Afrikaans
Akan
Albanian
Amharic
Arabic
Armenian
Azerbaijani
Basque
Belarusian
Bemba
Bengali
Bihari
Bosnian
Breton
Bulgarian
Cambodian
Catalan
Cebuano
Cherokee
Chichewa
Chinese (Simplified)
Chinese (Traditional)
Corsican
Croatian
Czech
Danish
Dutch
English
Esperanto
Estonian
Ewe
Faroese
Filipino
Finnish
French
Frisian
Ga
Galician
Georgian
German
Greek
Guarani
Gujarati
Haitian Creole
Hausa
Hawaiian
Hebrew
Hindi
Hmong
Hungarian
Icelandic
Igbo
Indonesian
Interlingua
Irish
Italian
Japanese
Javanese
Kannada
Kazakh
Kinyarwanda
Kirundi
Kongo
Korean
Krio (Sierra Leone)
Kurdish
Kurdish (Soranรฎ)
Kyrgyz
Laothian
Latin
Latvian
Lingala
Lithuanian
Lozi
Luganda
Luo
Luxembourgish
Macedonian
Malagasy
Malay
Malayalam
Maltese
Maori
Marathi
Mauritian Creole
Moldavian
Mongolian
Myanmar (Burmese)
Montenegrin
Nepali
Nigerian Pidgin
Northern Sotho
Norwegian
Norwegian (Nynorsk)
Occitan
Oriya
Oromo
Pashto
Persian
Polish
Portuguese (Brazil)
Punjabi
Quechua
Romanian
Romansh
Runyakitara
Russian
Samoan
Scots Gaelic
Serbian
Serbo-Croatian
Sesotho
Setswana
Seychellois Creole
Shona
Sindhi
Sinhalese
Slovak
Slovenian
Somali
Spanish
Spanish (Latin American)
Sundanese
Swahili
Swedish
Tajik
Tamil
Tatar
Telugu
Thai
Tigrinya
Tonga
Tshiluba
Tumbuka
Turkish
Turkmen
Twi
Uighur
Ukrainian
Urdu
Uzbek
Vietnamese
Welsh
Wolof
Xhosa
Yiddish
Yoruba
Zulu
Send this example let's assume A is sending a frame to D.
So the source address that led to will be a.
And the destination address will be D.
I will send the frame to switch one which one will then copy that frame to all ports based once again
on the switch architecture.
The central async will check the destination in the camp table and let's assume for the moment that
does not answer which ones can table or MAC Address table.
So the frame will attempt to go out of this port to 0 2 but because the internal tagged color is red
for that frame.
And this is a Greenport.
The frame is not permitted out of 0 2.
However on this port because it's a trunk link.
And let's assume for the moment that all the lands are allowed across this trunk that frame will be
sent out of port 0 3 to switch to however just before the frame is sent out.
It needs to be tagged with the villain number.
So in this case the villain identifier would be red.
Now as mentioned in switches villans identified by numbers but to keep these examples simple we are
going to use colors.
So this would in actual fact be a number from 0 to 4000 and 96 bedframe is then sent across the trunk
to switch to who then receives the frame once again the frame is processed internally.
Now this switch reads the villain identify an edited or one Q header and sees that it belongs to the
red Villon that is tagged internally within the switch the frame is sent to Allport 0 2 as well as 0
1.
And let's assume once again that the MAC address table is switched to does not contain the MAC address
of D.
So when the frame is attempting to go to port 0 1 it is denied because the color of the frame is red
and this interface is in the green Villon.
So the frame is dropped.
However out of this interface the frame is permitted because the port is in the red villain and the
frame is tagged with the red villaine all tagging is stripped out of this port.
So it's same as a normal Ethernet frame to PCD.
Once again the PCs are oblivious to the fact that they have been put into villains.
They just see stented Ethernet.
So a standard frame where the source address of a destination address a D is transmitted out of port
0 to and processed by the PC edited in one key trunked have a spatial villain known as the native villaine
native villans are untagged when a port on the switch is set up as a trunk.
For instance this interface on switch one and switch to that interface can receive and transmit tagged
frames frames belonging to the native villaine do not carry violent tags when sent over this trunk by
the same token if an untagged frame were received on the trunk port that frame would automatically be
associated with the native land for the sport.
Now specific management traffic will go across the native land.
So for instance spanning tree BPT use will use the native Villon and so will dynamic trunking critical
dynamic trunking protocol is a way that switches negotiate to set up a trunk between themselves automatically
and I'll show you an example of that in a moment.
Certain management traffic always uses villaine one if you have left the line one as the native LAN
traffic like CPV DP AGP and you DL D will be transmitted across the native land.
Untagged if I ever The native land is changed to something other than land one these protocols will
then be tagged in that specific villaine CTP was explained in the ICD 1 portion of this course.
It allows us to view directly connected devices and trunking protocol we are going to discuss in the
next few slides.
It is a way to dynamically update other switches with changes made on a single switch in a VTB domain
AGP or port aggregation protocol is a protocol used for the automatic creation of ether channels and
you DLT or you need directional linked detection is used to monitor the physical configuration of cables
between devices and detect unique directional links.
This allows us to detect incorrectly cabled links.
The important thing to take note of here is that trunk links there is a special villain known as the
native land where traffic is sent untagged if left at the default of Villa and one a lot of management
traffic will be sent across that native land.
Its important that the native land on both sides of the trunk be the same if they not set the same.
The searchers will notify you by telling you that theres a native villaine mismatch.
The issue that arises if the native lands are not the same is that traffic from one villain on the switch
will automatically be associated and end up in a different than on another switch.
And obviously the whole concept of feline's is to separate traffic into a specific Thielen.
In other words a separate broadcast domain or separate subnet traffic from one VLAN should not end up
in another villaine because of a native villaine misconfiguration.
Now this is something you probably not see in networks today.
In theory with a native villaine a switch like switch one could say tagged frame's to switch to and
untagged frames to this MacBook.
So by using the native Villon this MacBook or a PC would still be able to communicate with the network
even though it doesn't understand tagged frames edited or one keyframes or tagged frames are used for
communicating via information between networking devices like switches.
This device wouldn't necessarily understand edited or one keyframes but could still communicate with
the network by using the native villaine.
However that's not common today.
What is more typical Today is a scenario like this where you have a PC connected to an IP phone connected
to a Cisco switch.
Now Cisco IP phone has a built in three way switch one port is connected back to the network infrastructure.
So a Cisco switch a second port allows the PC to connect to the infrastructure through the phone and
a third port allows for voice traffic from the handset to be prioritized over data when sent to the
network infrastructure.
So the phone has a built in three way switch always proud rising voice over data.
The thing to take note of here though is that the phone can be configured in a separate Villon to the
PC.
So the phone could be in the red violin and the PC could be in the green line.
There are a lot of advantages to doing it this way.
So usually from a security point of view this PC will not be able to sniff voice traffic and therefore
listening on the voice conversation.
Now there are a lot of caveats relating to Cisco phones and different models are set up different ways
but in theory the concept is that the phone is in a separate violent to the PC and therefore the PC
is not able to see the voice traffic.
There are applications like Cain and Abel which is a very powerful hacking tool that allow you to sniff
the network capture the voice traffic and then replay that traffic as a file on your local PC so you
can replay the voice conversation.
But if the phone is in a separate Villon security is enhanced because the PC is not able to see the
voice traffic from a quality of service point of view.
This is also a lot better because its easier to prioritize the voice traffic over the data traffic.
If its in a separate VM setting up your network this way also has the advantages of easier IP address
management because you can assign a separate subnet to your phones.
This is your PCs and thus scale your IP addressing.
So what happens is the switch is configured with what's called a voice Freelon and a native villaine
the voice feel is tagged so tagged frames get sent to the phone and the phone with its boltin threeway
switch is able to read the edited or one keyframes untagged frames are saved on what's called the native
illum or data line.
That information is sent to the phone and the phone just switches that to the PC.
So the PC receives the untagged on native land frames and the phone receives that tagged or voice file
and frames no configuration and the phone is necessary to enable this.
You literally typed a few commands on the switch telling the switch what the voice the land is and what
the DTV Bil'in is.
And this happens automatically because when the phone's boot up they query the switch through CGP to
find out which feel they belong to.
So the switch up dates the phone's configuration through the use of CTP.
So this is a very common implementation of native lands in the real world today.
So just to sum up how ports are assigned to villans seriously they can be statically assigned by an
administrator.
So to use an administrator go into an interface and steadily put that port into a villain.
The second option is to create what are called Dynamic villains using a villain membership policy server
dynamic villans allow for a ports deal and to be done emic updated based on the Mac address of the device
attached to that port.
So in a boardroom for example when a director plugs in a laptop based on the Mac address of that laptop
that port is dynamically assigned to the directors the plan when a manager plugs his laptop into that
same port the next day for example that Villon is automatically updated to the managers Villon.
So based on the source Mac address of frame's received in the port the port is automatically assigned
to different lands and last year we have voice villans which are used specifically for IP phones BTP
or villaine trunking protocol is a Cisco proprietary layer to protocol which allows for the Propagation
of the information from one switch to another rather than telnetting to multiple switches.
You can Karaite delete or rename the lands on one switch and have that information automatically propagated
to other switches across trunk links.
Notice the name villaine trunking protocol.
This information can only be propagated across trunk links.
Now ETP can save you a lot of time that has a lot of Sisk engineers will tell the BTP can cause you
a lot of headaches.
Switches can have the entire villaine configuration wiped out if a new switch is added to the network
without following a proper procedure.
So a lot of Cisco engineers will not enable VCP in modern environments because of the inherent risks
associated with this protocol.
GTP messages are sent to the following Mac address which is a well-known multicast address for flooding
of the CTP and DTP protocols.
There are three types of messages in DTP.
You have some free advertisement subset advertisements and advertisement requests and I'll explain each
of these in more detail in the upcoming slides.
But please be aware that there are three message typed when setting up DP devices will by default belong
to the null domain VDB to work.
You need to configure and put the devices into a specific VTB domain only devices within the same DTP
domain will be updated with the line information.
A switch can only be configured in a single VTB domain at any given time by default Cisco switches are
in the nold domain or no management domain until they receive an advertisement for a domain over trunked
link.
Or until you manually configure a management domain.
So in this example let's assume that these devices have been put into the VTB domain with the name of
Cecka.
Remember these VCP is a layer to protocol and requires trunked links for communication.
So VDB will not traverse Harada an important concept to understand NVP is the concept of a revision
number.
Every time it changes made to the villain database the revision number in BTP will increment by 1.
So let's assume that all devices in this apology have a revision number of 1 yours in a ministry to
a villain let's say we three to the switch it's revision number will then increment from a vision number
1 to revision number 2 that information will then be advertised to all other switches in the VTB domain
so that they can synchronize their databases to the latest revision number which is revision number
2.
So the switch at the top will send what is called a GTP summary advertisement to all of the switches
informing them that a change has been made.
Remember this is sent using a multicast address.
So all of these devices will see that message.
They will then request the latest information using an advertisement request and the switch at the top
will send them detailed information about the change using a subset advertisement.
The net result is that the revision numbers and all of these switches will increment to the same revision
number as a switch where the change was made.
So Viola and three will appear in all the databases of the switches and the revision number will be
set to revision number two.
The whole concept with VTB is that you can make changes on an individual device as those changes are
made.
All other switches are informed of the change and they will synchronize their databases to the latest
revision number so that they end up having the same B plans and maybe Lenn databases.
That means that you as the administrator only to make changes on one switch rather than five switches
in the apology please note ports are put into individual villans by for example an administrator.
The DP does not put ports into individual villans it just updates the database so that the switches
know which villains exist use an administrator still need to put those ports into the relevant villans.
So this is just a villain database update mechanism so that switches know the villains that exist in
the typology.
So let's look at the VDB messages in more detail.
The first stop of VDB message is a summary advertisement.
This is sent every five minutes or whenever there's a change.
So whenever an administrator makes a change on a switch by for instance adding a Villon a summary advertisement
will be sent out on the well-known multicast address to all of the switches in the domain.
So this is used to inform other switches of the current VCP domain and the current configuration revision
number.
So as an example on switch one the administrator adds another villain let's say villain for the revision
number will be incremented.
So if the revision number was three it would not be incremented to 4.
This switch will say in a summary advertisement to all neighboring switches informing them of the current
VTB domain and the new configuration revision number switches that receive that summary advertisement
will then send back a summary request asking for detailed information of the changes that have been
made.
There are three situations when some requests are used Firstly when a switch has been reset or when
the VTB domain name is being changed or when the switch has received a VTB summary advertisement with
a higher configuration revision number than its own.
So because switch to received the summary advertisement from one indicating a high revision number.
In other words the revision number and which one is revision before and the revision number on switch
2 is revision number 3 switch 2 will now request information from switch 1 so that it can update its
database with the latest the information that detailed information is sent from which one to switch
to using what's called a subset.
Advertisement.
This contains a list of the information and if they are several villans more than one subset advertisement
may be required to update and synchronize the databases of other switches.
So essentially what this is is detailed information of the changes that have been made.
The summary advertisement just informs the switch in summary format of the latest revision number and
BTP domain.
If the local switch sees that it's out of date it will request detailed information so that it can synchronize
its database and that information will be provided using a subset advertisement.
The switch is now able to synchronize the local databases to the database of the switch with the latest
information.
Now there are three modes in BTP.
The default mode is server a VTB switch in server mode can create villans modify villains and delete
villans.
It also sends and forwards advertisements.
So if it received an advertisement from another switch it would forward that on.
If you made changes on the local switch it would send some real advertisements.
It would also synchronize its local database to the latest revision number.
And it also saves the villain configuration information locally.
So this is the device where you're going to make your changes multiple switches can be configured as
VTB servers but you need to be really careful with this.
The second mode is VTB client a VTB client can not create change or delete villans.
It is also able to send forward advertisements so it can say in any violence currently listed in its
database to other VTB switches it can also forward advertisement receive from other switches.
Thirdly it would also synchronize its database to the latest configuration revision number this is a
major potential issue with GTP and has burned to many Cisco engineers in the past.
A lot of Cisco engineers will not use VTB because of this issue.
So he has a sample typology.
Now we have a VTB server and it's a scene that all of the switches at the top are configured as VTB
clients the host machines are in the raid Villano green Bil'in and currently the revision number for
the domain is the revision number.
So the latest configuration revision number is to the VTB domain.
Is Cisco and the villains that have been configured on the switches are villains red and green.
Please note once again that the switches have a villain database.
That is what VTB updates the individual ports and the switches need to manually be put in the correct
the.
Now someone plugs a nother switch into the topology from for instance a lab environment.
The reason why this is dangerous is that in a lab environment the lens may have been added and removed
and thus the revision number may be a lot higher than the production network.
So let's assume for the moment that the revision number is 50 this switch only has the blue villaine
configured on it.
So the green and red villans do not exist in the villain database.
A lot of people make the mistake of assuming that as long as the switches configured as a VTB client
it will not cause any problems on the network.
So an administrator plugged in the switch and configures this port as a trunk.
Please note once again that ETP advertisement only sent across trunk ports.
So let's assume that throughout the network all of these links are configured as trunk's as soon as
this client is added to the VCP domain.
And what's really scary is that this client can be automatically updated with the VCP information.
In other words if it's configured with a nold domain it can automatically join the current VCP domain
of Cisco.
And as soon as that happens the devices will synchronize their databases to the latest configuration
revision number which in this case is 50 sun all switches in the live domain.
The revision number is changed to 50 because all of the switches including the VTB server will synchronize
automatically to the VTB client the current villans red and green are automatically removed from the
violent database and the only villain that will now be available in the violent databases of all of
these switches is violently.
Now all of the ports on all the switches that have manually been put into the green or red Villon or
heire disabled.
The issue here is that a port belongs to the red Villon but the red Villon does not exist in the database.
So the port is automatically disabled.
That means that no traffic can be sent or received on the sport and the same thing happens on all other
switches.
Essentially what happens is that the entire network is brought down by the introduction of the single
switch.
That's extremely worrying to say the least that the introduction of a single switch can bring down an
entire enterprise network.
The only way to fix this is to physically connect to the VTB server and then manually add the villans
that have been deleted.
Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.