Routelearn.net
Course menu

Course 4: VLANs and TrunksLesson 1.1 (1 of 7 in this course)9 of 91 in the CCNA series

VLAN

One set of switches, several separate networks: why VLANs exist, the common VLAN roles, access and trunk ports, routing between VLANs, and a complete Cisco lab with verification.

Beginner · 20 min read · Before this: Ethernet & Switching

VLAN (Virtual Local Area Network) is a logical group of switch ports that forms its own Layer 2 broadcast domain, separate from other VLANs on the same switches. Traffic between different VLANs must be routed, and trunk links carry several VLANs between devices by marking frames with 802.1Q tags.

In simple terms: VLANs let one set of switches act like several separate networks. Devices only hear broadcasts from their own VLAN, and a router is needed to go from one VLAN to another.

Why VLANs exist

Situation: an office has employees, guests and security cameras, all plugged into the same switches. Employees need company servers, guests should only reach the internet, and cameras should only talk to their recorder.

Without VLANs they'd all share one broadcast domain: every ARP and DHCP broadcast reaches every device, and there's no clean way to apply different rules to each group. With VLANs (Virtual LANs), each group becomes its own logical network on the same hardware:

GroupVLANSubnetGateway
Employees10192.168.10.0/24192.168.10.1
Guests20192.168.20.0/24192.168.20.1
Cameras30192.168.30.0/24192.168.30.1

A VLAN separates Layer 2 traffic; a subnet is the IP addressing plan for it. They come in pairs, but they're different things: one is a switch setting, the other is IP addressing.

Each VLAN is a separate broadcast domain

Situation: the employee laptop needs the printer's MAC address, so it sends an ARP broadcast.

SW1VLAN 10EmployeeGi1/0/1VLAN 10PrinterGi1/0/2VLAN 20GuestGi1/0/3VLAN 30CameraGi1/0/4
  1. 1. Broadcast arrives. It enters Gi1/0/1, an access port in VLAN 10, so the switch treats it as VLAN 10 traffic.
  2. 2. Flooded within VLAN 10 only. The switch sends it out every other VLAN 10 port (the printer) and nowhere else.
  3. 3. Other VLANs are separate. A guest broadcast stays in VLAN 20 the same way; the employee and camera never see it.

Why: a switch only floods a frame to ports in the same VLAN as the port it arrived on. Each VLAN therefore behaves like its own physical switch.

🔎 How to verify

The switch keeps a separate MAC table per VLAN. The employee and printer are listed under VLAN 10; nothing from VLAN 10 appears in VLAN 20:

Example output · based on Cisco documentation; exact format varies by platform and software version
SW1#show mac address-table vlan 10
          Mac Address Table
-------------------------------------------
Vlan    Mac Address       Type        Ports
----    -----------       --------    -----
  10    0200.0000.0010    DYNAMIC     Gi1/0/1
  10    0200.0000.0020    DYNAMIC     Gi1/0/2
Total Mac Addresses for this criterion: 2

Common VLAN roles

Some VLAN names describe a purpose (voice, management, guest); others describe behaviour (native, default). A VLAN can have more than one role, and all of them are ordinary VLANs underneath.

Data VLAN

Carries ordinary user traffic: web, email, files, applications. Example: employee laptops and printers in VLAN 10, as above.

Voice VLAN

Situation: a desk phone sits between the wall port and a PC, so one switch port serves both. The phone's calls should be separated from the PC's data.

VLAN 10PCdataVLAN 40IP phonevoiceSW1Gi1/0/5Network
  1. 1. The phone learns its VLAN. The switch advertises the voice VLAN with CDP or LLDP-MED (depending on the equipment).
  2. 2. Voice is tagged. The phone tags its own voice traffic with VLAN 40.
  3. 3. Data stays untagged. The PC's frames pass through the phone untagged, and the switch puts them in access VLAN 10.
interface GigabitEthernet1/0/5 switchport mode access switchport access vlan 10 switchport voice vlan 40

One port, two VLANs: untagged data in VLAN 10, tagged voice in VLAN 40.

Separating voice makes policy and troubleshooting easier, but it doesn't guarantee call quality on its own: QoS must be configured too.

Management VLAN

Carries traffic used to manage the network equipment itself (SSH, HTTPS, SNMP). Example: administrators reach the switches at 192.168.99.2 and .3 in VLAN 99. Restrict who can reach it. It isn't an out-of-band network: if the production switches fail, management traffic fails with them.

Default VLAN

On Cisco Catalyst switches, every port starts in VLAN 1. "Default" describes the starting configuration only; moving user and management traffic out of VLAN 1 is common practice.

Native VLAN

Decides how an 802.1Q trunk handles untagged frames: incoming untagged frames are placed in the native VLAN, and native-VLAN traffic leaves the trunk untagged (unless native tagging is configured). Both ends must match. Covered in detail in The native VLAN in detail below.

Guest VLAN

A separate network for visitors. Example: VLAN 20 can reach the internet but not employee servers. The VLAN separates the traffic; an ACL or firewall rule enforces the "internet only" policy. ("Guest VLAN" is also the name of an 802.1X feature that places unauthenticated devices into a limited VLAN.)

Design-purpose VLANs

NameExample use
Department VLANSeparate Finance from other employees
Server VLANGroup application servers
IoT VLANSensors and building devices
Camera VLANCameras and their recorder

These are naming conventions, not different kinds of Ethernet. The restrictions always come from policy.

Access ports

Situation: a laptop is plugged into Gi1/0/1. What happens: it sends ordinary, untagged frames, and the switch places them in the port's access VLAN. Why: endpoints don't need to know about VLANs; the port configuration decides membership.

PortDeviceModeAccess VLAN
Gi1/0/1Employee laptopaccess10
Gi1/0/2Printeraccess10
Gi1/0/3Guest laptopaccess20

🔎 How to verify

Example output · based on Cisco documentation; exact format varies by platform and software version
SW1#show interfaces Gi1/0/1 switchport
Name: Gi1/0/1
Switchport: Enabled
Administrative Mode: static access
Operational Mode: static access
Access Mode VLAN: 10 (EMPLOYEES)
...
Operational Mode: static access confirms it's an access port; Access Mode VLAN: 10 is the VLAN its device joins.

Trunks: following a VLAN 10 frame between switches

Situation: employees and guests work on two floors, each with its own switch. VLAN 10 and VLAN 20 must exist on both. Instead of one cable per VLAN, one trunk link carries them all. Follow a single employee frame:

trunk Gi1/0/23 ↔ Gi1/0/24SW1 · Floor 1SW2 · Floor 2VLAN 10EmployeeGi1/0/1VLAN 20GuestGi1/0/3VLAN 10Employee PCGi1/0/1VLAN 20Guest phoneGi1/0/3
  1. 1. Into an access port. The laptop sends an ordinary frame. SW1 knows it's VLAN 10 only because Gi1/0/1 is an access port in VLAN 10.
  2. 2. Tagged on the trunk. The destination is through the trunk, so SW1 inserts a 4-byte 802.1Q tag with VLAN ID 10 before sending it.
  3. 3. Read at the other end. SW2 reads VLAN ID 10 from the tag and looks the destination up in its VLAN 10 MAC table only.
  4. 4. Out of an access port. SW2 removes the tag and sends the frame out Gi1/0/1, a VLAN 10 access port. The PC never sees a tag.
  5. 5. Guests share the cable. Guest frames cross the same trunk tagged VLAN 20, and only ever leave on VLAN 20 ports.

Why it works: the tag is the only thing on the trunk that says which VLAN a frame belongs to, so both switches must agree on tagging (802.1Q) and on which VLANs the trunk may carry.

Destination MAC6 B
Source MAC6 B
802.1Q tag4 B
Type / Length2 B
Payload46–1500 B
FCS4 B
TPID16 bits0x8100 = "tagged frame"
PCP3 bitsPriority
DEI1 bitDrop eligible
VLAN ID12 bits1–4094 usable
An 802.1Q tag adds 4 bytes between the source MAC and the original Type/Length field. VLAN IDs 0 and 4095 are reserved.
Access portTrunk port
ConnectsLaptops, printers, phonesSwitches, routers, firewalls, access points
VLANsOne data VLAN (plus an optional voice VLAN)Many: the allowed list
FramesUntaggedTagged, except the native VLAN

Allowed VLANs

A trunk only carries the VLANs on its allowed list. Creating VLAN 30 on both switches is not enough: if the trunk allows only 10 and 20, camera traffic never crosses it.

Tagged vs. untagged frames

Every frame on a switch belongs to a VLAN, but not every frame carries its VLAN number. That's the whole difference:

Untagged frame
Dest MAC
Src MAC
Type
Payload
FCS
No VLAN information on the wire. The receiving switch decides the VLAN from the port.
Tagged frame (802.1Q)
Dest MAC
Src MAC
802.1Q tag: VLAN 10
Type
Payload
FCS
4 extra bytes carry the VLAN ID, so the frame says which VLAN it belongs to.
UntaggedTagged
VLAN ID in the frame?NoYes, in a 4-byte 802.1Q tag
How the VLAN is knownFrom the receiving port (its access VLAN, or the trunk's native VLAN)From the tag itself
Who needs to understand itAny Ethernet deviceVLAN-aware devices only (switches, routers, hypervisors, APs, firewalls)
VLANs per linkOneMany on the same link
Maximum frame size1518 bytes1522 bytes
Cisco port typeAccess port (and the native VLAN on a trunk)Trunk port (and the voice VLAN on an access port)

Why both exist: ordinary devices like PCs and printers don't understand tags; a tagged frame would look like an unknown protocol to them. So tags are added only on links between devices that need to carry several VLANs, and removed before frames reach ordinary devices.

Watch one frame gain and lose its tag

accesstrunktrunkaccessVLAN 10Employee PCSW1SW2HypervisorVMs in VLAN 10 & 20VLAN 10Printer
  1. 1. PC → access port: untagged. The PC sends a normal frame. SW1 puts it in VLAN 10 because of the port's configuration.
  2. 2. Across the trunk: tagged. The link carries several VLANs, so SW1 adds a tag saying VLAN 10.
  3. 3. To a VLAN-aware server: still tagged. The hypervisor's virtual switch reads the tag and hands the frame to the right VM's network.
  4. 4. To the printer: untagged. SW2 removes the tag before sending it out the printer's access port.

Where each one is used

ConnectionFrames on the wireWhy
PC, printer, camera → switchUntaggedOne VLAN, and the device doesn't understand tags
IP phone with a PC behind itVoice tagged, PC data untaggedThe phone tags its own voice VLAN; the PC stays untagged
Switch ↔ switchTagged (native VLAN untagged)Many VLANs share the link
Switch ↔ router (router-on-a-stick)TaggedEach subinterface matches one VLAN tag
Switch ↔ hypervisor or VLAN-aware serverTaggedVMs in different VLANs share one physical NIC
Switch ↔ wireless access pointTagged (management often native/untagged)Each SSID maps to a different VLAN
Switch ↔ firewallTaggedThe firewall has an interface (and policy) per VLAN

Other vendors say "tagged member" and "untagged member"

HP/Aruba, Netgear, Ubiquiti and many others don't use the words access and trunk. Instead, each port is an untagged member of one VLAN and a tagged member of any number of VLANs, and the untagged VLAN is often called the PVID (port VLAN ID). It maps directly onto Cisco terms:

Other vendorsCisco equivalent
Untagged in VLAN 10 onlyswitchport mode access + switchport access vlan 10
Tagged in 10 and 20, untagged in 99 (PVID 99)switchport mode trunk + allowed vlan 10,20,99 + native vlan 99
Untagged in 10, tagged in 40Access VLAN 10 + switchport voice vlan 40

⚠️ A port can be untagged in only one VLAN. If a frame arrives without a tag, the switch needs a single answer to "which VLAN is this?"

How to verify

Example output · based on Cisco documentation; exact format varies by platform and software version
SW1#show interfaces GigabitEthernet1/0/23 switchport
Name: Gi1/0/23
Switchport: Enabled
Administrative Mode: trunk
Operational Mode: trunk
Administrative Trunking Encapsulation: dot1q
Operational Trunking Encapsulation: dot1q
Access Mode VLAN: 1 (default)
Trunking Native Mode VLAN: 99 (NATIVE)
Administrative Native VLAN tagging: disabled
Trunking VLANs Enabled: 10,20,99
...
On a trunk: Trunking VLANs Enabled are carried tagged, except the Native Mode VLAN, which is untagged (unless native tagging is enabled). On an access port you'd instead see Operational Mode: static access and its untagged Access Mode VLAN.

Check yourself

Predict · scenario 1

A tagged frame for VLAN 10 is sent out an access port in VLAN 10 to a PC. What does the PC receive?

Predict · scenario 2

On another vendor's switch, a port is 'untagged in VLAN 30, tagged in VLANs 10 and 20'. What's the Cisco equivalent?

Predict · scenario 3

A hypervisor hosts VMs in VLANs 10 and 20 over one cable. How should the switch port be set?

The native VLAN in detail

On an 802.1Q trunk, every VLAN is tagged except one: the native VLAN. Its frames cross the trunk with no tag at all. Two rules define it:

DirectionRule
SendingFrames from the native VLAN leave the trunk untagged
ReceivingAny untagged frame arriving on the trunk is put into this switch's native VLAN
DefaultVLAN 1 on Cisco switches, unless you change it

Why it exists: 802.1Q was designed so a trunk could still carry traffic from devices that don't understand tags. One VLAN had to be the "home" for untagged frames, and that's the native VLAN.

Watch it: native vs. tagged traffic

Situation: both switches use the default native VLAN 1. A VLAN 10 frame and a VLAN 1 frame cross the same trunk:

802.1Q trunkSW1 · native 1SW2 · native 1VLAN 10PC AVLAN 1PC BVLAN 10PC CVLAN 1PC D
  1. 1. Normal VLAN: PC A's frame is tagged VLAN 10 on the trunk, as usual.
  2. 2. Native VLAN frame: PC B is in VLAN 1, which is the native VLAN.
  3. 3. Crosses untagged. SW1 sends it across the trunk with no 802.1Q tag, because VLAN 1 is native.
  4. 4. Placed in SW2's native VLAN. SW2 sees no tag, so it puts the frame into its own native VLAN (1) and delivers it to PC D. It works because both ends agree.

The key point: an untagged frame carries no VLAN information at all. The receiving switch simply assumes it belongs to its own native VLAN. That assumption is what makes a mismatch dangerous.

What goes wrong: a native VLAN mismatch

Situation: SW1 still uses native VLAN 1, but someone changed SW2 to native VLAN 99.

802.1Q trunkSW1 · native 1SW2 · native 99VLAN 1PC BVLAN 1PC DVLAN 99PC X
  1. 1. Sent untagged. PC B's VLAN 1 frame crosses untagged, because VLAN 1 is SW1's native VLAN.
  2. 2. Lands in the wrong VLAN. SW2 sees no tag and puts it into its native VLAN, 99. It can reach PC X, while PC D in VLAN 1 never gets it.
  3. 3. Spanning tree reacts. Cisco's spanning tree notices the mismatch and blocks the affected VLANs on that port ("PVID inconsistent"), so the link may stop working.

Why it happens: neither switch can tell from the frame itself which VLAN it came from. Each end applies its own native setting, so traffic silently moves between VLANs. Cisco switches usually catch it, through CDP warnings and spanning-tree inconsistency, but other vendors' switches may not.

The security angle: VLAN hopping by double tagging

Situation: an attacker's laptop is in VLAN 1, and VLAN 1 is also the trunk's native VLAN. The attacker wants to reach a server in VLAN 20.

trunk · native 1VLAN 1 = nativeAttackerSW1SW2VLAN 20Server
  1. 1. Two tags. The attacker crafts a frame with an outer tag 1 and an inner tag 20.
  2. 2. Outer tag stripped. SW1 removes the outer tag (VLAN 1 is native, so it's sent untagged), leaving the hidden tag 20 exposed on the trunk.
  3. 3. Delivered into VLAN 20. SW2 reads tag 20 and delivers the frame to the server. It's one-way (replies can't come back), but the attacker crossed VLANs.

Why it works: it only works when the attacker's access VLAN is the same as the trunk's native VLAN. Take that away and the attack fails.

Best practices

  • Use an unused VLAN as native (VLAN 99 in this lesson) and never put an access port in it.
  • Configure the same native VLAN on both ends of every trunk.
  • Keep it separate from the management VLAN and from VLAN 1.
  • Optionally tag the native VLAN too, so nothing crosses the trunk untagged.
  • Turn off trunk negotiation on user ports (switchport mode access and switchport nonegotiate), so a device can't talk a port into becoming a trunk.

Configure it

interface GigabitEthernet1/0/23 switchport mode trunk switchport trunk native vlan 99 switchport nonegotiate

Same native VLAN on the other end of the link. nonegotiate turns off DTP on the trunk.

vlan dot1q tag native

Global command (supported platforms): tag native-VLAN frames on all trunks too.

On a router-on-a-stick, the router must agree with the switch: either a subinterface marked native, or untagged on the physical interface.

interface GigabitEthernet0/0.99 encapsulation dot1Q 99 native

The router treats untagged frames on Gi0/0 as VLAN 99, matching the switch.

Verify it

Example output · based on Cisco documentation; exact format varies by platform and software version
SW1#show interfaces GigabitEthernet1/0/23 switchport
Name: Gi1/0/23
Switchport: Enabled
Administrative Mode: trunk
Operational Mode: trunk
Administrative Trunking Encapsulation: dot1q
Negotiation of Trunking: Off
Access Mode VLAN: 1 (default)
Trunking Native Mode VLAN: 99 (NATIVE)
Administrative Native VLAN tagging: enabled
...
Trunking Native Mode VLAN: 99 is this end's native VLAN; compare it with the other switch. Negotiation of Trunking: Off confirms DTP is disabled. The quick check across all trunks is the Native vlan column of show interfaces trunk.

If the two ends don't match, these log messages are the giveaway:

Example output · based on Cisco documentation; exact format varies by platform and software version
%CDP-4-NATIVE_VLAN_MISMATCH: Native VLAN mismatch discovered on GigabitEthernet1/0/23 (1), with SW2 GigabitEthernet1/0/24 (99).
%SPANTREE-2-RECV_PVID_ERR: Received BPDU with inconsistent peer vlan id 99 on GigabitEthernet1/0/23 VLAN1.
%SPANTREE-2-BLOCK_PVID_LOCAL: Blocking GigabitEthernet1/0/23 on VLAN0001. Inconsistent local vlan.
The CDP message names both ends and their native VLANs. The spanning-tree messages show the port being blocked for the affected VLAN until the native VLANs match.

Check yourself

Predict · scenario 1

A trunk uses native VLAN 99 on both ends. A frame from VLAN 99 crosses it. What does it look like on the wire?

Predict · scenario 2

SW1's trunk has native VLAN 10, SW2's end has native VLAN 20. A VLAN 10 user on SW1 sends a broadcast. Where does it end up on SW2?

Predict · scenario 3

Which change stops the double-tagging attack shown above?

Routing between VLANs

A switch alone never forwards traffic from VLAN 10 into VLAN 20. A Layer 3 device (router, firewall or multilayer switch) has to route between the subnets, and each VLAN gets its own gateway address.

Design 1: router-on-a-stick

Situation: employee 192.168.10.25 sends to guest device 192.168.20.50. One router link is a trunk, with a subinterface (and gateway) per VLAN.

trunkR1Gi0/0.10 · Gi0/0.20SW1VLAN 10Employee192.168.10.25VLAN 20Guest device192.168.20.50
  1. 1. Off-subnet, so use the gateway. 192.168.20.50 isn't in 192.168.10.0/24, so the laptop addresses the frame to its gateway 192.168.10.1.
  2. 2. Up the trunk. SW1 tags the frame VLAN 10; R1 receives it on subinterface Gi0/0.10.
  3. 3. Routed. R1 has 192.168.20.0/24 on Gi0/0.20, so (if policy allows) it sends a new frame back down the trunk, tagged VLAN 20.
  4. 4. Delivered. SW1 removes the tag and delivers it on the guest's access port. The destination IP never changed.
interface GigabitEthernet0/0 no shutdown interface GigabitEthernet0/0.10 encapsulation dot1Q 10 ip address 192.168.10.1 255.255.255.0 interface GigabitEthernet0/0.20 encapsulation dot1Q 20 ip address 192.168.20.1 255.255.255.0 interface GigabitEthernet0/0.99 encapsulation dot1Q 99 native

One subinterface per VLAN; 'encapsulation dot1Q' ties it to the VLAN tag. The native subinterface matches the switch's native VLAN 99.

Design 2: multilayer switch with SVIs

A multilayer switch routes internally using Switch Virtual Interfaces (SVIs), one per VLAN, so traffic never leaves the switch to be routed. It scales better than a single router link.

Multilayer switchSVI Vlan10 · Vlan20VLAN 10Employee192.168.10.25VLAN 20Guest device192.168.20.50
  1. 1. To the gateway. The laptop's gateway, 192.168.10.1, is the switch's own SVI for VLAN 10.
  2. 2. Routed inside the switch. The switch routes from SVI Vlan10 to SVI Vlan20 and delivers the frame on the guest's port.
ip routing interface Vlan10 ip address 192.168.10.1 255.255.255.0 no shutdown interface Vlan20 ip address 192.168.20.1 255.255.255.0 no shutdown

'ip routing' turns on Layer 3 forwarding. An SVI only comes up when its VLAN exists and has at least one active port in it.

Either way, VLANs separate traffic but routing reconnects it: use ACLs or firewall rules to decide what's allowed between them.

Configuration lab

Build a small two-floor office with router-on-a-stick. Each command is explained below the configuration.

trunktrunkR1Gi0/0SW1Gi1/0/24 ↑ · Gi1/0/23 →SW2Gi1/0/24 ←VLAN 10PC1192.168.10.11VLAN 20PC2192.168.20.11VLAN 10PC3192.168.10.12
  1. 1. Test 1: same VLAN, two switches. PC1 → PC3 crosses the SW1–SW2 trunk. No router needed.
  2. 2. Test 2: between VLANs. PC1 → PC2 goes up to R1 and back down, tagged VLAN 10 then VLAN 20.
DeviceInterfaceVLANIP addressGateway
R1Gi0/0.1010192.168.10.1/24—
R1Gi0/0.2020192.168.20.1/24—
PC1SW1 Gi1/0/110192.168.10.11/24192.168.10.1
PC2SW1 Gi1/0/320192.168.20.11/24192.168.20.1
PC3SW2 Gi1/0/110192.168.10.12/24192.168.10.1
TrunksR1–SW1, SW1–SW210, 20, native 99——

SW1 (SW2 is the same, minus the router trunk and PC2's port)

vlan 10 name EMPLOYEES vlan 20 name GUESTS vlan 99 name NATIVE interface GigabitEthernet1/0/1 switchport mode access switchport access vlan 10 interface GigabitEthernet1/0/3 switchport mode access switchport access vlan 20 interface range GigabitEthernet1/0/23 - 24 switchport mode trunk switchport trunk allowed vlan 10,20,99 switchport trunk native vlan 99

R1

Use the router-on-a-stick configuration from Design 1 above.

CommandWhat it does
vlan 10 / nameCreates the VLAN in the switch's database and labels it
switchport mode accessMakes the port a fixed access port (no trunk negotiation)
switchport access vlan 10Puts the port's device into VLAN 10
switchport mode trunkMakes the port a permanent 802.1Q trunk
switchport trunk allowed vlanLimits the trunk to the VLANs listed
switchport trunk native vlan 99Moves untagged trunk traffic to unused VLAN 99, on both ends

Some older platforms also need switchport trunk encapsulation dot1q before switchport mode trunk.

Verification: what you should see

Example output · based on Cisco documentation; exact format varies by platform and software version
SW1#show vlan brief
VLAN Name                             Status    Ports
---- -------------------------------- --------- -------------------------------
1    default                          active    Gi1/0/2, Gi1/0/4, Gi1/0/5, ...
10   EMPLOYEES                        active    Gi1/0/1
20   GUESTS                           active    Gi1/0/3
99   NATIVE                           active
1002 fddi-default                     act/unsup
1003 token-ring-default               act/unsup
1004 fddinet-default                  act/unsup
1005 trnet-default                    act/unsup
Each access port is listed beside its VLAN. Trunk ports never appear here: Gi1/0/23 and Gi1/0/24 are missing on purpose. VLANs 1002–1005 are legacy defaults you can ignore.
Example output · based on Cisco documentation; exact format varies by platform and software version
SW1#show interfaces trunk
Port        Mode             Encapsulation  Status        Native vlan
Gi1/0/23    on               802.1q         trunking      99
Gi1/0/24    on               802.1q         trunking      99

Port        Vlans allowed on trunk
Gi1/0/23    10,20,99
Gi1/0/24    10,20,99

Port        Vlans allowed and active in management domain
Gi1/0/23    10,20,99
Gi1/0/24    10,20,99

Port        Vlans in spanning tree forwarding state and not pruned
Gi1/0/23    10,20,99
Gi1/0/24    10,20,99
Status: trunking means the link is up as a trunk. Native vlan must match the other end. A VLAN must appear in all three lists to actually be forwarded: allowed, active (it exists on this switch), and forwarding in spanning tree.
Example output · based on Cisco documentation; exact format varies by platform and software version
R1#show ip interface brief
Interface              IP-Address      OK? Method Status                Protocol
GigabitEthernet0/0     unassigned      YES unset  up                    up
GigabitEthernet0/0.10  192.168.10.1    YES manual up                    up
GigabitEthernet0/0.20  192.168.20.1    YES manual up                    up
GigabitEthernet0/0.99  unassigned      YES unset  up                    up
Each subinterface should be up/up with its gateway address. The physical Gi0/0 has no IP of its own.
show ip route connected

On R1: both 192.168.10.0/24 and 192.168.20.0/24 should appear as connected networks.

Example output · based on Cisco documentation; exact format varies by platform and software version
PC1> ping 192.168.20.11
Reply from 192.168.20.11: bytes=32 time=1ms TTL=127
Reply from 192.168.20.11: bytes=32 time=1ms TTL=127
A reply from PC2 proves inter-VLAN routing works. TTL=127 (one less than Windows' 128) shows the packet crossed one router.

A working ping proves connectivity, not that the design is secure. If guests shouldn't reach employees, also test that the prohibited paths are blocked once your ACLs or firewall rules are in place.

Troubleshooting

For each problem: what you'll notice, why it happens, and how to prove it.

1. Wrong access VLAN

Symptom: PC1 gets a 192.168.20.x address, or can't reach other employees. Why: its port is in the wrong VLAN, so it's in the wrong broadcast domain. Verify: show vlan brief lists Gi1/0/1 under VLAN 20. Fix: switchport access vlan 10 on that port.

2. VLAN missing from the trunk's allowed list

Symptom: PC1 can't reach PC3 (same VLAN, different switches), but everything else works. Why: the trunk doesn't carry VLAN 10. Verify:

Example output · based on Cisco documentation; exact format varies by platform and software version
SW1#show interfaces trunk
Port        Vlans allowed on trunk
Gi1/0/23    20,99
VLAN 10 is missing. Fix: switchport trunk allowed vlan add 10. Use add — without it, the command replaces the whole list.

3. Native VLAN mismatch

Symptom: untagged traffic appears in the wrong VLAN, and the switches log warnings. Why: each end puts untagged frames in a different VLAN. Verify: the "Native vlan" column of show interfaces trunk differs between the two switches; Cisco CDP reports:

Example output · based on Cisco documentation; exact format varies by platform and software version
%CDP-4-NATIVE_VLAN_MISMATCH: Native VLAN mismatch discovered on GigabitEthernet1/0/23 (99), with SW2 GigabitEthernet1/0/24 (1).
Fix: set the same switchport trunk native vlan on both ends.

4. DHCP fails in one VLAN

Symptom: guests get 169.254.x.x addresses; employees are fine. Why: the DHCP server is on another subnet and VLAN 20's gateway has no relay, or the server has no VLAN 20 pool. Verify: check ip helper-address on the VLAN 20 subinterface or SVI, and the server's pools. Fix: add the helper or the pool. See DHCP.

5. Gateway problems

Symptom: PC1 reaches PC3 (same VLAN) but not PC2. Why: Layer 2 works; routing doesn't. Typical causes are a wrong gateway on the PC, a subinterface with the wrong encapsulation dot1Q VLAN, the VLAN not allowed on the router trunk, or an SVI that's down. Verify: ipconfig on the PC, show ip interface brief on R1 (subinterfaces up/up?), and show interfaces trunk on SW1's router-facing port.

Practice

Predict · scenario 1

VLAN 30 exists on both switches, but the trunk between them shows 'Vlans allowed on trunk: 10,20,99'.

Predict · scenario 2

PC1 (VLAN 10) and PC2 (VLAN 20) are on the same switch, and no router or SVI is configured.

Predict · scenario 3

After 'switchport trunk allowed vlan 30' is typed on a working trunk that carried 10 and 20, employees on floor 2 lose contact with floor 1.

Small tasks

Task 1: Put port Gi1/0/7 into VLAN 20 as an access port.
interface GigabitEthernet1/0/7 switchport mode access switchport access vlan 20

Then confirm it with show vlan brief: Gi1/0/7 appears in the VLAN 20 row.

Task 2: Allow VLAN 30 on trunk Gi1/0/23 without removing VLANs 10, 20 and 99.
interface GigabitEthernet1/0/23 switchport trunk allowed vlan add 30

show interfaces trunk should now list 10,20,30,99. The same change is needed on SW2's end.

Task 3: Add a gateway for VLAN 30 (192.168.30.1/24) on R1.
interface GigabitEthernet0/0.30 encapsulation dot1Q 30 ip address 192.168.30.1 255.255.255.0

VLAN 30 must also be allowed on the R1–SW1 trunk, or the subinterface has nothing to route.

Advanced VLAN lessons

Once the core is solid, each advanced topic has its own short lesson:

✅ Key takeaways
  • A VLAN is a separate Layer 2 broadcast domain; its subnet is the matching IP plan.
  • Access ports put untagged endpoint traffic into one VLAN (plus an optional voice VLAN).
  • Trunks carry the allowed VLANs between switches using 802.1Q tags; native VLAN frames go untagged.
  • Different VLANs need a router or SVIs to communicate, and ACLs decide what's allowed.
  • Verify with show vlan brief, show interfaces trunk and show ip interface brief.

FAQ

Does every VLAN need its own subnet?
In practice, yes. The VLAN separates Layer 2 traffic; the subnet is its IP addressing plan, and routing between VLANs works subnet to subnet.
Are the default, native and management VLAN the same thing?
No. They're three different roles: default is where ports start (VLAN 1 on Cisco), native is how a trunk handles untagged frames, and management is where you reach the switches. They may start out as the same VLAN, but they don't have to be, and usually shouldn't stay that way.
Do VLANs make a network secure on their own?
They separate Layer 2 traffic. Once routing exists between VLANs, it's ACLs or firewall rules that decide which traffic is allowed.