The problem VTP solves
With fifty switches, creating VLAN 30 by hand on every one is slow and error-prone. VTP (VLAN Trunking Protocol, Cisco) lets you create, rename or delete a VLAN on one switch and have the change copied to every switch in the same VTP domain, over trunk links.
VTP shares the VLAN database (VLAN numbers and names) only. It doesn't assign ports to VLANs; that's still done on each switch.
The modes
| Mode | Can create VLANs? | Syncs from others? | Forwards adverts? |
|---|---|---|---|
| Server (default) | Yes | Yes | Yes |
| Client | No | Yes | Yes |
| Transparent | Yes, locally only | No | Yes (v2 forwards them unchanged) |
| Off | Yes, locally only | No | No |
Watch a change spread
- 1. VLAN 30 created on the server. SW1's revision number goes from 4 to 5, and it advertises the new database out its trunks.
- 2. The client applies it. SW2 sees revision 5 is newer than its 4, so it copies the database: VLAN 30 now exists there.
- 3. Transparent passes it on, untouched. SW3 ignores the change for itself but forwards the advert, so SW4 (a client) still gets VLAN 30.
The revision number, and the classic disaster
Every change increases the configuration revision number. Switches accept a database with a higher revision from their domain, whoever sends it. In VTP versions 1 and 2, even a client with a higher revision can overwrite the server.
- 1. An old lab switch is plugged in. It's in the same domain name, with revision 50 (from months of lab changes) and almost no VLANs.
- 2. Its database wins. The production switches see revision 50 > 5 and accept the lab switch's database.
- 3. VLANs vanish everywhere. Every switch deletes the missing VLANs; ports in those VLANs go inactive and users are cut off.
⚠️ Before connecting any switch to a VTP network, reset its revision to 0: change it to transparent mode (or a different domain name) and back. Many networks avoid the risk entirely by running every switch in transparent mode, or use VTP version 3, where only the designated primary server can make changes.
Advertisements and pruning
- Summary adverts: sent every 5 minutes and after every change, carrying the domain and revision.
- Subset adverts: the actual VLAN details, sent after a change.
- Requests: a switch asks for the database when it needs it (for example after a reload).
- VTP pruning: stops flooded traffic (broadcasts, unknown unicasts) for a VLAN from being sent down trunks toward switches that have no ports in that VLAN.
A new switch with a blank domain name adopts the domain from the first VTP advertisement it receives on a trunk.
Versions
| Version | Notable features |
|---|---|
| 1 | Original; transparent switches forward adverts only for their own domain |
| 2 | Transparent switches forward adverts regardless of domain; Token Ring support; consistency checks |
| 3 | Primary server (protects against accidental overwrites), extended VLANs 1006–4094, private VLANs, MST database, off mode, hidden passwords |
Check yourself
Which VTP mode keeps its own VLANs but still forwards VTP advertisements to other switches?
A switch with a higher revision number joins the domain (VTP v2). What happens?