All language subtitles for 2. VLANs Part 2

af Afrikaans
ak Akan
sq Albanian
am Amharic
ar Arabic
hy Armenian
az Azerbaijani
eu Basque
be Belarusian
bem Bemba
bn Bengali
bh Bihari
bs Bosnian
br Breton
bg Bulgarian
km Cambodian
ca Catalan
ceb Cebuano
chr Cherokee
ny Chichewa
zh-CN Chinese (Simplified)
zh-TW Chinese (Traditional)
co Corsican
hr Croatian
cs Czech
da Danish
nl Dutch
en English
eo Esperanto
et Estonian
ee Ewe
fo Faroese
tl Filipino
fi Finnish
fr French
fy Frisian
gaa Ga
gl Galician
ka Georgian
de German
el Greek
gn Guarani
gu Gujarati
ht Haitian Creole
ha Hausa
haw Hawaiian
iw Hebrew
hi Hindi
hmn Hmong
hu Hungarian
is Icelandic
ig Igbo
id Indonesian
ia Interlingua
ga Irish
it Italian
ja Japanese
jw Javanese
kn Kannada
kk Kazakh
rw Kinyarwanda
rn Kirundi
kg Kongo
ko Korean
kri Krio (Sierra Leone)
ku Kurdish
ckb Kurdish (Soranรฎ)
ky Kyrgyz
lo Laothian
la Latin
lv Latvian
ln Lingala
lt Lithuanian
loz Lozi
lg Luganda
ach Luo
lb Luxembourgish
mk Macedonian
mg Malagasy
ms Malay
ml Malayalam
mt Maltese
mi Maori
mr Marathi
mfe Mauritian Creole
mo Moldavian
mn Mongolian
my Myanmar (Burmese)
sr-ME Montenegrin
ne Nepali
pcm Nigerian Pidgin
nso Northern Sotho
no Norwegian
nn Norwegian (Nynorsk)
oc Occitan
or Oriya
om Oromo
ps Pashto
fa Persian
pl Polish
pt-BR Portuguese (Brazil)
pt Portuguese (Portugal) Download
pa Punjabi
qu Quechua
ro Romanian
rm Romansh
nyn Runyakitara
ru Russian
sm Samoan
gd Scots Gaelic
sr Serbian
sh Serbo-Croatian
st Sesotho
tn Setswana
crs Seychellois Creole
sn Shona
sd Sindhi
si Sinhalese
sk Slovak
sl Slovenian
so Somali
es Spanish
es-419 Spanish (Latin American)
su Sundanese
sw Swahili
sv Swedish
tg Tajik
ta Tamil
tt Tatar
te Telugu
th Thai
ti Tigrinya
to Tonga
lua Tshiluba
tum Tumbuka
tr Turkish
tk Turkmen
tw Twi
ug Uighur
uk Ukrainian
ur Urdu
uz Uzbek
vi Vietnamese
cy Welsh
wo Wolof
xh Xhosa
yi Yiddish
yo Yoruba
zu Zulu

Original subtitles

Send this example let's assume A is sending a frame to D.

So the source address that led to will be a.

And the destination address will be D.

I will send the frame to switch one which one will then copy that frame to all ports based once again

on the switch architecture.

The central async will check the destination in the camp table and let's assume for the moment that

does not answer which ones can table or MAC Address table.

So the frame will attempt to go out of this port to 0 2 but because the internal tagged color is red

for that frame.

And this is a Greenport.

The frame is not permitted out of 0 2.

However on this port because it's a trunk link.

And let's assume for the moment that all the lands are allowed across this trunk that frame will be

sent out of port 0 3 to switch to however just before the frame is sent out.

It needs to be tagged with the villain number.

So in this case the villain identifier would be red.

Now as mentioned in switches villans identified by numbers but to keep these examples simple we are

going to use colors.

So this would in actual fact be a number from 0 to 4000 and 96 bedframe is then sent across the trunk

to switch to who then receives the frame once again the frame is processed internally.

Now this switch reads the villain identify an edited or one Q header and sees that it belongs to the

red Villon that is tagged internally within the switch the frame is sent to Allport 0 2 as well as 0

1.

And let's assume once again that the MAC address table is switched to does not contain the MAC address

of D.

So when the frame is attempting to go to port 0 1 it is denied because the color of the frame is red

and this interface is in the green Villon.

So the frame is dropped.

However out of this interface the frame is permitted because the port is in the red villain and the

frame is tagged with the red villaine all tagging is stripped out of this port.

So it's same as a normal Ethernet frame to PCD.

Once again the PCs are oblivious to the fact that they have been put into villains.

They just see stented Ethernet.

So a standard frame where the source address of a destination address a D is transmitted out of port

0 to and processed by the PC edited in one key trunked have a spatial villain known as the native villaine

native villans are untagged when a port on the switch is set up as a trunk.

For instance this interface on switch one and switch to that interface can receive and transmit tagged

frames frames belonging to the native villaine do not carry violent tags when sent over this trunk by

the same token if an untagged frame were received on the trunk port that frame would automatically be

associated with the native land for the sport.

Now specific management traffic will go across the native land.

So for instance spanning tree BPT use will use the native Villon and so will dynamic trunking critical

dynamic trunking protocol is a way that switches negotiate to set up a trunk between themselves automatically

and I'll show you an example of that in a moment.

Certain management traffic always uses villaine one if you have left the line one as the native LAN

traffic like CPV DP AGP and you DL D will be transmitted across the native land.

Untagged if I ever The native land is changed to something other than land one these protocols will

then be tagged in that specific villaine CTP was explained in the ICD 1 portion of this course.

It allows us to view directly connected devices and trunking protocol we are going to discuss in the

next few slides.

It is a way to dynamically update other switches with changes made on a single switch in a VTB domain

AGP or port aggregation protocol is a protocol used for the automatic creation of ether channels and

you DLT or you need directional linked detection is used to monitor the physical configuration of cables

between devices and detect unique directional links.

This allows us to detect incorrectly cabled links.

The important thing to take note of here is that trunk links there is a special villain known as the

native land where traffic is sent untagged if left at the default of Villa and one a lot of management

traffic will be sent across that native land.

Its important that the native land on both sides of the trunk be the same if they not set the same.

The searchers will notify you by telling you that theres a native villaine mismatch.

The issue that arises if the native lands are not the same is that traffic from one villain on the switch

will automatically be associated and end up in a different than on another switch.

And obviously the whole concept of feline's is to separate traffic into a specific Thielen.

In other words a separate broadcast domain or separate subnet traffic from one VLAN should not end up

in another villaine because of a native villaine misconfiguration.

Now this is something you probably not see in networks today.

In theory with a native villaine a switch like switch one could say tagged frame's to switch to and

untagged frames to this MacBook.

So by using the native Villon this MacBook or a PC would still be able to communicate with the network

even though it doesn't understand tagged frames edited or one keyframes or tagged frames are used for

communicating via information between networking devices like switches.

This device wouldn't necessarily understand edited or one keyframes but could still communicate with

the network by using the native villaine.

However that's not common today.

What is more typical Today is a scenario like this where you have a PC connected to an IP phone connected

to a Cisco switch.

Now Cisco IP phone has a built in three way switch one port is connected back to the network infrastructure.

So a Cisco switch a second port allows the PC to connect to the infrastructure through the phone and

a third port allows for voice traffic from the handset to be prioritized over data when sent to the

network infrastructure.

So the phone has a built in three way switch always proud rising voice over data.

The thing to take note of here though is that the phone can be configured in a separate Villon to the

PC.

So the phone could be in the red violin and the PC could be in the green line.

There are a lot of advantages to doing it this way.

So usually from a security point of view this PC will not be able to sniff voice traffic and therefore

listening on the voice conversation.

Now there are a lot of caveats relating to Cisco phones and different models are set up different ways

but in theory the concept is that the phone is in a separate violent to the PC and therefore the PC

is not able to see the voice traffic.

There are applications like Cain and Abel which is a very powerful hacking tool that allow you to sniff

the network capture the voice traffic and then replay that traffic as a file on your local PC so you

can replay the voice conversation.

But if the phone is in a separate Villon security is enhanced because the PC is not able to see the

voice traffic from a quality of service point of view.

This is also a lot better because its easier to prioritize the voice traffic over the data traffic.

If its in a separate VM setting up your network this way also has the advantages of easier IP address

management because you can assign a separate subnet to your phones.

This is your PCs and thus scale your IP addressing.

So what happens is the switch is configured with what's called a voice Freelon and a native villaine

the voice feel is tagged so tagged frames get sent to the phone and the phone with its boltin threeway

switch is able to read the edited or one keyframes untagged frames are saved on what's called the native

illum or data line.

That information is sent to the phone and the phone just switches that to the PC.

So the PC receives the untagged on native land frames and the phone receives that tagged or voice file

and frames no configuration and the phone is necessary to enable this.

You literally typed a few commands on the switch telling the switch what the voice the land is and what

the DTV Bil'in is.

And this happens automatically because when the phone's boot up they query the switch through CGP to

find out which feel they belong to.

So the switch up dates the phone's configuration through the use of CTP.

So this is a very common implementation of native lands in the real world today.

So just to sum up how ports are assigned to villans seriously they can be statically assigned by an

administrator.

So to use an administrator go into an interface and steadily put that port into a villain.

The second option is to create what are called Dynamic villains using a villain membership policy server

dynamic villans allow for a ports deal and to be done emic updated based on the Mac address of the device

attached to that port.

So in a boardroom for example when a director plugs in a laptop based on the Mac address of that laptop

that port is dynamically assigned to the directors the plan when a manager plugs his laptop into that

same port the next day for example that Villon is automatically updated to the managers Villon.

So based on the source Mac address of frame's received in the port the port is automatically assigned

to different lands and last year we have voice villans which are used specifically for IP phones BTP

or villaine trunking protocol is a Cisco proprietary layer to protocol which allows for the Propagation

of the information from one switch to another rather than telnetting to multiple switches.

You can Karaite delete or rename the lands on one switch and have that information automatically propagated

to other switches across trunk links.

Notice the name villaine trunking protocol.

This information can only be propagated across trunk links.

Now ETP can save you a lot of time that has a lot of Sisk engineers will tell the BTP can cause you

a lot of headaches.

Switches can have the entire villaine configuration wiped out if a new switch is added to the network

without following a proper procedure.

So a lot of Cisco engineers will not enable VCP in modern environments because of the inherent risks

associated with this protocol.

GTP messages are sent to the following Mac address which is a well-known multicast address for flooding

of the CTP and DTP protocols.

There are three types of messages in DTP.

You have some free advertisement subset advertisements and advertisement requests and I'll explain each

of these in more detail in the upcoming slides.

But please be aware that there are three message typed when setting up DP devices will by default belong

to the null domain VDB to work.

You need to configure and put the devices into a specific VTB domain only devices within the same DTP

domain will be updated with the line information.

A switch can only be configured in a single VTB domain at any given time by default Cisco switches are

in the nold domain or no management domain until they receive an advertisement for a domain over trunked

link.

Or until you manually configure a management domain.

So in this example let's assume that these devices have been put into the VTB domain with the name of

Cecka.

Remember these VCP is a layer to protocol and requires trunked links for communication.

So VDB will not traverse Harada an important concept to understand NVP is the concept of a revision

number.

Every time it changes made to the villain database the revision number in BTP will increment by 1.

So let's assume that all devices in this apology have a revision number of 1 yours in a ministry to

a villain let's say we three to the switch it's revision number will then increment from a vision number

1 to revision number 2 that information will then be advertised to all other switches in the VTB domain

so that they can synchronize their databases to the latest revision number which is revision number

2.

So the switch at the top will send what is called a GTP summary advertisement to all of the switches

informing them that a change has been made.

Remember this is sent using a multicast address.

So all of these devices will see that message.

They will then request the latest information using an advertisement request and the switch at the top

will send them detailed information about the change using a subset advertisement.

The net result is that the revision numbers and all of these switches will increment to the same revision

number as a switch where the change was made.

So Viola and three will appear in all the databases of the switches and the revision number will be

set to revision number two.

The whole concept with VTB is that you can make changes on an individual device as those changes are

made.

All other switches are informed of the change and they will synchronize their databases to the latest

revision number so that they end up having the same B plans and maybe Lenn databases.

That means that you as the administrator only to make changes on one switch rather than five switches

in the apology please note ports are put into individual villans by for example an administrator.

The DP does not put ports into individual villans it just updates the database so that the switches

know which villains exist use an administrator still need to put those ports into the relevant villans.

So this is just a villain database update mechanism so that switches know the villains that exist in

the typology.

So let's look at the VDB messages in more detail.

The first stop of VDB message is a summary advertisement.

This is sent every five minutes or whenever there's a change.

So whenever an administrator makes a change on a switch by for instance adding a Villon a summary advertisement

will be sent out on the well-known multicast address to all of the switches in the domain.

So this is used to inform other switches of the current VCP domain and the current configuration revision

number.

So as an example on switch one the administrator adds another villain let's say villain for the revision

number will be incremented.

So if the revision number was three it would not be incremented to 4.

This switch will say in a summary advertisement to all neighboring switches informing them of the current

VTB domain and the new configuration revision number switches that receive that summary advertisement

will then send back a summary request asking for detailed information of the changes that have been

made.

There are three situations when some requests are used Firstly when a switch has been reset or when

the VTB domain name is being changed or when the switch has received a VTB summary advertisement with

a higher configuration revision number than its own.

So because switch to received the summary advertisement from one indicating a high revision number.

In other words the revision number and which one is revision before and the revision number on switch

2 is revision number 3 switch 2 will now request information from switch 1 so that it can update its

database with the latest the information that detailed information is sent from which one to switch

to using what's called a subset.

Advertisement.

This contains a list of the information and if they are several villans more than one subset advertisement

may be required to update and synchronize the databases of other switches.

So essentially what this is is detailed information of the changes that have been made.

The summary advertisement just informs the switch in summary format of the latest revision number and

BTP domain.

If the local switch sees that it's out of date it will request detailed information so that it can synchronize

its database and that information will be provided using a subset advertisement.

The switch is now able to synchronize the local databases to the database of the switch with the latest

information.

Now there are three modes in BTP.

The default mode is server a VTB switch in server mode can create villans modify villains and delete

villans.

It also sends and forwards advertisements.

So if it received an advertisement from another switch it would forward that on.

If you made changes on the local switch it would send some real advertisements.

It would also synchronize its local database to the latest revision number.

And it also saves the villain configuration information locally.

So this is the device where you're going to make your changes multiple switches can be configured as

VTB servers but you need to be really careful with this.

The second mode is VTB client a VTB client can not create change or delete villans.

It is also able to send forward advertisements so it can say in any violence currently listed in its

database to other VTB switches it can also forward advertisement receive from other switches.

Thirdly it would also synchronize its database to the latest configuration revision number this is a

major potential issue with GTP and has burned to many Cisco engineers in the past.

A lot of Cisco engineers will not use VTB because of this issue.

So he has a sample typology.

Now we have a VTB server and it's a scene that all of the switches at the top are configured as VTB

clients the host machines are in the raid Villano green Bil'in and currently the revision number for

the domain is the revision number.

So the latest configuration revision number is to the VTB domain.

Is Cisco and the villains that have been configured on the switches are villains red and green.

Please note once again that the switches have a villain database.

That is what VTB updates the individual ports and the switches need to manually be put in the correct

the.

Now someone plugs a nother switch into the topology from for instance a lab environment.

The reason why this is dangerous is that in a lab environment the lens may have been added and removed

and thus the revision number may be a lot higher than the production network.

So let's assume for the moment that the revision number is 50 this switch only has the blue villaine

configured on it.

So the green and red villans do not exist in the villain database.

A lot of people make the mistake of assuming that as long as the switches configured as a VTB client

it will not cause any problems on the network.

So an administrator plugged in the switch and configures this port as a trunk.

Please note once again that ETP advertisement only sent across trunk ports.

So let's assume that throughout the network all of these links are configured as trunk's as soon as

this client is added to the VCP domain.

And what's really scary is that this client can be automatically updated with the VCP information.

In other words if it's configured with a nold domain it can automatically join the current VCP domain

of Cisco.

And as soon as that happens the devices will synchronize their databases to the latest configuration

revision number which in this case is 50 sun all switches in the live domain.

The revision number is changed to 50 because all of the switches including the VTB server will synchronize

automatically to the VTB client the current villans red and green are automatically removed from the

violent database and the only villain that will now be available in the violent databases of all of

these switches is violently.

Now all of the ports on all the switches that have manually been put into the green or red Villon or

heire disabled.

The issue here is that a port belongs to the red Villon but the red Villon does not exist in the database.

So the port is automatically disabled.

That means that no traffic can be sent or received on the sport and the same thing happens on all other

switches.

Essentially what happens is that the entire network is brought down by the introduction of the single

switch.

That's extremely worrying to say the least that the introduction of a single switch can bring down an

entire enterprise network.

The only way to fix this is to physically connect to the VTB server and then manually add the villans

that have been deleted.

Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.