Routelearn.net
Course menu

Unit 14: Network TroubleshootingLesson 14.6 (6 of 10 in this unit)78 of 84 in the Network Fundamentals course

Layer 1 and 2 problems

Down interfaces, duplex mismatches, errors and VLAN mistakes, and how to spot each one.

Intermediate · 8 min read

Layer 1 and Layer 2 problems are faults in the physical link or in Ethernet switching, such as a disconnected or err-disabled port, a damaged cable, a duplex mismatch that causes CRC errors and late collisions, an access port in the wrong VLAN, or a VLAN missing from a trunk.

In simple terms: These are problems with the cable, the switch port or the switch settings. While they exist, nothing higher up, such as IP or DNS, can work properly.

A real-life situation

A PC in the warehouse “works, but very slowly”. Large files copy very slowly and video calls freeze. A ping to the gateway works, with a little loss. Nothing is completely broken, so it is easy to blame the internet. The real cause is that the PC and its switch port disagree about how to use the link.

What Layer 1 and 2 problems look like

Layer 1 is the physical part: cables, connectors, signals and speed. Layer 2 is how frames move inside one local network: switch ports, duplex, VLANs and trunks. Faults here cause either no connection at all, or a connection that keeps dropping or is slow.

SymptomLikely causeWhere to look
Port is notconnect, no lightFaulty or unplugged cable, device switched off, network adapter disabledshow interfaces status
Port is err-disabledThe switch shut the port down for protection, for example by port security or BPDU guardshow interfaces status err-disabled, logs
Slow, some packet loss, error counters risingDuplex mismatch or damaged cableshow interfaces counters
Link up, but no DHCP address and no reply from the gatewayAccess port in the wrong VLANshow vlan brief
One VLAN fails across switches, others workVLAN missing from the trunk's allowed list, or not created on a switchshow interfaces trunk

Why a duplex mismatch hurts

Duplex says whether a link sends and receives at the same time (full duplex) or takes turns (half duplex). If one end is set by hand to full duplex and the other is left on auto, autonegotiation fails, and the auto side usually falls back to half duplex. The half-duplex side thinks it sees collisions and backs off; the full-duplex side just keeps sending. Frames are damaged and have to be resent by the upper layers, such as TCP.

100 MbpsWarehouse PCauto → halfSW2 Gi1/0/7100 / full (hard-set)
  1. 1. Switch sends at full duplex: it never checks whether the PC is already sending.
  2. 2. PC is half duplex: when the switch's traffic arrives while the PC is sending, the PC treats it as a collision, stops and retries, often late in the frame.
  3. 3. Result: the switch receives cut-off frames and counts them as CRC errors and runts. Everything slows down.

Based on Cisco documentation, not run on a lab device:

Example output · based on Cisco documentation; exact format varies by platform and software version
SW2#show interfaces gigabitEthernet1/0/7
GigabitEthernet1/0/7 is up, line protocol is up (connected)
  Hardware is Gigabit Ethernet, address is 0200.0000.2007 (bia 0200.0000.2007)
  MTU 1500 bytes, BW 100000 Kbit/sec, DLY 100 usec,
  Full-duplex, 100Mb/s, media type is 10/100/1000BaseTX
  ...
  5 minute input rate 412000 bits/sec, 61 packets/sec
     183402 packets input, 51882031 bytes, 0 no buffer
     Received 2113 broadcasts (1980 multicasts)
     418 runts, 0 giants, 0 throttles
     2364 input errors, 1946 CRC, 0 frame, 0 overrun, 0 ignored
     ...
     0 output errors, 0 collisions, 1 interface resets
     0 late collision, 0 deferred
What to look for: Full-duplex, 100Mb/s shows the switch side is full duplex, and the counters show 418 runts and 1946 CRC errors. On a half-duplex end you would instead see late collisions. Fix it by setting both ends the same way, ideally both to auto. Then run clear counters and check that the error counters stay at 0.

💡 CRC errors when the duplex settings match usually mean a damaged cable, a faulty connector or a cable that is too long. Replace the cable before you try anything else.

How to verify VLAN and trunk problems

Gi1/0/7trunkVLAN 20PCshould be VLAN 10SW2SW1VLAN 10 gatewayDHCP server
  1. 1. The PC asks for an address: the switch places the request in VLAN 20, because that is the access VLAN of the PC's port.
  2. 2. It arrives in the wrong network: the request never reaches VLAN 10, so no DHCP offer comes back and the PC falls back to a 169.254.x.x address.

Based on Cisco documentation, not run on a lab device:

Example output · based on Cisco documentation; exact format varies by platform and software version
SW2#show vlan brief
VLAN Name                             Status    Ports
---- -------------------------------- --------- -------------------------------
1    default                          active    Gi1/0/9, Gi1/0/10
10   STAFF                            active    Gi1/0/1, Gi1/0/2, Gi1/0/3
20   GUEST                            active    Gi1/0/7, Gi1/0/8
What to look for: Gi1/0/7 is listed under VLAN 20, but the PC should be in VLAN 10. Fix it with switchport access vlan 10 on the interface. Trunk ports are not listed in this output, so use show interfaces trunk to check them.
Example output · based on Cisco documentation; exact format varies by platform and software version
SW2#show interfaces trunk
Port        Mode         Encapsulation  Status        Native vlan
Gi1/0/24    on           802.1q         trunking      1

Port        Vlans allowed on trunk
Gi1/0/24    1,20

Port        Vlans allowed and active in management domain
Gi1/0/24    1,20

Port        Vlans in spanning tree forwarding state and not pruned
Gi1/0/24    1,20
What to look for: the Vlans allowed on trunk line for Gi1/0/24 shows only 1,20. VLAN 10 is not allowed, so even with the access port fixed, VLAN 10 traffic could not leave SW2. Add it on Gi1/0/24 with switchport trunk allowed vlan add 10. (Use add; without it, the command replaces the whole list.)

Check yourself

Predict · scenario 1

A PC is slow, and its switch port shows a rising number of late collisions. What is the most likely cause?

Predict · scenario 2

A PC's link is up, but it gets a 169.254.x.x address. show vlan brief shows its port in VLAN 99 instead of the staff VLAN. What should you do next?