Chapter 13 Configuring VLANs

Configuring VLAN Trunks

To reduce the risk of spanning-tree loops or storms, you can disable VLAN 1 on any individual VLAN trunk port by removing VLAN 1 from the allowed list. When you remove VLAN 1 from a trunk port, the interface continues to sent and receive management traffic, for example, Cisco Discovery Protocol (CDP), Port Aggregation Protocol (PAgP), Link Aggregation Control Protocol (LACP), DTP, and VTP in VLAN 1.

If a trunk port with VLAN 1 disabled is converted to a nontrunk port, it is added to the access VLAN. If the access VLAN is set to 1, the port will be added to VLAN 1, regardless of the switchport trunk allowed setting. The same is true for any VLAN that has been disabled on the port.

A trunk port can become a member of a VLAN if the VLAN is enabled, if VTP knows of the VLAN, and if the VLAN is in the allowed list for the port. When VTP detects a newly enabled VLAN and the VLAN is in the allowed list for a trunk port, the trunk port automatically becomes a member of the enabled VLAN. When VTP detects a new VLAN and the VLAN is not in the allowed list for a trunk port, the trunk port does not become a member of the new VLAN.

Beginning in privileged EXEC mode, follow these steps to modify the allowed list of a trunk:

 

Command

Purpose

Step 1

 

 

configure terminal

Enter global configuration mode.

Step 2

 

 

interface interface-id

Specify the port to be configured, and enter interface configuration

 

 

mode.

Step 3

 

 

switchport mode trunk

Configure the interface as a VLAN trunk port.

 

 

 

Step 4 switchport trunk allowed vlan {add

(Optional) Configure the list of VLANs allowed on the trunk.

 

all except remove} vlan-list

For explanations about using the add, all, except, and remove keywords,

 

 

 

 

see the command reference for this release.

 

 

The vlan-listparameter is either a single VLAN number from 1 to 4094

 

 

or a range of VLANs described by two VLAN numbers, the lower one

 

 

first, separated by a hyphen. Do not enter any spaces between

 

 

comma-separated VLAN parameters or in hyphen-specified ranges.

 

 

All VLANs are allowed by default.

Step 5

 

 

end

Return to privileged EXEC mode.

Step 6

 

 

show interfaces interface-idswitchport

Verify your entries in the Trunking VLANs Enabled field of the display.

Step 7

 

 

copy running-config startup-config

(Optional) Save your entries in the configuration file.

 

 

 

To return to the default allowed VLAN list of all VLANs, use the no switchport trunk allowed vlan interface configuration command.

This example shows how to remove VLAN 2 from the allowed VLAN list on a port:

Switch(config)# interface gigabitethernet1/0/1

Switch(config-if)#switchport trunk allowed vlan remove 2

Switch(config-if)# end

Changing the Pruning-Eligible List

The pruning-eligible list applies only to trunk ports. Each trunk port has its own eligibility list. VTP pruning must be enabled for this procedure to take effect. The “Enabling VTP Pruning” section on page 14-14describes how to enable VTP pruning.

 

Catalyst 3750-E and 3560-E Switch Software Configuration Guide

13-22

OL-9775-02

Page 366
Image 366
Cisco Systems 3750E Changing the Pruning-Eligible List, Switchport trunk allowed vlan add, All except remove vlan-list