All guided builds

Guided buildcore5 steps~15 min4 devices

Two cables, one logical link

Add a second uplink between two switches, watch spanning tree block it, then bundle both into an LACP EtherChannel so they carry traffic together.

What you'll be able to do: Two switches joined by a Port-channel built from two physical links: both forward at once, spanning tree treats them as one port instead of a loop, and either cable can fail without the other noticing.

Topics: EtherChannel · LACP · Spanning Tree · Switching

What you'll build

Step by step

  1. 1. Two switches, one uplink, and a root you chose

    Drag two switches onto the canvas, name them, and cable SW-Core's Gi0/1 to SW-Access's Gi0/1. Then make SW-Core the root bridge with `spanning-tree vlan 1 root primary`. That line decides in advance which end of any redundant link will block later — always the end farther from the root.

    • Cable SW-Core Gi0/1 ↔ SW-Access Gi0/1

    On SW-Core — Name the core switch and make it the root bridge

    enable
    configure terminal
    hostname SW-Core
    spanning-tree vlan 1 root primary
    end

    On SW-Access — Name the access switch

    enable
    configure terminal
    hostname SW-Access
    end

    Check: run show spanning-tree on SW-Access and look for Port Gi0/1.

    Why: With default priorities, the root bridge is whichever switch has the lowest MAC address — an accident of manufacturing. Pinning it on the core makes the rest of the spanning tree predictable, and the core is where the traffic converges anyway.

  2. 2. A server on the core, a PC on the floor

    Plug a server into SW-Core's Fa0/1 and a PC into SW-Access's Fa0/1, and put both in 192.168.1.0/24. Every byte between them has to cross the uplink, which is what makes the uplink the link worth doubling.

    • Cable SRV-Files Eth0 ↔ SW-Core Fa0/1
    • Cable PC-Floor Eth0 ↔ SW-Access Fa0/1

    On SRV-Files — Name the file server and address it

    hostname SRV-Files
    ipconfig Eth0 192.168.1.100 255.255.255.0

    On PC-Floor — Name the floor PC, address it, and reach the server

    hostname PC-Floor
    ipconfig Eth0 192.168.1.20 255.255.255.0
    ping 192.168.1.100

    Check: run show interfaces status on SW-Access and look for Gi0/1 connected 1 auto 1000 gigabit.

    Why: Hosts on many access ports all funnel into one uplink, so the uplink saturates first. That is why the link between switches is the one engineers want to double — and why the next step is so disappointing.

  3. 3. Add a second uplink — and watch spanning tree block it

    Cable SW-Core's Gi0/2 to SW-Access's Gi0/2, hoping for twice the bandwidth. Spanning tree sees two paths between the same two switches — a loop — and blocks one. Run `show spanning-tree` on SW-Access: Gi0/1 is still the root port, and the new Gi0/2 reads Altn BLK. All traffic still rides one cable.

    • Cable SW-Core Gi0/2 ↔ SW-Access Gi0/2

    Check: run show spanning-tree on SW-Access and look for Gi0/2 Altn BLK 4 128.Gi0/2 P2p.

    Why: Spanning tree cannot tell a deliberate second cable from an accidental loop. Two parallel links are a loop, so one of them is held in reserve: it takes over if Gi0/1 fails, but carries nothing until then.

  4. 4. Bundle one end — and see that half a bundle is nothing

    On SW-Core, put both uplinks into channel-group 1 with LACP in active mode. Active means SW-Core now asks the far end, over both cables, to form a bundle. SW-Access is not configured, so nobody answers: `show etherchannel summary` shows both ports stand-alone (I), Po1 down (SD), and SW-Access's Gi0/2 is still blocked.

    On SW-Core — Put both uplinks into channel-group 1, LACP active

    enable
    configure terminal
    interface range Gi0/1 - 2
    channel-group 1 mode active
    end

    Check: run show etherchannel summary on SW-Core and look for 1 Po1(SD) LACP Gi0/1(I) Gi0/2(I).

    Why: LACP is a negotiation: a channel exists only when both ends agree on it. Until the far end answers, each member behaves as an ordinary port — the safe way to fail, because a half-configured bundle can never create a loop of its own.

  5. 5. Finish the bundle on the other end

    Give SW-Access's Gi0/1 and Gi0/2 the same channel-group 1, LACP active. Now both ends agree: Po1 comes up (SU), both members read P, and spanning tree stops seeing two cables at all — `show spanning-tree` lists a single logical port, Po1, forwarding. The loop is gone because, as far as spanning tree knows, there is only one link.

    On SW-Access — Put the matching uplinks into channel-group 1, LACP active

    enable
    configure terminal
    interface range Gi0/1 - 2
    channel-group 1 mode active
    end

    On PC-Floor — Confirm the server is still reachable over the bundle

    ping 192.168.1.100

    Check: run show etherchannel summary on SW-Access and look for 1 Po1(SU) LACP Gi0/1(P) Gi0/2(P).

    Why: EtherChannel turns several physical links into one logical link. Spanning tree cannot block half of a single link, so every member carries traffic, and losing one member is not even a topology change — the channel just runs on the rest.

The theory behind it

Build it for real

The lab walks you through these steps and ticks each one off as your network starts working.

Open in the lab
Two cables, one logical link — step-by-step network lab · NetForge-AI