Avatar of jskfan
jskfan
Flag for Cyprus asked on

Changing Native Vlan in Cisco Switch

If I understand ,Cisco Switches have VLAN 1 as the default native Vlan.
Many resources say that leaving Native VLAN to VLAN 1, can be security breach.
1- Can someone explain why leaving VLAN 1 can be security breach  ?
2- If I need to change Native VLAN 1 to VLAN 777, I believe this is done at the Interface Level. Does that mean I need to go to each switch and change the interfaces that are in VLAN1 to VLAN 777 ?
3- if some switches Native VLAN is VLAN1 and some is VLAN 777, does that mean traffic coming from those Native Vlans will be forwarding to all ports on the switch...
in other words if a PC is connected to Native Vlan , will be able to ping another PC which is connected to VLAN 33 and the other way around is also True?

Thank you
Switches / HubsRouters

Avatar of undefined
Last Comment
jskfan

8/22/2022 - Mon
SOLUTION
Don Johnston

Log in or sign up to see answer
Become an EE member today7-DAY FREE TRIAL
Members can start a 7-Day Free trial then enjoy unlimited access to the platform
Sign up - Free for 7 days
or
Learn why we charge membership fees
We get it - no one likes a content blocker. Take one extra minute and find out why we block content.
Not exactly the question you had in mind?
Sign up for an EE membership and get your own personalized solution. With an EE membership, you can ask unlimited troubleshooting, research, or opinion questions.
ask a question
jskfan

ASKER
vlan
in the topology above, R1 e2/2 IP =1.1.1.1/24 and R2 e2/2 IP=1.1.1.2/24
both interfaces can ping each other.
I changed Native Vlan for Switch2  e2/2:
interface Ethernet2/2
 switchport trunk native vlan 777

Still both interfaces on R1 and R2 can ping each other. However when I run : Show Vlan Brief, it still shows e2/2 on SW2 in VLAN1 and native VLAN 777, does not show up:
SW2#sh vlan brief

VLAN Name                             Status    Ports
---- -------------------------------- --------- -------------------------------
1    default                          active    Et0/1, Et0/2, Et0/3, Et1/0
                                                Et1/2, Et1/3, Et2/0, Et2/1
                                                Et2/2, Et2/3, Et3/0, Et3/1
                                                Et3/2, Et3/3
55   VLAN0055                         active    
66   VLAN0066                         active    
77   VLAN0077                         active    
88   VLAN0088                         active    
1002 fddi-default                     act/unsup
1003 token-ring-default               act/unsup
1004 fddinet-default                  act/unsup
1005 trnet-default                    act/unsup
SW2#
Don Johnston

The native VLAN is only a factor on trunks.

E2/2 is not a trunk. So issuing the command "switchport trunk native vlan 777" has no effect on this interface.
jskfan

ASKER
I made e2/2 on SW2 as Trunk then changed its native Vlan to 777
Now I cannot ping from R1 to R2.
I thought 2 interfaces in 2 different Native Vlans will still be able to Ping each other ?
This is the best money I have ever spent. I cannot not tell you how many times these folks have saved my bacon. I learn so much from the contributors.
rwheeler23
Don Johnston

I would stick to keeping the trunk links limited to inter-switch links until you've got a better handle on things. Otherwise you're just going to confuse yourself.

Lets call trunks to end stations an Advanced Topic for now. ;-)
jskfan

ASKER
I agree..
I am trying to see when Switch Trunk interfaces are in different Native Vlans , whether the Hosts connected to those switches can ping each other.

in the topology above, I configured SW2 e0/0  connected to SW1 and e1/1 connected to SW4  both in Native Vlan 777

Now I cannot ping from R1 to R2 and back....
Don Johnston

Well, it doesn't sound like you've got the trunks configured correctly.  The native VLAN should match on each end of the link.
Get an unlimited membership to EE for less than $4 a week.
Unlimited question asking, solutions, articles and more.
jskfan

ASKER
for Native VLAN 1 and Native VLAN 777 to talk to each other, do I need L3 device ?
Don Johnston

trunksI think you're missing the concept of the native VLAN.

The native VLAN is the VLAN on a trunk that does not get tagged.   It only exists on a trunk between two switches (or a switch and a trunking capable device).

Best practice is to not have the native VLAN communicate with anything.

In the attached topology diagram, all inter-switch links are trunks.
jskfan

ASKER
- In your Diagram above will R1 be able to ping R2 and vice-versa ?
- If R1 was in VLAN 777 and R2 in VLAN 55, will still be able to ping each other ?
Experts Exchange is like having an extremely knowledgeable team sitting and waiting for your call. Couldn't do my job half as well as I do without it!
James Murphy
ASKER CERTIFIED SOLUTION
Don Johnston

Log in or sign up to see answer
Become an EE member today7-DAY FREE TRIAL
Members can start a 7-Day Free trial then enjoy unlimited access to the platform
Sign up - Free for 7 days
or
Learn why we charge membership fees
We get it - no one likes a content blocker. Take one extra minute and find out why we block content.
Not exactly the question you had in mind?
Sign up for an EE membership and get your own personalized solution. With an EE membership, you can ask unlimited troubleshooting, research, or opinion questions.
ask a question
jskfan

ASKER
Thanks Don !