Cisco's VTP: VLAN Trunking Protocol

randal

Golden Member
Jun 3, 2001
1,890
0
71
I have seen VTP implemented in a couple places a lot of places with no VTP implemented. I'm looking for people's pros, cons and experiences with it. We're looking at building out a couple floors of a building, and the network design is firing up and we have 2 staunchly opposed groups - those folks who say VTP will make life 1000x easier, and those who say that it is terrible.

Using VTP will make things easier due to centralized management. Don't have to login to a ton of switches and add vlans to the vlan database, no manual vlan configuration anywhere - all of it is done in one place.

The Anti-VTP folks warn about someone plugging in VTP-enabled device with a higher revision number taking down the entire network. I don't see why people would be allowed to plug in a random managed switch (port security, anyone?), but this is apparently a big deal.

I'm hit or miss. I've used both and admittedly, VTP seems to make things a lot easier management wise, but I'm OK without it as long as the documentation is OK. Thoughts?
 

spidey07

No Lifer
Aug 4, 2000
65,469
5
76
use VTP in the core/server farm area where you probably are trunking from the server farm access switches to the core.

Transpent everywhere else.

In best practices design only the access layer contains contains the VLAN. And then at the distriburtion layer you have your two ports that feed the access layer (this are in the access layer VLAN)

The vlan isn't used anywhere else as best practices call for only a single VLAN (or two if using voice) in a single access closet. Distribution to the core is all done by layer3 ports (no spanning-tree, no trunking allowed).

As far as somebody plugging a VTP switch in server mode (domain would have to be the same as well) is a valid concern - it has happened and will cause you a world of hurt if it does.

But VTP version 3 alleviates this problem.
 
Jun 6, 2005
34
0
0
If VTP works for your type of setup, and you won't be using so many VLANs that you don't want populated to all switches.. then I say use it.. Pick you central switches to be the server(s) and absolutely set a password.. You can avoid the problems the skeptics have.

 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |