Hi Laz,
I followed your discussion with Alexis regarding default and native vlans and i try to lab it but the results is still not making sense to me.
I have two switches as seen below.
- vlan 10 is in subnet: 192.168.10.0/24
- vlan 20 is in subnet: 192.168.20.0/24
- vlan 99 is the native vlan
when i configure two PCs on both switches connected to any interface on vlan 1 at 192.168.2.0/24, pings are still successful⌠how is that possible.
I thought changing the native vlan from vlan 1 to vlan 99 while avoid that but it did not, so how is it a security reason to change the default native vlan?
I was expecting that, pings will fail when i change the native vlan from vlan 1 to vlan 99 since the switchports on both switches are still in vlan 1. Please, I will be super clad if you clarify this to me.
Host_SW#show vlan brief
VLAN Name Status Ports
---- -------------------------------- --------- -------------------------------
1 default active Fa3/0/4, Fa3/0/5, Fa3/0/6
Fa3/0/7, Fa3/0/8, Fa3/0/9
Fa3/0/10, Fa3/0/11, Fa3/0/12
Fa3/0/13, Fa3/0/14, Fa3/0/15
Fa3/0/16, Fa3/0/17, Fa3/0/18
Fa3/0/19, Fa3/0/20, Fa3/0/21
Fa3/0/22, Fa3/0/23, Fa3/0/24
Fa3/0/25, Fa3/0/26, Fa3/0/27
Fa3/0/28, Fa3/0/29, Fa3/0/30
Fa3/0/31, Fa3/0/32, Fa3/0/33
Fa3/0/34, Fa3/0/35, Fa3/0/36
Fa3/0/37, Fa3/0/38, Fa3/0/39
Fa3/0/40, Fa3/0/41, Fa3/0/42
Fa3/0/43, Fa3/0/44, Fa3/0/45
Fa3/0/46, Fa3/0/47, Fa3/0/48
Gi3/0/1, Gi3/0/2, Gi3/0/3
Gi3/0/4
10 VLAN0010 active Fa3/0/2
20 VLAN0020 active Fa3/0/3
99 native active
1002 fddi-default act/unsup
Host_SW#
Host_SW#
Host_SW#show int trunk
Port Mode Encapsulation Status Native vlan
Fa3/0/1 on 802.1q trunking 99
Port Vlans allowed on trunk
Fa3/0/1 1-4094
Port Vlans allowed and active in management domain
Fa3/0/1 1,10,20,99
Port Vlans in spanning tree forwarding state and not pruned
Fa3/0/1 1,10,20,99
Host_SW#
WAN_Sw#
WAN_Sw#show vlan brie
VLAN Name Status Ports
---- -------------------------------- --------- -------------------------------
1 default active Fa0/4, Fa0/5, Fa0/6, Fa0/7
Fa0/8, Fa0/9, Fa0/10, Fa0/11
Fa0/12, Fa0/13, Fa0/14, Fa0/15
Fa0/16, Fa0/17, Fa0/18, Fa0/19
Fa0/20, Fa0/21, Fa0/22, Fa0/23
Fa0/24, Gi0/1, Gi0/2
10 VLAN0010 active Fa0/2
20 VLAN0020 active Fa0/3
99 VLAN0099 active
500 VLAN0500 active
501 VLAN0501 active
502 VLAN0502 active
1002 fddi-default act/unsup
1003 token-ring-default act/unsup
1004 fddinet-default act/unsup
1005 trnet-default act/unsup
WAN_Sw#
WAN_Sw#
WAN_Sw#show int trunk
Port Mode Encapsulation Status Native vlan
Fa0/1 on 802.1q trunking 99
Port Vlans allowed on trunk
Fa0/1 1-4094
Port Vlans allowed and active in management domain
Fa0/1 1,10,20,99,500-502
Port Vlans in spanning tree forwarding state and not pruned
Fa0/1 1,10,20,99,500-502