VLAN hopping
An attack that sends traffic from one VLAN into another without passing the layer-3 device meant to control it, by switch spoofing or by double tagging on the native VLAN.
VLAN hopping is any attack that gets frames from one VLAN into another without crossing the layer-3 device meant to control traffic between them. Two techniques are commonly taught. In switch spoofing, the attacker’s device negotiates a trunk with a switch port left free to form one automatically, and receives every VLAN the trunk carries. In double tagging, an attacker on the native VLAN sends a frame carrying two IEEE 802.1Q tags. Because the native VLAN’s frames are commonly sent untagged on a trunk, the first switch strips the outer tag and forwards the frame; the next switch reads the inner tag and delivers it into the victim VLAN. This works in one direction only.
The defences: set user ports to access mode and turn off automatic trunk negotiation, restrict each trunk to the VLANs it needs, and move the native VLAN to an unused ID, or tag it. A VLAN is separation by configuration, and on its own it is not a security boundary for sensitive network segmentation.
Exam relevance: a scenario is likely to mention an unexpected trunk, the native VLAN or a frame carrying two tags. Candidates are expected to recognise VLAN hopping from those details, to name switch hardening as the fix, and not to treat a VLAN alone as enough isolation for sensitive systems.