Cisco CCNA (200-301)Network AccessMedium
A syslog message '%CDP-4-NATIVE_VLAN_MISMATCH' appears on SW1's Gi0/1 trunk to SW2. CDP shows SW1's native VLAN as 1 while SW2's native VLAN on the matching port is 99. The trunk remains up and passes tagged traffic normally. What is the primary security/operational risk this mismatch creates?
- AThe trunk link will immediately be disabled by CDP
- BBoth switches will fail to elect a spanning-tree root bridge
- CThe EtherChannel bundle carrying this trunk will automatically shut down
- DUntagged frames from VLAN 1 on one switch could be received into VLAN 99 on the other switch, crossing VLAN boundaries
Show answer & explanationAnswer & explanation
Correct answer: D. Untagged frames from VLAN 1 on one switch could be received into VLAN 99 on the other switch, crossing VLAN boundaries
Untagged (native VLAN) frames are not tagged when sent across a trunk, so if the two ends disagree on which VLAN is native, an untagged frame sent as VLAN 1 by one switch will be interpreted as VLAN 99 by the other, effectively leaking traffic between VLANs. CDP only logs a warning; it does not disable the trunk.
Why the other options are wrong
- A. CDP only warns via syslog; it does not shut down the interface.
- B. Spanning-tree root election is unrelated to native VLAN tagging.
- C. This is not an EtherChannel scenario and CDP mismatches don't disable channels.
Native VLAN Mismatch
Occurs when two ends of an 802.1Q trunk are configured with different native VLANs, causing untagged frames to be misclassified.
- CDP detects and logs the mismatch via syslog
- Untagged frames are not tagged with a VLAN ID on the wire
- Mismatch can allow VLAN traffic leakage, a security concern
- Fix by matching 'switchport trunk native vlan' on both ends
Memory trick: Untagged frames trust the native label — if the labels disagree, traffic slips into the wrong room.