközök felé.

Magasabb revíziós szám (revision number)

Ha egy switch ugyanabban a VTP domainben magasabb revíziós számmal rendelkező VTP hirdetést kap, frissíti a VLAN adatbázisát, hogy megegyezzen azzal.

A VTP Revíziós Szám Visszaállítása (Reset)

A revíziós szám nullára való visszaállítása kétféleképpen történhet:

  1. A VTP domain módosítása egy nem használt domain névre.
  2. A VTP mód átállítása transparent módra.

VTP domain null & Automatikus csatlakozás VTP domainhez

Ha egy VTP domain nélküli switch (domain értéke null) olyan VTP hirdetést kap, amely tartalmaz egy VTP domain nevet, automatikusan csatlakozik ahhoz a VTP domainhez.