4.1 802.1Q Trunking, Native VLAN, and Dynamic Trunking Protocol Troubleshooting
Key Takeaways
IEEE 802.1Q inserts a 4-byte (32-bit) tag directly into Ethernet frame headers between the Source MAC address and EtherType fields, requiring mandatory recalculation of the Frame Check Sequence (FCS).
The 802.1Q tag header comprises the Tag Protocol Identifier (TPID 0x8100), Priority Code Point (PCP, 3 bits), Drop Eligible Indicator (DEI, 1 bit), and a 12-bit VLAN Identifier (VID) supporting VLAN IDs 1 through 4094.
Native VLAN frames traverse 802.1Q trunks untagged by default, creating vulnerability to double-tagging VLAN hopping attacks unless mitigated by designating an unused native VLAN ID or enabling global native tagging via
vlan dot1q tag native.Dynamic Trunking Protocol (DTP) automates trunk negotiation via Dynamic Auto, Dynamic Desirable, Trunk, and Access modes, while
switchport nonegotiateexplicitly disables DTP packet transmission on static trunks.Common trunking failures stem from native VLAN mismatches (flagged by
%CDP-4-NATIVE_VLAN_MISMATCH), allowed VLAN list pruning omissions, and encapsulation disagreements, diagnosable viashow interfaces trunkandshow dtp interface.
802.1Q Trunking, Native VLAN, and Dynamic Trunking Protocol Troubleshooting
Modern enterprise campus networks rely on Virtual Local Area Networks (VLANs) to partition physical switching infrastructure into isolated Layer 2 broadcast domains. When traffic between switches must traverse a shared physical uplink, VLAN trunking encapsulates or tags frames to preserve VLAN identity across device boundaries. Understanding frame tagging standards, native VLAN handling, and trunk negotiation mechanisms is critical for maintaining reliable Layer 2 transport.
IEEE 802.1Q Frame Tagging Architecture
The IEEE 802.1Q standard defines an industry-standard method for multiplexing multiple VLANs over a single physical or logical link. Rather than encapsulating the entire original Ethernet frame inside an external header (as was done by legacy protocols like Cisco Inter-Switch Link [ISL]), 802.1Q inserts an internal 4-byte (32-bit) tag directly into the original Ethernet frame header.
+---------------+---------------+--------------------+---------------+---------------+-----+
| Dest MAC (6B) | Src MAC (6B) | 802.1Q Tag (4B) | EtherType (2B)| Payload (46B- | FCS |
| | | [TPID | TCI] | (Original) | 1500B) | (4B)|
+---------------+---------------+--------------------+---------------+---------------+-----+
|
+-----------------------------+-----------------------------+
| |
+-----------------------+-------+-----+-------------------------+
| TPID: 0x8100 (16 bits)| PCP | DEI | VLAN ID (VID) (12 bits) |
| | (3 b) | (1b)| Range: 0 to 4095 |
+-----------------------+-------+-----+-------------------------+
Tag Header Fields and Bit Allocations
The 4-byte 802.1Q tag header is inserted immediately after the Source MAC address field and before the original EtherType/Length field. It consists of two primary elements:
- Tag Protocol Identifier (TPID - 16 bits): Set to the fixed hexadecimal value
0x8100. This value indicates that the frame carries an 802.1Q tag header. Receiving devices examine this field to differentiate tagged frames from standard untagged Ethernet II frames. - Tag Control Information (TCI - 16 bits): Subdivided into three distinct operational subfields:
- Priority Code Point (PCP - 3 bits): Implements IEEE 802.1p Class of Service (CoS) marking. Provides 8 discrete traffic priority levels (values 0 through 7), enabling Quality of Service (QoS) classification and prioritization directly at Layer 2.
- Drop Eligible Indicator (DEI - 1 bit): Formerly designated as the Canonical Format Indicator (CFI) for Token Ring interoperability. In modern Ethernet implementations, DEI indicates whether the frame may be dropped during link congestion (0 indicates non-eligible, 1 indicates drop-eligible).
- VLAN Identifier (VID - 12 bits): Specifies the VLAN to which the frame belongs. A 12-bit binary field supports 4096 total VLAN IDs (0 through 4095).
| Field Name | Bit Width | Binary/Hex Range | Operational Function |
|---|---|---|---|
| TPID | 16 bits (2 bytes) | 0x8100 | Identifies frame as 802.1Q-tagged Ethernet |
| PCP / CoS | 3 bits | 000 to 111 (0–7) | Layer 2 Quality of Service prioritization |
| DEI / CFI | 1 bit | 0 or 1 | Discard eligibility indicator under congestion |
| VLAN ID (VID) | 12 bits | 0 to 4095 | Identifies the logical broadcast domain |
VLAN ID Allocation Ranges
- VLAN 0: Reserved for priority-tagged frames. Frames carry valid PCP bits for QoS handling but specify no VLAN membership; switches process the payload within the port's native VLAN.
- VLAN 1: Factory default VLAN for management, native trunking, and control plane protocols (CDP, VTP, PAgP, DTP). Cannot be deleted.
- VLANs 2–1001: Standard-range VLANs used for user and data traffic. Stored in flash non-volatile memory (
vlan.dat) or within the startup configuration in VTP transparent mode. - VLANs 1002–1005: Reserved standard-range IDs for legacy FDDI and Token Ring bridging. Cannot be modified or deleted.
- VLANs 1006–4094: Extended-range VLANs intended for enterprise service providers and dense campus segments. Stored in running-config and saved to startup-config; supported in VTP version 3 or VTP transparent mode.
- VLAN 4095: Reserved for system architecture and internal switch control use.
Frame Size Modification and FCS Recalculation
Inserting the 4-byte tag expands the maximum untagged Ethernet II frame size from 1518 bytes to 1522 bytes. Frames between 1519 and 1522 bytes are termed "baby giant" frames. Modern Ethernet switching hardware natively processes these frames without fragmentation. Because the header bytes are altered, the switch must recalculate the 4-byte Frame Check Sequence (FCS) cyclic redundancy check (CRC) prior to transmitting the frame across the trunk.
Native VLAN Mechanics and Security Hardening
In 802.1Q trunking, the native VLAN provides backward compatibility for legacy non-802.1Q devices by transmitting and receiving frames without an 802.1Q tag. By default, Cisco switches assign VLAN 1 as the native VLAN on all 802.1Q trunk ports.
When a switch receives an untagged frame on an 802.1Q trunk interface, it associates that frame with the configured native VLAN of the receiving port. Conversely, when the switch forwards traffic belonging to the native VLAN out an 802.1Q trunk, it strips the 802.1Q tag, transmitting raw Ethernet frames.
Security Vulnerability: Double-Tagging VLAN Hopping
Leaving the native VLAN in its default state (VLAN 1) creates exposure to double-tagging VLAN hopping attacks. In this attack, an attacker circumvents Layer 2 security controls to transmit unidirectional traffic into a restricted VLAN:
[Attacker on Access VLAN 10]
|
| Crafts frame with:
| Outer Tag = VLAN 10 (Native VLAN)
| Inner Tag = VLAN 20 (Target VLAN)
v
[Switch A (Trunk Native VLAN 10)]
|
| Switch A strips outer VLAN 10 tag
| because it matches trunk native VLAN
v
[Untagged Trunk Link Carrying Inner Tag]
|
| Frame reaches Switch B with Inner Tag = VLAN 20
v
[Switch B]
|
| Reads VLAN 20 tag and forwards to victim
v
[Victim Host in VLAN 20]
- Crafted Frame: An attacker connected to an access port in VLAN 10 generates an Ethernet frame with two 802.1Q tags: an outer tag set to VLAN 10 (which happens to match the trunk's native VLAN) and an inner tag set to the victim VLAN (e.g., VLAN 20).
- First Switch Forwarding: Switch A receives the frame, determines that the destination MAC requires transit across the trunk link, and strips the outer VLAN 10 tag because native VLAN traffic must be sent untagged across the trunk.
- Second Switch Processing: Switch B receives the frame across the trunk. Because the outer tag was stripped by Switch A, the inner tag (VLAN 20) now sits immediately behind the Source MAC address. Switch B reads the 0x8100 TPID and VLAN ID 20, forwarding the packet directly into VLAN 20 without routing.
Native VLAN Hardening Best Practices
- Dedicate an Unused Native VLAN: Change the native VLAN on all trunks to an unused non-default VLAN ID (e.g., VLAN 999) across the switching domain:
interface GigabitEthernet0/1 switchport trunk native vlan 999 - Exclude Access Ports from the Native VLAN: Never assign end-user access ports to the designated native VLAN ID.
- Enforce Global Native VLAN Tagging: Force the switch to tag native VLAN frames across all trunks using the global configuration command:
When native tagging is active, the switch inserts an 802.1Q tag on all frames traversing the trunk, including native VLAN frames, neutralizing double-tagging exploitation.vlan dot1q tag native
Dynamic Trunking Protocol (DTP) Operation
The Dynamic Trunking Protocol (DTP) is a Cisco-proprietary point-to-point protocol operating at Layer 2. DTP automates the negotiation of link operating modes (access vs. trunk) and encapsulation types between adjacent switch ports.
DTP Port Modes
switchport mode access: Unconditionally places the port into permanent 802.1Q access (non-trunking) mode. Generates DTP frames to negotiate the remote link partner into access mode.switchport mode trunk: Unconditionally places the port into permanent 802.1Q trunking mode. Continues generating periodic DTP frames every 30 seconds to convert the neighbor port into a trunk.switchport mode dynamic auto: Configures the port to passively listen for DTP negotiation frames. The interface converts to a trunk if the remote neighbor initiates trunking (Dynamic Desirable or Trunk). If both sides operate in dynamic auto, the link defaults to an access port.switchport mode dynamic desirable: Configures the port to actively initiate trunk negotiation by transmitting DTP packets. The interface successfully converts to a trunk if the remote neighbor is set to dynamic desirable, dynamic auto, or static trunk.switchport nonegotiate: Explicitly stops the transmission of DTP frames. Can only be applied when an interface is manually set to static access or static trunk mode. Required when connecting to non-Cisco switches, routers, or hardened end hosts to eliminate security exposure.
DTP Negotiation Outcome Matrix
| Local Port Mode | Remote: Dynamic Auto | Remote: Dynamic Desirable | Remote: Static Trunk | Remote: Static Access |
|---|---|---|---|---|
| Dynamic Auto | Access | Trunk | Trunk | Access |
| Dynamic Desirable | Trunk | Trunk | Trunk | Access |
| Static Trunk | Trunk | Trunk | Trunk | Link Inconsistency / Mismatch |
| Static Access | Access | Access | Link Inconsistency / Mismatch | Access |
Note: If one side is configured with switchport nonegotiate while the remote partner is set to dynamic auto or dynamic desirable, DTP negotiation fails. The remote port remains in its default access state, causing an operational link state mismatch.
Allowed VLAN List Configuration and Pruning
By default, an 802.1Q trunk permits all standard and extended VLANs (1 through 4094) to traverse the link. In production environments, administrators restrict unnecessary broadcast propagation by configuring an explicit allowed list.
Manual Allowed List Syntax
interface GigabitEthernet0/1
switchport mode trunk
switchport trunk allowed vlan 10,20,30
switchport trunk allowed vlan add 40
Each allowed vlan command edits the same list, so order matters. The two commands above leave VLANs 10, 20, 30, and 40 allowed, which matches the show interfaces trunk output later in this section. Adding switchport trunk allowed vlan remove 20 would leave 10, 30, and 40, while switchport trunk allowed vlan except 100-200 would replace the whole list with every VLAN except 100 to 200.
switchport trunk allowed vlan <list>: Replaces the existing allowed list with the specified IDs.switchport trunk allowed vlan add <list>: Appends specified VLANs without modifying current entries.switchport trunk allowed vlan remove <list>: Excises specified VLANs from the permitted list.switchport trunk allowed vlan except <list>: Permits all active VLANs except the specified range.
Dynamic VTP Pruning
VLAN Trunking Protocol (VTP) pruning dynamically monitors broadcast, multicast, and unknown unicast flooding across the trunk. If a downstream switch has no active access interfaces assigned to a specific VLAN, VTP pruning dynamically suppresses that VLAN's traffic from traversing the trunk uplink, conserving link bandwidth without manual intervention.
Troubleshooting Trunking and VLAN Mismatches
Trunking faults disrupt inter-switch connectivity, cause traffic black-holing, and introduce Spanning Tree forwarding loops.
Common Failure Scenarios
- Native VLAN Mismatch:
- Occurs when adjacent trunk ports are configured with differing native VLAN IDs (e.g., Switch A uses VLAN 1, Switch B uses VLAN 99).
- The Cisco Discovery Protocol (CDP) detects this discrepancy and generates console alerts:
%CDP-4-NATIVE_VLAN_MISMATCH: Native VLAN mismatch detected on GigabitEthernet0/1 (1), with Switch2 GigabitEthernet0/1 (99). - Consequences: Traffic from VLAN 1 on Switch A leaks directly into VLAN 99 on Switch B without routing. Spanning Tree places the port into a
PVID-inconsistentstate for the mismatched VLANs to prevent forwarding loops.
- DTP Negotiation Failures:
- Setting one end to static trunk with
nonegotiatewhile leaving the remote peer set todynamic autoresults in the remote port remaining in access mode. Unicast frames tagged by the static trunk are dropped by the access port.
- Setting one end to static trunk with
- Encapsulation Disagreements:
- Older Catalyst platforms support both ISL and 802.1Q. If trunk encapsulation is not explicitly defined with
switchport trunk encapsulation dot1qprior to issuingswitchport mode trunk, trunk initialization fails.
- Older Catalyst platforms support both ISL and 802.1Q. If trunk encapsulation is not explicitly defined with
Diagnostic Verification Commands
Switch# show interfaces trunk
Port Mode Encapsulation Status Native vlan
Gi0/1 on 802.1q trunking 1
Port Vlans allowed on trunk
Gi0/1 10,20,30,40
Port Vlans allowed and active in management domain
Gi0/1 10,20,30
Port Vlans in spanning tree forwarding state and not pruned
Gi0/1 10,20,30
show interfaces trunk: Confirms operational trunk status, negotiated encapsulation, native VLAN, permitted VLANs, active VLANs, and STP forwarding states.show dtp interface <id>: Displays administrative vs. operational DTP modes, negotiation status, and hello timer intervals.show interfaces <id> switchport: Provides deep administrative settings including administrative mode, operational mode, encapsulation, and native VLAN tagging status.
In an IEEE 802.1Q tagged Ethernet frame, what is the bit length and primary function of the Priority Code Point (PCP) field within the Tag Control Information (TCI)?
12 bits, used to specify the logical VLAN Identifier supporting up to 4096 distinct broadcast domains
1 bit, used as the Drop Eligible Indicator to mark frames for potential discard under network congestion
3 bits, used for IEEE 802.1p Class of Service (CoS) marking providing 8 priority levels for Layer 2 QoS
16 bits, used as the Tag Protocol Identifier fixed at hexadecimal value 0x8100
A network engineer configures Switch 1's uplink port with switchport mode trunk and switchport nonegotiate. Switch 2's adjacent uplink port is left at its factory default setting of switchport mode dynamic auto. What is the resulting operational state of the link between the two switches?
The link fails to establish a trunk; Switch 1 acts as a static trunk while Switch 2 remains in access mode, dropping tagged traffic
Both switchports successfully negotiate 802.1Q trunking because Switch 1's trunk configuration overrides Switch 2's dynamic state
Switch 1 automatically disables its port into an err-disabled state due to the Dynamic Trunking Protocol negotiation mismatch
Both switchports fall back to an unmanaged access link belonging to the native VLAN
How does enabling global native VLAN tagging via the vlan dot1q tag native command mitigate double-tagging VLAN hopping attacks?
It disables the transmission of untagged frames across access ports connected to end-user workstations
It keeps an 802.1Q tag on native VLAN frames sent over trunks, so the first switch never strips the attacker's outer tag
It automatically changes the native VLAN ID from VLAN 1 to extended VLAN 4095 on all operational trunk links
It encrypts the Tag Control Information field with SHA-256 before transmitting each frame across the inter-switch uplinks
Sections you finish are checked off in the contents.