Routelearn.net
Course menu

Course 5: LAN SwitchingLesson 3.2 (6 of 6 in this course)21 of 91 in the CCNA series

Configuring and verifying VTP v2

A server, a client and a transparent switch, step by step, with verification.

Intermediate · 8 min read

VTP (VLAN Trunking Protocol) is a Cisco protocol that distributes VLAN definitions (VLAN numbers and names) from switches in server mode to the other switches in the same VTP domain, using advertisements sent over trunk links. Configuring it means setting the domain name, the mode of each switch (server, client or transparent), the version and, optionally, a password.

In simple terms: You create a VLAN once on the VTP server, and the other switches in the same domain learn it automatically instead of you typing it on every switch.

Lab topology

trunk Gi1/0/1trunk Gi1/0/2SW1VTP serverSW2VTP clientSW3VTP transparent
  1. 1. Goal: VLANs created on SW1 appear on SW2 automatically; SW3 keeps its own VLANs but still passes adverts on.

⚠️ Based on Cisco IOS / IOS XE documentation, not run in a lab here. Start from switches with no important VLANs: VTP changes affect every switch in the domain.

Step 1: SW1 as the server

vtp domain ROUTELEARN vtp version 2 vtp mode server vtp password Lab-Secret vlan 10 name EMPLOYEES vlan 20 name GUESTS

Domain name and password are case-sensitive and must match on every switch.

Step 2: SW2 as a client

vtp domain ROUTELEARN vtp version 2 vtp mode client vtp password Lab-Secret

Clients can't create VLANs; 'vlan 30' here returns an error.

Step 3: SW3 transparent

vtp domain ROUTELEARN vtp version 2 vtp mode transparent vlan 99 name LOCAL-ONLY

VLAN 99 exists only on SW3 and is saved in its running configuration rather than shared.

Step 4: make sure the links are trunks

interface GigabitEthernet1/0/1 switchport mode trunk

VTP only travels over trunks. Configure both ends of SW1–SW2 and SW1–SW3.

Verify

Example output · based on Cisco documentation; exact format varies by platform and software version
SW2#show vtp status
VTP Version capable             : 1 to 3
VTP version running             : 2
VTP Domain Name                 : ROUTELEARN
VTP Pruning Mode                : Disabled
VTP Traps Generation            : Disabled
Device ID                       : 0200.0000.0002
Configuration last modified by 0.0.0.0 at 10-5-26 10:15:03

Feature VLAN:
--------------
VTP Operating Mode                : Client
Maximum VLANs supported locally   : 1005
Number of existing VLANs          : 7
Configuration Revision            : 2
MD5 digest                        : 0x3A 0x1F ...
On SW2 check: the domain name and version match SW1, the mode is Client, and the Configuration Revision equals SW1's. "Number of existing VLANs: 7" counts the defaults (1, 1002–1005) plus 10 and 20.
show vlan brief

On SW2: VLANs 10 and 20 should appear without having been created there. On SW3 they won't (but VLAN 99 will).

show vtp password

Confirms the password configured on this switch.

Safely adding a new switch

  1. Before connecting it, run vtp mode transparent (this resets its revision to 0).
  2. Then set vtp mode client and the domain, version and password.
  3. Connect it and check show vtp status: its revision should match the server's.

Practice tasks

Task 1: create VLAN 30 named PRINTERS so it reaches SW2. Where do you configure it?

Show answer
vlan 30 name PRINTERS

On SW1, the server. SW1's revision goes up by one, and SW2 shows VLAN 30 shortly after.

Task 2: SW2 shows revision 0 and none of the VLANs. List three things to check.

Show answer
  • The link between SW1 and SW2 is really a trunk (show interfaces trunk).
  • The domain name matches exactly, including case.
  • The password and VTP version match (a password mismatch shows up as an MD5 digest error in the logs).