What two trunk and access-port weaknesses allow Ethernet VLAN hopping, and which configuration choices close each one?
answer
- two weaknesses, two fixes
- the native VLAN is sent bare
- a port that negotiates trunking
- unused native VLAN; fixed access ports
basics
~20 sVLAN hopping relies on two weaknesses: the native VLAN crossing a trunk untagged, and an edge port that auto-negotiates trunking. Using a native VLAN no host sits in (or tagging it) and fixing edge ports as access ports with negotiation off closes both.
solid answer
~50 sA learner should know the two preconditions interviewers probe, because the fix follows from each. First, the **native VLAN leaves a trunk untagged**: if an access port shares the trunk's native VLAN, a frame bearing an extra outer tag for that native VLAN has the outer tag removed at the first switch and the inner tag honoured at the next, reaching another VLAN; the path is one-way because replies carry no return tag. Make the native VLAN one **no access port uses**, or tag the native VLAN, and the precondition is gone. Second, some edge ports **auto-negotiate trunking** through a proprietary protocol, so a host can talk itself a trunk and then carry every allowed VLAN. **Fix edge ports as access ports with negotiation disabled**, shut unused ports, and trim each trunk's allowed-VLAN list so only needed VLANs cross.
go deeper
Know that VLAN hopping reaches another VLAN without a router, and that leaving edge ports as fixed access ports and not reusing the native VLAN on hosts are the basic defences.
Explain why native traffic crossing a trunk untagged lets one tag be stripped, and why a port that negotiates trunking exposes every allowed VLAN.
Lay out the full hardening set, an unused or tagged native VLAN, access-mode edge ports with negotiation off, shut unused ports and trimmed allowed lists, and say which fix answers which weakness.
Treat VLAN hopping as one layer: decide where tagging mechanics stop and routed access policy or admission control must take over, and set the trunk and edge-port standard for the estate.
## What VLAN hopping is, and why it matters VLANs put departments in separate broadcast domains, and traffic between VLANs is meant to pass through a router where access policy applies. **VLAN hopping** is the umbrella term for a frame reaching a VLAN other than its own **without** going through that router. Interviewers ask about it to see whether a candidate understands the native VLAN and trunk-negotiation mechanics well enough to harden them; the value is in the defences, not the exploit. Two distinct weaknesses are discussed, each with its own mitigation. ## Weakness 1: the native VLAN crosses a trunk untagged Recall the rule: one VLAN per trunk, the **native VLAN**, is transmitted with no 802.1Q tag, and a switch strips the tag of a frame it is about to send untagged. The weakness appears when an **access port shares the trunk's native VLAN**. A frame built with **two 802.1Q tags**, an outer tag naming the native VLAN and an inner tag naming a different VLAN, is handled like this: 1. The first switch receives the frame in the native VLAN (the outer tag matches), and since the destination is across a trunk whose native VLAN is that same VLAN, it removes **only the outer tag** before sending. 2. The frame leaves carrying just the inner tag. 3. The next switch reads the inner tag as the frame's VLAN and delivers it accordingly, into a VLAN the sender was never a member of. Two facts limit and explain it: - It is **one-way**. A reply originates in the target VLAN and has no second tag to steer it back, so there is no return path; it suits one-directional traffic only. - It only works when the attacker's VLAN equals the trunk's native VLAN, because that is what lets the first switch strip the single outer tag. **The fix:** make the native VLAN a VLAN **no access port is a member of** (a dedicated, unused ID), so no host can originate a frame in it. Stronger still, configure the trunk so the native VLAN is **tagged too**, or so the port admits only tagged frames; then nothing crosses untagged and the outer tag is never stripped for free. ## Weakness 2: an edge port that negotiates itself a trunk Many switches ship edge ports in a mode that **auto-negotiates** whether a link becomes a trunk, using a proprietary vendor protocol. A device on such a port can answer the negotiation and bring up a **trunk** instead of an access connection. Once it is a trunk, the port tags and accepts frames for **every VLAN on its allowed list**, both directions, so the attached host can send into and receive from many VLANs at once. Unlike double tagging this is bidirectional, which makes it the more dangerous of the two. **The fix** is to stop edge ports ever becoming trunks: - Configure every host-facing port **statically as an access port** and **disable trunk negotiation** on it, so no negotiation frame can promote it. - **Administratively shut unused ports** (and optionally place them in a dead VLAN), so an unplugged socket cannot be used. - **Prune allowed-VLAN lists** to the VLANs each trunk genuinely needs, limiting the blast radius if a trunk is ever reached. ## Side by side | | Double tagging | Switch spoofing | |---|---|---| | Precondition | Attacker's access VLAN equals the trunk native VLAN | Edge port auto-negotiates trunking | | Mechanism | Outer tag stripped on the native VLAN; inner tag honoured onward | Port becomes a trunk and carries all allowed VLANs | | Direction | One-way only | Bidirectional | | Primary fix | Native VLAN uses an unused ID, or tag the native VLAN | Fix ports as access, disable negotiation | | Secondary fix | Admit only tagged frames on trunks | Shut unused ports, trim allowed lists | ## What VLAN hopping is not - It is **not** a flaw in the 802.1Q tag format; the tag does exactly what it is designed to do. The weakness is in how the **native VLAN and port modes** are configured. - It is **not** a substitute for routing policy. Even with hopping closed, anything the router forwards between VLANs still needs its own access control. - The access-port controls that decide **whether a device may join a port at all** are a separate, complementary layer; this leaf is about the tagging and trunk-mode mechanics those controls sit beside.
- Why is double tagging a one-way technique?The trick depends on an attacker-crafted outer tag that the first switch strips, exposing the inner tag for the next switch. A reply originates inside the target VLAN as an ordinary single-tagged or untagged frame; it has no crafted outer tag to steer it back out, so there is no return path. It therefore suits one-directional sends, not an interactive session.
- Does moving the native VLAN to an unused ID stop switch spoofing too?No, and conflating the two is a common error. An unused native VLAN defeats double tagging, which abuses untagged native traffic. Switch spoofing abuses trunk auto-negotiation, so it is stopped by fixing edge ports as access ports and disabling negotiation. Each weakness needs its own fix; neither mitigation covers both.
- Why does tagging the native VLAN help?Double tagging works because the first switch sends native-VLAN traffic untagged and so strips exactly one tag for the attacker. If the trunk tags the native VLAN as well, no frame ever leaves untagged, the free outer-tag strip never happens, and the inner tag is never exposed to the next switch.
saying these in an interview costs you the question
- VLAN hopping is a bug in the 802.1Q tag format itself.
- Double tagging gives a two-way path into the target VLAN.
- Moving the native VLAN to an unused ID also stops trunk-negotiation abuse.
- An access port can never be turned into a trunk by the attached device.
- Pruning the allowed-VLAN list has nothing to do with containing VLAN hopping.