Home › Networking › VLAN Trunk Visualizer

VLAN Trunk Visualizer

Send a frame between two switches and watch where the 802.1Q tag is added and removed — including what happens when the two ends disagree about the native VLAN.

Local toolYour network plan stays in your browser. Nothing you enter is uploaded, logged, or sent to any server.

Checks

Tagging, native VLANs, and why a mismatch is dangerous

An access port belongs to one VLAN. A frame arriving there carries no VLAN information — the switch classifies it by the port. When that frame leaves on a trunk, the switch inserts an 802.1Q tag naming the VLAN, so the switch at the far end knows which broadcast domain it belongs to.

The native VLAN is the exception. Traffic in the native VLAN crosses the trunk untagged. That exists for historical compatibility with devices that do not understand tagging.

Which produces the fault worth understanding. If switch 1 has native VLAN 10 and switch 2 has native VLAN 20, a frame from VLAN 10 leaves untagged, arrives at switch 2, and — having no tag — is classified into VLAN 20. Two broadcast domains are now joined. Neither switch logs an error, because from each one's point of view it did exactly what it was configured to do. This is sometimes called VLAN hopping, and it is why security guidance recommends setting the native VLAN to an unused ID carrying no traffic at all.

The allowed list prunes which VLANs a trunk carries. A VLAN missing from one end's list is dropped in that direction, which produces the confusing symptom of traffic working one way and not the other.

Negotiated trunks are a configuration you did not make

Some platforms default an access port to negotiating its own mode, offering to become a trunk if whatever is plugged in asks. It is convenient between two switches you control and it is a liability everywhere else: a device that speaks the negotiation protocol can turn a wall port into a trunk and reach every VLAN the port is allowed to carry.

The remedy is to state the intent rather than let it be inferred. Ports facing users are configured explicitly as access ports with negotiation switched off; ports facing switches are configured explicitly as trunks, also with negotiation off. It removes an entire category of surprise, and it makes the running configuration a description of the design rather than a record of what the two ends happened to agree on.

Allow the VLANs you meant, not all of them

A trunk left at its default carries every VLAN that exists. That is rarely what anyone intended, and the cost is not only security: every broadcast in every VLAN crosses every trunk, so a broadcast storm in one segment is felt across the whole network rather than staying where it began.

Pruning the allowed list to the VLANs that genuinely need to cross a given link contains both problems, and it makes the topology legible — the trunk configuration becomes a statement of which segments are meant to reach where. The maintenance cost is real and worth naming: a new VLAN has to be added to each trunk along its path, and the failure mode when somebody forgets is a segment that works in one building and not another. That is a considerably better failure than the alternative, because it is obvious, local, and fixed by adding one number.

Related tools

VLAN + Subnet Designer allocates the addressing. VLAN Planner documents what you already have.