Cisco VLAN — настройка vlan на коммутаторе Cisco
Технология VLAN позволяет разделять сеть на логические сегменты. Каждый такой логический сегмент имеет свой широковещательный домен. Уникастовый, бродкастовый и мультикастовый трафик передается только между устройствами входящими в один VLAN. VLAN часто используется для разделения IP сегментов сети, с последующей маршрутизацией и фильтрацией трафика между разными VLAN на маршрутизаторе или на L3 коммутаторе.
Как настраивать VLAN на Cisco роутере можно посмотреть в статье Cisco VLAN — настройка vlan на маршрутизаторе Cisco. Здесь речь пойдёт о настройке VLAN на коммутаторах Cisco Catalyst.
Перед настройкой VLAN на коммутаторе, необходимо определиться будет ли в сети использоваться протокол VTP (VLAN Trunking Protocol) или нет. Использование VTP облегчает управление (создание, удаление, переименовывание) VLAN-ами в сети. В случае с VTP изменение (информацию о VLAN) можно внести централизованно, на одном коммутаторе, и эти изменения распространятся на другие коммутаторы в сети. Если не использовать VTP, то изменения нужно вносить на каждом коммутаторе.
VTP накладывает свои ограничения: протокол VTP версии 1 и 2 поддерживает только базовый диапазон VLAN (c 1 по 1005), поддержка расширенного диапазона (с 1006 по 4094) возможна только в версии протокола 3. Поддержка протокола VTP 3 версии начинается с Cisco IOS версии 12.2(52)SE и выше. Настройку протокола VTP рассмотрим в другой статье, а в этой будем подразумевать, что не используем VTP.
Настройку VLAN на коммутаторе можно выделить в три этапа: создание VLAN, настройка портов, проверка.
1. Создание VLAN на Cisco Catalyst
Номера VLAN (VLAN ID) могут быть в диапазоне от 1 до 4094:
1 — 1005 базовый диапазон (normal-range)
1002 — 1005 зарезервированы для Token Ring и FDDI VLAN
1006 — 4094 расширенный диапазон (extended-range)
При создании или изменении VLAN можно задать следующие параметры:
| VLAN ID | Номер VLAN |
| VLAN name (name) | Имя VLAN |
| VLAN type (media) | Тип VLAN (Ethernet, Fiber Distributed Data Interface [FDDI], FDDI network entity title [NET], TrBRF, или TrCRF, Token Ring, Token Ring-Net) |
| VLAN state (state) | Состояние VLAN (active или suspended) |
| VLAN MTU (mtu) | Максимальный размер блока данных, который может быть передан на канальном уровне |
| SAID (said) | Security Association Identifier — идентификатор ассоциации безопасности (стандарт IEEE 802.10) |
| Remote SPAN (remote-span) | Создание VLAN для удаленного мониторинга трафика (В дальнейшем в такой VLAN можно зеркалировать трафик с какого-нибудь порта, и передать его через транк на другой коммутатор, в котором из этого VLAN трафик отправить на нужный порт с подключенным снифером) |
| Bridge identification number для TrBRF VLAN (bridge) | Идентификатор номера моста для функции TrBRF (Token Ring Bridge Relay Function). Цель функции — создание моста из колец. |
| Ring number для FDDI и TrCRF VLAN (ring) | Номер кольца для типов VLAN FDDI и TrCRF (Token Ring concentrator relay functions). TrCRF называют кольца, которые включены в мост. |
| Parent VLAN number для TrCRF VLAN (parent) | Номер родительского VLAN для типа VLAN FDDI или Token Ring |
| Spanning Tree Protocol (STP) type для TrCRF VLAN (stp type) | Тип протокола связующего дерева (STP) для VLAN типа TrCRF |
| Translational VLAN number 1 (tb-vlan1) | Номер VLAN для первичного преобразования одного типа VLAN в другой |
| Translational VLAN number 2 (tb-vlan2) | Номер VLAN для вторичного преобразования одного типа VLAN в другой |
На практике чаще всего, при создании VLAN задаётся только VLAN ID и VLAN name
Значения по умолчанию:
| VLAN ID | 1 |
| VLAN name | VLANxxxx, где xxxx четыре цифры номера VLAN (Например: VLAN0003, VLAN0200 и т.д.) |
| SAID | 100000 плюс VLAN ID (Например: 100001 для VLAN 1, 100200 для VLAN 200 и т.д.) |
| VLAN MTU | 1500 |
| Translational VLAN number 1 | 0 |
| Translational VLAN number 2 | 0 |
| VLAN state | active |
| Remote SPAN | disabled |
Для создания VLAN нужно:
1. Войти в привилегированный режим и ввести необходимый пароль (команда «enable«)
2. Переключиться в режим глобального конфигурирования (команда «configure terminal«)
3. Создать VLAN командой «vlan id«, где id — номер VLAN (После создания, консоль окажется в режиме конфигурирования VLAN, где можно задать перечисленные выше параметры для VLAN)
4. Задать необходимые параметры, для созданного VLAN (например имя)
Если, в режиме конфигурирования VLAN, ввести знак вопроса, то отобразятся параметры, которые можно задать для данного VLAN:
5. Выйти из режима конфигурирования vlan (команда «exit«, либо «end» — выход из режима глобального конфигурирования)
Не забываем сохранять конфигурацию командой «copy running-config startup-config» в привилегированном режиме
Удалить VLAN можно командой «no vlan id» в режиме глобального конфигурирования:
2. Настройка портов на Cisco Catalyst
Порт на коммутаторе Cisco может находиться в одном из режимов:
access — порт предназначен для подключения оконечного устройства. Принадлежит только одному VLAN. Входящий трафик от подключенного к порту устройства, маркируется заданным на порту VLAN.
trunk — порт предназначен для подключения к другому коммутатору или маршрутизатору. Порт передаёт тегированный трафик. Может передавать трафик как одного, так и нескольких VLAN через один физический кабель.
На Cisco Catalyst можно самому задать режим порта (trunk или access), либо задать автоопределение. При автоопределении режима, порт будет согласовываться с соседом (подключенным к этому порту коммутатором или иным устройством). Согласование режима порта происходит путём передачи DTP (Dynamic Trunking Protocol) фреймов. Для успешной работы протокола DTP, необходимо, что бы интерфейсы были в одном VTP домене (либо один из VTP доменов был null, неточно)
Автоопределение режима порта задаётся командой «switchport mode dynamic auto» или «switchport mode dynamic desirable» в режиме конфигурации интерфейса.
Если на интерфейсе установлено «switchport mode dynamic auto» — то порт переходит в режим trunk, только, если порт соседнего коммутатора установлен в режим «trunk» или «dynamic desirable«
Если на интерфейсе установлено «switchport mode dynamic desirable» — то порт переходит в режим trunk, только, если порт соседнего коммутатора установлен в режим «trunk» или «dynamic desirable» или «dynamic auto«
Не все устройства поддерживают DTP, либо могут некорректно передавать DTP фреймы, в таком случае лучше задать режим (access или trunk) принудительно командами «switchport mode access» или «switchport mode trunk» в режиме конфигурации интерфейса, и отключить передачу DTP фреймов командой «switchport nonegotiate«.
Конфигурация порта по умолчанию:
| Режим порта/интерфейса | switchport mode dynamic auto |
| Разрешённые VLAN, если порт в режиме trunk | с 1 по 4094 |
| VLAN по умолчанию, если порт в режиме access | 1 |
| Native VLAN, если порт в режиме trunk (IEEE 802.1q) | 1 |
Настройка порта в режим автоопределения.
— войти в привилегированный режим (команда: «enable«)
— войти в режим глобального конфигурирования (команда: «configure terminal«)
— войти в режим конфигурирования сетевого интерфейса (команда: «interface interface-id«, где interface-id — имя и номер интерфейса, например «interface GigabitEthernet0/21″)
— задать динамический режим порта/интерфейса (команда: «switchport mode dynamic auto» или «switchport mode dynamic desirable«)
— (не обязательно) задать VLAN, который будет на интерфейсе, если порт перейдёт из режима trunk в режим access, по умолчанию VLAN 1 (команда: «switchport access vlan vlan-id«, где vlan-id — номер VLAN)
— (не обязательно) задать Native VLAN, для IEEE 802.1q транка, по умолчанию Native VLAN 1 (команда: «switchport trunk native vlan vlan-id«, где vlan-id — номер Native VLAN)
— добавить/удалить VLAN в транке, по умолчанию все номера VLAN разрешены (команды: «switchport trunk allowed vlan add vlan-list» — добавить в транк VLAN-ы перечисленные в vlan-list, «switchport trunk allowed vlan remove vlan-list» — удалить из транка VLAN-ы, перечисленные в vlan-list, в vlan-list вланы перечисляются через запятую без пробелов, а диапазоны через дефис, например 2,20,30-40,50 ). Можно сразу задать список необходимых VLAN (командой: «switchport trunk allowed vlan vlan-list«)
— включить порт/интерфейс (команда: «no shutdown«)
— выйти из режима конфигурирования интерфейса (команда: «exit» или «end» )
В данном примере порт 23 переведётся в режим trunk, если порт на соседнем коммутаторе установлен в режиме dynamic auto или dynamic disirable или trunk . В транке будут передаваться только VLAN 2, VLAN с 30 по 35 и VLAN 40. При работе порта в режиме trunk, приходящий на него не тегированный (native) трафик будет помещаться (маркироваться) в VLAN 100. Если порт на соседнем коммутаторе работает в режиме access, то интерфейс будет помещён в VLAN 50.
Настройка access порта.
VLAN на access порту может задаваться статически либо автоматически. Автоматическое назначение VLAN основывается на МАК адресе источника, используя протокол VQP (VLAN Query Protocol) и сервер VMPS (VLAN Management Policy Server). Сервером VMPS могут выступать коммутаторы только старших моделей, такие серии как Catalyst 4000, 5000 и 6500. Автоматическую настройку access порта через VQP в данной статье рассматривать не будем. Здесь будет показано только статическое задание VLAN на access порту.
Для включения access порта в необходимый VLAN, нужно сделать:
— войти в привилегированный режим (команда: «enable«)
— войти в режим глобального конфигурирования (команда: «configure terminal«)
— войти в режим конфигурирования сетевого интерфейса (команда: «interface interface-id«, где interface-id — имя и номер интерфейса)
— задать режим порта/интерфейса «access» (команда: «switchport mode access«)
— задать VLAN на порту/интерфейсе (команда: «switchport access vlan vlan-id«, где vlan-id — номер VLAN)
— включить порт/интерфейс (команда: «no shutdown«)
— выйти из режима конфигурирования интерфейса (команда: «exit» или «end» )
Пусть к 22-му порту коммутатора подключен сервер, который необходимо поместить в 200-й VLAN
Настройка trunk порта.
Настройка порта в режиме trunk идентична настройки порта в режиме автоопределения, за исключением того, что режим нужно указать не dynamic а trunk.
В примере задаётся транк на 23-м порту, в транке разрешены только VLAN 2, VLAN с 30 по 35 и VLAN 40
Добавление VLAN в транковый порт выполняет команда: «switchport trunk allowed vlan add VLAN_NUM«
Пример добавления вланов 100 и 200 к существующим, в транковом порту 23:
УдалениеVLAN из транкового порта выполняет команда: «switchport trunk allowed vlan remove VLAN_NUM«
Пример удаления вланов 100 и 200 из существующих, в транковом порту 23:
Некоторые cisco коммутаторы поддерживают два протокола для работы с VLAN это IEEE 802.1q и ISL. Протокол ISL уже устарел и на многих современных коммутаторах не поддерживается. Поэтому предпочтительнее использовать протокол IEEE 802.1q
На таких коммутаторах, перед настройкой порта в режиме транка, нужно выбрать тип инкапсуляции dot1q (комана: «switchport trunk encapsulation dot1q» в режиме конфигурации интерфейса)
3. Проверка настройки VLAN
Посмотреть информацию о VTP протоколе: «show vtp status«
Показать информацию обо всех VLAN на коммутаторе: «show vlan«
Посмотреть информацию об конкретном VLAN, и узнать на каких он портах: «show vlan id vlan-id«
Посмотреть режим работы порта, native vlan, access vlan и прочее: «show interfaces interface-id switchport«
Иногда, необходимо на коммутаторе создать интерфейс 3-го уровня для VLAN. Например, для маршрутизации и фильтрации IP трафика между разными VLAN (должна быть поддержка L3 уровня как самой моделью коммутатора так и версией IOS). Либо просто создать интерфейс для управления этим коммутатором в специальном VLAN.
Сетевой интерфейс для VLAN создаётся в режиме глобального конфигурирования командой: «interface vlan-id«, где vlan-id — это номер VLAN.
Далее консоль переходит в режим конфигурирования интерфейса, где можно задать необходимые сетевые настройки ip адрес, маску сети, повесить ACL и прочее.
Тегирование нативного vlan на Cisco Catalyst
По умолчанию все транковые интерфейсы уже настроены на тегирование native vlan трафика:
Эта опция, также по умолчанию, отключена глобально, и толку от этой настройки интерфейса никакого. Что и показывает нам вывод команды show vlan dot1q tag native
Отключить глобально и незадумываясь тегирование native vlan неразумно, поскольку все транки тут же его подхватят (они делают это по умолчанию), и мы получим ошибки в работе например MST, LACP PDU, UDLD и пр.
На тех транках которые знают, что native vlan идет без тега, необходимо сперва отключить подобное тегирование.
Безопасный порядок отключения native vlan tagging будет следующим:
- На тех интерфейсах, где мы не хотим тегировать native vlan выполняем команду no switchport trunk native vlan tag
После того, как мы обезопасили те интерфейсы, которым такое тегирование не требуется — даем глобальную команду vlan dot1q native tag , которая включает тегирование глобально.
И соответственно проверяем результат:
Теперь нам видно какие транки тегируют native vlan, а какие нет.
Собственно мы добились желаемого результата.
Cisco Business Switches 350 Series CLI Guide
The documentation set for this product strives to use bias-free language. For the purposes of this documentation set, bias-free is defined as language that does not imply discrimination based on age, disability, gender, racial identity, ethnic identity, sexual orientation, socioeconomic status, and intersectionality. Exceptions may be present in the documentation due to language that is hardcoded in the user interfaces of the product software, language used based on RFP documentation, or language that is used by a referenced third-party product. Learn more about how Cisco is using Inclusive Language.
Book Title
Cisco Business Switches 350 Series CLI Guide
VLAN Commands
View with Adobe Reader on a variety of devices
Results
Chapter: VLAN Commands
VLAN Commands
This chapter contains the following sections:
vlan database
Use the vlan database Global Configuration mode command to enter the VLAN Configuration mode. This mode is used to create VLAN(s) and define the default VLAN.
Use the exit command to return to Global Configuration mode.
Syntax
vlan database
Default Configuration
VLAN 1 exists by default.
Command Mode
Global Configuration mode
Example
The following example enters the VLAN Configuration mode, creates VLAN 1972 and exits VLAN Configuration mode.
Use the vlan VLAN Configuration mode or Global Configuration mode command to create a VLAN and assign it a name (if only a single VLAN is being created). Use the no form of this command to delete the VLAN(s).
Syntax
vlan vlan-range | <vlan-id [name vlan-name]> [media ethernet] [state active]
no vlan vlan-range
Parameters
vlan-range—Specifies a list of VLAN IDs. Separate nonconsecutive VLAN IDs with a comma and no spaces. Use a hyphen to designate a range of IDs (range: 2-4094).
vlan-id—Specifies a VLAN ID. (range: 2-4094).
vlan-name—Specifies the VLAN name. (range: 1–32 characters).
media—Specifies the media type of the VLAN. Valid values are ethernet.
state—Specifies whether the state of the VLAN. Valid values are active.
Default Configuration
VLAN 1 exists by default.
Command Mode
Global Configuration mode
VLAN Database Configuration mode
User Guidelines
If the VLAN does not exist, it is created. If the VLAN cannot be created then the command is finished with error and the current context is not changed.
Example
The following example creates a few VLANs. VLAN 1972 is assigned the name Marketing.
show vlan
Use the show vlan Privileged EXEC mode command to display the following VLAN information.
Syntax
show vlan [tag vlan-id | name vlan-name]
Parameters
tag vlan-id—Specifies a VLAN ID.
name vlan-name—Specifies a VLAN name string (length: 1–32 characters)
Default Configuration
All VLANs are displayed.
Command Mode
Privileged EXEC mode
Examples
Example 1—The following example displays information for all VLANs:
interface vlan
Use the interface vlan Global Configuration mode command to enter the Interface Configuration (VLAN) mode for a specific VLAN. After this command is entered, all commands configure this VLAN.
Syntax
interface vlan vlan-id
Parameters
vlan-id—Specifies the VLAN to be configured.
Command Mode
Global Configuration mode
User Guidelines
If the VLAN does not exist, the VLAN is created. If the VLAN cannot be created, this command is finished with an error and the current context is not changed.
Example
The following example configures VLAN 1 with IP address 131.108.1.27 and subnet mask 255.255.255.0.
interface range vlan
Use the interface range vlan Global Configuration mode command to configure multiple VLANs simultaneously.
Syntax
interface range vlan vlan-range
Parameters
vlan-range—Specifies a list of VLANs. Separate nonconsecutive VLANs with a comma and no spaces. Use a hyphen to designate a range of VLANs.
Command Mode
Global Configuration mode
User Guidelines
Commands under the interface VLAN range context are executed independently on each VLAN in the range. If the command returns an error on one of the VLANs, an error message is displayed, and the system attempts to configure the remaining VLANs.
Example
The following example groups VLANs 221 through 228 and 889 to receive the same command(s).
Use the name Interface Configuration (VLAN) mode command to name a VLAN. Use the no form of this command to remove the VLAN name.
Syntax
name string
no name
Parameters
string—Specifies a unique name associated with this VLAN. (Length: 1–32 characters).
Default Configuration
No name is defined.
Command Mode
Interface (VLAN) Configuration mode
User Guidelines
The VLAN name must be unique.
Example
The following example assigns VLAN 19 the name Marketing.
switchport
Use the switchport Interface Configuration mode command to put an interface that is in Layer 3 mode into Layer 2 mode. Use the no form of this command to put an interface in Layer 3 mode.
Syntax
switchport
no switchport
Default Configuration
Command Mode
Interface (Ethernet, Port Channel) Configuration mode
User Guidelines
Use the no switchport command to set the interface as a Layer 3 interface.
An interface cannot be set as a Layer 3 interface if 802x.1 is enabled on the interface and one of the following conditions is true:
The host mode differs from multi-host.
MAC-Based or WEB-Based authentication is enabled.
Radius VLAN assignment is enabled.
Examples
Example 1 — The following example puts the port gi1/0/1 into Layer 2 mode.
Example 2 — The following example puts the port gi1/0/1 into Layer 3 mode.
switchport mode
Use the switchport mode Interface Configuration mode command to configure the VLAN membership mode. Use the no form of this command to restore the default configuration.
Syntax
switchport mode access | trunk | general | private-vlan <promiscuous | host> | customer | vlan-mapping <tunnel | one-to-one >
no switchport mode
Parameters
access—Specifies an untagged layer 2 VLAN port.
trunk—Specifies a trunking layer 2 VLAN port.
general—Specifies a full 802-1q-supported VLAN port.
customer—Specifies that an edge port connected to customer equipment. Traffic received from this port will be tunneled with the additional 802.1q VLAN tag (Q-in-Q VLAN tunneling).
private-vlan promiscuous—Private-VLAN promiscuous port.
private-vlan host—Private-VLAN host port.
vlan-mapping tunnel—VLAN Mapping tunel edge port.
vlan-mapping one-to-one—VLAN Mapping one-to-one edge port.
Default Configuration
Command Mode
Interface (Ethernet, Port Channel) Configuration mode
User Guidelines
When the port’s mode is changed, it receives the configuration corresponding to the mode.
If the port mode is changed to access and the access VLAN does not exist, then the port does not belong to any VLAN.
Use the switchport mode vlan-mapping <tunnel | one-to-one> command to configure a VLAN mapping mode of an edge interface of a Provider Edge switch. The edge interface is an interface where a Customer network is connected to the Provider Edge switch. The network which the switch belongs to is a Provider network. These networks (Customer ones and Provider one) can use the same VLAN-IDs and the edge interface must perform vlan mapping between Customer VLANs (C-VLANs) and Provider VLANs (S-VLANs).
On an edge interface C-VLANs are mapped to S-VLANs and the original C-VLAN tags are kept as part of payload. When a frame is sent on non-edge tagged interface, it is encapsulated with another layer of S-VLAN tag to which the original C-VLAN-ID is mapped. Therefore, transmitted on non-edge interfaces frames are double-tagged, with the outer S-VLAN tag and inner C-VLAN tag. When a frame is sent on an edge interface the S-VLAN tag is stripped.
On an edge interface C-VLANs are mapped to the S-VLANs and the original C-VLAN-ID in input frame is replaced by the S-VLAN ID to which it is mapped. Untagged frames are dropped. Symmetrical translating back to the edge interface.
The following features cannot be enabled if vlan-mapping is allowed:
Auto Smart Port
The switchport vlan-mapping commands cannot add a port to a S-VLAN.
IPv4 and IPv6 interfaces cannot be defined on VLANs containing edge interfaces.
The following Layer 2 features are not supported into VLANs containing edge interfaces:
IPv6 First Hop Security
The following protocols cannot be enabled on edge interfaces:
The following features are not supported on edge interfaces:
Radius VLAN assignment
802.1x Guest VLAN
Egress ACLs are not supported on one-to-one VLAN mapping edge ports.
A destination port with the network keyword or reflector port cannot be configured on an edge port.
Note. All the limitations for edge ports specified above are checked by the switchport vlan-mapping commands and by the commands configuring these features.
By default the switch does not forward frames received on edge ports with the following destination MAC addresses:
Note. The following protocols using these MAC addresses can be enabled on edge ports:
Examples
Example 1 — The following example configures gi1/0/1 as an access port (untagged layer 2) VLAN port.
Example 2 — The following example puts the port gi1/0/2 into private-vlan host mode.
switchport access vlan
A port in access mode can be an untagged member of at most a single VLAN. The switchport access vlan Interface Configuration command reassigns an interface to a different VLAN than it currently belongs or assigns it to none, in which case it is not a member of any VLAN.
The no form of this command to restore the default configuration.
Syntax
switchport access vlan <vlan-id | none>
no switchport access vlan
Parameters
vlan-id—Specifies the VLAN to which the port is configured.
none—Specifies that the access port cannot belong to any VLAN.
Default Configuration
The interface belongs to the Default VLAN.
Command Mode
Interface (Ethernet, Port Channel) Configuration mode
User Guidelines
When the port is assigned to a different VLAN, it is automatically removed from its previous VLAN and added it to the new VLAN. If the port is assigned to none, it is removed from the previous VLAN and not assigned to any other VLAN.
Example
The following example assigns access port gi1/0/1 to VLAN 2 (and removes it from its previous VLAN).
switchport trunk allowed vlan
A trunk interface is an untagged member of a single VLAN, and, in addition, it may be an tagged member of one or more VLANs. Use the switchport trunk allowed vlan Interface Configuration mode command to add/remove VLAN(s) to/from a trunk port. Use the no form of the command to return to the default.
Syntax
switchport trunk allowed vlan <all | none | vlan-list | add vlan-list | remove vlan-list | except vlan-list>
no switchport trunk allowed vlan
Parameters
all—Specifies all VLANs from 1 to 4094. At any time, the port belongs to all VLANs existing at the time. (range: 1–4094).
none—Specifies an empty VLAN list The port does not belong to any VLAN.
vlan-list— Specifies the list of VLAN IDs the interface is member of. The VLAN(s) specified in this command are the only VLAN(s) the port will be member of (all previous settings related to trunk VLAN membership are discarded). Use a hyphen to designate a range of IDs. Separate nonconsecutive VLAN IDs with a comma and no spaces (range: 1-4094).
add vlan-list—List of VLAN IDs to add to the port. Separate nonconsecutive VLAN IDs with a comma and no spaces. Use a hyphen to designate a range of IDs.
remove vlan-list—List of VLAN IDs to remove from a port. Separate nonconsecutive VLAN IDs with a comma and no spaces. Use a hyphen to designate a range of IDs.
except vlan-list—List of VLAN IDs including all VLANs from range 1-4094 except VLANs belonging to vlan-list.
Default Configuration
By default, trunk ports belongs to all created VLANs.
Command Mode
Interface (Ethernet, Port Channel) Configuration mode
User Guidelines
Use the switchport trunk allowed vlan command to specify which VLANs the port belongs to when its mode is configured as trunk.
Non-existed VLANs can be configured. When a non-existed VLAN is created the port will add to it automatically.
Forbidden VLANs can be configured.
Example
To add VLANs 2,3 and 100 to trunk ports 1 to 13
switchport trunk native vlan
If an untagged packet arrives on a trunk port, it is directed to the port’s native VLAN. Use the switchport trunk native vlan Interface Configuration mode command to define the native VLAN for a trunk interface. Use the no form of this command to restore the default native VLAN.
Syntax
switchport trunk native vlan <vlan-id | none>
no switchport trunk native vlan
Parameters
vlan-id—Specifies the native VLAN ID.
none—Specifies the access port cannot belong to any VLAN.
Default Configuration
The default native VLAN is the Default VLAN.
Command Mode
Interface (Ethernet, Port Channel) Configuration mode
User Guidelines
A value of the interface PVID is set to this VLAN ID.When the interface belongs to the Native VLAN it is set as VLAN untagged egress interface.
The configuration is applied only when the port mode is trunk.
Examples
The following example defines VLAN 2 as native VLAN for port gi1/0/1:
switchport general allowed vlan
General ports can receive tagged or untagged packets. Use the switchport general allowed vlan Interface Configuration mode command to add/remove VLANs to/from a general port and configure whether packets on the egress are tagged or untagged. Use the no form of this command to reset to the default.
Syntax
switchport general allowed vlan add vlan-list [tagged | untagged]
switchport general allowed vlan remove vlan-list
no switchport general allowed vlan
Parameters
add vlan-list—List of VLAN IDs to add. Separate nonconsecutive VLAN IDs with a comma and no spaces. Use a hyphen to designate a range of IDs. (range: 1–4094)
remove vlan-list—List of VLAN IDs to remove. Separate nonconsecutive VLAN IDs with a comma and no spaces. Use a hyphen to designate a range of IDs.
tagged—Specify that packets are transmitted tagged for the configured VLANs
untagged—Specify that packets are transmitted untagged for the configured VLANs (this is the default)
Default Configuration
The port is not a member of any VLAN.
Command Mode
Interface (Ethernet, Port Channel) Configuration mode
User Guidelines
If the interface is a forbidden member of an added VLAN, the interface does not become a member of this specific VLAN. There will be an error message in this case («An interface cannot become a a member of a forbidden VLAN. This message will only be displayed once.») and the command continues to execute in case if there are more VLANs in the vlan-list.
A non-existed VLAN cannot be configured. When a VLAN is removed it is deleted from the vlan-list.
The configuration is applied only when the port mode is general.
Example
The example adds gi1/0/1 and to VLAN 2 and 3. Packets are tagged on the egress:
switchport general pvid
Use the switchport general pvid Interface Configuration mode command to configure the Port VLAN ID (PVID) of an interface when it is in general mode. Use the no form of this command to restore the default configuration.
Syntax
switchport general pvid vlan-id
no switchport general pvid
Parameters
vlan-id—Specifies the Port VLAN ID (PVID).
Default Configuration
The PVID is the Default VLAN PVID.
Command Mode
Interface (Ethernet, Port Channel) Configuration mode
Examples
Example 1 — The following example sets the gi1/0/2 PVID to 234.
Example 2 — The following example performs the following:
Adds VLANs 2&3 as tagged, and VLAN 100 as untagged to gi1/0/4
Defines VID 100 as the PVID
switchport general ingress-filtering disable
Use the switchport general ingress-filtering disable Interface Configuration mode command to disable port ingress filtering (no packets are discarded at the ingress) on a general port. Use the no form of this command to restore the default configuration.
Syntax
switchport general ingress-filtering disable
no switchport general ingress-filtering disable
Default Configuration
Ingress filtering is enabled.
Command Mode
Interface (Ethernet, Port Channel) Configuration mode
Example
The following example disables port ingress filtering on gi1/0/1.
switchport general acceptable-frame-type
The switchport general acceptable-frame-type Interface Configuration mode command configures the types of packets (tagged/untagged) that are filtered (discarded) on the interface. Use the no form of this command to return ingress filtering to the default.
Syntax
no switchport general acceptable-frame-type
Parameters
tagged-only—Ignore (discard) untagged packets and priority-tagged packets.
untagged-only—Ignore (discard) VLAN-tagged packets (not including priority-tagged packets)
all—Do not discard packets untagged or priority-tagged packets.
Default Configuration
All frame types are accepted at ingress (all).
Command Mode
Interface (Ethernet, Port Channel) Configuration mode
Example
The following example configures port gi1/0/3 to be in general mode and to discard untagged frames at ingress.
switchport general forbidden vlan
Use the switchport general forbidden vlan Interface Configuration mode command to forbid adding/removing specific VLANs to/from a port. Use the no form of this command to restore the default configuration.
Syntax
switchport general forbidden vlan <add vlan-list | remove vlan-list>
no switchport general forbidden vlan
Parameters
add vlan-list—Specifies a list of VLAN IDs to add to interface. Separate nonconsecutive VLAN IDs with a comma and no spaces. Use a hyphen to designate a range of IDs.
remove vlan-list—Specifies a list of VLAN IDs to remove from interface. Separate nonconsecutive VLAN IDs with a comma and no spaces. Use a hyphen designate a range of IDs.
Default Configuration
All VLANs are allowed.
Command Mode
Interface (Ethernet, Port Channel) Configuration mode
User Guidelines
The forbidden VLAN cannot be one that does not exist on the system, or one that is already defined on the port.
Example
The following example define s gi1/0/4 as a forbidden membership in VLANs 5-7:
switchport customer vlan
Use the switchport customer vlan Interface Configuration mode command to set the port’s VLAN when the interface is in customer mode (set by the switchport mode command). Use the no form of this command to restore the default configuration.
Syntax
switchport customer vlan vlan-id
no switchport customer vlan
Parameters
vlan-id—Specifies the customer VLAN.
Default Configuration
No VLAN is configured as customer.
Command Mode
Interface (Ethernet, Port Channel) Configuration mode
User Guidelines
When a port is in customer mode it is in QinQ mode. This enables the user to use their own VLAN arrangements (PVID) across a provider network. The switch is in QinQ mode when it has one or more customer ports.
Example
The following example defines gi1/0/4 as a member of customer VLAN 5.
show interfaces switchport
Use the show interfaces switchport Privileged EXEC command to display the administrative and operational status of all interfaces or a specific interface.
Syntax
show interfaces switchport [interface-id]
Parameters
Interface-id—Specifies an interface ID. The interface ID can be one of the following types: Ethernet port or port-channel.
Command Mode
Privileged EXEC mode
Default
Displays the status of all interfaces.
User Guidelines
Each port mode has its own private configuration. The show interfaces switchport command displays all these configurations, but only the port mode configuration that corresponds to the current port mode displayed in «Administrative Mode» is active.
Example
vlan prohibit-internal-usage
Use the vlan prohibit-internal-usage command in Global configuration mode to specify VLANs that cannot be used by the switch as internal VLANs.
Syntax
vlan prohibit-internal-usage none |
Parameters
none—The Prohibit Internal Usage VLAN list is empty: any VLAN can be used by the switch as internal.
except—The Prohibit Internal Usage VLAN list includes all VLANs except the VLANs specified by the vlan-list argument: only the VLANs specified by the vlan-list argument can be used by the switch as internal.
add—Add the given VLANs to the Prohibit Internal Usage VLAN list.
remove—Remove the given VLANs from the Prohibit Internal Usage VLAN list.
vlan-list—List of VLAN. Separate nonconsecutive VLAN IDs with a comma and no spaces. Use a hyphen to designate a range of IDs. The VLAN ID that can be used is from 1 through 4094.
Default Configuration
The Prohibit Internal usage VLAN list is empty.
Command Mode
Global Configuration mode
User Guidelines
The switch requires an internal VLAN in the following cases:
One VLAN for each IP interface is defined directly on an Ethernet port or on a Port channel.
One VLAN for each IPv6 tunnel.
One VLAN for 802.1x.
When a switch needs an internal VLAN it takes a free VLAN with the highest VLAN ID.
Use the vlan prohibit-internal-usage command to define a list of VLANs that cannot be used as internal VLANs after reload.
If a VLAN was chosen by the software for internal usage, but you want to use that VLAN for a static or dynamic VLAN, do one of the following
Add the VLAN to the Prohibited User Reserved VLAN list.
Copy the Running Configuration file to the Startup Configuration file
Reload the switch
Create the VLAN
Examples
Example 1—The following example specifies that VLANs 4010, 4012, and 4090-4094 cannot be used as internal VLANs:
Example 2—The following specifies that all VLANs except 4000-4107 cannot be used as internal VLANs:
Example 3—The following specifies that all VLANs except 4000-4107 cannot be used as internal VLANs:
show vlan internal usage
Use the show vlan internal usage Privileged EXEC mode command to display a list of VLANs used internally by the device (defined by the user).
switchport trunk native vlan
The switchport trunk native vlan command specifies the native (untagged) VLAN for a Layer 2 interface operating in trunk mode on a Cisco IOS device. This command only takes effect for interfaces that are operating in trunk mode.
802.1Q encapsulation and VLAN tagging
A Layer 2 interface operating in trunk mode can carry traffic belonging to multiple VLANs. In order to specify the VLAN to which a particular frame belongs to, the ethernet header is modified and tagged with a VLAN ID tag. The format of the tag is specified the 802.1Q specification.
On any trunk interface, one VLAN can be configured to carry untagged traffic. This VLAN is referred to as the native VLAN for the trunk interface. This implies that traffic belonging to the native VLAN does not include an 802.1Q tag specifying the VLAN ID. (Traffic belonging to the native VLAN is sent as untagged ethernet frames across a trunk link.)
Untagged traffic received on a trunk interface can only be mapped to a single VLAN — hence, only one VLAN can be specified as the native VLAN for a trunk interface. By default, the native VLAN for a trunk interface on a Cisco IOS device is the default VLAN on Cisco IOS devices — VLAN 1. The default behaviour can be changed by using the command switchport trunk native vlan .
The format of the command is as follows:
switchport trunk native vlan <vlan-id>
where <vlan-id> is the desired VLAN for which traffic must be untagged.
Let’s take a look at an example. If we wanted to configure interface GigabitEthernet 0/1 to operate in trunk mode and set VLAN 100 as the native (untagged) VLAN, we would enter configuration commands as follows: