Why VLANs exist
Situation: an office has employees, guests and security cameras, all plugged into the same switches. Employees need company servers, guests should only reach the internet, and cameras should only talk to their recorder.
Without VLANs they'd all share one broadcast domain: every ARP and DHCP broadcast reaches every device, and there's no clean way to apply different rules to each group. With VLANs (Virtual LANs), each group becomes its own logical network on the same hardware:
| Group | VLAN | Subnet | Gateway |
|---|---|---|---|
| Employees | 10 | 192.168.10.0/24 | 192.168.10.1 |
| Guests | 20 | 192.168.20.0/24 | 192.168.20.1 |
| Cameras | 30 | 192.168.30.0/24 | 192.168.30.1 |
A VLAN separates Layer 2 traffic; a subnet is the IP addressing plan for it. They come in pairs, but they're different things: one is a switch setting, the other is IP addressing.
Each VLAN is a separate broadcast domain
Situation: the employee laptop needs the printer's MAC address, so it sends an ARP broadcast.
- 1. Broadcast arrives. It enters Gi1/0/1, an access port in VLAN 10, so the switch treats it as VLAN 10 traffic.
- 2. Flooded within VLAN 10 only. The switch sends it out every other VLAN 10 port (the printer) and nowhere else.
- 3. Other VLANs are separate. A guest broadcast stays in VLAN 20 the same way; the employee and camera never see it.
Why: a switch only floods a frame to ports in the same VLAN as the port it arrived on. Each VLAN therefore behaves like its own physical switch.
🔎 How to verify
The switch keeps a separate MAC table per VLAN. The employee and printer are listed under VLAN 10; nothing from VLAN 10 appears in VLAN 20:
SW1#show mac address-table vlan 10 Mac Address Table ------------------------------------------- Vlan Mac Address Type Ports ---- ----------- -------- ----- 10 0200.0000.0010 DYNAMIC Gi1/0/1 10 0200.0000.0020 DYNAMIC Gi1/0/2 Total Mac Addresses for this criterion: 2
Common VLAN roles
Some VLAN names describe a purpose (voice, management, guest); others describe behaviour (native, default). A VLAN can have more than one role, and all of them are ordinary VLANs underneath.
Data VLAN
Carries ordinary user traffic: web, email, files, applications. Example: employee laptops and printers in VLAN 10, as above.
Voice VLAN
Situation: a desk phone sits between the wall port and a PC, so one switch port serves both. The phone's calls should be separated from the PC's data.
- 1. The phone learns its VLAN. The switch advertises the voice VLAN with CDP or LLDP-MED (depending on the equipment).
- 2. Voice is tagged. The phone tags its own voice traffic with VLAN 40.
- 3. Data stays untagged. The PC's frames pass through the phone untagged, and the switch puts them in access VLAN 10.
interface GigabitEthernet1/0/5
switchport mode access
switchport access vlan 10
switchport voice vlan 40One port, two VLANs: untagged data in VLAN 10, tagged voice in VLAN 40.
Separating voice makes policy and troubleshooting easier, but it doesn't guarantee call quality on its own: QoS must be configured too.
Management VLAN
Carries traffic used to manage the network equipment itself (SSH, HTTPS, SNMP). Example: administrators reach the switches at 192.168.99.2 and .3 in VLAN 99. Restrict who can reach it. It isn't an out-of-band network: if the production switches fail, management traffic fails with them.
Default VLAN
On Cisco Catalyst switches, every port starts in VLAN 1. "Default" describes the starting configuration only; moving user and management traffic out of VLAN 1 is common practice.
Native VLAN
Decides how an 802.1Q trunk handles untagged frames: incoming untagged frames are placed in the native VLAN, and native-VLAN traffic leaves the trunk untagged (unless native tagging is configured). Both ends must match. Covered in detail in The native VLAN in detail below.
Guest VLAN
A separate network for visitors. Example: VLAN 20 can reach the internet but not employee servers. The VLAN separates the traffic; an ACL or firewall rule enforces the "internet only" policy. ("Guest VLAN" is also the name of an 802.1X feature that places unauthenticated devices into a limited VLAN.)
Design-purpose VLANs
| Name | Example use |
|---|---|
| Department VLAN | Separate Finance from other employees |
| Server VLAN | Group application servers |
| IoT VLAN | Sensors and building devices |
| Camera VLAN | Cameras and their recorder |
These are naming conventions, not different kinds of Ethernet. The restrictions always come from policy.
Access ports
Situation: a laptop is plugged into Gi1/0/1. What happens: it sends ordinary, untagged frames, and the switch places them in the port's access VLAN. Why: endpoints don't need to know about VLANs; the port configuration decides membership.
| Port | Device | Mode | Access VLAN |
|---|---|---|---|
| Gi1/0/1 | Employee laptop | access | 10 |
| Gi1/0/2 | Printer | access | 10 |
| Gi1/0/3 | Guest laptop | access | 20 |
🔎 How to verify
SW1#show interfaces Gi1/0/1 switchport Name: Gi1/0/1 Switchport: Enabled Administrative Mode: static access Operational Mode: static access Access Mode VLAN: 10 (EMPLOYEES) ...
Trunks: following a VLAN 10 frame between switches
Situation: employees and guests work on two floors, each with its own switch. VLAN 10 and VLAN 20 must exist on both. Instead of one cable per VLAN, one trunk link carries them all. Follow a single employee frame:
- 1. Into an access port. The laptop sends an ordinary frame. SW1 knows it's VLAN 10 only because Gi1/0/1 is an access port in VLAN 10.
- 2. Tagged on the trunk. The destination is through the trunk, so SW1 inserts a 4-byte 802.1Q tag with VLAN ID 10 before sending it.
- 3. Read at the other end. SW2 reads VLAN ID 10 from the tag and looks the destination up in its VLAN 10 MAC table only.
- 4. Out of an access port. SW2 removes the tag and sends the frame out Gi1/0/1, a VLAN 10 access port. The PC never sees a tag.
- 5. Guests share the cable. Guest frames cross the same trunk tagged VLAN 20, and only ever leave on VLAN 20 ports.
Why it works: the tag is the only thing on the trunk that says which VLAN a frame belongs to, so both switches must agree on tagging (802.1Q) and on which VLANs the trunk may carry.
| Access port | Trunk port | |
|---|---|---|
| Connects | Laptops, printers, phones | Switches, routers, firewalls, access points |
| VLANs | One data VLAN (plus an optional voice VLAN) | Many: the allowed list |
| Frames | Untagged | Tagged, except the native VLAN |
Allowed VLANs
A trunk only carries the VLANs on its allowed list. Creating VLAN 30 on both switches is not enough: if the trunk allows only 10 and 20, camera traffic never crosses it.
Tagged vs. untagged frames
Every frame on a switch belongs to a VLAN, but not every frame carries its VLAN number. That's the whole difference:
| Untagged | Tagged | |
|---|---|---|
| VLAN ID in the frame? | No | Yes, in a 4-byte 802.1Q tag |
| How the VLAN is known | From the receiving port (its access VLAN, or the trunk's native VLAN) | From the tag itself |
| Who needs to understand it | Any Ethernet device | VLAN-aware devices only (switches, routers, hypervisors, APs, firewalls) |
| VLANs per link | One | Many on the same link |
| Maximum frame size | 1518 bytes | 1522 bytes |
| Cisco port type | Access port (and the native VLAN on a trunk) | Trunk port (and the voice VLAN on an access port) |
Why both exist: ordinary devices like PCs and printers don't understand tags; a tagged frame would look like an unknown protocol to them. So tags are added only on links between devices that need to carry several VLANs, and removed before frames reach ordinary devices.
Watch one frame gain and lose its tag
- 1. PC → access port: untagged. The PC sends a normal frame. SW1 puts it in VLAN 10 because of the port's configuration.
- 2. Across the trunk: tagged. The link carries several VLANs, so SW1 adds a tag saying VLAN 10.
- 3. To a VLAN-aware server: still tagged. The hypervisor's virtual switch reads the tag and hands the frame to the right VM's network.
- 4. To the printer: untagged. SW2 removes the tag before sending it out the printer's access port.
Where each one is used
| Connection | Frames on the wire | Why |
|---|---|---|
| PC, printer, camera → switch | Untagged | One VLAN, and the device doesn't understand tags |
| IP phone with a PC behind it | Voice tagged, PC data untagged | The phone tags its own voice VLAN; the PC stays untagged |
| Switch ↔ switch | Tagged (native VLAN untagged) | Many VLANs share the link |
| Switch ↔ router (router-on-a-stick) | Tagged | Each subinterface matches one VLAN tag |
| Switch ↔ hypervisor or VLAN-aware server | Tagged | VMs in different VLANs share one physical NIC |
| Switch ↔ wireless access point | Tagged (management often native/untagged) | Each SSID maps to a different VLAN |
| Switch ↔ firewall | Tagged | The firewall has an interface (and policy) per VLAN |
Other vendors say "tagged member" and "untagged member"
HP/Aruba, Netgear, Ubiquiti and many others don't use the words access and trunk. Instead, each port is an untagged member of one VLAN and a tagged member of any number of VLANs, and the untagged VLAN is often called the PVID (port VLAN ID). It maps directly onto Cisco terms:
| Other vendors | Cisco equivalent |
|---|---|
| Untagged in VLAN 10 only | switchport mode access + switchport access vlan 10 |
| Tagged in 10 and 20, untagged in 99 (PVID 99) | switchport mode trunk + allowed vlan 10,20,99 + native vlan 99 |
| Untagged in 10, tagged in 40 | Access VLAN 10 + switchport voice vlan 40 |
⚠️ A port can be untagged in only one VLAN. If a frame arrives without a tag, the switch needs a single answer to "which VLAN is this?"
How to verify
SW1#show interfaces GigabitEthernet1/0/23 switchport Name: Gi1/0/23 Switchport: Enabled Administrative Mode: trunk Operational Mode: trunk Administrative Trunking Encapsulation: dot1q Operational Trunking Encapsulation: dot1q Access Mode VLAN: 1 (default) Trunking Native Mode VLAN: 99 (NATIVE) Administrative Native VLAN tagging: disabled Trunking VLANs Enabled: 10,20,99 ...
Check yourself
A tagged frame for VLAN 10 is sent out an access port in VLAN 10 to a PC. What does the PC receive?
On another vendor's switch, a port is 'untagged in VLAN 30, tagged in VLANs 10 and 20'. What's the Cisco equivalent?
A hypervisor hosts VMs in VLANs 10 and 20 over one cable. How should the switch port be set?
The native VLAN in detail
On an 802.1Q trunk, every VLAN is tagged except one: the native VLAN. Its frames cross the trunk with no tag at all. Two rules define it:
| Direction | Rule |
|---|---|
| Sending | Frames from the native VLAN leave the trunk untagged |
| Receiving | Any untagged frame arriving on the trunk is put into this switch's native VLAN |
| Default | VLAN 1 on Cisco switches, unless you change it |
Why it exists: 802.1Q was designed so a trunk could still carry traffic from devices that don't understand tags. One VLAN had to be the "home" for untagged frames, and that's the native VLAN.
Watch it: native vs. tagged traffic
Situation: both switches use the default native VLAN 1. A VLAN 10 frame and a VLAN 1 frame cross the same trunk:
- 1. Normal VLAN: PC A's frame is tagged VLAN 10 on the trunk, as usual.
- 2. Native VLAN frame: PC B is in VLAN 1, which is the native VLAN.
- 3. Crosses untagged. SW1 sends it across the trunk with no 802.1Q tag, because VLAN 1 is native.
- 4. Placed in SW2's native VLAN. SW2 sees no tag, so it puts the frame into its own native VLAN (1) and delivers it to PC D. It works because both ends agree.
The key point: an untagged frame carries no VLAN information at all. The receiving switch simply assumes it belongs to its own native VLAN. That assumption is what makes a mismatch dangerous.
What goes wrong: a native VLAN mismatch
Situation: SW1 still uses native VLAN 1, but someone changed SW2 to native VLAN 99.
- 1. Sent untagged. PC B's VLAN 1 frame crosses untagged, because VLAN 1 is SW1's native VLAN.
- 2. Lands in the wrong VLAN. SW2 sees no tag and puts it into its native VLAN, 99. It can reach PC X, while PC D in VLAN 1 never gets it.
- 3. Spanning tree reacts. Cisco's spanning tree notices the mismatch and blocks the affected VLANs on that port ("PVID inconsistent"), so the link may stop working.
Why it happens: neither switch can tell from the frame itself which VLAN it came from. Each end applies its own native setting, so traffic silently moves between VLANs. Cisco switches usually catch it, through CDP warnings and spanning-tree inconsistency, but other vendors' switches may not.
The security angle: VLAN hopping by double tagging
Situation: an attacker's laptop is in VLAN 1, and VLAN 1 is also the trunk's native VLAN. The attacker wants to reach a server in VLAN 20.
- 1. Two tags. The attacker crafts a frame with an outer tag 1 and an inner tag 20.
- 2. Outer tag stripped. SW1 removes the outer tag (VLAN 1 is native, so it's sent untagged), leaving the hidden tag 20 exposed on the trunk.
- 3. Delivered into VLAN 20. SW2 reads tag 20 and delivers the frame to the server. It's one-way (replies can't come back), but the attacker crossed VLANs.
Why it works: it only works when the attacker's access VLAN is the same as the trunk's native VLAN. Take that away and the attack fails.
Best practices
- Use an unused VLAN as native (VLAN 99 in this lesson) and never put an access port in it.
- Configure the same native VLAN on both ends of every trunk.
- Keep it separate from the management VLAN and from VLAN 1.
- Optionally tag the native VLAN too, so nothing crosses the trunk untagged.
- Turn off trunk negotiation on user ports (
switchport mode accessandswitchport nonegotiate), so a device can't talk a port into becoming a trunk.
Configure it
interface GigabitEthernet1/0/23
switchport mode trunk
switchport trunk native vlan 99
switchport nonegotiateSame native VLAN on the other end of the link. nonegotiate turns off DTP on the trunk.
vlan dot1q tag nativeGlobal command (supported platforms): tag native-VLAN frames on all trunks too.
On a router-on-a-stick, the router must agree with the switch: either a subinterface marked native, or untagged on the physical interface.
interface GigabitEthernet0/0.99
encapsulation dot1Q 99 nativeThe router treats untagged frames on Gi0/0 as VLAN 99, matching the switch.
Verify it
SW1#show interfaces GigabitEthernet1/0/23 switchport Name: Gi1/0/23 Switchport: Enabled Administrative Mode: trunk Operational Mode: trunk Administrative Trunking Encapsulation: dot1q Negotiation of Trunking: Off Access Mode VLAN: 1 (default) Trunking Native Mode VLAN: 99 (NATIVE) Administrative Native VLAN tagging: enabled ...
show interfaces trunk.If the two ends don't match, these log messages are the giveaway:
%CDP-4-NATIVE_VLAN_MISMATCH: Native VLAN mismatch discovered on GigabitEthernet1/0/23 (1), with SW2 GigabitEthernet1/0/24 (99). %SPANTREE-2-RECV_PVID_ERR: Received BPDU with inconsistent peer vlan id 99 on GigabitEthernet1/0/23 VLAN1. %SPANTREE-2-BLOCK_PVID_LOCAL: Blocking GigabitEthernet1/0/23 on VLAN0001. Inconsistent local vlan.
Check yourself
A trunk uses native VLAN 99 on both ends. A frame from VLAN 99 crosses it. What does it look like on the wire?
SW1's trunk has native VLAN 10, SW2's end has native VLAN 20. A VLAN 10 user on SW1 sends a broadcast. Where does it end up on SW2?
Which change stops the double-tagging attack shown above?
Routing between VLANs
A switch alone never forwards traffic from VLAN 10 into VLAN 20. A Layer 3 device (router, firewall or multilayer switch) has to route between the subnets, and each VLAN gets its own gateway address.
Design 1: router-on-a-stick
Situation: employee 192.168.10.25 sends to guest device 192.168.20.50. One router link is a trunk, with a subinterface (and gateway) per VLAN.
- 1. Off-subnet, so use the gateway. 192.168.20.50 isn't in 192.168.10.0/24, so the laptop addresses the frame to its gateway 192.168.10.1.
- 2. Up the trunk. SW1 tags the frame VLAN 10; R1 receives it on subinterface Gi0/0.10.
- 3. Routed. R1 has 192.168.20.0/24 on Gi0/0.20, so (if policy allows) it sends a new frame back down the trunk, tagged VLAN 20.
- 4. Delivered. SW1 removes the tag and delivers it on the guest's access port. The destination IP never changed.
interface GigabitEthernet0/0
no shutdown
interface GigabitEthernet0/0.10
encapsulation dot1Q 10
ip address 192.168.10.1 255.255.255.0
interface GigabitEthernet0/0.20
encapsulation dot1Q 20
ip address 192.168.20.1 255.255.255.0
interface GigabitEthernet0/0.99
encapsulation dot1Q 99 nativeOne subinterface per VLAN; 'encapsulation dot1Q' ties it to the VLAN tag. The native subinterface matches the switch's native VLAN 99.
Design 2: multilayer switch with SVIs
A multilayer switch routes internally using Switch Virtual Interfaces (SVIs), one per VLAN, so traffic never leaves the switch to be routed. It scales better than a single router link.
- 1. To the gateway. The laptop's gateway, 192.168.10.1, is the switch's own SVI for VLAN 10.
- 2. Routed inside the switch. The switch routes from SVI Vlan10 to SVI Vlan20 and delivers the frame on the guest's port.
ip routing
interface Vlan10
ip address 192.168.10.1 255.255.255.0
no shutdown
interface Vlan20
ip address 192.168.20.1 255.255.255.0
no shutdown'ip routing' turns on Layer 3 forwarding. An SVI only comes up when its VLAN exists and has at least one active port in it.
Either way, VLANs separate traffic but routing reconnects it: use ACLs or firewall rules to decide what's allowed between them.
Configuration lab
Build a small two-floor office with router-on-a-stick. Each command is explained below the configuration.
- 1. Test 1: same VLAN, two switches. PC1 → PC3 crosses the SW1–SW2 trunk. No router needed.
- 2. Test 2: between VLANs. PC1 → PC2 goes up to R1 and back down, tagged VLAN 10 then VLAN 20.
| Device | Interface | VLAN | IP address | Gateway |
|---|---|---|---|---|
| R1 | Gi0/0.10 | 10 | 192.168.10.1/24 | — |
| R1 | Gi0/0.20 | 20 | 192.168.20.1/24 | — |
| PC1 | SW1 Gi1/0/1 | 10 | 192.168.10.11/24 | 192.168.10.1 |
| PC2 | SW1 Gi1/0/3 | 20 | 192.168.20.11/24 | 192.168.20.1 |
| PC3 | SW2 Gi1/0/1 | 10 | 192.168.10.12/24 | 192.168.10.1 |
| Trunks | R1–SW1, SW1–SW2 | 10, 20, native 99 | — | — |
SW1 (SW2 is the same, minus the router trunk and PC2's port)
vlan 10
name EMPLOYEES
vlan 20
name GUESTS
vlan 99
name NATIVE
interface GigabitEthernet1/0/1
switchport mode access
switchport access vlan 10
interface GigabitEthernet1/0/3
switchport mode access
switchport access vlan 20
interface range GigabitEthernet1/0/23 - 24
switchport mode trunk
switchport trunk allowed vlan 10,20,99
switchport trunk native vlan 99R1
Use the router-on-a-stick configuration from Design 1 above.
| Command | What it does |
|---|---|
vlan 10 / name | Creates the VLAN in the switch's database and labels it |
switchport mode access | Makes the port a fixed access port (no trunk negotiation) |
switchport access vlan 10 | Puts the port's device into VLAN 10 |
switchport mode trunk | Makes the port a permanent 802.1Q trunk |
switchport trunk allowed vlan | Limits the trunk to the VLANs listed |
switchport trunk native vlan 99 | Moves untagged trunk traffic to unused VLAN 99, on both ends |
Some older platforms also need switchport trunk encapsulation dot1q before switchport mode trunk.
Verification: what you should see
SW1#show vlan brief VLAN Name Status Ports ---- -------------------------------- --------- ------------------------------- 1 default active Gi1/0/2, Gi1/0/4, Gi1/0/5, ... 10 EMPLOYEES active Gi1/0/1 20 GUESTS active Gi1/0/3 99 NATIVE active 1002 fddi-default act/unsup 1003 token-ring-default act/unsup 1004 fddinet-default act/unsup 1005 trnet-default act/unsup
SW1#show interfaces trunk Port Mode Encapsulation Status Native vlan Gi1/0/23 on 802.1q trunking 99 Gi1/0/24 on 802.1q trunking 99 Port Vlans allowed on trunk Gi1/0/23 10,20,99 Gi1/0/24 10,20,99 Port Vlans allowed and active in management domain Gi1/0/23 10,20,99 Gi1/0/24 10,20,99 Port Vlans in spanning tree forwarding state and not pruned Gi1/0/23 10,20,99 Gi1/0/24 10,20,99
R1#show ip interface brief Interface IP-Address OK? Method Status Protocol GigabitEthernet0/0 unassigned YES unset up up GigabitEthernet0/0.10 192.168.10.1 YES manual up up GigabitEthernet0/0.20 192.168.20.1 YES manual up up GigabitEthernet0/0.99 unassigned YES unset up up
show ip route connectedOn R1: both 192.168.10.0/24 and 192.168.20.0/24 should appear as connected networks.
PC1> ping 192.168.20.11 Reply from 192.168.20.11: bytes=32 time=1ms TTL=127 Reply from 192.168.20.11: bytes=32 time=1ms TTL=127
A working ping proves connectivity, not that the design is secure. If guests shouldn't reach employees, also test that the prohibited paths are blocked once your ACLs or firewall rules are in place.
Troubleshooting
For each problem: what you'll notice, why it happens, and how to prove it.
1. Wrong access VLAN
Symptom: PC1 gets a 192.168.20.x address, or can't reach other employees. Why: its port is in the wrong VLAN, so it's in the wrong broadcast domain. Verify: show vlan brief lists Gi1/0/1 under VLAN 20. Fix: switchport access vlan 10 on that port.
2. VLAN missing from the trunk's allowed list
Symptom: PC1 can't reach PC3 (same VLAN, different switches), but everything else works. Why: the trunk doesn't carry VLAN 10. Verify:
SW1#show interfaces trunk Port Vlans allowed on trunk Gi1/0/23 20,99
switchport trunk allowed vlan add 10. Use add — without it, the command replaces the whole list.3. Native VLAN mismatch
Symptom: untagged traffic appears in the wrong VLAN, and the switches log warnings. Why: each end puts untagged frames in a different VLAN. Verify: the "Native vlan" column of show interfaces trunk differs between the two switches; Cisco CDP reports:
%CDP-4-NATIVE_VLAN_MISMATCH: Native VLAN mismatch discovered on GigabitEthernet1/0/23 (99), with SW2 GigabitEthernet1/0/24 (1).
switchport trunk native vlan on both ends.4. DHCP fails in one VLAN
Symptom: guests get 169.254.x.x addresses; employees are fine. Why: the DHCP server is on another subnet and VLAN 20's gateway has no relay, or the server has no VLAN 20 pool. Verify: check ip helper-address on the VLAN 20 subinterface or SVI, and the server's pools. Fix: add the helper or the pool. See DHCP.
5. Gateway problems
Symptom: PC1 reaches PC3 (same VLAN) but not PC2. Why: Layer 2 works; routing doesn't. Typical causes are a wrong gateway on the PC, a subinterface with the wrong encapsulation dot1Q VLAN, the VLAN not allowed on the router trunk, or an SVI that's down. Verify: ipconfig on the PC, show ip interface brief on R1 (subinterfaces up/up?), and show interfaces trunk on SW1's router-facing port.
Practice
VLAN 30 exists on both switches, but the trunk between them shows 'Vlans allowed on trunk: 10,20,99'.
PC1 (VLAN 10) and PC2 (VLAN 20) are on the same switch, and no router or SVI is configured.
After 'switchport trunk allowed vlan 30' is typed on a working trunk that carried 10 and 20, employees on floor 2 lose contact with floor 1.
Small tasks
Task 1: Put port Gi1/0/7 into VLAN 20 as an access port.
interface GigabitEthernet1/0/7
switchport mode access
switchport access vlan 20Then confirm it with show vlan brief: Gi1/0/7 appears in the VLAN 20 row.
Task 2: Allow VLAN 30 on trunk Gi1/0/23 without removing VLANs 10, 20 and 99.
interface GigabitEthernet1/0/23
switchport trunk allowed vlan add 30show interfaces trunk should now list 10,20,30,99. The same change is needed on SW2's end.
Task 3: Add a gateway for VLAN 30 (192.168.30.1/24) on R1.
interface GigabitEthernet0/0.30
encapsulation dot1Q 30
ip address 192.168.30.1 255.255.255.0VLAN 30 must also be allowed on the R1–SW1 trunk, or the subinterface has nothing to route.
Advanced VLAN lessons
Once the core is solid, each advanced topic has its own short lesson:
- A VLAN is a separate Layer 2 broadcast domain; its subnet is the matching IP plan.
- Access ports put untagged endpoint traffic into one VLAN (plus an optional voice VLAN).
- Trunks carry the allowed VLANs between switches using 802.1Q tags; native VLAN frames go untagged.
- Different VLANs need a router or SVIs to communicate, and ACLs decide what's allowed.
- Verify with show vlan brief, show interfaces trunk and show ip interface brief.