Trunks and pruning...

I am trying to find a good reason why I should go through the extra effort of pruning vlans off trunks.  No DTP or VTP in the network.  The core has all the vlans and the IDFs only needs 2 vlans, management and an access vlan.  So the only thing I can think of is if I don't prune all the vlans then extra unneed broadcast traffic will be sent to IDFs that don't need it.  So here is my question.  If the vlan isn't on the IDF switch will the core still send the traffic down the trunk?  Does the "Vlans allowed and active in management domain" mean that is forwarding all boardcast traffic down those links?

Show int trunk on the core

6509#sh int trunk

Port                Mode         Encapsulation  Status        Native vlan

Po1              on           802.1q         trunking      1

Port                Vlans allowed on trunk

Po1               1-4094

Port                Vlans allowed and active in management domain

Po1              1-20

Port                Vlans in spanning tree forwarding state and not pruned

Po1              1-20


c3560#sh int trunk

Port        Mode             Encapsulation  Status        Native vlan

Po1         on               802.1q         trunking      1

Port        Vlans allowed on trunk

Po1         1-4094

Port        Vlans allowed and active in management domain

Po1         1,10

Port        Vlans in spanning tree forwarding state and not pruned

Po1         1,10

Joseph W. Doherty
Hall of Fame Expert


In answer to your questions, yes and yes.

Beside broadcast, VLAN(s) multicast could be sent down the link along with VLAN(s) unicast flooding.

If you have another switch downstream of the IDF, also trunked, it (the IDF) wouldn't forward the traffic for a VLAN(s) it didn't also recognize.


I want to add a comment to Joseph's reply

To avoid these broadcast and unicast traffic issues and also to secure the core switches from the layer 2 attacks from the IDFs (Users) cisco suggests to go with the Layer 3 links between core and MDF/IDFs.