3.2.1. Trunk Ports
Trunk ports tag frames with VLAN information so the receiving switch knows which VLAN the frame belongs to.
Trunk Configuration:
Switch(config)# interface GigabitEthernet0/24
Switch(config-if)# switchport trunk encapsulation dot1q
Switch(config-if)# switchport mode trunk
Switch(config-if)# switchport trunk allowed vlan 10,20,30
Switch(config-if)# switchport trunk native vlan 99
switchport trunk allowed vlan 10,20,30 replaces the whole allowed list. To change an existing list without retyping it, use switchport trunk allowed vlan add 40 or switchport trunk allowed vlan remove 40.
DTP (Dynamic Trunking Protocol) is Cisco's protocol for negotiating whether a link becomes a trunk:
| Mode | Behavior |
|---|---|
switchport mode trunk | Always trunks; still sends DTP unless switchport nonegotiate is added |
switchport mode dynamic desirable | Actively asks to trunk: trunks with trunk, desirable or auto |
switchport mode dynamic auto | Trunks only if the other side asks: auto + auto stays an access link |
switchport mode access | Never trunks, but still sends DTP frames unless switchport nonegotiate is added |
⚠️ Exam Trap: DTP is also an attack path. A host that speaks DTP to a desirable or auto port can negotiate a trunk and reach every VLAN (switch spoofing). Hard-code switchport mode access on user ports and switchport mode trunk on trunks, and add switchport nonegotiate to both: hard-coding the mode stops the port from becoming a trunk, but only nonegotiate stops it sending DTP frames at all.