cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
4386
Views
12
Helpful
5
Replies

Native VLAN and Spanning Tree

BlakeR11
Frequent Visitor
Frequent Visitor

Recently I have wanted to make my trunk connections from switch to switch more secure by only allowing the necessary VLANs. I wanted to remove the Native VLAN from the Allowed List (for VLAN hopping) but came upon Meraki documentation that advises to add the Native VLAN to the allowed list. Also, I am running Rapid-PVST on my other non-Meraki switches. I did have a MS switch connected to a non-Meraki switch without the Native VLAN included on the trunk allowed list and it seemed like STP was running properly.

https://documentation.meraki.com/MS/Deployment_Guides/Advanced_MS_Setup_Guide
- "If a Native VLAN is specified, ensure that it is also added to the Allowed VLANs configuration"
- "MS series switches can participate in spanning tree only when a spanning tree instance is running on VLAN 1 of all switches. In addition, VLAN 1 must be allowed on all trunk ports running Rapid-PVST, so that BPDUs are seen by the Meraki switches in the topology"


Would I need to include the Native VLAN to a hybrid network (Meraki and Non-Meraki)? Also, would I need to include the Native VLAN into a Meraki only network?

1 Accepted Solution

Accepted Solutions

aleabrahao
Meraki Community All-Star
Meraki Community All-Star

Yes, it needs to be included in the hybrid network, as Meraki recommends. In other words, it needs to be included in non-Meraki devices as well.

I am not a Cisco employee. My suggestions are based on documentation of Cisco, best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.

View solution in original post

5 Replies 5

aleabrahao
Meraki Community All-Star
Meraki Community All-Star

Yes, it needs to be included in the hybrid network, as Meraki recommends. In other words, it needs to be included in non-Meraki devices as well.

I am not a Cisco employee. My suggestions are based on documentation of Cisco, best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.

How about a Meraki only network?

aleabrahao
Meraki Community All-Star
Meraki Community All-Star

If they are only Meraki switches then it is not necessary, this recommendation is only for when you have non-Meraki switches connected.

I am not a Cisco employee. My suggestions are based on documentation of Cisco, best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.

Philip D'Ath
Meraki Community All-Star
Meraki Community All-Star

>I wanted to remove the Native VLAN from the Allowed List

Spanning tree packets are transmitted on the native VLAN, so that is why you shouldn't prune it.

VLAN hopping doesn't affect ports configured as access ports (they don't accept tagged frames). Consequently, if you configure every port as an access port - except those going to other network devices, you have mitigated the vast majority of the risk.

BlakeR11
Frequent Visitor
Frequent Visitor

To follow up on this.
I have Meraki Catalyst switches connecting to a catalyst switch, and last month I removed the native VLAN 1 from the allowed list on the Meraki switches without knowing this information. Nothing panicked and it looked like everything was working properly. I just added VLAN 1 back to the allowed list causing the network to crash with switches going offline and not being able to reach the catalyst switch.

How did removing the native VLAN not cause a problem but adding it back did?

Edit:
I realized that I didn't adjust the Catalyst switch trunk allow list, it remained as trunk allow all. This could be why it continued to work. So I guess my question is, why did adding it back cause a problem and why does it work without adding native VLAN 1 to the trunk on the Meraki switch?