5.1 AOS-CX VLAN Configuration and Native VLAN Handling
Key Takeaways
Virtual Local Area Networks (VLANs) divide physical switches into isolated Layer 2 broadcast domains, improving network security, performance, and traffic management.
The IEEE 802.1Q standard inserts a 4-byte tag containing a 12-bit VLAN Identifier (VID); VIDs 0 and 4095 are reserved, so usable VLAN IDs are 1 through 4094.
On CX 6000-6400 access and campus switches, interfaces are Layer 2 by default (routing disabled), while CX 8100 and 8360 ports are routed by default; use
no routingon a routed port beforevlan access <id>orvlan trunk allowed <list>.Trunks carry multiple VLANs with 802.1Q tags, the native VLAN is sent untagged unless
vlan trunk native <id> tagis set, and on AOS-CX the native VLAN must also be in the allowed list.Native VLAN mismatches cause cross-VLAN frame leakage and Spanning Tree type inconsistencies; best practices require pruning unused VLANs and setting an unused native VLAN ID.
AOS-CX VLAN Configuration and Native VLAN Handling
Quick Summary: Virtual Local Area Networks (VLANs) segment physical switches into independent logical broadcast domains at Layer 2. By default, all ports on a factory-fresh switch belong to VLAN 1. Modern campus networks use IEEE 802.1Q tagging to multiplex multiple VLANs across high-speed switch-to-switch and switch-to-AP interconnects known as trunks. On AOS-CX access and campus switches such as the CX 6300 and 6400, routing is disabled on interfaces by default, so ports start as Layer 2 access ports in VLAN 1. On aggregation and core models such as the CX 8100 and 8360, routing is enabled by default, so
no routingis required before assigning access or trunk parameters. Mismatched native VLANs across trunks present severe security risks and spanning tree instability, requiring rigorous trunk pruning and native VLAN tagging best practices.
The Role of VLANs in Campus Network Architecture
In a flat, unsegmented Layer 2 network, every broadcast frame transmitted by an endpoint—such as an Address Resolution Protocol (ARP) request or a DHCP Discover—is flooded out every switch port across the entire local area network. As campus networks scale to hundreds or thousands of connected workstations, wireless access points, IP surveillance cameras, and IoT sensors, unrestricted broadcast traffic consumes substantial link bandwidth and forces every connected endpoint's CPU to process irrelevant frames.
Virtual Local Area Networks (VLANs) solve this scaling limitation by dividing a single physical switch chassis into multiple isolated logical broadcast domains. Key architectural benefits include:
- Broadcast Containment: Broadcast, unknown unicast, and multicast (BUM) traffic is strictly confined to the originating VLAN, preventing campus-wide broadcast saturation.
- Security Segmentation: Devices residing in different VLANs cannot communicate directly at Layer 2. Inter-VLAN communication requires an intermediate Layer 3 device (such as an AOS-CX switch with active routing or an upstream firewall), enabling centralized access control lists (ACLs) and stateful security inspection.
- Logical Topology Independence: Endpoints can be grouped logically by department, function, or security tier (e.g., Corporate Users, Voice, Guest Wi-Fi, Facility IoT) regardless of their physical patch panel or switch port location.
- Simplified Subnet Engineering: In standard campus network design, each Layer 2 VLAN maps directly to a single, dedicated Layer 3 IPv4 subnet and IPv6 prefix (e.g., VLAN 10 =
10.10.10.0/24, VLAN 20 =10.10.20.0/24).
IEEE 802.1Q Encapsulation and Tag Structure
When Ethernet frames travel between an access switch and an end-user workstation, they are transmitted as standard, untagged Ethernet II frames. However, when frames traverse an uplink connecting two switches, or an uplink between a switch and a multi-SSID wireless access point, the receiving device must identify which VLAN each frame belongs to. The IEEE 802.1Q standard defines an industry-standard method for frame tagging.
An 802.1Q tag is a 4-byte (32-bit) header inserted directly between the original Source MAC address and the EtherType/Length fields of the Ethernet frame:
+-------------------+-------------------+-------------------+-------------------+-------------------+
| Dest MAC (6B) | Source MAC (6B) | 802.1Q Tag (4B) | EtherType (2B) | Payload & FCS |
+-------------------+-------------------+-------------------+-------------------+-------------------+
|<- TPID ->|<- TCI ------------->|
| 16 bits | 3b | 1b | 12 bits |
| 0x8100 | PCP |DEI | VID |
The 4-byte 802.1Q tag is partitioned into two distinct subfields:
- Tag Protocol Identifier (TPID - 16 bits): Set to the fixed hexadecimal value
0x8100. This value indicates to the receiving network interface card (NIC) or switch ASIC that an 802.1Q encapsulation header follows. - Tag Control Information (TCI - 16 bits): Composed of three operational fields:
- Priority Code Point (PCP - 3 bits): Implements IEEE 802.1p Quality of Service (QoS) classification at Layer 2. Supports eight priority levels (0 through 7) to differentiate delay-sensitive voice (CoS 5/6) and video from best-effort data (CoS 0).
- Drop Eligible Indicator (DEI - 1 bit): Formerly known as the Canonical Format Indicator (CFI). When set to
1, it signals to intermediate switches that the frame may be dropped preferentially during link congestion. - VLAN Identifier (VID - 12 bits): Specifies the particular VLAN to which the frame belongs. Because the VID field contains 12 bits, it supports theoretical numerical values (0 through 4095).
Inserting the 4-byte 802.1Q tag increases the maximum untagged Ethernet frame size from 1518 bytes to 1522 bytes. Modern switch ASICs automatically accommodate this overhead without fragmenting frames.
VLAN ID Ranges and System Reservations
The 12-bit VID field supports values from 0 to 4095, which fall into three groups:
| VLAN ID Range | Classification | Operational Behavior and Characteristics |
|---|---|---|
| 0 | Reserved | Used strictly for priority-tagged frames. Frames contain Layer 2 CoS/PCP priority tags, but no VLAN membership is specified. Cannot be configured as a user VLAN. |
| 1 | Default VLAN | Factory default VLAN on AOS-CX switches. Ports on access models start as untagged members of VLAN 1. VLAN 1 cannot be deleted. |
| 2 - 4094 | User VLANs | Configurable VLANs for user, voice, management, and IoT traffic. AOS-CX supports up to 4,096 VLANs on the 6300 and 6400 series. (The "normal" and "extended" VLAN ranges are a Cisco VTP concept and do not apply to AOS-CX.) |
| 4095 | Reserved | Reserved by the IEEE standard. Cannot be assigned to user traffic. |
AOS-CX Port Modes: Access vs. Trunk
A port can be either Layer 2 (no routing) or Layer 3 (routing). The default depends on the platform (AOS-CX 10.14 CLI Guides): on the CX 6300 and 6400 (and other access models) routing is disabled on all interfaces by default, so ports are Layer 2; on the CX 8100 and 8360 routing is enabled by default, so ports are routed. Before assigning VLAN parameters to a routed port, disable routing with no routing. Including no routing in a template is harmless on ports that are already Layer 2.
Once converted to Layer 2, AOS-CX switch interfaces can operate in two primary modes:
1. Access Ports (vlan access <id>)
- Deployment: Connected directly to single-homed end-user devices such as desktop computers, printers, scanners, and standard servers.
- Behavior: The switch port belongs to exactly one VLAN. When the connected host transmits an untagged Ethernet frame, the ingress switch port automatically associates the frame with its configured access VLAN. When the switch forwards a frame out an access port to the client, the switch hardware strips any internal 802.1Q tag, delivering a standard, untagged frame to the endpoint.
- Voice VLAN Capability: When connecting an IP phone that contains an internal 3-port switch (connecting to the wall jack, the phone's internal VoIP processor, and a daisy-chained PC), the port carries the data VLAN untagged and the voice VLAN tagged. The voice VLAN is flagged with the
voicecommand in VLAN context and advertised to the phone through LLDP-MED.
2. Trunk Ports (vlan trunk allowed <list>)
- Deployment: Connected to other Layer 2 switches, Layer 3 aggregation/core switches, firewalls, hypervisors hosting virtual switches, and multi-SSID wireless access points.
- Behavior: A trunk port carries traffic for multiple VLANs across a single physical cable or Link Aggregation Group (LAG). Frames traversing a trunk link retain their 4-byte 802.1Q header, enabling the receiving switch to identify the correct broadcast domain for each frame.
- VLAN Pruning / Allowed List: Define which VLANs are permitted across the link with
vlan trunk allowed <list>(orvlan trunk allowed all). Pruning prevents unnecessary broadcast flooding for VLANs that do not exist on the remote switch.
Native VLAN Mechanics and the Mismatch Hazard
Every 802.1Q trunk link includes a designated Native VLAN (configured as VLAN 1 by default on AOS-CX):
- Ingress Processing: If an untagged Ethernet frame arrives at an 802.1Q trunk port, the switch assumes the frame belongs to the trunk's configured native VLAN and directs it to that broadcast domain.
- Egress Processing: When the switch transmits a frame belonging to the native VLAN across a trunk link, it strips the 802.1Q header by default, sending the frame as untagged Ethernet.
- Tagged Native Option: AOS-CX provides the
vlan trunk native <id> tagcommand. When this parameter is configured, the switch enforces 802.1Q encapsulation for all frames transmitted across the trunk, including the native VLAN. This prevents double-tagging attacks.
+---------------------------------------------------------------------------------------------------------+
| THE NATIVE VLAN MISMATCH HAZARD |
| |
| [ Switch A ] ---------------------- 802.1Q Trunk Link ---------------------- [ Switch B ] |
| Native VLAN: 10 Native VLAN: 20 |
| Allowed: 10, 20 Allowed: 10, 20 |
| |
| 1. Host in VLAN 10 sends frame. |
| 2. Switch A treats VLAN 10 as native -> transmits frame UNTAGGED across trunk. |
| 3. Switch B receives UNTAGGED frame -> assigns frame to its local native VLAN (VLAN 20)! |
| |
| RESULT: Unintended cross-VLAN frame leakage, security boundary violation, and STP BPDU inconsistencies! |
+---------------------------------------------------------------------------------------------------------+
Consequences of Native VLAN Mismatch
If Switch A designates VLAN 10 as native while Switch B designates VLAN 20 as native:
- Traffic Bleed (VLAN Hopping): Unencapsulated traffic originating from VLAN 10 on Switch A emerges directly into VLAN 20 on Switch B without passing through a Layer 3 firewall or router. This breaks data confidentiality and tenant isolation.
- Spanning Tree Type Inconsistencies: Spanning tree BPDUs transmitted untagged or tagged with mismatched PVIDs cause Spanning Tree to detect an inconsistent topology, placing affected ports into blocking/inconsistent states to halt forwarding.
Enterprise Trunk Security and Hardening Practices
To ensure resilient campus operations, enterprise engineers apply strict Layer 2 trunk hardening rules:
- Avoid Default VLAN 1 for User Traffic or Trunk Native: VLAN 1 is the default membership for every unconfigured port, so leaving users or the native VLAN in VLAN 1 makes it easy for an unconfigured port to land in a production network.
- Assign a Dedicated, Unused Native VLAN: Set the native VLAN on all inter-switch trunks to a non-routable, dummy VLAN ID (e.g., VLAN 999 or VLAN 4094) that is not assigned to any user access ports or Layer 3 interfaces.
- Explicitly Prune Allowed VLAN Lists: Never permit unpruned trunks (
vlan trunk allowed all). Restrict the trunk allowed list strictly to the VLANs actively needed on the downstream switch (e.g.,vlan trunk allowed 10,20,30,999). - Enforce Native VLAN Tagging: Enable
vlan trunk native <id> tagon trunks to ensure every frame traversing the link carries an explicit 802.1Q header. This completely mitigates Double-Tagging VLAN Hopping attacks, where an attacker transmits an outer tag matching the native VLAN and an inner tag matching a target victim VLAN. - Park Unused Switch Ports: Administratively shut down all unused physical switch ports (
shutdown), set them to access mode (no routing), and assign them to an isolated quarantine/dead VLAN.
AOS-CX Configuration Commands and Verification
The following configuration session demonstrates creating VLANs, provisioning an access port with an active voice VLAN, configuring an 802.1Q trunk port with a dedicated native VLAN, and verifying port states:
switch# configure terminal
! Step 1: Create global VLANs and assign descriptive names
switch(config)# vlan 10
switch(config-vlan-10)# name DATA-USERS
switch(config-vlan-10)# vlan 20
switch(config-vlan-20)# name VOICE-PHONES
switch(config-vlan-20)# vlan 999
switch(config-vlan-999)# name DUMMY-NATIVE
switch(config-vlan-999)# exit
! Step 2: Configure an Access Port for Workstation and IP Phone
switch(config)# interface 1/1/1
switch(config-if)# description Desk-101-PC-and-Phone
switch(config-if)# no shutdown
switch(config-if)# no routing
switch(config-if)# vlan trunk native 10
switch(config-if)# vlan trunk allowed 10,20
switch(config-if)# exit
! Flag VLAN 20 as the voice VLAN (VLAN context, not interface context)
switch(config)# vlan 20
switch(config-vlan-20)# voice
switch(config-vlan-20)# exit
! Step 3: Configure an 802.1Q Trunk Port to Aggregation Switch
switch(config)# interface 1/1/48
switch(config-if)# description Uplink-to-Agg-Switch
switch(config-if)# no shutdown
switch(config-if)# no routing
switch(config-if)# vlan trunk allowed 10,20,999
switch(config-if)# vlan trunk native 999 tag
switch(config-if)# exit
Essential Verification Commands
| Command | Output and Operational Purpose |
|---|---|
show vlan | Displays all configured VLAN IDs, operational statuses (up/down), and assigned port lists. |
show vlan 10 | Displays detailed status, description, jumbo frame setting, and interfaces bound to VLAN 10. |
show interface 1/1/1 | Shows port status, speed, duplex, Layer 2 mode (access), and assigned access VLAN ID. |
show interface 1/1/48 | Shows port status, Layer 2 mode (trunk), native VLAN ID, and the explicit list of allowed VLANs. |
show vlan port 1/1/48 | Details the exact tagged and untagged VLAN memberships active on interface 1/1/48. |
show mac-address-table vlan 10 | Displays learned MAC addresses associated specifically with VLAN 10 across local switch ports. |
Common Exam Traps
- Omitting
no routing: VLAN commands are accepted only on Layer 2 (non-routed) interfaces. Ports on the CX 8100/8360 are routed by default, sovlan access 10fails there untilno routingis executed; CX 6300/6400 ports are already Layer 2. - Cisco vs. AOS-CX Trunk Syntax: Cisco IOS uses
switchport mode trunkandswitchport trunk allowed vlan 10,20. AOS-CX usesno routingfollowed directly byvlan trunk allowed 10,20andvlan trunk native <id> [tag]. - Native VLAN in the Allowed List: On AOS-CX, if you want untagged native VLAN traffic to traverse a trunk, the native VLAN ID must be explicitly included in the
vlan trunk allowedlist (e.g.,vlan trunk allowed 10,20,999). Omitting the native VLAN from the allowed list causes untagged native frames to be dropped at ingress. - VLAN 1 Deletion: VLAN 1 is the default VLAN and cannot be deleted (
no vlan 1fails).
An administrator needs to configure interface 1/1/5 on an Aruba CX 6200 switch to connect to a downstream access switch, allowing traffic for VLANs 10, 20, and 30 with native traffic placed into VLAN 99. Which configuration commands correctly accomplish this task?
interface 1/1/5 switchport mode trunk switchport trunk allowed vlan 10,20,30 switchport trunk native vlan 99
interface 1/1/5 no shutdown vlan access 10,20,30 vlan trunk native 99 tag
interface 1/1/5 routing vlan trunk allowed 10,20,30 vlan trunk native 99
interface 1/1/5 no routing vlan trunk allowed 10,20,30,99 vlan trunk native 99
According to the IEEE 802.1Q standard, how many bits are allocated for the VLAN Identifier (VID) field in an Ethernet frame tag, and what is the valid configurable VLAN range on an AOS-CX switch?
10 bits, allowing VLAN IDs from 1 to 1023 (0 is reserved)
12 bits, allowing VLAN IDs 1 to 4094 (0 and 4095 reserved)
8 bits, allowing VLAN IDs from 1 to 255 (with 0 reserved)
16 bits, allowing VLAN IDs from 1 to 65535 (0 is reserved)
What primary security and operational risk occurs when two interconnected switches have mismatched native VLAN configurations across an 802.1Q trunk link?
Both switches automatically convert the trunk port into a routed Layer 3 sub-interface to prevent a forwarding loop
Every 802.1Q tagged frame is stripped of its tag and then dropped in hardware by the receiving switch's forwarding ASIC
Untagged frames from one native VLAN arrive in a different VLAN on the neighbor, leaking traffic and confusing spanning tree
The trunk interface moves to an error-disabled state as soon as it detects mismatched Tag Protocol Identifier (TPID) values
Sections you finish are checked off in the contents.