Cisco CCNA (200-301)Network AccessHard
A network engineer needs to configure a trunk link between two switches, SW1 and SW2, that are running 802.1Q encapsulation. The engineer wants to ensure that VLAN 99, which carries management traffic, is never tagged when traversing this trunk link. Which command should be used on the trunk port to achieve this requirement?
- Aswitchport trunk allowed vlan add 99
- Bswitchport access vlan 99
- Cswitchport trunk encapsulation dot1q
- Dswitchport trunk native vlan 99
Show answer & explanationAnswer & explanation
Correct answer: D. switchport trunk native vlan 99
To ensure that traffic from a specific VLAN is sent untagged across an 802.1Q trunk, that VLAN must be configured as the native VLAN for the trunk port. All other allowed VLANs will be tagged, but the native VLAN traffic is sent untagged.
Why the other options are wrong
- A. This command allows VLAN 99 on the trunk but does not specify it as untagged; it would be tagged by default.
- B. This command configures an access port for VLAN 99, not a trunk port.
- C. This command sets the encapsulation type but does not specify which VLAN will be untagged.
802.1Q Native VLAN
In 802.1Q trunking, the native VLAN is the VLAN whose traffic traverses the trunk link untagged. All other VLANs on the trunk are tagged.
- Only one native VLAN can be configured per trunk port.
- Native VLANs must match on both ends of a trunk to avoid mismatches and potential security issues.
- Untagged frames received on a trunk port are assumed to belong to the native VLAN.
Memory trick: Native VLAN: No Tag, Just Go!