Linux VLAN Tagging: Diagnose a Cisco Trunk Mismatch
Follow a Linux VLAN mismatch from a failed ping to packet captures and Cisco trunk output, then restore connectivity.
Virtual LANs and Layer 2 switching, the foundation of every campus network. Articles tagged VLAN cover fundamentals, trunking, inter-VLAN routing, EtherChannel, troubleshooting, and campus design on Cisco Catalyst switches.
Follow a Linux VLAN mismatch from a failed ping to packet captures and Cisco trunk output, then restore connectivity.
The default Layer 2 posture is wide open. This checklist ties every switch-hardening control to the specific attack it stops, with live CML proof where possible: 8 spoofed ARPs dropped, an intra-VLAN ping killed, and more.
Private VLANs isolate hosts that share a subnet, at Layer 2, without a subnet per host. Primary, isolated, and community secondary VLANs on Cisco IOS XE, with the classic DMZ use case and real show output.
A router ACL only sees routed traffic, so it can never filter two hosts in the same VLAN. A VACL can. Real CML before/after: intra-VLAN ping goes 0% to 100% loss while the gateway ping still works.
DAI needs DHCP snooping bindings to validate ARP. On a static-IP segment there are none, so you supply the legitimate IP-to-MAC pairs with a static ARP ACL. Proven in CML: 8 spoofed ARPs dropped.
Five Layer 2 faults built and broken in a CML lab, ticket style: VLANs, trunks, and a spanning tree quietly blocking the port you need. Real show output, real syslog messages, and the real fix for each one.
SDM templates, errdisable recovery, and CAM aging: the unglamorous switch administration features that prevent table-full errors, dead ports, and mystery flooding, with real output from a CML lab.
ARP believes any answer it hears, which is why ARP spoofing works. Dynamic ARP Inspection and IP Source Guard fix that using the DHCP snooping binding table. Real CML output, plus an honest note on what a virtual switch can enforce.
DHCP snooping builds the binding table that DAI and IP Source Guard depend on. You see how the table populates, trusted vs untrusted ports, Option 82, and verification, with real CML output and an honest platform limitation.
One flooding host can saturate an entire VLAN. Storm control caps broadcast, multicast, and unknown-unicast rates per port; this covers the configuration, both threshold styles, the right action, and an honest note on platform support.
An MST core touching a Rapid-PVST access layer is one of the most misunderstood seams in Layer 2. Build the boundary in a CML lab, see the CIST at work, and deliberately trigger the PVST simulation inconsistency so you can recognize it.
Learn, forward, flood: the three rules a switch applies to every frame. Watch MAC addresses enter the CAM table, age, and trigger flooding, with real Cisco IOS XE output from two Linux hosts and a router in VLAN 10.