07-12-2021 08:37 AM
I have a used Catalyst 3650, and I am attempting to change the the unused VLANs' state to suspend. Unfortunately I get the following return message:
%Default VLAN 1002 may not have its operational state changed.
Current VLAN configuration:
#show vlan VLAN Name Status Ports ---- -------------------------------- --------- ------------------------------- 1 default active 1002 fddi-default act/unsup 1003 token-ring-default act/unsup 1004 fddinet-default act/unsup 1005 trnet-default act/unsup VLAN Type SAID MTU Parent RingNo BridgeNo Stp BrdgMode Trans1 Trans2 ---- ----- ---------- ----- ------ ------ -------- ---- -------- ------ ------ 1 enet 100001 1500 - - - - - 0 0 1002 fddi 101002 1500 - - - - - 0 0 1003 tr 101003 1500 - - - - - 0 0 1004 fdnet 101004 1500 - - - ieee - 0 0 1005 trnet 101005 1500 - - - ibm - 0 0
Is it possible to suspend them with a different command so that I can close the unused VLANs, or is this older model not capable of doing so?
Thank you in advance.
Solved! Go to Solution.
07-12-2021 09:21 AM
Those vlans are legacy vlans and you would not be able to use them even if you wanted to ie. the act/unsup part where unsup mean unsupported.
So you are fine to leave them as is.
Jon
07-12-2021 09:58 AM
You do not need to worry those VLAN (100X range one), they no Longer work in new Lan Segment.
07-12-2021 08:41 AM - edited 07-12-2021 08:42 AM
Those are extended VLAN and reserved, they will be default VLAN,
this will not going to effect anything with standard setup ?
what you mean suspend ?
07-12-2021 08:48 AM
We do not use those VLANs, and have no purpose that I am aware of, so we just wanted to suspend them so that our vulnerability scanners do not show them as open. There are other VLANs that I removed from the lines for privacy reasons that we do use, but if you believe it will cause a conflict we can leave 1002-1005 open.
07-12-2021 09:21 AM
Those vlans are legacy vlans and you would not be able to use them even if you wanted to ie. the act/unsup part where unsup mean unsupported.
So you are fine to leave them as is.
Jon
07-12-2021 09:58 AM
You do not need to worry those VLAN (100X range one), they no Longer work in new Lan Segment.
07-12-2021 10:00 AM
Thank you both for the explanation, I will use them as my request for risk acceptance..
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide