User's Manual
17-16
Cisco IE 2000 Switch Software Configuration Guide
OL-25866-01
Chapter 17 Configuring VLANs
VLANs
  • Trunk ports cannot be dynamic-access ports, but you can enter the switchport access vlan dynamic 
interface configuration command for a trunk port. In this case, the switch retains the setting and 
applies it if the port is later configured as an access port. 
You must turn off trunking on the port before the dynamic-access setting takes effect.
  • Dynamic-access ports cannot be monitor ports.
  • Secure ports cannot be dynamic-access ports. You must disable port security on a port before it 
becomes dynamic.
  • Private VLAN ports cannot be dynamic-access ports.
  • Dynamic-access ports cannot be members of an EtherChannel group. 
  • Port channels cannot be configured as dynamic-access ports.
  • A dynamic-access port can participate in fallback bridging.
  • The VTP management domain of the VMPS client and the VMPS server must be the same.
  • The VLAN configured on the VMPS server should not be a voice VLAN.
VMPS Reconfirmation Interval
VMPS clients periodically reconfirm the VLAN membership information received from the VMPS.You 
can set the number of minutes after which reconfirmation occurs.
If you are configuring a member switch in a cluster, this parameter must be equal to or greater than the 
reconfirmation setting on the command switch. You must also first use the rcommand privileged EXEC 
command to log in to the member switch.
Dynamic-Access Port VLAN Membership
The VMPS shuts down a dynamic-access port under these conditions:
  • The VMPS is in secure mode, and it does not allow the host to connect to the port. The VMPS shuts 
down the port to prevent the host from connecting to the network.
  • More than 20 active hosts reside on a dynamic-access port.
To reenable a disabled dynamic-access port, enter the shutdown interface configuration command 
followed by the no shutdown interface configuration command.










