Guided buildcore5 steps~15 min4 devices
Two cables, one logical link
Add a second uplink between two switches, watch spanning tree block it, then bundle both into an LACP EtherChannel so they carry traffic together.
What you'll be able to do: Two switches joined by a Port-channel built from two physical links: both forward at once, spanning tree treats them as one port instead of a loop, and either cable can fail without the other noticing.
Topics: EtherChannel · LACP · Spanning Tree · Switching
What you'll build
- SW-Core — a switch, the core switch, and the root bridge
- SW-Access — a switch, the floor's access switch
- SRV-Files — a server, the file server hanging off the core
- PC-Floor — a pc, a workstation on the floor
Step by step
1. Two switches, one uplink, and a root you chose
Drag two switches onto the canvas, name them, and cable SW-Core's Gi0/1 to SW-Access's Gi0/1. Then make SW-Core the root bridge with `spanning-tree vlan 1 root primary`. That line decides in advance which end of any redundant link will block later — always the end farther from the root.
- Cable SW-Core Gi0/1 ↔ SW-Access Gi0/1
On SW-Core — Name the core switch and make it the root bridge
enable configure terminal hostname SW-Core spanning-tree vlan 1 root primary endOn SW-Access — Name the access switch
enable configure terminal hostname SW-Access endCheck: run
show spanning-treeon SW-Access and look forPort Gi0/1.Why: With default priorities, the root bridge is whichever switch has the lowest MAC address — an accident of manufacturing. Pinning it on the core makes the rest of the spanning tree predictable, and the core is where the traffic converges anyway.
2. A server on the core, a PC on the floor
Plug a server into SW-Core's Fa0/1 and a PC into SW-Access's Fa0/1, and put both in 192.168.1.0/24. Every byte between them has to cross the uplink, which is what makes the uplink the link worth doubling.
- Cable SRV-Files Eth0 ↔ SW-Core Fa0/1
- Cable PC-Floor Eth0 ↔ SW-Access Fa0/1
On SRV-Files — Name the file server and address it
hostname SRV-Files ipconfig Eth0 192.168.1.100 255.255.255.0On PC-Floor — Name the floor PC, address it, and reach the server
hostname PC-Floor ipconfig Eth0 192.168.1.20 255.255.255.0 ping 192.168.1.100Check: run
show interfaces statuson SW-Access and look forGi0/1 connected 1 auto 1000 gigabit.Why: Hosts on many access ports all funnel into one uplink, so the uplink saturates first. That is why the link between switches is the one engineers want to double — and why the next step is so disappointing.
3. Add a second uplink — and watch spanning tree block it
Cable SW-Core's Gi0/2 to SW-Access's Gi0/2, hoping for twice the bandwidth. Spanning tree sees two paths between the same two switches — a loop — and blocks one. Run `show spanning-tree` on SW-Access: Gi0/1 is still the root port, and the new Gi0/2 reads Altn BLK. All traffic still rides one cable.
- Cable SW-Core Gi0/2 ↔ SW-Access Gi0/2
Check: run
show spanning-treeon SW-Access and look forGi0/2 Altn BLK 4 128.Gi0/2 P2p.Why: Spanning tree cannot tell a deliberate second cable from an accidental loop. Two parallel links are a loop, so one of them is held in reserve: it takes over if Gi0/1 fails, but carries nothing until then.
4. Bundle one end — and see that half a bundle is nothing
On SW-Core, put both uplinks into channel-group 1 with LACP in active mode. Active means SW-Core now asks the far end, over both cables, to form a bundle. SW-Access is not configured, so nobody answers: `show etherchannel summary` shows both ports stand-alone (I), Po1 down (SD), and SW-Access's Gi0/2 is still blocked.
On SW-Core — Put both uplinks into channel-group 1, LACP active
enable configure terminal interface range Gi0/1 - 2 channel-group 1 mode active endCheck: run
show etherchannel summaryon SW-Core and look for1 Po1(SD) LACP Gi0/1(I) Gi0/2(I).Why: LACP is a negotiation: a channel exists only when both ends agree on it. Until the far end answers, each member behaves as an ordinary port — the safe way to fail, because a half-configured bundle can never create a loop of its own.
5. Finish the bundle on the other end
Give SW-Access's Gi0/1 and Gi0/2 the same channel-group 1, LACP active. Now both ends agree: Po1 comes up (SU), both members read P, and spanning tree stops seeing two cables at all — `show spanning-tree` lists a single logical port, Po1, forwarding. The loop is gone because, as far as spanning tree knows, there is only one link.
On SW-Access — Put the matching uplinks into channel-group 1, LACP active
enable configure terminal interface range Gi0/1 - 2 channel-group 1 mode active endOn PC-Floor — Confirm the server is still reachable over the bundle
ping 192.168.1.100Check: run
show etherchannel summaryon SW-Access and look for1 Po1(SU) LACP Gi0/1(P) Gi0/2(P).Why: EtherChannel turns several physical links into one logical link. Spanning tree cannot block half of a single link, so every member carries traffic, and losing one member is not even a topology change — the channel just runs on the rest.
The theory behind it
More in Switching & wireless
- Map the network with CDP and LLDP — Let two switches and a router discover each other, find the router's address from a switch that was never told it, add LLDP, then stop the router announcing itself toward the internet.
- Two departments, one switch — Split a single switch into Sales and Ops with VLANs, and watch the pings between them stop.
- One VLAN across two switches — Split four PCs into two VLANs across two switches, then carry both VLANs between the switches over a single tagged trunk.
- Router on a stick — Split one switch into two VLANs and route between them over a single router port.
- Route between VLANs on the switch — Give one switch an SVI in each VLAN, find out why the VLANs still can't talk, then turn on ip routing — inter-VLAN routing with no router at all.
- Choose your root bridge — Close a loop of three switches, find the port spanning tree blocks on its own, then decide which switch is root — and which one takes over when it fails.
Build it for real
The lab walks you through these steps and ticks each one off as your network starts working.
Open in the lab