Afrikaans
Akan
Albanian
Amharic
Arabic
Armenian
Azerbaijani
Basque
Belarusian
Bemba
Bengali
Bihari
Bosnian
Breton
Bulgarian
Cambodian
Catalan
Cebuano
Cherokee
Chichewa
Chinese (Simplified)
Chinese (Traditional)
Corsican
Croatian
Czech
Danish
Dutch
English
Esperanto
Estonian
Ewe
Faroese
Filipino
Finnish
French
Frisian
Ga
Galician
Georgian
German
Greek
Guarani
Gujarati
Haitian Creole
Hausa
Hawaiian
Hebrew
Hindi
Hmong
Hungarian
Icelandic
Igbo
Indonesian
Interlingua
Irish
Italian
Japanese
Javanese
Kannada
Kazakh
Kinyarwanda
Kirundi
Kongo
Korean
Krio (Sierra Leone)
Kurdish
Kurdish (Soranî)
Kyrgyz
Laothian
Latin
Latvian
Lingala
Lithuanian
Lozi
Luganda
Luo
Luxembourgish
Macedonian
Malagasy
Malay
Malayalam
Maltese
Maori
Marathi
Mauritian Creole
Moldavian
Mongolian
Myanmar (Burmese)
Montenegrin
Nepali
Nigerian Pidgin
Northern Sotho
Norwegian
Norwegian (Nynorsk)
Occitan
Oriya
Oromo
Pashto
Persian
Polish
Portuguese (Brazil)
Punjabi
Quechua
Romanian
Romansh
Runyakitara
Russian
Samoan
Scots Gaelic
Serbian
Serbo-Croatian
Sesotho
Setswana
Seychellois Creole
Shona
Sindhi
Sinhalese
Slovak
Slovenian
Somali
Spanish
Spanish (Latin American)
Sundanese
Swahili
Swedish
Tajik
Tamil
Tatar
Telugu
Thai
Tigrinya
Tonga
Tshiluba
Tumbuka
Turkish
Turkmen
Twi
Uighur
Ukrainian
Urdu
Uzbek
Vietnamese
Welsh
Wolof
Xhosa
Yiddish
Yoruba
Zulu
1
So switch 1 we're gonna shut this interface down
2
to force traffic to go via the hub
3
So interface gigabit 0/2 shut it down
4
sh in g0/3 switchport
5
this port gigabit 0/3 is acting as a trunk
6
using 802.1Q all VLANs are allowed.
7
So let’s do a capture on the hub, were receiving PVST information
8
and notice the difference here's an 802.1Q header
9
so we have Ethernet but notice the type is not IPv4
10
the type is 802.1Q, so the type is 0x8100 rather than 0x0800 for IP.
11
so 802.1Q frame, we can see here
12
that the VLAN ID for this PVST message is VLAN 1
13
Per-VLAN Spanning Tree sends what are called BPDUs on every VLAN
14
so here we can see some Spanning Tree information
15
and as we scroll down
16
we can see that as an example CDP and VTP messages
17
or in this case, DTP is sent as an untagged frame.
18
So we can see some DTP information arriving here.
19
And that will continue on.
20
So let’s do a ping from router 2 acting as PC 2 to router 4
21
and see if we can see why the frames are not permitted.
22
So ICMP is showing nothing, so we can see a broadcast here
23
this is an ARP message saying who has 10.1.2.4
24
so in this ARP message, I'll just stop that capture for a moment.
25
Here’s the ARP you can see it's an Ethernet 2 frame
26
with the broadcast so the destination is broadcast.
27
Source MAC address is the MAC address of router 2.
28
We can see that by looking at the interface
29
so sh int f0/0 notice there’s the MAC address of the router
30
and they're already shown in the Wireshark capture
31
but notice the type is once again 802.1Q and the VLAN is set to VLAN 2.
32
So in other words, the router is sending the frame untagged to the switch.
33
But when it go across this link it's going as a tagged frame.
34
The switch is setting the VLAN tag to 2
35
because it arrived on this port which is in VLAN 2.
36
I’m just reset that capture
37
and what I want to show you is on this port
38
it's gonna show us untagged, so it's standard Ethernet
39
but on this one, it's gonna show us tagged
40
because the switch is tagging the frame.
41
So I'll do the ping again
42
now this is the frame to the switch from the router
43
and we'll the switch for ARP, you can see this, the ARP traffic
44
from the router to a broadcast address it's untagged, this is the type for ARP.
45
There is no 802.1Q header here at all.
46
But when we look for ARP on the link between these switches
47
notice you can see the 802.1Q tagged set to 2.
48
So the traffic is arriving here as untagged
49
and the switch is tagging it to send the frame to switch 2.
50
The problem here is when the traffic hits switch 2
51
switch 2 is not configured with trunking
52
this is just an access port in VLAN 1.
53
So that traffic will be sent to this port
54
but not out of this port which is in VLAN 2.
55
So on switch 2 let’s see if we can see that.
56
sh int trunk
57
At the moment no interfaces are trunking
58
so sh int g0/3
59
and let’s put switchport at the end
60
so sh interfaces g0/3 switchport
61
this interface gigabit 0/3 is enabled
62
it's set for negotiation of trunking. So it’s in VLAN 1.
63
This port belongs to VLAN 1, it’s an access port, no trunking is enabled
64
so traffic from router 2 is simply gonna be sent out of this port.
65
So let’s do a capture there to prove that
66
and then we'll do a capture on this port
67
to check if any traffic arrives on this port.
68
So there's the Wireshark capture
69
do the ping again on router 2
70
I’ll do a filter for ARP
71
and notice there's the broadcast traffic from 10.1.2.2
72
which is router 2 asking for the MAC address of 10.1.2.4
73
So router 2 is asking for the MAC address of router 4 but it never receives it.
74
So what you'll also notice here is there is no 8021.Q tag.
75
So the frame was sent untagged here
76
it was sent tagged cross here
77
arrived here but this port was configured as an access port in VLAN 1.
78
So the traffic was simply copied out on this port in VLAN 1 and with no tag.
79
The traffic never arrived in this port.
80
So let’s prove that do a capture here.
81
I’ll do the ping again, and try and filter for ARP
82
and what you’ll notice is there's no ARP traffic
83
because the traffic is arriving on an access port.
84
Port 1 it’s only gonna be sent out of this port which is port 1.
85
It’s not gonna set out of this port at all.
86
so let’s stop all captures
87
and then what we'll do now is configure this port to be a trunk port
88
and this port to be a trunk port
89
but we'll leave this port shutdown for the moment
90
so that we can see the traffic being captured.
Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.