Frequently Asked Questions of VTP
Got questions? We've got the answers quick, clear, and hassle-free as per mentioned FAQ
FAQ Execution
VTP is a Cisco proprietary Layer 2 messaging protocol that automates the synchronization and management of VLAN configurations (VLAN IDs, names, and parameters) across interconnected switches within a single administrative domain.
It eliminates the need to manually create, edit, or delete VLANs on every single switch in a enterprise network. Updating the configuration on a central switch propagates changes automatically across the domain, reducing administrative overhead and human error.
VTP operates at Layer 2 (Data Link Layer) of the OSI model using Ethernet frames sent to a specific multicast MAC address (01-00-0C-CC-CC-CC).
VTP is proprietary to Cisco. While some non-Cisco vendors support transparent/passthrough handling of VTP frames, true VTP administration is exclusive to Cisco IOS/NX-OS devices.
VTP frames are encapsulated in IEEE 802.1Q or ISL trunking frames and sent as LLC (Logical Link Control) frames with a destination MAC address of 01-00-0C-CC-CC-CC.
VTP Modes
Server Mode: Can create, modify, and delete VLANs; originates and propagates VTP advertisements; saves configuration to NVRAM.
Client Mode: Cannot create, modify, or delete VLANs; receives and applies updates from VTP servers; forwards advertisements; does not save VLANs to NVRAM.
Transparent Mode: Ignores incoming VTP updates and does not advertise local changes, but forwards VTP messages across trunk links; saves VLAN configuration locally in NVRAM.
In VTP Version 3, "Off" mode disables VTP functionality completely. Unlike Transparent mode, a switch in Off mode does not forward received VTP advertisements to other switches.
By default, Cisco switches boot in Server Mode.
VLAN configurations are stored in the non-volatile vlan.dat file located in flash memory. In VTP Transparent mode, settings are also saved to startup-config.
Client mode stores the VLAN database purely in volatile RAM. Upon a reboot, the client relies on receiving fresh VTP advertisements from a server to repopulate its VLAN table.
VTP Revision Numbers & Synchronization
It is a 32-bit scalar value that starts at 0 and increments by 1 every time a change (addition, deletion, rename) is made to the VLAN database on a VTP Server.
When a switch receives a VTP advertisement with a higher Configuration Revision Number than its current revision number, it overwrites its local VLAN database to match the update.
If a previously configured switch with a higher revision number and matching domain name/password is connected to the network, all other switches in Server or Client mode will immediately adopt its VLAN table, potentially erasing all active VLANs and causing a network blackout.
1. Change the VTP domain name to a temporary dummy string, then change it back.
2. Change the VTP mode to Transparent and then back to Server or Client mode.
No, Transparent mode always reports its Configuration Revision Number as 0 and ignores revision numbers in incoming advertisements.
VTP Messages & Packets
Summary Advertisements: Sent every 5 minutes or immediately after a change to announce the domain name and revision number.
Subset Advertisements: Follow a Summary advertisement and contain the actual detailed VLAN configuration changes.
Advertisement Requests: Sent by a client or server when it boots up, resets, or receives a Summary frame with a higher revision number than its own.
VTP Pruning Advertisements: Used to coordinate dynamic pruning of unneeded broadcast traffic over trunk links.
By default, VTP Summary Advertisements are multicast every 5 minutes (300 seconds), even if no configuration changes have occurred.
1. Trunk link configured and active between them.
2. Identical VTP domain names (case-sensitive).
3. Matching VTP passwords (if configured).
4. Compatible VTP versions.
No, VTP advertisements are strictly transmitted and received over trunk links (IEEE 802.1Q or Cisco ISL).
VTP Version, Domain Name, Revision Number, Updater Identity (IP address), Timestamp, MD5 Checksum and the number of Subset Advertisements to follow.
VTP Versions (v1, v2, v3)
Version 2 adds support for Token Ring VLANs, It supports unrecognized TLV (Type-Length-Value) parsing in Transparent mode and performs consistency checks on input commands when entering new parameters via CLI/SNMP.
Support for Extended Range VLANs (VLAN IDs 1006–4094), Support for Private VLANs (PVLANs), Enhanced security via Primary/Secondary server roles to prevent rogue switch overwrites, Ability to turn VTP off completely per interface or globally (vtp mode off) and Propagation of MST (Multiple Spanning Tree) configuration databases.
VTP v3 introduces the concept of a Primary Server. VLAN modifications can only be made on a explicitly designated Primary Server (promoted using the vtp primary command). Switches with higher revision numbers cannot blindly overwrite the network database unless promoted.
Yes, provided that Version 2-capable switches are configured in VTP v1 mode or automatically fall back. However, all switches in a domain should ideally run the same version for consistency.
VTP Pruning
VTP Pruning is a feature that reduces unnecessary network traffic by preventing broadcast, multicast, and unknown unicast frames from being forwarded over trunk links to switches that have no active ports in that specific VLAN.
No, VTP Pruning is disabled by default.
Execute the global configuration command vtp pruning on a VTP Server switch. This enables pruning across the entire VTP domain.
Standard range VLANs (VLANs 2–1001) are pruning-eligible by default. VLAN 1 and extended VLANs (1006–4094) cannot be pruned.
Switches exchange VTP Pruning Advertisements indicating which VLANs have active access ports connected. If a neighboring switch reports no active ports for VLAN 10, traffic for VLAN 10 is pruned from that trunk link.
Security & Password Protection
When a password is configured using vtp password 'string', the switch computes an MD5 checksum using the password, domain name, revision number, and VLAN configurations. The checksum is included in every summary advertisement.
No, The password itself is not transmitted over the wire. Only the resulting MD5 hash is sent in VTP summary messages.
In VTP v1 and v2, it is stored in the vlan.dat file or visible in running-config (depending on device version and encryption settings). In VTP v3, it can be hidden using the hidden keyword.
VTP advertisements are rejected due to MD5 hash verification failure. VLAN updates will not synchronize between the switches.
No. VTP uses MD5 hashing for authentication/integrity checks, but the actual payload (VLAN names, IDs, states) is sent in unencrypted plaintext frames.
Troubleshooting & Common Issues
The VLAN deletion propagates to all Server and Client switches in the domain. Any access ports assigned to that deleted VLAN become inactive/orphaned, blocking traffic until reassigned to a valid VLAN.
Common causes include: Mismatched VTP Domain names, Mismatched VTP Passwords, Native VLAN mismatch on the trunk link, The interconnecting link is set as an access port instead of a trunk and One or both switches are in VTP Transparent or Off mode.
VTP messages are sent over trunk links using the Native VLAN (VLAN 1 by default). If native VLANs mismatch, VTP frames may drop or fail MD5 integrity checks.
Yes (in VTP v1 and v2), If a Client switch has a higher revision number and matching domain/password, it will overwrite the VLAN configuration of a Server switch with a lower revision number.
Set the VTP mode of the new switch to Transparent, Reset its revision number to 0 by temporarily changing the domain name, Verify its revision number is 0 (show vtp status) and Connect the trunk link and set the desired VTP mode (Client/Server).
Modern enterprise design practices generally recommend running VTP in Transparent Mode (or Off Mode in v3) and manually/automating VLAN provisioning using centralized orchestration tools (such as Cisco DNA Center / Catalyst Center, Ansible, or Terraform) to prevent accidental VLAN wipeouts caused by revision number mismatches.