Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

Removing vlan 1 from trunk

Posted on 2011-02-10
5
Medium Priority
?
1,335 Views
Last Modified: 2012-05-11
I would like to know if there are any problems associated with removing VLAN 1 from all trunks.  I found the following from Cisco's website:

Remove VLAN 1 from the allowed list so you can disable VLAN 1 on any individual VLAN trunk port in order to reduce the risk of spanning-tree loops or storms. When you remove VLAN 1 from a trunk port, the interface continues to send and receive management traffic, for example, Cisco Discovery Protocol (CDP), Port Aggregation Protocol (PAgP), Link Aggregation Control Protocol (LACP), Dynamic Trunking Protocol (DTP), and VLAN Trunking Protocol (VTP) in VLAN 1.

Is this true that management traffic passes even when VLAN 1 is disabled for all Cisco switches?  What about other managed switches such as Dell?
0
Comment
Question by:B1izzard
  • 2
  • 2
5 Comments
 
LVL 22

Accepted Solution

by:
eeRoot earned 1200 total points
ID: 34864634
You can safely disable VLAN 1 as long as the network traffic has other VLAN's to use.  Most management protocols are layer 1, trunking affects layer 2 traffic.  The management traffic that uses layer 2 (SNMP, telnet, ssh, etc) can be set to a specific management VLAN meant just for network administration

The configs can be a bid tricky when you use different vendors, but yes, you can use switches from other manufacturers.
0
 

Author Comment

by:B1izzard
ID: 34864874
If it uses another VLAN for traffic, any idea on how it chooses the VLAN?  Does it use the numerically lowest VLAN, cost, or ???
0
 
LVL 12

Assisted Solution

by:jjmartineziii
jjmartineziii earned 800 total points
ID: 34864975
Yes, on cisco switches, management traffic is still passed. Not sure about other vendors.

This article may help:

http://blog.ipexpert.com/2011/01/19/old-ccie-myths-vlan-1/
0
 
LVL 22

Expert Comment

by:eeRoot
ID: 34865160
No, vlan's are not auto-detected.  It would depend on the IP address of the device, whether software or the operating system has been set to tag the network traffic with a particular VLAN, and what the switchport's native VLAN setting is.
0
 

Author Closing Comment

by:B1izzard
ID: 34867783
Thanks.
0

Featured Post

Free Tool: Subnet Calculator

The subnet calculator helps you design networks by taking an IP address and network mask and returning information such as network, broadcast address, and host range.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Arrow Electronics was searching for a KVM  (Keyboard/Video/Mouse) switch that could display on one single monitor the current status of all units being tested on the rack.
WARNING:   If you follow the instructions here, you will wipe out your VTP and VLAN configurations.  Make sure you have backed up your switch!!! I recently had some issues with a few low-end Cisco routers (RV325) and I opened a case with Cisco TA…
In response to a need for security and privacy, and to continue fostering an environment members can turn to for support, solutions, and education, Experts Exchange has created anonymous question capabilities. This new feature is available to our Pr…
We’ve all felt that sense of false security before—locking down external access to a database or component and feeling like we’ve done all we need to do to secure company data. But that feeling is fleeting. Attacks these days can happen in many w…

916 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question