VLAN, VTP, and The Trunking Best Practices

Vlan, VTP and Trunking are most fundamentals yet important topics in Layer 2 Networking.

I explain this topic from design, theory and hands-on perspective in my CCIE Enterprise Infrastructure Training. 

Before using Vlan, VTP or enabling Trunk in the network, below best practices should be kept in mind.

Of course best practices may not be applicable to every network, so whichever is suitable for your network, on your networking devices, and necessary, then consider them.  

  • VTP is generally not recommended anymore because of configuration complexity and the potential for catastrophic failure. In other words, a small mistake on the VTP configuration can take whole network down.
  • If VTP must be used, VTP Transparent mode is best practice because it decreases the potential for operational error.
  • Always configure VTP Domain name and password.
  • Manually prune unused VLANs from trunked interfaces to avoid broadcast propagation.
  • Don’t keep default VLAN as native VLAN, it protects from VLAN hopping attacks.
  • Disable trunks on host ports.
  • Don’t put too many host in one VLAN; keep it small to provide manageable fault domain. In the same VLAN all broadcast unknown unicast packets have to be processed by all the nodes.
  • If fast convergence is required, don’t use Dynamic Trunking Protocol (DTP). DTP slows down the convergence because switches negotiate the trunking mode.
There are other Layer 2 networking topics and the best practices post on the website. I recommend you to have a look at them as well. If you want to see more Best Practice post, share your comment in the comment section below.

Created by
Orhan Ergun

Orhan Ergun, CCIE/CCDE Trainer, Author of Many Networking Books, Network Design Advisor, and Cisco Champion 2019/2020/2021

He created OrhanErgun.Net 10 years ago and has been serving the IT industry with his renowned and awarded training.

Wrote many books, mostly on Network Design, joined many IETF RFCs, gave Public talks at many Forums, and mentored thousands of his students.  

Today, with his carefully selected instructors, OrhanErgun.Net is providing IT courses to tens of thousands of IT engineers. 

View profile