
Access your free CCNA security 210-260 course from the left navigation, view the introductory section, download videos, and receive daily updates as switching fundamentals and SDM launch the boot camp.
Explore switching fundamentals from hubs and CSMA/CD to collision and broadcast domains, and learn how switches build MAC address tables, forward frames, and contrast static versus dynamic entries.
Explore how a newly booted switch builds its MAC address table, with dynamic learning and static entries, floods unknown unicast frames, and forwards to learned destination ports.
Learn how dynamically learned mac addresses age out of the mac address table, set aging time with the mac address table aging time command, and disable aging with 0.
Explore dynamically learned MAC addresses and VLAN behavior on a live multi-layer switch, watching the MAC address table aging with a 10 minute timer and a port move alter VLAN membership.
Discover how SDM templates allocate switch resources among routing, switching, and security, and learn to apply and reload templates to optimize unicast MAC addresses and IPv4/IPv6 routing.
Explore how autonegotiation affects port speed and duplex settings, including parallel detection, duplex mismatch, and the impact of hard coded speeds on Cisco switches.
Explore power over ethernet fundamentals, including Cisco discovery protocol negotiation and 802.3af/802.3at standards, and how switches power IP phones, using show power commands to monitor watts and power classes.
Explore how to configure inline power over Ethernet on switches using auto, max, consumption, and high-priority options, including milliwatt limits and cooling considerations.
Explore the fundamentals of VLANs and trunking, and how dividing a switch into VLANs limits broadcasts. Learn static and dynamic VLAN membership and how to verify with show vlan brief.
Create and name VLAN 12, assign ports one and two as access ports, and verify connectivity; learn that inter-VLAN traffic requires a router or multilayer switch.
Learn the fundamentals of dynamic VLANs, including how VMP assigns port membership automatically, how to view VLANs, and why dynamic VLANs simplify moving devices compared to static VLANs.
Troubleshoot vlan connectivity by verifying cabling and port assignments, checking layer 1 basics, enabling CDP, and correcting a cabling mix-up to restore host communication in vlan 12.
Verify host connectivity and CVP neighbor status with ping tests in VLAN 5 troubleshooting lab part 2, and use Cisco discovery protocol to confirm physical connections in a shared lab.
Learn how trunk links connect multiple switches to carry traffic for multiple VLANs, configure 802.1Q trunks, examine native VLANs and allowed VLANs, and verify connectivity with pings.
Compare ISL and 802.1Q trunking, highlight ISL's Cisco proprietary double tagging overhead, and contrast with 802.1Q's single tagging and native VLAN considerations for multi-vendor environments.
Configure the native VLAN on trunk ports using the interface range command, assign VLAN 12 to access ports, and resolve native VLAN mismatches with trunk verification.
Explore trunk negotiation and 802.1Q encapsulation on Cisco switches, comparing desirable and auto modes, and examine why disabling DTP reduces overhead and enhances security.
Demonstrate vlan 10 dtp lab realities, verify per-port DTP with show interface and interface range commands, and disable DTP to enforce unconditional trunking on fast 0/11–12.
Configure and troubleshoot DTP trunking on Cisco switches, convert ports to unconditional trunking, disable DTP negotiation, and verify trunk status with show interface trunk across switches.
Configure the allowed vlans on a trunk to reduce unnecessary broadcast traffic, then use add, remove, or except to tailor the list and verify with show interface trunk.
Learn to control vlan access on trunks by using allow and except commands, verify with show interface trunk, and troubleshoot via layer 2 checks and selective debugs.
Explore configuring voice VLANs on switches, using 802.1Q trunks and access links to prioritize voice traffic, set PVIDs and voice VLAN IDs, and enable port fast to reduce jitter.
Showcases how VTP domains manage VLAN information across switches, detailing versions 1–3 and four modes, highlighting domain name case sensitivity, advertisements, and server-mode joins.
Explore VTP modes—server, client, transparent, and off for version 3—and how they affect advertisements, domain changes, and switch behavior, including the configuration revision process.
Explore how vtp config revision numbers propagate between switches via summary and subset advertisements, and learn how to reset revisions to zero to prevent sync issues.
Explore differences among VTP versions 1–3, including token ring switching, consistency checks, and the introduction of secure mode and password handling, plus the primary server concept for synchronization.
Learn how VTP versions affect compatibility, and how pruning limits broadcast, unknown unicast, and multicast traffic to active VLANs, following Cisco's guidance for a homogeneous environment.
Explore the spanning tree protocol: prevent layer 2 switching loops by blocking backup paths and unblocking the primary path, and compare layer 2 and layer 3 redundancy with feasible successors.
Stp 2: configuring BPDU use, understand root bridge election, and how bids, priority, and MAC addresses determine the root switch in a multi-switch network.
Identify the root and non-root bridges in STP using show spanning-tree, recognizing route IDs, bridge IDs, designated ports, and the distinction between route ports and alternate ports on non-root switches.
explain how stp uses port path costs and root path costs carried in bpdu to select root and route ports, with blocking and designated ports across a multi-switch lab.
Explore how STP port costs shaped by speed determine the shortest path, adjust costs, and observe transitions to blocking, listening, learning, and forwarding in a lab, plus per-VLAN load balancing.
Configure per-VLAN load balancing with spanning-tree path cost to steer VLANs 30 and 40 along an alternate path while VLANs 10 and 20 stay on the primary path.
Review STP port states from disabled through blocking, listening, learning, and forwarding, and apply per-VLAN load balancing using port priority to influence path selection.
Explore the spanning tree protocol timers, including hello time, forward delay, and max age, and learn static versus dynamic changes and where to apply them on root and non-root switches.
Configure and manage STP root bridges across VLANs to distribute routing roles. Use spanning-tree commands to set primary and secondary routes for VLANs 20 and 30.
Explain how spanning-tree priorities are calculated, including route priority with the system ID extension and increments of 4096. Demonstrate how manual priority changes affect the root and route across switches.
Learn how port fast works, how to enable or disable it globally or per port, and when to apply it on non-trunk ports to avoid bridging loops.
Master uplinkfast in stp to speed failover by bypassing listening and learning. Learn how uplink group ports, route costs, and mac address table updates ensure quick, loop-free switching.
Enable Cisco proprietary backbone fast across switches to speed recovery from indirect link failures and root bridge role, while inferior BPTs are ignored and requests and responses sustain backbone heartbeat.
Demonstrates STP root guard in action by configuring root guard on the link to prevent rogue switches from becoming the root, observing BPDU blocking and route-inconsistent states.
Enable bpdu guard on portfast ports to automatically disable a port when a bpdu arrives, placing the interface into an error-disabled state and preventing loops.
Explore bpdu filter and bpdu guard on portfast-enabled ports, loop guard to prevent loops, and use show spanning summary to read per-vlan and port states and spanning-tree modes.
UDLD detects unidirectional links by exchanging DLT frames and echoes. In normal mode it alerts, while aggressive mode sends frames every second and may disable the port on no response.
Explore rapid spanning tree protocol as an extension of stp, enabling faster convergence and clearer port roles, including edge ports, alternate and backup ports, and edge port behavior.
Explore how rapid spanning tree protocol synchronizes networks, moving ports from discarding to forwarding as the root coordinates proposals and agreements, with BPDU version numbers.
Learn how CST, MST, and PVST types govern spanning tree behavior, including CST scope, MST region concepts, and PVST plus advantages for load balancing across multiple VLANs.
Explore building an ether channel (port channel) to aggregate multiple links, boosting bandwidth and reducing delay, while the channel behaves as a single link and adapts to failures.
Learn how to negotiate and verify ether channels using LACP and PAGP, configure port channels, troubleshoot failures, and verify load distribution with key show commands.
Understand how etherchannel load distribution uses a Cisco hash algorithm to map traffic flows to links, based on source/destination ip addresses, mac addresses, or ports, enabling per-flow balancing.
Explore the nuts and bolts of multilayer switching, including layer 2 versus layer 3 roles, MLS architecture, CEF, FIB and adjacency tables, and hardware-based routing on layer 3 switches.
Enable IP routing on the multilayer switch, create two switched virtual interfaces for VLAN 11 and VLAN 33, assign IPs, configure default gateways, and verify with pings.
Configure a routed port on the multilayer switch and assign a layer 3 IP to connect to the router. Establish an EIGRP adjacency and verify connectivity with targeted pings.
explore the virtual switching system (vss) where a pair of physical switches forms a single logical switch, communicates over the VSL, and uses stateful switchover and NSF to minimize downtime.
Stackwise links up to nine switches into a single master-controlled stack with a shared iOS image, automatic member onboarding, and seamless failover, delivering up to 32 Gbps bidirectional capacity.
Explore how HSRP creates a virtual router with active and standby roles on multi-layer switches, enabling hosts to use the virtual IP as the default gateway.
Explore how HSRP active router elections use priority and preemption to determine the active router, verify with show standby, and understand when the highest IP address theory may fail.
Explore HSRP load balancing by configuring multiple HSRP groups with virtual router IPs to share traffic across switches, and learn HSRP states and hosts' default gateways.
Learn to configure hsrp interface tracking to monitor a specified interface, dynamically adjust the standby priority, and enable preemption so a higher-priority router takes over when the interface fails.
Configure hsrp interface tracking to influence failover by adjusting the tracking interface's decrement value and priority, and verify behavior with show standby during interface down and back up.
Configure HSRP timers, including hello and hold times, and implement MD5 authentication with key strings or key chains. Encrypt passwords with service password encryption.
Explore VRRP fundamentals and object tracking, compare VRRP to HSRP, configure master and backup roles with preemption enabled, and implement interface tracking using a track object.
Demonstrates VRRP load balancing with two virtual routers, separate VRRP groups, and master/backup roles, distributing host default gateways across both routers for redundancy and traffic balance.
Use GLBP show commands to configure a virtual router in group 1 and verify the 172.16.23.12 address, then examine preemption, forwarders, and active standby states.
Learn how GLBP uses priority to select the active virtual gateway and how preemption shifts roles among three forwarders, with verification via the brief option.
Explore how GLBP AVF cutover handles router failure by observing virtual MAC addresses, active and standby roles, and the timers that manage load distribution across routers.
this lecture explains GLBP timers, including hello time, hold time, redirect timeout, and forwarder timeout, showing how timer values affect virtual mac addresses, active routers, and failover.
Explore GLBP tracking and interface tracking to control the default active and backup groups, adjust priority with preemption, and set thresholds to govern AVF eligibility.
Explore port security on Cisco switches by configuring per-port secure MAC addresses, handling violations with shutdown, protect, or restrict, and using static, dynamic, sticky addresses with aging options.
Enable port security on the switch port and apply a static secure MAC address. Then shut and no shut the port to observe secure, dynamic MAC learning and violations.
Explore port security on fast ethernet 0/2, set a max of three secure MAC addresses, configure two static addresses, verify the next learned address becomes dynamic, and review outputs.
Explore port security aging time and MAC address table aging, mastering static versus dynamic entries, inactivity timers, and correctly interpreting iOS time units to avoid exam pitfalls.
Explore port security sticky addressing: convert dynamic MAC addresses to sticky, preserve secure addresses across reloads, and verify with show port security address while understanding per-port aging.
Demonstrates error disable recovery for port security violations by configuring MAC addresses, triggering a violation, and using the error disable recovery command with a 30-second timer to recover the interface.
Explore dot1x port-based authentication with radius and EAP extensions, the roles of supplicant and authenticator, and the use of controlled and uncontrolled ports alongside port security.
Discover how to configure local span and remote span to mirror traffic to a network analyzer, using source and destination ports across switches for effective traffic analysis.
Master remote span setup with monitor sessions by defining source ports and a destination VLAN, such as VLAN 30, to mirror traffic between switches.
Explore storm control to prevent broadcast, multicast, and unknown unicast floods by configuring rising and falling thresholds per port and selecting actions (drop, shutdown, trap) with verification via show commands.
Explore how VLAN access control lists (VACLs) filter traffic within a VLAN on a multilayer switch, and block the first three hosts 10.1.1.1-3 using a VLAN access map.
Explore private VLAN theory, detailing primary and secondary private VLANs and three port types—promiscuous, community, and isolated—and how mappings control host communication.
Verify private vlan configurations via commands showing primary and secondary vlans, community or isolated types, and port details; use show interface switchport to inspect administrative and operational modes and associations.
Master dhcp fundamentals by following the discover–offer–request–ack flow, learn to configure pools, exclude addresses, and set leases on a router or multilayer switch in a hands-on lab.
Explore DHCP address assignments, including pools, leases, bindings, and static versus dynamic addresses, and learn to use ip helper-address to relay messages across routers and switches.
Configure DHCP manual address binding on a Cisco switch using a client identifier to assign a static IP from a dedicated pool, verify bindings, and manage conflicts.
Explore dhcpv6 concepts, including stateless auto configuration, link-local addresses, duplicate address detection, and router solicitation and advertisement for IPv6 configuration.
Enable dhcp snooping to block rogue dhcp offers by classifying ports as trusted or untrusted, configure globally with ip dhcp snooping, and use option 82 to extend trust where needed.
Discover how dynamic ARP inspection prevents ARP spoofing and man-in-the-middle attacks by validating IP-to-MAC mappings with DCP snooping data on trusted and untrusted ports.
Explore ip source guard theory as the lab begins, showing how dhcp snooping binds host ip addresses to switch ports, prevents spoofing, and teaches commands like ip verify source.
Explore IP source guard and complete the binding steps, then examine VLAN hopping risks from double tagging and switch spoofing, and implement protections with access ports and pruning native VLANs.
Learn to use Cisco Discovery Protocol to verify network topology, view neighbors, and diagnose issues, while evaluating security risks and alternatives like LLDP for mixed vendor environments.
Explore telnet versus ssh, their encryption and authentication methods, and essential steps to enable ssh on Cisco devices using vty lines and crypto keys.
Design and analyze the Cisco three-layer switching model, core, distribution, and access layers, with emphasis on redundancy, quality of service, and the enterprise composite network for campus networks.
The CCNP SWITCH exam is a tough one, and I'm ready to help you pass it with my CCNP SWITCH Video Boot Camp. I've packed this course with real-world networking examples, so while you're learning the skills you need to pass the CCNP SWITCH exam, you're also learning important real-world networking skills that you'll use long after you earn your CCNP.
All videos fully downloadable and my Udemy courses all carry a 30-day money-back guarantee!
I've been preparing CCNP candidates for success on the SWITCH exam for years with my no-nonsense lectures using REAL Cisco switches - no simulators here - and now I'm going to do the same for you.
No prepackaged slides here - you'll see CCNP Switch Lab after lab on REAL Cisco switches, all designed to teach you the finer points of advanced Cisco switching and prepare you for success in the exam room and real-world networking. From advanced STP features to multicasting and everything in between it's all here - and there's a forum right here on this site where you can ask me questions.
Your access to this online course is unlimited - you can watch the videos as often as you like and for as long as it takes for you to pass!
Let's get started!
Chris Bryant CCIE #12933
"The Computer Certification Bulldog"