Configuring a Switch Port as a Trunk Port
By default, all switch ports are shut down. This procedure tells how to create a trunk port that can carry multiple VLANs using 802.1Q tagging. Trunk mode is available only with the Security Plus license.
To create an access port, where an interface is assigned to only one VLAN, see the "Configuring Switch Ports as Access Ports" section on page 4-9.
By default, the speed and duplex for switch ports are set to auto-negotiate. The default auto-negotiation setting also includes the Auto-MDI/MDIX feature. Auto-MDI/MDIX eliminates the need for crossover cabling by performing an internal crossover when a straight cable is detected during the auto-negotiation phase. Either the speed or duplex must be set to auto-negotiate to enable Auto-MDI/MDIX for the interface. If you explicitly set both the speed and duplex to a fixed value, thus disabling auto-negotiation for both settings, then Auto-MDI/MDIX is also disabled.
To configure a trunk port, perform the following steps:
Step 1 To specify the switch port you want to configure, enter the following command:
hostname(config)# interface ethernet0/port
Where port is 0 through 7. For example, enter the following command:
hostname(config)# interface ethernet0/1
Step 2 To assign VLANs to this trunk, enter one or more of the following commands.
• To assign native VLANs, enter the following command:
hostname(config-if)# switchport trunk native vlan vlan_id where the vlan_id is a single VLAN ID between 1 and 4090.
Packets on the native VLAN are not modified when sent over the trunk. For example, if a port has VLANs 2, 3 and 4 assigned to it, and VLAN 2 is the native VLAN, then packets on VLAN 2 that egress the port are not modified with an 802.1Q header. Frames which ingress (enter) this port and have no 802.1Q header are put into VLAN 2.
Each port can only have one native VLAN, but every port can have either the same or a different native VLAN.
• To assign VLANs, enter the following command:
hostname(config-if)# switchport trunk allowed vlan vlan_range where the vlan_range (with VLANs between 1 and 4090) can be identified in one of the following ways:
Separate numbers and ranges by commas, for example:
You can enter spaces instead of commas, but the command is saved to the configuration with commas.
You can include the native VLAN in this command, but it is not required; the native VLAN is passed whether it is included in this command or not.
This switch port cannot pass traffic until you assign at least one VLAN to it, native or non-native.
Step 3 To make this switch port a trunk port, enter the following command:
hostname(config-if)# switchport mode trunk
To restore this port to access mode, enter the switchport mode access command.
Step 4 (Optional) To prevent the switch port from communicating with other protected switch ports on the same VLAN, enter the following command:
hostname(config-if)# switchport protected
You might want to prevent switch ports from communicating with each other if the devices on those switch ports are primarily accessed from other VLANs, you do not need to allow intra-VLAN access, and you want to isolate the devices from each other in case of infection or other security breach. For example, if you have a DMZ that hosts three web servers, you can isolate the web servers from each other if you apply the switchport protected command to each switch port. The inside and outside networks can both communicate with all three web servers, and vice versa, but the web servers cannot communicate with each other.
Step 5 (Optional) To set the speed, enter the following command:
The auto setting is the default. Step 6 (Optional) To set the duplex, enter the following command:
hostname(config-if)# duplex {auto | full | half}
The auto setting is the default. Step 7 To enable the switch port, if it is not already enabled, enter the following command:
hostname(config-if)# no shutdown
To disable the switch port, enter the shutdown command.
The following example configures seven VLAN interfaces, including the failover interface which is configured using the failover lan command. VLANs 200, 201, and 202 are trunked on Ethernet 0/1.
|
hostname |
(config) |
# : |
interface vlan 100 |
||
|
hostname |
(config- |
if |
)# |
nameif outside |
|
|
hostname |
(config- |
if |
)# |
security-level |
0 |
|
hostname |
(config- |
if |
)# |
ip address 10.1 |
.1.1 |
|
hostname |
(config- |
if |
)# |
no shutdown |
|
|
hostname |
(config- |
if |
)# |
interface vlan |
200 |
|
hostname |
(config- |
if |
)# |
nameif inside |
|
|
hostname |
(config- |
if |
)# |
security-level |
100 |
|
hostname |
(config- |
if |
)# |
ip address 10.2 |
.1.1 |
|
hostname |
(config- |
if |
)# |
no shutdown |
|
|
hostname |
(config- |
if |
)# |
interface vlan |
201 |
|
hostname |
(config- |
if |
)# |
nameif dept1 |
|
|
hostname |
config- |
if |
# |
security-level 90 |
||||
|
hostname |
config- |
if |
# |
ip address 10.2.2.1 |
255 |
255 |
255 |
0 |
|
hostname |
config- |
if |
# |
no shutdown |
||||
|
hostname |
config- |
if |
# |
interface vlan 202 |
||||
|
hostname |
config- |
if |
# |
nameif dept2 |
||||
|
hostname |
config- |
if |
# |
security-level 90 |
||||
|
hostname |
config- |
if |
# |
ip address 10.2.3.1 |
255 |
255 |
255 |
0 |
|
hostname |
config- |
if |
# |
no shutdown |
||||
|
hostname |
config- |
if |
# |
interface vlan 300 |
||||
|
hostname |
config- |
if |
# |
nameif dmz |
||||
|
hostname |
config- |
if |
# |
security-level 50 |
||||
|
hostname |
config- |
if |
# |
ip address 10.3.1.1 |
255 |
255 |
255 |
0 |
|
hostname |
config- |
if |
# |
no shutdown |
||||
|
hostname |
config- |
if |
# |
interface vlan 400 |
||||
|
hostname |
config- |
if |
# |
nameif backup-isp |
||||
|
hostname |
config- |
if |
# |
security-level 50 |
||||
|
hostname |
config- |
if |
# |
ip address 10.1.2.1 |
255 |
255 |
255 |
0 |
|
hostname |
config- |
if |
# |
no shutdown |
hostname hostname 255.255.:
hostname hostname hostname hostname hostname hostname hostname hostname hostname hostname hostname hostname hostname hostname hostname hostname hostname config-if)# failover lan faillink vlan500
config)# failover interface ip faillink 10.4.1.1 255.255.255.0 standby 10.4.1.2 55.0
config)# interface ethernet 0/0 config-if)# switchport access vlan 100
config-if)# no shutdown config-if)# interface ethernet 0/1 config-if)# switchport mode trunk config-if)# switchport trunk allowed vlan 200-202 config-if)# switchport trunk native vlan 5
config-if)# no shutdown config-if)# interface ethernet 0/2 config-if)# switchport access vlan 300
config-if)# no shutdown config-if)# interface ethernet 0/3 config-if)# switchport access vlan 400
config-if)# no shutdown config-if)# interface ethernet 0/4 config-if)# switchport access vlan 500
config-if)# no shutdown
Continue reading here: Configuring and Enabling VLAN Subinterfaces and 8021Q Trunking
Was this article helpful?
Readers' Questions
-
samuli5 months ago
- Reply