Untagged vlan ports что это
Часовой пояс: UTC + 3 часа
Tagged и UnTagged порты обьясните разницу!
Ребята обьясните пож. разницу в логике работы Tagged и UnTagged портов.
Я так понимаю что UnTagged порт предназначен для включения конечного пользователя, а Tagged порт это что-то типа транка?
у меня нет возможности скачать с фтп вы б не могли на почту бросить, буду очень признателен!
Ребята обьясните пож. разницу в логике работы Tagged и UnTagged портов.
Я так понимаю что UnTagged порт предназначен для включения конечного пользователя, а Tagged порт это что-то типа транка?
еще хотел уточнить, если я делаю порт маркированным для какой-то VLAN то соответственно я не смогу зайти на комутатор по этому порту, потому что :
1. Телнет вышлет комутатору нетегированный фрейм и комутатор не приймет его вообще?
2. Телнет вышлет комутатору нетегированный фрейм и комутатор ответит ему тегированным фреймом и уже мой компютер не приймет фрейм?
Записки IT специалиста
Виртуализацией сегодня уже никого не удивить. Эта технология прочно вошла в нашу жизнь и помогает более эффективно использовать имеющиеся ресурсы, а также обеспечивает достаточную гибкость в изменении существующей конфигурации, позволяя перераспределять ресурсы буквально налету. Не обошла виртуализация и локальные сети. Технология VLAN (Virtual Local Area Network) позволяет создавать и гибко конфигурировать виртуальные сети поверх физической. Это позволяет реализовывать достаточно сложные сетевые конфигурации без покупки дополнительного оборудования и прокладки дополнительных кабелей.
Научиться настраивать MikroTik с нуля или систематизировать уже имеющиеся знания можно на углубленном курсе по администрированию MikroTik. Автор курса, сертифицированный тренер MikroTik Дмитрий Скоромнов, лично проверяет лабораторные работы и контролирует прогресс каждого своего студента. В три раза больше информации, чем в вендорской программе MTCNA, более 20 часов практики и доступ навсегда.
Прежде чем продолжить сделаем краткое отступление о работе локальных сетей. В данном контексте мы будем говорить об Ethernet-сетях описанных стандартом IEEE 802.3, куда входят всем привычные проводные сети на основе витой пары. Основой такой сети является коммутатор (свич, switch), который работает на втором уровне сетевой модели OSI (L2).
Второй уровень, он же канальный, работает в пределах одного сегмента сети и использует для адресации уникальные физические адреса оборудования — MAC-адреса. Передаваемая между узлами информация разделяется на специальные фрагменты — Ethernet-кадры (фреймы, frame), которые не следует путать с IP-пакетами, которые находятся на более высоком уровне модели OSI и передаются внутри Ethernet-кадров. Таким образом коммутатор ничего не знает об IP-адресах и никак эту информацию в работе не учитывает.
Коммутатор анализирует заголовки каждого входящего кадра и заносит соответствие MAC-адреса источника в специальную MAC-таблицу, после чего кадр, адресованный этому узлу, будет направляться сразу на определенный порт, если МАС-адрес получателя неизвестен, то кадр отправляется на все порты устройства. После получения ответа коммутатор привяжет MAC-адрес к порту и будет отправлять кадры только через него.
Этим достигается возможность одновременной передачи данных по нескольким портам одновременно и увеличивается безопасность сети, так как данные будут передаваться только на требуемый порт. Одновременно передавать данные через порт коммутатора может только один узел сети. Попытка одновременно передавать несколько кадров в одном сегменте сети называется коллизией, а такой сегмент — доменом коллизий. Чем больше устройств в домене коллизий, тем медленнее работает сеть.
Коммутатор позволяет разделять домен коллизий на отдельные домены по числу портов, таким образом каждый порт коммутатора — это отдельный домен коллизий и в каждом из них данные могут передаваться одновременно, не мешая друг другу.
Совокупность доменов коллизии, соединенных на втором уровне, является широковещательным доменом, если говорить проще, то широковещательный домен — это совокупность всех портов коммутаторов соединенных в один сегмент.
Как мы уже говорили выше, к широковещанию прибегает сам коммутатор, когда получает кадр MAC-адрес которого отсутствует в MAC-таблице, а также узлы сети, отправляя кадры на адрес FF:FF:FF:FF:FF:FF, такие кадры будут доставлены всем узлам сети в широковещательном сегменте.
А теперь вернемся немного назад, к доменам коллизий и вспомним о том, что в нем может передаваться только один кадр одновременно. Появление широковещательных кадров снижает производительность сети, так как они доставляются и тем, кому надо и тем, кому не надо. Делая невозможным в это время передачу целевой информации. Кроме того, записи в MAC-таблице имеют определенное время жизни, по окончании которого они удаляются, что снова приводит к необходимости рассылки кадра на все порты устройства.
Чем больше в сети узлов, тем острее стоит проблема широковещания, поэтому широковещательные домены крупных сетей принято разделять. Это уменьшает количество паразитного трафика и увеличивает производительность, а также повышает безопасность, так как ограничивает передачу кадров только своим широковещательным доменом.
Как это можно сделать наиболее простым образом? Установить вместо одно коммутатора два и подключить каждый сегмент к своему коммутатору. Но это требует покупки нового оборудования и, возможно, прокладки новых кабельных сетей, поэтому нам на помощь приходит технология VLAN.
Данная технология описана стандартом 802.1Q и предусматривает добавление к заголовкам кадра дополнительного поля, которое содержит в том числе определенную метку (тег) с номером виртуальной сети — VLAN ID, всего можно создать 4094 сети, для большинства применений этого достаточно.
Давайте рассмотрим, как работает коммутатор с виртуальными сетями. В нашем примере мы возьмем условный 8-портовый коммутатор и настроим на нем три порта на работу с одним VLAN, а еще три порта с другим.
Каждый VLAN обозначается собственным номером, который является идентификатором виртуально сети. Порты, которые не настроены ни для какого VLAN считаются принадлежащими Native VLAN, по умолчанию он обычно имеет номер 1 (может отличаться у разных производителей), поэтому не следует использовать этот номер для собственных сетей. Порты, настроенные нами для работы с VLAN, образуют как-бы два отдельных виртуальных коммутатора, передавая кадры только между собой. Каким образом это достигается?
Как мы уже говорили выше, каждый кадр 802.1Q содержит дополнительное поле, в котором содержится тег — номер виртуальной сети. При входе Ethernet-кадра в коммутатор с поддержкой VLAN (такой трафик называется входящим — ingres) в его состав добавляется поле с тегом. При выходе из коммутатора (исходящий трафик — egress), данное поле из кадра удаляется, т.е. тег снимается. Все кадры внутри коммутатора являются тегированными. Если трафик пришел на порт, не принадлежащий ни одному VLAN, он получает тег с номером Native VLAN.

В порт, принадлежащий определенному VLAN, могут быть отправлены только пакеты с тегом, принадлежащим этому VLAN, остальные будут отброшены. Фактически мы только что разделили единый широковещательный домен на несколько меньших и трафик из одного VLAN никогда не попадет в другой, даже если эти подсети будут использовать один диапазон IP. Для конечных узлов сети такой коммутатор нечем ни отличается от обычного. Вся обработка виртуальных сетей происходит внутри.
Такие порты коммутатора называются портами доступа или нетегированными портами (access port, untagged). Обычно они используются для подключения конечных узлов сети, которые не должны ничего знать об иных VLAN и работать в собственном сегменте.
А теперь рассмотрим другую картину, у нас есть два коммутатора, каждый из которых должен работать с обоими VLAN, при этом соединены они единственным кабелем и проложить дополнительный кабель невозможно. В этом случае мы можем настроить один или несколько портов на передачу тегированного трафика, при этом можно передавать как трафик любых VLAN, так и только определенных. Такой порт называется магистральным (тегированным) или транком (trunk port, tagged).

Магистральные порты используются для соединения сетевого оборудования между собой, к конечным узлам сети тегированный трафик обычно не доставляется. Но это не является догмой, в ряде случаев тегированный трафик удобнее доставить именно конечному узлу, скажем, гипервизору, если он содержит виртуальные машины, принадлежащие разным участкам сети.
Так как кадр 802.1Q отличается от обычного Ehternet-кадра, то работать с ним могут только устройства с поддержкой данного протокола. Если на пути тегированного трафика попадется обычный коммутатор, то такие кадры будут им отброшены. В случае доставки 802.1Q кадров конечному узлу сети такая поддержка потребуется от сетевой карты устройства. Если на магистральный порт приходит нетегированный трафик, то ему обычно назначается Native VLAN.
Кроме указанных двух портов доступа существует еще одна разновидность — гибридный порт (hybrid port), его реализация и наименование у разных производителей сетевого оборудования может быть разным, но суть от этого не меняется. Такой порт передает как тегированный, так и нетегированный трафик. Для этого в его настройках указывается Default VLAN ID и для всех кадров этого VLAN данный порт работает как порт доступа, т.е для исходящего трафика указанного VLAN тег снимается, а входящему кадру без тега, наоборот, присваивается. Трафик остальных VLAN передается с тегами.
Для чего это нужно? Наиболее частое применение — это IP-телефоны со встроенным коммутатором, которые умеют работать с тегированным трафиком, но не умеют передавать его дальше. В этом случае в качестве VLAN ID по умолчанию устанавливается номер VLAN в котором расположены пользовательские ПК, а для телефона на этот же порт добавляется тегированный трафик VLAN для телефонии.
![]()
Все это время мы говорили только о VLAN, не поднимая вопроса: как попасть из одного VLAN в другой. Если продолжать рассматривать канальный уровень — то никак. Каждый VLAN мы можем рассматривать как отдельный физический коммутатор, а магистральный канал — как жгут кабелей между ними. Только все это сделано виртуально, на более высоком уровне абстракции, чем L1 — физический уровень, который как раз представлен кабелями и физическим оборудованием.
Если мы соединим два физических коммутатора кабелем — то получим расширение широковещательного домена на все порты этих устройств, а это совсем не то, что нам нужно. В тоже время сетевые устройства работают на более высоких уровнях модели ОSI, начиная с сетевого — L3. Здесь уже появляется понятие IP-адреса и IP-сетей. Если смотреть на VLAN с этого уровня, то они ничем не отличаются от физических сегментов сетей. А что мы делаем, когда нам нужно попасть из одной сети в другую? Ставим маршрутизатор.
Маршрутизатор или роутер — устройство, работающее на третьем уровне модели OSI и умеющее выполнять маршрутизацию трафика, т.е. поиск оптимального пути для доставки его получателю. И здесь мы говорим уже не о Ethernet-кадрах, а об IP-пакетах. Маршрутизация между VLAN называется межвлановой (межвланной) маршрутизацией (InterVLAN Routing), но, по сути, она ничем не отличается от обычной маршрутизации между IP-подсетями.
Для обеспечения связи между сетями в нашей схеме появляется новая сущность — маршрутизатор, как правило к нему от одного из коммутаторов идет магистральный канал (транк), содержащий все необходимые VLAN, эта схема называется роутер на палочке (леденец, Router-on-a-Stick).
![]()
Как работает эта схема? Допустим ПК из синей сети (VLAN ID 40), хочет обратиться к другому узлу синей сети. IP-адрес адресата ему известен, но для того, чтобы отправить кадр нужно знать физический адрес устройства. Для этого ПК источник делает широковещательный ARP-запрос, передавая в нем нужный ему IP-адрес, в ответ на него обладатель этого IP сообщит ему собственный MAC-адрес.
Все кадры, попадающие с порта доступа в коммутатор, получают тег с VLAN ID 40 и могут покинуть коммутатор только через порты, принадлежащие этому VLAN или транк. Таким образом любые широковещательные запросы не уйдут дальше своего VLAN. Получив ответ узел сети формирует кадр и отправляет его адресату. Далее в дело снова вступают коммутаторы, сверившись с MAC-таблицей они отправляют кадр в один из портов, который будет либо принадлежать своему VLAN, либо будет являться магистральным. В любом случае кадр будет доставлен по назначению без использования маршрутизатора, только через коммутаторы.
Совсем иное дело, если узел одного из VLAN хочет получить доступ к узлу другого VLAN. В нашем случае узел из красной сети (VLAN ID 30) хочет получить доступ к узлу синей сети (VLAN ID 40). Узел источник знает IP-адрес адресата и также знает, что этот адрес не принадлежит его сети. Поэтому он формирует IP-пакет на адрес основного шлюза сети (роутера), помещает его в Ethernet-кадр и отправляет на порт коммутатора. Коммутатор добавляет к кадру тег с VLAN ID 30 и доставляет его роутеру.
Роутер получает данный кадр, извлекает из него IP-пакет и анализирует заголовки. Обнаружив адрес назначения, он сверяется с таблицей маршрутизации и принимает решение куда отправить данный пакет дальше. После чего формируется новый Ethernet-кадр, который получает тег с новым VLAN ID сети-получателя в него помещается IP-пакет, и он отправляется по назначению.
Таким образом любой трафик внутри VLAN доставляется только с помощью коммутаторов, а трафик между VLAN всегда проходит через маршрутизатор, даже если узлы находятся в соседних физических портах коммутатора.
Говоря о межвлановой маршрутизации нельзя обойти вниманием такие устройства как L3 коммутаторы. Это устройства уровня L2 c некоторыми функциями L3, но, в отличие от маршрутизаторов, данные функции существенно ограничены и реализованы аппаратно. Этим достигается более высокое быстродействие, но пропадает гибкость применения. Как правило L3 коммутаторы предлагают только функции маршрутизации и не поддерживают технологии для выхода во внешнюю сеть (NAT) и не имеют брандмауэра. Но они позволяют быстро и эффективно осуществлять маршрутизацию между внутренними сегментами сети, в том числе и между VLAN.
Маршрутизаторы предлагают гораздо большее число функций, но многие из них реализуются программно и поэтому данный тип устройств имеет меньшую производительность, но гораздо более высокую гибкость применения и сетевые возможности.
При этом нельзя сказать, что какое-то из устройств хуже, каждое из них хорошо на своем месте. Если мы говорим о маршрутизации между внутренними сетями, в том числе и о межвлановой маршрутизации, то здесь предпочтительно использовать L3 коммутаторы с их высокой производительностью, а когда требуется выход во внешнюю сеть, то здесь нам потребуется именно маршрутизатор, с широкими сетевыми возможностями.
Научиться настраивать MikroTik с нуля или систематизировать уже имеющиеся знания можно на углубленном курсе по администрированию MikroTik. Автор курса, сертифицированный тренер MikroTik Дмитрий Скоромнов, лично проверяет лабораторные работы и контролирует прогресс каждого своего студента. В три раза больше информации, чем в вендорской программе MTCNA, более 20 часов практики и доступ навсегда.
Помогла статья? Поддержи автора и новые статьи будут выходить чаще:
![]()
Или подпишись на наш Телеграм-канал: ![]()
VLAN Tagged vs Untagged – What is the difference?

VLAN Tagged vs Untagged
VLAN Tagged vs Untagged Tutorial
After reading an in-depth article about VLANs, you might still have questions about the differences between VLAN tagged vs. untagged? This blog post will discuss this topic in easy to understand language. Let’s briefly discuss the VLAN and VLAN tag and then dive into the difference between Vlan tagged vs. Untagged.
VLANs:- Virtual LANs, or Virtual Local Area Networks, works on the Data link layer of the OSI model. VLANs help create virtual separations within a switch that provide distinct logical LANs or segregated broadcast domains that each behaves as if they were configured on a separate physical switch.
Before the invention of VLANs, a switch used to serve a single LAN and maintained a single broadcast domain, due to which broadcast packets were sent to all ports.
VLAN ethernet tags enabled a single switch to serve multiple LANs by dividing a single broadcast domain into multiple broadcast domains.
Learn how to manage VLANs centrally through VTP.
What is a VLAN tag, and why do we need a VLAN tag in the network?

Layer2 Frame fields and Dot1q Header
- VLAN tags are a core part of the VLANs. Therefore, packets must be “tagged.” to support VLANs.
- IEEE 802.1Q is the widely used standard for setting VLAN tags on switches.
- 802.1Q adds a 32-bit field (4 bytes) to each Ethernet frame.
- The first 16 bits identify the frame as an 802. 1Q. The remaining 16 bits are split into two parts: 12 for VLAN tags and 4 for QoS operations.
- The VLAN ID is 12 bits long so that the switch can handle 4096 VLANs (2^12 = 4096), with usable numbers between 1 and 4094.
Let us look further into Untagged Port, Tagged Port, Default, and Native VLAN.
What is VLAN untagging, and what does Untagged packet mean?

VLAN Untag
Ports on the switches normally connect to the end devices that don’t understand VLAN tags, so the switch performs VLAN untagging before forwarding packets from the switch to the end device. The switch strips the VLAN tag from the frame before sending it out from the port.

Untagged frame from Laptop
Also, when a packet comes from the end device to the switchport, it is Untagged. “Untagged” traffic means that the connected host or Workstation doesn’t know which VLAN is connected to the switch port .
Frames don’t have dot1Q tags on them when they come into the switch port. Instead, the switch adds the VLAN tag, such as “200,” to the frame and sends it across the network.
In Cisco terms, the port is called Access port, and this VLAN is called Access VLAN.
In Short:- A switch port that carries traffic for one VLAN is known as an Access port by Cisco and Untagged ports by other vendors.
What is VLAN tagging?

VLAN Tagging on Tagged or Trunk Port
VLAN tagging refers to understanding tagged VLAN information and carrying multiple VLANs on a single switch port.
When an interface expects frames with VLAN tags, it is referred to as a ‘tagged port’ or “trunk” port in Cisco terminology. Tagged ports or Trunk ports connect two switches to pass multiple VLAN tags on a single port.
In Short – A switch port that carries multiple VLANs is known as a Trunk port by Cisco and VLANs Tagged ports by other vendors.
So to summarize VLAN tagging vs. Untagging, the terms “Access port” and “Trunk port” are frequently used in the context of the Cisco network. On the other hand, VLANs are an open standard, which means that other vendors will also implement them. And other Vendors call it Untagged (Access port) and Tagged (Trunk Port) ports simultaneously.
What is a Native VLAN?

Native VLAN
A native VLAN is used to identify or mark all untagged packets on a tagged or a trunk port.
Native VLANs are generally the same as the switch’s default VLAN, e.g., VLAN 1, unless you change it something else, e.g., 999.
What is Default VLAN?
Most switches that support VLANs come pre-installed with a default VLAN. Therefore, all ports on that switch will belong to the default VLAN by default.
Devices connected to the default VLAN on switch ports can access one another without configuration, creating hacking possibilities for the network. So you should always make sure you change the default VLAN to something different as per your company policies.
For example:- All cisco switches mostly come with VLAN 1 preconfigured as default VLAN on all ports.
VLAN tagged vs Untagged head to head comparison Sheet
| Technology Area | VLAN Tagged | VLAN Untagged |
|---|---|---|
| Definition | A switch port that carries traffic for one VLAN is known as an Access port by Cisco and an Untagged port by other vendors. | A switch port that carries multiple VLANs is a Trunk port by Cisco and a Tagged port by other vendors. |
| VLAN Quantity can be configured on a single port | A VLAN tagged port can be configured to carry multiple VLANs simultaneously. | A VLAN Untagged port can carry One Data VLAN and one Voice VLAN at maximum. |
| Frame Type | Frame with a VLAN tag. | Frame without a VLAN tag. |
| Cisco Terminology | Trunk Port | Access Port |
| Cisco Configuration Example | interface Fast Ethernet 0/3 switchport mode trunk switchport trunk encapsulation dot1q switchport trunk allowed vlan 100,200,300 |
interface Fast Ethernet 0/1 switchport mode access switchport access vlan 100 switchport voice vlan 300 |
VLAN Tagging and Untagging Example and Traffic Flow
Let’s take a scenario when Laptop-1 tries to ping Laptop-2. Both laptops are part of VLAN 200, so communication will work without using any layer3 device.
Laptop-1 and Laptop-2 are part of VLAN 200 and subnet 192.168.200.0/24 and their IP Address are 192.168.200.10/24 and 192.168.200.20/24 respectively.
Both switches have populated their MAC Address tables with all laptops/devices MAC addresses and their corresponding connected ports.
I have used the cisco 2900 series switches to demonstrate VLAN Tagged vs Untagged concept. But, of course, you can take any switch vendor of your choice, and the idea will remain the same.

VLAN tagged vs Untagged Traffic Flow
Ports 1 on both switches (layer2 switch-1, layer2 switch-2) are Untagged port or Access ports.
- interface Fa0/1
- switchport mode access
- switchport access vlan 200
Ports 2 on both switches (layer2 switch-1, layer2 switch-2) are Tagged port or Trunk ports.
- interface Fa0/2
- switchport mode trunk
- switchport encapsulation dot1q
- switchport Trunk allowed vlan 200
- Laptop-1 will forward an Untagged packet to layer2 switch-1 port1.
- layer2 switch-1 port1 will Tag the frame with VLAN tag 200.
- layer2 switch-1 will open the frame and look at the destination mac in its MAC Address table. It will find the mac address entry and forward the packet to port2.
- layer2 switch-1 port2 will check the VLAN tag of the frame, and if it matches with the configured VLAN Tag on port2, it will forward the frame to layer-2 switch-2 port2.
- Layer2 switch-2 port2 will repeat the above process.
- Layer2 switch-2 will open the frame and look at the destination mac in its MAC Address table. It will find the mac address entry and forward the packet to port1.
- Layer2 switch-2 port1 will remove the VLAN 200 tag or Untag the packet and send it over to Laptop-2.
- Laptop-2 will receive an Untag packet.
The result of the above process will be that ping will work from Laptop-1 to Laptop-2.
Acronyms Used in the Blog
- LAN:- Local Area Network
- VLAN:- Virtual Local Area Network
- DTP:- Dynamic Trunking Protocol
Conclusion
In conclusion, in this blog post, we started with a basic understanding of VLAN and VLAN tags, then we discussed the difference between VLAN tagged vs. Untagged. Finally, we finished the article with the traffic flow.
Tagged, UnTagged and Native VLANS Tutorial – A Quick Guide about What they Are?

In the early days of networks, we used hubs to connect devices to a local area network (LAN). These devices were unintelligent – they forwarded every packet they received to every other device connected to them resulting in a very “noisy” network.
They also had a single broadcast domain meaning that all broadcast traffic was sent to all devices connected to them. Moreover, all the ports on a hub (of those days) were also in a single collision domain which meant that if two devices tried to talk on the network at the same time, their packets will collide and they will need to resend those packets.
As networks evolved, network devices got smarter and we saw the advent of switches.
Each port on a switch was in its own collision domain which means that multiple devices connected to a switch can send packets at the same time. Also, switches could keep track of the port to which devices were connected to.
This means that switches do not need to flood packets out all ports except to the port on which a device is connected.
Note: Flooding still occurs for broadcast packets and also for unicast packets for which the switch does not know about the destination MAC address.
However, switches were still limited to a single broadcast domain which means that broadcast packets are sent to all ports on that switch.
It also meant that segmentation was on a per-device basis: if you wanted to differentiate between sets of users on the network, you need to connect them to different switches.
While this is not a big deal on smaller networks, it is clearly inefficient on larger networks. Enter the world of VLANs.
Note: Throughout this article, the words “packet” and “frame” are used interchangeably even though from a technical point of view, they mean different things.
Virtual Local Area Network (VLAN)
A VLAN is a logical grouping of devices on a network with each VLAN being in its own broadcast domain.
Being logical, VLANs are not restricted to the physical location of devices and can even span multiple switches.
This means that devices within a certain group do not have to be connected to the same switch for local (layer 2) communication to occur between them.

Note: Communication between VLANs requires a Layer 3 device such as a router or multi-layer switch. We will not be discussing interVLAN communication in this article.
Apart from providing logical segmentation of devices, VLANs are also useful for addressing security, easing network management, and also improving the performance of a network (e.g. by reducing the size of the broadcast domain).
It is worth mentioning that devices can be assigned to VLANs using two approaches:
- Static VLANs where ports are statically mapped/assigned to a particular VLAN
- Dynamic VLANs where devices are assigned to VLANs based on different characteristics such as MAC addresses, the username used to log on to the network, and so on.
The VLAN tag
To support VLANs, a special “tag” needs to be applied to packets so that network devices can know how to forward those packets correctly.
While different vendors have their own proprietary method for creating this tag (e.g. the now deprecated Cisco ISL protocol), a standard supported by most networking devices for supporting VLANs on Ethernet networks is the IEEE 802.1Q standard.
802.1Q adds a 32-bit field (4 bytes) inside an Ethernet frame.

The first 16 bits in this field (TPID) are used to identify the frame as an 802.1Q tagged frame while 12 out of the remaining 16 bits are used to carry the VLAN ID.
The remaining 4 bits are mainly used for Quality of Service (QoS) operations.

12 bits used for the VLAN ID means that 4096 VLANs can theoretically be supported i.e. 2^12 = 4096.
However, all 0s (0x000 in hexadecimal) and all 1s (0xFFF in hexadecimal) are reserved bringing the total supported VLANs to 4094.
Note that network vendors may also implement their own VLAN ID restrictions.
How VLAN Works
Before VLANs, the decision a switch had to make was easy:
- If the switch receives a broadcast packet or a unicast packet for which it does not know the destination MAC address, it will flood that packet to all its other ports except the one it was received on
- If the switch receives a unicast packet and it knows the destination MAC address, it will forward that packet only to the port on which the destination device is connected
With VLANs, there are a couple of things to be considered:
- Is the packet destined for a device connected to the same switch or to a device on a different switch (in the same VLAN)?
- What should the switch do if it receives a packet without a VLAN tag i.e. untagged packet?
- What should the switch do if it receives a packet with a VLAN tag i.e. tagged packet?
To answer these questions, we will discuss the following concepts: Default VLAN, Untagged Port, Tagged Port, and Native VLAN.
Default VLAN
Most switches that support VLANs come pre-installed with a default VLAN. This means that all the ports on that switch will belong to the default VLAN by default (pun intended). This is the reason you can buy a new switch, connect multiple devices to this switch, assign these devices IP addresses, and they can immediately communicate with themselves. For most vendors, the default VLAN is VLAN 1.
The snapshot below shows all the ports on a new Cisco 2960 switch in the default VLAN 1:

You will need to manually configure a port as part as another VLAN to remove it from the default VLAN.
Untagged Packet/Port
Most end devices that connect to a switch do not care about or understand VLAN tagging.
They just want to be able to communicate on the network.
This includes devices like workstations, IP cameras, and even some servers.
When these devices send packets to the switch, they send plain Ethernet frames (i.e. untagged packets) and it is up to the switch to determine how to forward that packet.
Note: Many network interface cards can be configured to understand VLAN information and even tag packets with VLAN IDs but this is not enabled by default since it is not a common requirement. See this article for how to enable VLAN tagging on Windows.
In most cases, the switch ports that connect to such end devices will be configured with a specific VLAN ID and that’s how the switch will determine how to forward the packet.
For example, if a switch receives an untagged packet from a device connected to its Fa0/1 port and that port is assigned to VLAN 10, then the switch will know that it needs to forward the packet to another device (or devices) in VLAN 10.

Note: If that port is in its default state, then it will belong to the default VLAN and untagged packets will be treated as belonging to that default VLAN.
These ports that connect to end devices are called “untagged ports” and can only be configured for a single VLAN.
Hint: Cisco calls this type of ports “access ports“.
Before the switch forwards packets out of an untagged port, it strips away any VLAN information from that packet since the receiving device won’t understand them anyway.

Note: Depending on the vendor, an untagged port that receives a tagged packet will drop that packet, except the VLAN tag matches the VLAN configured on that port.
Tagged Packet/Port
On the other hand, some devices understand and participate in VLAN tagging.
It means these devices tag the packets they send and can also understand when they received a tagged packet.
A switch is a typical example of such a device.
Since VLANs can span multiple switches, it means there needs to be a way for tagged packets to travel from one switch to another.
To do this, a single port on the same VLAN can be used on both the switches to carry traffic for that VLAN:

However, this becomes impractical and defeats the purpose of VLANs when you have multiple VLANs.
A better alternative will be a single port that can carry packets from multiple VLANs.
In this case, the switch will need to tag packets correctly for their correct VLANs as they exit the port and the receiving device (e.g. another switch) on the other end must understand this tagging and forward these packets to the correct VLANs:

These ports are known as “tagged ports” because the switch applies tags to the packets sent from such ports.
Depending on the vendor, tagged ports are able to carry traffic for all VLANs by default but a filter can be applied on such ports to limit the allowed VLANs.
Hint: Cisco calls this type of ports “trunk ports“.
Native VLAN
In the subsections above, we have considered the following scenarios:
- Untagged packet received on an untagged port: forward based on VLAN configured on the port
- Tagged packet received on an untagged port: drop packet except the tag is the same as the VLAN configured on the port
- Tagged packet received on a tagged port: forward based on the VLAN tag in the packet
There is the last scenario we have not considered: what should a tagged port do if it receives an untagged packet?
Since that port can carry multiple VLANs and is not assigned to a single VLAN, what VLAN tag should it apply to that untagged packet?
This is where the Native VLAN comes in.
The Native VLAN is the VLAN associated with all untagged packets on a tagged/trunk port.

Depending on the vendor, the Native VLAN is usually the same as the default VLAN on the switch e.g. VLAN 1.
This can be changed on a per-port basis.
Note: On Cisco switches, any packet sent from a trunk port that matches the Native VLAN ID will be sent untagged. This is why, among other reasons, it is recommended that native VLANs match on both sides of a trunk.
VLAN Tagging Scenarios
To deepen our understanding of these different terms, let us look at a few scenarios.
We will use the following lab built using Cisco Packet Tracer:

The port configuration on the switches is as follows:
| Switch | Port | Type | VLAN |
| Switch1 | Fa0/1 | Access | 10 |
| Fa0/2 | Access | 10 | |
| Fa0/3 | Trunk | ALL | |
| Fa0/4 | Access | 20 | |
| Gi0/1 | Trunk | ALL | |
| Switch2 | Fa0/1 | Access | 10 |
| Fa0/2 | Access | 20 | |
| Gi0/1 | Trunk | ALL |
The IP and MAC addresses on the PCs are as follows:
| PC | MAC Address | IP Address |
| PC1-10 | 0000.0000.0101 | 192.168.10.1 |
| PC2-10 | 0000.0000.0102 | 192.168.10.2 |
| PC3-10 | 0000.0000.0103 | 192.168.10.3 |
| PC1-20 | 0000.0000.0201 | 192.168.20.1 |
| PC2-20 | 0000.0000.0202 | 192.168.20.2 |
| PC-Unassigned | 0000.0000.0FF1 | NIL |
There is communication between all the devices in the same VLAN and ping has been used to test this connectivity.
This means that the MAC address tables of the switches have already been populated with the correct port to MAC address mapping.


Note: There is currently no communication between devices in VLAN 10 and VLAN 20. To enable interVLAN communication, a layer 3 device is required.
Scenario #1: Untagged Packet Received On/Sent Out from Untagged port
In this scenario, PC1-10 will ping PC2-10. The configuration on the switch ports they are connected to is as follows:

Since both ports (Fa0/1 and Fa0/2 on Switch1) are untagged ports, there will be no VLAN tagging on those ports.
The switch will just use the VLAN configured on the port to forward the packets correctly.
We can see this by switching to “Simulation” mode in Packet Tracer.
The packet as received on Fa0/1 (ingress) is shown below:

The packet as sent out from Fa0/2 (egress) is as shown below:

Notice that there is no VLAN information in the Ethernet frames of both ingress and egress packets.

Scenario #2: Tagged Packet Sent From/Received on Tagged port
In this scenario, PC1-20 will ping PC2-20. Since these devices are on the same VLAN, communication will be permitted.
However, since they are on different switches, the packets will need to be tagged on the trunk link between Switch1 and Switch2.
The images below show the trunking operation on both switches.
Notice that Gi0/1 on both switches are trunk ports:

Let’s look at the packets as they flow from port to port.
First, PC1-20 will send an untagged packet to Fa0/4 on Switch1:

Based on its MAC address table, the switch will determine that the packet needs to flow out through the Gi0/1 interface.
Since this is a trunk port, the switch will include the VLAN tag of 20 (hexadecimal 0x0014) into the frame:

When Switch2 receives this packet, it will see the VLAN tag in the packet:

Based on its MAC address table, Switch2 will determine that the packet needs to go out through its Fa0/2 interface.
Since Fa0/2 is an untagged/access port, the switch will strip all VLAN information from the frame before sending it along:


Scenario #3: Untagged packet received on Tagged port
In this scenario, we will simulate an UnTagged packet being received on a tagged port.
To do this, we will send a DHCP packet from PC-Unassigned through the Hub to the Fa0/3 port on Switch1.
This port is configured as a trunk port on Switch1:
![]()
PC-Unassigned will send an untagged packet to Switch1 (through the Hub):

Since this is an untagged packet received on a tagged port, Switch1 will associate that packet with the Native VLAN on that port.
In our case, the Native VLAN is VLAN 1.
This brings us to two options:
- The native VLAN on the ingress port is the same as the native VLAN on the egress port
- The native VLAN on the ingress port is different from the native VLAN on the egress port
Let’s consider the first option:

Since the packet is a broadcast packet (destination address of FFFF.FFFF.FFFF), Switch1 will flood it to all ports in that VLAN (VLAN 1 in this case).
In our lab, the only other device in VLAN 1 is the trunk port to Switch2 so the packet will be sent out the Gi0/1 port towards Switch1.
However, since the tag on the packet (VLAN 1) is the same as the Native VLAN on the egress port (Gi0/1), the packet will be sent untagged:

When Switch2 receives the untagged packet, it will also apply its own configured native VLAN to that packet and forward it appropriately:

In our lab, there are no other devices on VLAN 1 so this packet will eventually be dropped.

To see the second option, we will change the Native VLAN on the Fa0/3 port to another VLAN e.g. VLAN 10:

In this case, Switch1 will send the packet to all devices in VLAN 10, including over the trunk link to Switch2.
Since the tag on this packet is different from the Native VLAN, the packet will be sent with its tag on:


Scenario #4: Mismatched Native VLAN
Scenario #3 above presents a potential problem – if traffic that matches the Native VLAN is sent untagged, what if there is a mismatch in the native VLAN on the trunk link between two switches?
Let us see this with a theoretical scenario:

The switches are connected via trunk ports.
The server is also connected via a trunk port to SW1.
Now, imagine that SERVER-1 sends an untagged packet to SW1.
When SW1 receives this packet, it will apply a VLAN tag of “10” to that packet.
Now, assuming that this packet needs to be sent to SW2, SW1 will strip the VLAN tag away and send the packet untagged to SW2 since the tag on the packet matches the Native VLAN on the egress port.
When SW2 receives this untagged packet, it will apply a VLAN tag of “20” to that packet because that is the Native VLAN configured on that ingress port.
Therefore, SW2 will forward that packet to VLAN 20 on its own end.
This means that traffic that started on VLAN 10 ended up on VLAN 20.

However, the theory is different from what will happen on most networks today that have VLAN-aware Spanning Tree Protocol (STP) running.
For example, on Cisco switches with CDP enabled, CDP will detect that the native VLANs are mismatched:
![]()
Secondly, STP will block that port on the affected VLANs:

What it means is that traffic will not flow on that link for the affected VLANs.
All other VLANs will still be fine.
You can read more about this in this document.
This scenario has shown us a couple of things, especially from a Layer 2 security perspective:
- As much as possible, keep the Native VLAN on both sides of a trunk the same to avoid unforeseen issues
- For security reasons, change the Native VLAN on trunk ports from the default VLAN to a VLAN that is unused by other devices. Even if untagged packets get on that trunk port, the traffic will end up in an unused VLAN.
- Statically configure ports as either access or trunk ports and don’t allow for trunk negotiation. This will prevent an attacker from negotiating a trunk link and sending harmful packets.
- Any unused port should be placed in an unused VLAN and put in shutdown mode.
Conclusion
In this article, we have looked at VLANs in detail with a focus on the type of ports involved in VLAN tagging.
To summarize this article:
- VLANs allow us to segment layer 2 networks
- To achieve VLANs, a tag is applied to frames to identify what VLAN a particular packet belongs to
- The ports on most network switches belong to a default VLAN e.g. VLAN 1
- 1Q is the standard used for VLAN encapsulation on Ethernet frames
- Packets can either be untagged (no VLAN tag) or tagged (VLAN tag)
- Ports on a switch can either be untagged (does not tag packets; belongs to a single VLAN) or tagged (tags packets; can carry multiple VLANs)
- When an untagged port receives an untagged packet, the switch will forward the packet based on the VLAN configured on that port
- When an untagged port receives a tagged packet, the switch will drop the packet if the tag on the packet is not the same as the VLAN configured on that port. This behavior is vendor-specific
- A tagged port can send both untagged and tagged packets
- When a tagged port receives an untagged packet, it applies its native VLAN to that packet
- Packets that match the native VLAN configured on a tagged port are sent out untagged
- Mismatched Native VLANs can cause unforeseen problems in a network
Tagged, UnTagged and Native VLANS FAQs
What is the difference between tagged and untagged VLANs?
Tagged VLANs use VLAN tagging to add an additional header, called a VLAN tag, to the packet, which contains the VLAN ID. This allows for multiple VLANs to traverse the same link.