ZNetLab › Published › Article

Trunks, native VLANs, and the mismatch that drops traffic quietly

ArticleSwitching@admin2 min read

Trunks, native VLANs, and the mismatch that drops traffic quietly

A trunk carries a tag per frame — except for one VLAN, which it does not. That exception is where the outages come from.

An access port belongs to one VLAN and carries untagged frames. A trunk carries many VLANs over one cable, and tells them apart with a 4-byte 802.1Q tag inserted into each frame. Simple enough — and then there is the native VLAN, which is the one VLAN on a trunk whose frames are sent without a tag.

Why the untagged exception exists

Historically, so a trunk could still talk to something that does not understand tags. In practice it is a trap, because the two ends of a trunk each decide for themselves which VLAN "untagged" means.

SW1(config)# interface GigabitEthernet0/1
SW1(config-if)# switchport mode trunk
SW1(config-if)# switchport trunk native vlan 99
SW1(config-if)# switchport trunk allowed vlan 10,20,99

If SW1 says native 99 and SW2 says native 1, then a frame SW1 sends untagged for VLAN 99 arrives at SW2 and is put into VLAN 1. Traffic does not stop — it goes somewhere else. That is worse than a failure, because a failure gets reported and this gets reported months later as "sometimes the printer is unreachable".

The three things to check when a VLAN will not cross a trunk

Check it, do not assume it

SW1# show interfaces trunk
Port        Mode         Encapsulation  Status        Native vlan
Gi0/1       on           802.1q         trunking      99

Port Vlans allowed on trunk Gi0/1 10,20,99 ```

Two columns, both worth reading every time: Native vlan and Vlans allowed. The campus VLAN lab in the simulator has a trunk you can break this way deliberately — change the allowed list to one VLAN and watch which PC stops answering, then put it back with add and notice that this time nothing else was lost.

And the advice everybody gives

Set the native VLAN to something unused — 999 is common — and put no access ports in it. Then an untagged frame arriving on a trunk lands in a VLAN with nothing in it, which is the safe answer to a question nobody asked.

vlantrunkdot1qccna

Join the discussion

Replies, likes and bookmarks live in the community half, which needs a free account. Writing here is free too, and everything is reviewed before it is published.

Open this in the communityEverything publishedHow this works