Articles

The native VLAN: what it is and why the design choice matters

What the native VLAN means on an 802.1Q trunk, how untagged traffic is classified, and why the choice affects spanning tree and segmentation.

Reading: 5 minNetworking

Article cover: The native VLAN: what it is and why the design choice matters

The native VLAN is the one VLAN on an IEEE 802.1Q trunk whose frames travel untagged. Every other VLAN on the trunk is identified by a four-byte tag inside the Ethernet frame; the native VLAN is identified by the absence of a tag. That single asymmetry is what turns a default value into a design decision: the two ends of the trunk must agree on it, a disagreement silently merges two broadcast domains, and the value you pick decides how much of the trunk is exposed to a tag-based attack.

The model: untagged means native

One pair of rules carries the whole mechanism:

  • Ingress — an untagged frame arriving on a trunk is placed in that port’s native VLAN.
  • Egress — a frame leaving in the native VLAN goes out with no tag; every other VLAN leaves tagged.
SW1 Gi1/0/48  ──  VLAN 10 frame  ──▶  [ 4-byte tag | VID 10 ]  ──▶  Gi1/0/48 SW2   VLAN 10
SW1 Gi1/0/48  ──  VLAN 99 frame  ──▶  ( no tag )               ──▶  Gi1/0/48 SW2   VLAN 99   (native, both ends)

Membership in the native VLAN is inferred, never stated. Everything else — the mismatch warning, the spanning-tree caution, the attack — follows from that one property.

Terms. A trunk is a point-to-point link carrying several VLANs. The 802.1Q tag is four bytes inserted between the source MAC address and the Type/Length field; it carries the VLAN identifier (VID) that names the frame’s VLAN. Cisco calls the untagged VLAN of a trunk the native VLAN; the standard describes it as a port’s ingress classification (PVID) and its one untagged egress VLAN.

Where it comes from

802.1Q has to accept untagged frames — from a host with no VLAN configuration, or from an older bridge that predates 802.1Q — so every trunk port keeps one VLAN to receive them. The convention costs the trunk one VLAN that is not self-describing, and that turns its value into a design decision with two consequences: it must match at both ends (a mismatch can join two broadcast domains and build a spanning-tree loop), and it is the precondition for a double-tagging hop.

The mechanism, step by step

  1. A host sends a plain, untagged frame to its access port; the port tags it internally with its own VLAN.
  2. The frame must cross a trunk. The switch compares the frame’s VLAN with the trunk port’s native VLAN.
  3. On a match, the frame is transmitted untagged; on a mismatch, the switch inserts the four-byte tag carrying that VLAN’s VID.
  4. At the far end a tagged frame is classified directly by its VID; an untagged frame is classified into that port’s native VLAN.
  5. The native VLAN must be identical on both ends, or untagged frames from one end are re-homed into the other end’s native VLAN. Cisco IOS XE signals this with %CDP-4-NATIVE_VLAN_MISMATCH.
  6. Best practice is a dedicated, unused native VLAN instead of VLAN 1. On platforms that support it, vlan dot1q tag native removes the untagged egress path entirely.

A mismatch, drawn out

If SW1 uses native VLAN 10 and SW2 uses native VLAN 99, the trunk does not go down. A VLAN 10 frame leaves SW1 untagged; SW2 reads no tag and files it in VLAN 99, so the two VLANs share one broadcast domain while every tagged VLAN keeps working — a fault hidden behind a healthy-looking link.

Reference trunk configuration on Cisco IOS XE (platform-specific syntax; portable concepts):

interface GigabitEthernet1/0/48
 description Uplink to SW2
 switchport mode trunk
 switchport nonegotiate
 switchport trunk allowed vlan 10,20,30
 switchport trunk native vlan 999

switchport trunk native vlan 999 moves the untagged VLAN to a value no access port uses. Where supported, the global command vlan dot1q tag native tags the native VLAN too, so the trunk carries no untagged data.

Limits and the common mistake

The common mistake is treating a native VLAN mismatch as harmless because the link stays up — or as an error to suppress by disabling CDP. Disabling CDP, or trunking to a non-Cisco device, removes the warning and not the mismatch: two VLANs stay bridged, and the alarm simply stops.

Four limits are worth stating:

  • The native VLAN is per trunk port, not a global setting; there is no single “the native VLAN” for a network.
  • Changing it on a live trunk can interrupt the untagged VLAN between the two changes; change both ends together in a maintenance window and check the management path first.
  • vlan dot1q tag native must be configured identically on every device that shares the trunk; enabling it on one side alone drops traffic.
  • VLAN isolation does not authenticate the tag: the tag is not protected, so VLANs are a segmentation tool, not a security boundary. The native VLAN is where a double-tagging hop begins: a station in the native VLAN sends a frame carrying two tags, the first switch strips the outer one (the native VLAN) and forwards the inner one, and the frame reaches a VLAN the sender was never given. A dedicated, unused native VLAN removes that entry point.

What to remember

  • The native VLAN is the VLAN whose frames cross a trunk untagged.
  • Untagged in, native; native out, untagged — everything else follows.
  • Both ends must agree, or two broadcast domains are merged silently.
  • Make it a dedicated, unused VLAN — not VLAN 1 — and tag it where the platform allows.
  • A healthy-looking link is not evidence of a correct native VLAN.

Level and prerequisites. L2 — operational. This sheet assumes the L1 material on Ethernet frames and broadcast domains, and the L2 ideas of VLANs and trunk ports.

Where to go next

References

  • IEEE 802.1Q-2022 — Bridges and Bridged Networks (normative text; see sources.md).
  • Cisco — Configuring VLAN Trunks, Cisco IOS XE 17.14.x (Catalyst 9400).
  • Cisco — VLAN Commands (vlan dot1q tag native), Cisco IOS XE 17.18.x (Catalyst 9300).
  • Cisco — Inter-Switch Link and IEEE 802.1Q Frame Format (Document ID 17056).
  • Cisco — Common CatOS Error Messages on Catalyst 6500/6000 (Document ID 29804), %CDP-4-NATIVE_VLAN_MISMATCH.
  • Cisco — Layer 2 Attacks and Their Mitigation; Layer 2 Security (vendor material on double tagging).