Cisco Switch Trunk Not Working: Native VLAN Mismatch and Allowed VLAN Fixes
VLAN traffic not crossing a Cisco trunk or seeing CDP native VLAN mismatch messages? Verify the trunk, align the native VLAN and fix the allowed VLAN list.
Common Symptoms and Quick Fixes
| Symptom | Likely Cause | Quick Fix |
|---|---|---|
| %CDP-4-NATIVE_VLAN_MISMATCH in the log | Different native VLAN on each end | Set the same native VLAN on both sides |
| One VLAN does not cross the link | VLAN missing from the allowed list | Add it with allowed vlan add |
| Port is not a trunk | One side is in access mode | Set switchport mode trunk on both ends |
Method 1: Verify the Trunk
Run these on both switches and compare the native VLAN and allowed VLANs.
show interfaces trunk
show interfaces gi0/1 switchport
show vlan brief
Method 2: Configure the Trunk Consistently
Apply the same settings to both ends. Omit the encapsulation line on switches that only support 802.1Q, such as the 2960.
interface GigabitEthernet0/1
switchport trunk encapsulation dot1q
switchport mode trunk
switchport trunk native vlan 99
switchport trunk allowed vlan 10,20,99
no shutdown
Pro Tip for AdministratorsNever run switchport trunk allowed vlan 30 alone. It replaces the whole list. Use switchport trunk allowed vlan add 30.
Method 3: Make Sure the VLAN Exists
A VLAN missing from the VLAN database does not pass traffic.
vlan 10
name Staff
vlan 99
name Native-Unused
Frequently Asked Questions (FAQ)
Q: Why change the native VLAN from 1?
Using an unused VLAN as the native VLAN reduces the risk of VLAN hopping attacks.
Q: Does a native VLAN mismatch break traffic?
Yes. Untagged frames land in the wrong VLAN on the other side.