Cisco VLAN-Trunking Protocol

Aus xinux.net
Zur Navigation springen Zur Suche springen

Was ist VTP

  • Synchronistation der Vlans über Switches hinweg.
  • Verwaltungsaufwand wird reduziert
  • Kann zu Fehlern führen
  • Austausch von
    • Vlan ID
    • Vlan Name
  • Kein Austausch von
    • Vlan Inetrface Zuordnungen
  • VTP MODI
    • VTP Server
    • VTP Client
    • VTP Transparent

Anzeigen Vlans?

  • switch-gelb#show vlan brief
VLAN Name                             Status    Ports
---- -------------------------------- --------- -------------------------------
1    default                          active    Fa1/0/1, Fa1/0/2, Fa1/0/3, Fa1/0/6, Fa1/0/7, Fa1/0/8, Fa1/0/12
                                                Fa1/0/18, Fa1/0/19, Fa1/0/20, Fa1/0/21, Fa1/0/22, Fa1/0/23
                                                Fa1/0/24, Fa1/0/25, Fa1/0/26, Fa1/0/27, Fa1/0/28, Fa1/0/29
                                                Fa1/0/30, Fa1/0/31, Fa1/0/32, Fa1/0/33, Fa1/0/34, Fa1/0/35
                                                Fa1/0/36, Fa1/0/37, Fa1/0/38, Fa1/0/39, Fa1/0/40, Fa1/0/41
                                                Fa1/0/42, Fa1/0/43, Fa1/0/44, Fa1/0/45, Fa1/0/46, Fa1/0/47
                                                Gi1/0/1, Gi1/0/2, Gi1/0/3, Gi1/0/4
10   office                           active    Fa1/0/4, Fa1/0/5
20   work                             active    Fa1/0/9, Fa1/0/10, Fa1/0/11
30   labor                            active    Fa1/0/13, Fa1/0/14, Fa1/0/15, Fa1/0/16, Fa1/0/17
1002 fddi-default                     act/unsup 
1003 token-ring-default               act/unsup 
1004 fddinet-default                  act/unsup 
1005 trnet-default                    act/unsup 
  • switch-rot#show vlan brief
VLAN Name                             Status    Ports
---- -------------------------------- --------- -------------------------------
1    default                          active    Gi1/0/1, Gi1/0/2, Gi1/0/15
                                                Gi1/0/16, Gi1/0/17, Gi1/0/18
                                                Gi1/0/19, Gi1/0/20, Gi1/0/21
                                                Gi1/0/22, Gi1/0/23, Gi1/0/25
                                                Gi1/0/26, Gi1/0/27, Gi1/0/28
10   office                           active    Gi1/0/3, Gi1/0/4, Gi1/0/5
                                                Gi1/0/6
20   work                             active    Gi1/0/7, Gi1/0/8, Gi1/0/9
                                                Gi1/0/10
30   labor                            active    Gi1/0/11, Gi1/0/12, Gi1/0/13
                                                Gi1/0/14
1002 fddi-default                     act/unsup 
1003 token-ring-default               act/unsup 
1004 fddinet-default                  act/unsup 
1005 trnet-default                    act/unsup

Löschen der Vlans

  • switch-rot#configure terminal
Enter configuration commands, one per line.  End with CNTL/Z.
  • switch-rot(config)#no vlan 10
  • switch-rot(config)#no vlan 20
  • switch-rot(config)#no vlan 30
  • switch-rot(config)#do show vlan brief
VLAN Name                             Status    Ports
---- -------------------------------- --------- -------------------------------
1    default                          active    Gi1/0/1, Gi1/0/2, Gi1/0/15
                                                Gi1/0/16, Gi1/0/17, Gi1/0/18
                                                Gi1/0/19, Gi1/0/20, Gi1/0/21
                                                Gi1/0/22, Gi1/0/23, Gi1/0/25
                                                Gi1/0/26, Gi1/0/27, Gi1/0/28
1002 fddi-default                     act/unsup 
1003 token-ring-default               act/unsup 
1004 fddinet-default                  act/unsup 
1005 trnet-default                    act/unsup 

Anzeigen des VTP Status

  • switch-gelb#show vtp status
VTP Version                     : running VTP1 (VTP2 capable)
Configuration Revision          : 10
Maximum VLANs supported locally : 1005
Number of existing VLANs        : 8
VTP Operating Mode              : Server
VTP Domain Name                 : 
VTP Pruning Mode                : Disabled
VTP V2 Mode                     : Disabled
VTP Traps Generation            : Disabled
MD5 digest                      : 0x0F 0x90 0x36 0xFF 0x8C 0x7D 0x06 0x59 
Configuration last modified by 192.168.240.154 at 2-1-16 10:31:50
Local updater ID is 192.168.240.154 on interface Vl1 (lowest numbered VLAN interface found)

Vtp domain ändern

  • switch-gelb(config)#vtp domain vtp-xinux
Changing VTP domain name from NULL to vtp-xinux
  • switch-gelb(config)#do show vtp status
VTP Version                     : running VTP1 (VTP2 capable)
Configuration Revision          : 10
Maximum VLANs supported locally : 1005
Number of existing VLANs        : 8
VTP Operating Mode              : Server
VTP Domain Name                 : vtp-xinux
VTP Pruning Mode                : Disabled
VTP V2 Mode                     : Disabled
VTP Traps Generation            : Disabled
MD5 digest                      : 0xF9 0xF2 0x8D 0xB0 0xAA 0x3C 0x67 0x7D 
Configuration last modified by 192.168.240.154 at 2-1-16 10:31:50
Local updater ID is 192.168.240.154 on interface Vl1 (lowest numbered VLAN interface found)

Vtp domain wird übernommen wenn sie leer war

  • switch-rot#show vtp status
VTP Version capable             : 1 to 3
VTP version running             : 1
VTP Domain Name                 : vtp-xinux
VTP Pruning Mode                : Disabled
VTP Traps Generation            : Disabled
Device ID                       : 0012.d9a3.4400
Configuration last modified by 192.168.240.154 at 2-1-16 10:31:50
Local updater ID is 192.168.240.153 on interface Vl1 (lowest numbered VLAN interface found)

Feature VLAN:
--------------
VTP Operating Mode                : Server
Maximum VLANs supported locally   : 1005
Number of existing VLANs          : 8
Configuration Revision            : 10
MD5 digest                        : 0xF9 0xF2 0x8D 0xB0 0xAA 0x3C 0x67 0x7D 
                                    0x29 0xA6 0x7A 0x08 0x66 0xC5 0xDE 0x6C 

Die Vlans sind wieder da

  • switch-rot#show vlan brief
VLAN Name                             Status    Ports
---- -------------------------------- --------- -------------------------------
1    default                          active    Gi1/0/1, Gi1/0/2, Gi1/0/15
                                                Gi1/0/16, Gi1/0/17, Gi1/0/18
                                                Gi1/0/19, Gi1/0/20, Gi1/0/21
                                                Gi1/0/22, Gi1/0/23, Gi1/0/25
                                                Gi1/0/26, Gi1/0/27, Gi1/0/28
10   office                           active    Gi1/0/3, Gi1/0/4, Gi1/0/5
                                                Gi1/0/6
20   work                             active    Gi1/0/7, Gi1/0/8, Gi1/0/9
                                                Gi1/0/10
30   labor                            active    Gi1/0/11, Gi1/0/12, Gi1/0/13
                                                Gi1/0/14
1002 fddi-default                     act/unsup 
1003 token-ring-default               act/unsup 
1004 fddinet-default                  act/unsup 
1005 trnet-default                    act/unsup 

vlan anlegen

  • switch-rot#configure terminal
Enter configuration commands, one per line.  End with CNTL/Z.
  • switch-rot(config)#vlan 40
  • switch-rot(config-vlan)#name tante-frieda
  • switch-rot(config-vlan)#end

automatisch übernahme

  • switch-gelb#show vlan brief
VLAN Name                             Status    Ports
---- -------------------------------- --------- -------------------------------
1    default                          active    Fa1/0/1, Fa1/0/2, Fa1/0/3, Fa1/0/6, Fa1/0/7, Fa1/0/8, Fa1/0/12
                                                Fa1/0/18, Fa1/0/19, Fa1/0/20, Fa1/0/21, Fa1/0/22, Fa1/0/23
                                                Fa1/0/24, Fa1/0/25, Fa1/0/26, Fa1/0/27, Fa1/0/28, Fa1/0/29
                                                Fa1/0/30, Fa1/0/31, Fa1/0/32, Fa1/0/33, Fa1/0/34, Fa1/0/35
                                                Fa1/0/36, Fa1/0/37, Fa1/0/38, Fa1/0/39, Fa1/0/40, Fa1/0/41
                                                Fa1/0/42, Fa1/0/43, Fa1/0/44, Fa1/0/45, Fa1/0/46, Fa1/0/47
                                                Gi1/0/1, Gi1/0/2, Gi1/0/3, Gi1/0/4
10   office                           active    Fa1/0/4, Fa1/0/5
20   work                             active    Fa1/0/9, Fa1/0/10, Fa1/0/11
30   labor                            active    Fa1/0/13, Fa1/0/14, Fa1/0/15, Fa1/0/16, Fa1/0/17
40   tante-frieda                     active    
1002 fddi-default                     act/unsup 
1003 token-ring-default               act/unsup 
1004 fddinet-default                  act/unsup 
1005 trnet-default                    act/unsup 

Configuration Revision wurde erhöht

switch-gelb#show vtp status

VTP Version                     : running VTP1 (VTP2 capable)
Configuration Revision          : 11
Maximum VLANs supported locally : 1005
Number of existing VLANs        : 9
VTP Operating Mode              : Server
VTP Domain Name                 : vtp-xinux
VTP Pruning Mode                : Disabled
VTP V2 Mode                     : Disabled
VTP Traps Generation            : Disabled
MD5 digest                      : 0xEE 0x2F 0x95 0xD3 0x1C 0x32 0xB8 0x00 
Configuration last modified by 192.168.240.153 at 3-1-93 04:57:01
Local updater ID is 192.168.240.154 on interface Vl1 (lowest numbered VLAN interface found)

Konfigurationsnummer

Der Switch mit der höheren Konfigurationsnummer gewinnt. Wenn sie in der VTP Domain sind.

VTP mode Client

  • switch-rot#configure terminal
Enter configuration commands, one per line.  End with CNTL/Z.
  • switch-rot(config)#vtp mode client
Setting device to VTP Client mode for VLANS.

Keine änderung der Vlans mehr möglich

  • switch-rot(config)#vlan 60
VTP VLAN configuration not allowed when device is in CLIENT mode.

Änderungen nur vom Server möglich

  • switch-gelb(config)#vlan 50
  • switch-gelb(config-vlan)#name ceo
  • switch-rot#show vlan brief
VLAN Name                             Status    Ports
---- -------------------------------- --------- -------------------------------
1    default                          active    Gi1/0/1, Gi1/0/2, Gi1/0/15
                                                Gi1/0/16, Gi1/0/17, Gi1/0/18
                                                Gi1/0/19, Gi1/0/20, Gi1/0/21
                                                Gi1/0/22, Gi1/0/23, Gi1/0/25
                                                Gi1/0/26, Gi1/0/27, Gi1/0/28
10   office                           active    Gi1/0/3, Gi1/0/4, Gi1/0/5
                                                Gi1/0/6
20   work                             active    Gi1/0/7, Gi1/0/8, Gi1/0/9
                                                Gi1/0/10
30   labor                            active    Gi1/0/11, Gi1/0/12, Gi1/0/13
                                                Gi1/0/14
40   tante-frieda                     active    
50   ceo                              active    
1002 fddi-default                     act/unsup 
1003 token-ring-default               act/unsup 
1004 fddinet-default                  act/unsup 
1005 trnet-default                    act/unsup 

VTP mode Transparent

Der transparente Modus leitet weiter übernimmt aber nicht

  • switch-rot(config)#vtp mode transparent
Setting device to VTP Transparent mode for VLANS.

Konfig ladet nicht mehr in vlan.dat

  • switch-rot#show running-config
!
vtp domain vtp-xinux
vtp mode transparent
...
!         
vlan 10   
 name office
!         
vlan 20   
 name work
!         
vlan 30   
 name labor
!         
vlan 40   
 name tante-frieda
!         
vlan 50   
 name ceo 
!
...

Neues Vlans landen nun in der Running Config

  • switch-rot#configure terminal
Enter configuration commands, one per line.  End with CNTL/Z.
  • switch-rot(config)#vlan 100
  • switch-rot(config-vlan)#name suxer
  • switch-rot(config-vlan)#end
  • switch-rot#show running-config
  • switch-rot(config-vlan)#end
  • switch-rot#show running-config
...
!
vlan 100  
 name suxer
! 
...

Vorsicht beim hinzufügen von Switches zu einer VTP Domain

  • switch-rot(config)#vtp mode server
Setting device to VTP Server mode for VLANS.

Passwort zur Sicherheit

  • switch-rot(config)#vtp password SauGei4eim
  • switch-gelb(config)#vtp password SauGei4eim