I'm going through the fun task of migrating twenty odd access switches to a new distribution later.
The downside seems to be that it looks as if there has been no deprovisioning process on these switches and they have unused vlans still active in the switches management domain and being trunked with the heinous 'switchport trunk allowed vlans all'
Before the migration takes place I would like to clean this all up by removing the vlans from the switches that are not in use and restricting the allowed vlan list on the uplinks with only layer two traffic that needs to span via the distrabution later. I would like to tell you how I plan on doing this and see if you can point out any gotchas that I have overlooked;
1. For each vlan on the switches management domain ; 'show vlan brief'
Run 'show mac address-table vlan X | ex CPU'
If the results show;
SWITCH#show mac address-table vlan 123| ex CPU
Mac Address Table
Vlan Mac Address Type Ports
---- ----------- -------- -----
Total Mac Addresses for this criterion: 20
This shows that no mac addresses are present within this vlan and the vlan is not in use at all.
This vlan can then be removed with the 'no vlan X' command.
2. To restrict the traffic spanning to the distrabution layer I would complete the same command;
'show mac address-table vlan X | ex CPU'
If only mac addresses for this vlan are seen on the interswitch trunk and no mac addresses are seen from any of the other local switches interfaces then this would show that no devices attached to the switch are using this vlan, only the system or dynamic macs of other devices on the fabric are being learnt from the interswitch trunk.
These vlans can be removed on the switch again with the 'no vlan X' command. Once the vlans have been removed from the switch the device will remove them from the uplinks allowed list 'show int trunk | i X' ( 'X' again means vlan number.)
This all hangs on the fact thateven if one of these vlans are in use and assigned to a trunk, if it's in use it must generate mac addresses to function on ethernet so if there are no mac addresses showing then as far as I see it the vlan is inactive and can be removed.
Can anyone point out anything that I am missing, or see any problems with this logic?
Cisco DNA Center version 2.2.2.x includes the features and improvements that
New intelligence provides an easy, gradual, and complete adoption of SD-Access. Faster Cisco DNA Center set-up saves time and effort.
When using Cisco cellular modules with a SIM card an APN must be provided. The APN cannot be stored in the SIM card and is supplied by your SIM card provider. Cisco cellular software contains a database of well-known APNs based on the country and ...
Cisco 3850: IOS-XE/Firmware Upgrade
This procedure is aimed at Cisco 3850 switch ONLY.
IOS-XE Bundle Mode is not covered.
9300, 9500 (vanilla & high-performance), ISR 1k, ISR 4k and ASR is not covered.
Listen: https://smarturl.it/CCRS8E46Follow us: twitter.com/ciscochampionsIt’s been several years since the release of Cisco DNA Center, and it’s matured into a complete network management system, an automation and orchestration engine, an AI/ML analy...
The 2021 IT Blog Awards, hosted by Cisco, is now open for submissions. Submit your blog, vlog or podcast today. For more information, including category details, the process, past winners and FAQs, check out: https://www.cisco.com/c/en/us/t...