Cisco DTP Explained: VLANs, Switchport Modes and Connectivity Lab
In this lab, we will explore how Dynamic Trunking Protocol (DTP) and VLAN configuration affect communication between interconnected Cisco IOS switches.
We will test three different scenarios by changing the switchport configuration, disabling DTP, and assigning different VLANs to the switches. We will then use ping tests and packet captures to understand how the switches handle Ethernet frames and VLAN traffic.
This lab provides a practical way to understand DTP, switchport modes, VLANs, trunking, access ports, and Layer 2 connectivity.
Task 1: Disable DTP on One Switch
In this scenario, DTP will be disabled on one switch while it remains enabled on the other switch. We will observe the behavior of PC1 and PC2 and use packet captures to analyze the frames exchanged between the switches.
Task 2: Disable DTP on Both Switches
In this scenario, DTP will be disabled on both switches. We will test connectivity between PC1 and PC2 and analyze the packet captures to understand how the switches communicate without DTP negotiation.
Task 3: Configure Different VLANs on Each Switch
In this scenario, we will assign one VLAN to the interfaces on the first switch and a different VLAN to the interfaces on the second switch. We will then test connectivity and analyze the packet captures to understand how the VLAN configuration affects Layer 2 communication.

Topology
Understanding Cisco Switchport Modes
Cisco switchports can operate in different modes depending on how the port is intended to be used. Access ports connect end devices to a single VLAN, while trunk ports can carry traffic for multiple VLANs. Some switchport modes also use Dynamic Trunking Protocol (DTP) to negotiate trunking with the neighboring switch.
The following sections explain the main switchport modes used in this lab.
Switchport Mode Trunk
The switchport mode trunk command configures the interface as a trunk port. The port can carry traffic for multiple VLANs. Depending on the platform and configuration, DTP may also be used to negotiate trunking with the neighboring device.
Switchport Nonegotiate
The switchport nonegotiate command disables DTP negotiation on the interface. The port will not send DTP frames. This is useful when the trunking configuration is manually controlled on both ends of a link.
Switchport Mode Dynamic Desirable
The switchport mode dynamic desirable command actively attempts to negotiate a trunk link using DTP. If the neighboring interface supports compatible DTP negotiation, the link can become a trunk.
Switchport Mode Dynamic Auto
The switchport mode dynamic auto command places the interface in a passive DTP state. The interface waits for the neighboring switch to initiate trunk negotiation.
Switchport Mode Access
The switchport mode access command configures the interface as an access port. The port carries traffic for a single VLAN and is typically used to connect end devices such as computers, printers, and servers.
Switchport Trunk Encapsulation
The switchport trunk encapsulation configuration is used to specify the trunking protocol used on the port. It means that the port will not negotiate the trunking protocol using DTP frames. Instead, it will only use the protocol specified in the configuration.
Disabling DTP on both switches
DTP behavior depends on the switchport configuration. The switchport nonegotiate command disables DTP negotiation on an interface. Configuring an interface as an access port also prevents it from operating as a negotiated trunk.
Test 1: DTP Disabled on One Switch
We changed the Ethernet 0/0 interface on Switch 1 to an access port, which prevented DTP negotiation on that interface. DTP remained enabled on Ethernet 0/0 of Switch 2.
We then tested connectivity between VPC3 and VPC4 by sending a ping from VPC3 to VPC4. Both switches remained in their default VLAN configuration, with VLAN 1 as the default VLAN.
Result:
The ping from VPC3 to VPC4 was successful. This shows that the hosts could communicate despite DTP being disabled on Switch 1.
Reason:
Why did the ping succeed?
DTP was disabled on Switch 1 because its Ethernet 0/0 interface was configured as an access port. Switch 2 continued to use its existing switchport configuration.
Both interfaces ultimately carried traffic for VLAN 1, allowing the hosts to remain in the same Layer 2 broadcast domain. As a result, the ARP request from the source host could reach the destination host, allowing the ping to succeed.
The packet capture also showed that Switch 2 continued to send DTP frames, while Switch 1 did not respond because DTP was disabled on its interface.
Screenshot of the source side switch exit interface

Screenshot of the destination side switch exit interface

After taking the packet capture from the source side switch exit interface, it is evident that the switchport is sending only STP and CDP packets and not DTP signals.
Packet Capture from source side switch exit interface

Switch 2 sends DTP packets, however, switch 1 does not respond to them as the DTP is disabled.
Then switch sends the CDP packet with native VLAN ID information and subsequently switch 1 sends the CDP packet with native VLAN information and finally switch 2 sets its switchport type to access mode, see the screenshot for reference
Source side switch exit interface PCAP screenshot

Both switchport ethernet 0/0 of switch 1 and switch are in the same VLAN, so the ARP broadcast traverses the switch and reaches the destination host and thus ping output is successful.
Test 2: DTP Disabled on Both Switches
We changed the Ethernet 0/0 interface on Switch 2 to an access port, disabling DTP negotiation on that interface. Both switchports were now operating as access ports in VLAN 1.
Result:
The ping between the hosts was successful.
Reason:
Why did the ping succeed?
Both switchports belonged to VLAN 1, so the hosts remained in the same Layer 2 broadcast domain. When a host sent an ARP request, the switches forwarded the broadcast within VLAN 1. The destination host received the request and returned an ARP response containing its MAC address.
The hosts could then use the learned MAC address to exchange traffic successfully.
Test 3 Different VLANs on Each Switch
We configured all relevant interfaces on Switch 1 as access ports in VLAN 10. The corresponding interfaces on Switch 2 were configured as access ports in VLAN 20. DTP was disabled on both switches.
Result:
The ping was successful.
Reason:
Once the switch receives an untagged from its host it marks the native VLAN ID of the receiving switchport to its tag field which in this case is VLAN 10 and does an ARP request in VLAN 10 broadcast domain, it reaches the egress port of the switch 1 (ethernet 0/0) and leaving the egress port it removes the VLAN tag from it, now the ingress port of the switch 2 receives the untagged frame and tags its native VLAN ID to it which is VLAN 20 in this case and relay the ARP broadcast to its broadcast domain and reaches the destination.
Interface VLAN information on switch 1

Switch Notifying the VLAN Mismatch

Packet Capture Screenshot from ingress interface of switch 2

Conclusion
This lab demonstrated how Dynamic Trunking Protocol (DTP), switchport modes, and VLAN configuration affect communication between interconnected Cisco IOS switches.
By testing different configurations, we observed how disabling DTP changes switchport behavior and how VLAN assignments influence Layer 2 connectivity. Packet captures provided additional evidence of the control and data traffic exchanged between the switches, including DTP, CDP, STP, ARP, and VLAN-related information.
The lab also highlights the importance of understanding access ports, trunk ports, DTP negotiation, and VLAN membership when troubleshooting Cisco switch connectivity.
Overall, this exercise provides a practical foundation for understanding Cisco DTP, VLAN configuration, switchport modes, trunking, and Layer 2 network troubleshooting.