05-04-2022 08:09 AM
Hi,
We have a checkpoint firewall with a one vlan trunked on an interface. The interface is plugged into a trunk port on a catalyst 9300 switch, but doesnt seem to receive traffic. after including the native vlan in the interface config, it starts working.
Can someone explain why we need a native vlan for these two interfaces to pass traffic? the native vlan shouldn't be used if the vlan is being trunked.
Best Regards,
Sabeel
05-04-2022 08:15 AM
Hello,
The purpose of the native vlan is to let the switch know that it will send 1 vlan untagged, the "native vlan". Switch access ports dont tag vlans so by default their native vlan is the vlan its configured for (however on access ports its not called native vlan, its just a vlan).
My best guess is that 1 VLAN coming from the firewall is untagged, therefore once it reaches the 9300 it comes in untagged. So configuring the native VLAN on the 9300 allows the untagged vlan to pass through.
-David.
05-04-2022 08:31 AM
Hello
By default as stated vlan 1 is untagged, it could be that the CP Fw is untagging a vlan that isn't untagged on your switch so when you set that specific switch interconnect to be native you began receiving traffic.
Pease note you can have multiple different native vlans on the same switch on multiple switch interconnects because they are not switch specific but interface specific, it is not recommended but its is viable.
05-04-2022 02:59 PM
traffic use native VLAN or other VLAN, it seem work but I think it use native VLAN.
05-04-2022 03:59 PM
@MHM Cisco World Can you elaborate on this please as I don't understand what you are stating?
05-06-2022 01:45 AM
Hi Paul,
The interface on the CP has one vlan on it and is the only virtual interface. that exact same VLAN was trunked on the switch without a native vlan statement when it wasn't working. see below:
CP(Eth1.951) -------- switch (Gi1/0/4)
Eth1.951 vlan 951 is the only vlan on Eth1.
Switch (Gi1/0/4) interface contains switchport trunk command, switchport trunk allowed vlan 951 (and is administratively enabled).
With Gi1/0/4 set up like this: the vlan was not accessible by the site. When the Native vlan statement was added then all started working.
The native vlan is 999, but shouldn't be used as i specified the vlan on both ends.
Hope that clears things up a bit.
Best Regards,
Sabeel
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide