cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
253
Views
0
Helpful
1
Replies

Native VLAN

pmkpal
Level 1
Level 1

Hi,

We use multiple 6509s,4006s and 3524/48s in our campus wide LAN. But still we are not very sure whether the native VLAN setup which is there is correct and whether we are following the best practice.

Can anybody out there suggest best practices for setting up Native Vlans and their use.

Thanks in advance.

Regards

1 Reply 1

milan.kulik
Level 10
Level 10

Hi,

see http://www.cisco.com/warp/customer/473/103.html#dtp

"There is a potential security consideration with dot1Q caused by the implicit tagging of the native VLAN, as it may be possible to send frames from one

VLAN to another without a router. The workaround is to use a VLAN ID for the trunk's native VLAN that is not used for end user access. The majority of Cisco customers achieve this simply by leaving VLAN 1 as the native VLAN on a trunk and assigning access ports to VLANs other than VLAN 1."

Regards,

Milan