Trunks, native VLANs, and the mismatch that drops traffic quietly
A trunk carries a tag per frame — except for one VLAN, which it does not. That exception is where the outages come from.
An access port belongs to one VLAN and carries untagged frames. A trunk carries many VLANs over one cable, and tells them apart with a 4-byte 802.1Q tag inserted into each frame. Simple enough — and then there is the native VLAN, which is the one VLAN on a trunk whose frames are sent without a tag.
Why the untagged exception exists
Historically, so a trunk could still talk to something that does not understand tags. In practice it is a trap, because the two ends of a trunk each decide for themselves which VLAN "untagged" means.
SW1(config)# interface GigabitEthernet0/1
SW1(config-if)# switchport mode trunk
SW1(config-if)# switchport trunk native vlan 99
SW1(config-if)# switchport trunk allowed vlan 10,20,99
If SW1 says native 99 and SW2 says native 1, then a frame SW1 sends untagged for VLAN 99 arrives at SW2 and is put into VLAN 1. Traffic does not stop — it goes somewhere else. That is worse than a failure, because a failure gets reported and this gets reported months later as "sometimes the printer is unreachable".
The three things to check when a VLAN will not cross a trunk
- Is the VLAN allowed?
switchport trunk allowed vlanis a list, and - Does the VLAN exist on both switches? A VLAN that has not been created
- Do the native VLANs match? CDP will tell you if both ends run it:
Check it, do not assume it
SW1# show interfaces trunk
Port Mode Encapsulation Status Native vlan
Gi0/1 on 802.1q trunking 99
Port Vlans allowed on trunk Gi0/1 10,20,99 ```
Two columns, both worth reading every time: Native vlan and Vlans
allowed. The campus VLAN lab in the simulator has a trunk you can break
this way deliberately — change the allowed list to one VLAN and watch which
PC stops answering, then put it back with add and notice that this time
nothing else was lost.
And the advice everybody gives
Set the native VLAN to something unused — 999 is common — and put no access ports in it. Then an untagged frame arriving on a trunk lands in a VLAN with nothing in it, which is the safe answer to a question nobody asked.
Join the discussion
Replies, likes and bookmarks live in the community half, which needs a free account. Writing here is free too, and everything is reviewed before it is published.
Open this in the communityEverything publishedHow this works