Question

Difficulty: HardTroubleshooting VLAN, Trunking, and Switching Issues

A network engineer is investigating an inter-switch trunk link issue between Switch-A and Switch-B. Console logs on Switch-A continuously report "%CDP-4-NATIVE_VLAN_MISMATCH: Native VLAN mismatch discovered on GigabitEthernet0/1 (50), with Switch-B GigabitEthernet0/1 (10)". Furthermore, hosts assigned to VLAN 50 on Switch-A are unable to reach services on VLAN 50 connected to Switch-B, and frame traffic is leaking into VLAN 10. Which TWO configuration actions must be performed to restore proper Layer 2 trunking and isolation? (Select TWO.)

  1. Reconfigure GigabitEthernet0/1 on Switch-B so its native VLAN setting matches VLAN 50 on Switch-A.Answer
  2. Ensure VLAN 50 is explicitly included in the allowed VLAN list on GigabitEthernet0/1 on both switches.Answer
  3. C
    Set the Spanning Tree Protocol (STP) priority to 0 on Switch-A for VLAN 50 to force root bridge election.
  4. D
    Configure both GigabitEthernet0/1 interfaces to manual 100 Mbps half-duplex operation to clear frame tagging mismatches.

Answer

To resolve the inter-switch trunking and isolation failures, the administrator must align the native VLAN setting on Switch-B to VLAN 50 to match Switch-A, and ensure VLAN 50 is added to the allowed VLAN list on both trunk ports.
The correct actions are aligning the native VLAN ID across both ends of the 802.1Q trunk link and ensuring that VLAN 50 is included in the allowed VLAN list on both switchports. A native VLAN mismatch causes untagged frames sent from Switch-A on VLAN 50 to be received on Switch-B and placed into VLAN 10, resulting in security leakage and cross-VLAN communication failures. Additionally, VLAN 50 must be permitted on the trunk allowed list for traffic to successfully traverse between switches.

Step-by-Step Solution

1
Identify the root cause of native VLAN traffic leakage
Console logs confirm Switch-A considers VLAN 50 native while Switch-B considers VLAN 10 native, causing untagged frames on VLAN 50 to be received into VLAN 10.
802.1Q trunks transmit native VLAN frames without an 802.1Q tag header. Mismatched native VLAN definitions cause frames to be placed into the wrong VLAN on the opposing switch.
2
Align native VLAN configuration on Switch-B
Changing Switch-B's native VLAN on interface GigabitEthernet0/1 to VLAN 50 resolves the CDP native VLAN mismatch log and stops traffic leakage.
Both trunk endpoints must agree on which VLAN ID handles untagged frames.
3
Verify allowed VLAN list on the trunk interfaces
Adding VLAN 50 to the trunk allowed list permits 802.1Q tagged frames for VLAN 50 to traverse the link.
If a VLAN is pruned or excluded from the switchport trunk allowed list, frames matching that VLAN ID are dropped at the egress interface.

Key Concept

802.1Q Trunking Native VLAN and Allowed List Troubleshooting
Rate this question