Troubleshooting labcore6 steps~15 min5 devices
Fix the VLAN that stops at the trunk
Engineering's server is unreachable and the south desk is cut off completely. Find the wrong VLAN and the trunk that drops it.
What you'll be able to do: Every engineering host reaches the build server across both switches, and you can tell a port in the wrong VLAN from a trunk that refuses a VLAN using nothing but `show vlan brief` and `show interfaces trunk`.
Topics: Troubleshooting · VLANs · Trunking · Access ports
The network you're handed
- SW-North — a switch, the north access switch, with the server on it
- SW-South — a switch, the south access switch
- Build-Server — a server, engineering's build server
- PC-Eng-N — a pc, an engineering desk on the north switch
- PC-Eng-S — a pc, an engineering desk on the south switch
Step by step
1. Scope the outage before touching anything
Engineering says the build server is down. Test from both desks: PC-Eng-N sits on the same switch as the server, PC-Eng-S is on the far side of the trunk. Then check the addressing — every host should be in 192.168.20.0/24.
On PC-Eng-N — Test the server from the desk on the same switch
ping 192.168.20.5 ipconfigOn PC-Eng-S — Test the server and the other desk from across the trunk
ping 192.168.20.5 ping 192.168.20.11Check: run
ipconfigon PC-Eng-N and look forIPv4 Address. . . . . . . . . . : 192.168.20.11.Why: All three hosts share one subnet, so none of them uses a gateway and no router is involved — the fault is at layer 1 or layer 2. And because PC-Eng-N cannot reach a server on its OWN switch, at least one fault has nothing to do with the trunk. Start with the smallest broken piece: two ports on SW-North.
2. Read the north switch's VLAN table
Two hosts in the same subnet on the same switch can only fail to talk if something separates them at layer 2. `show vlan brief` lists every VLAN with the access ports in it — find Fa0/1 (the server) and Fa0/2 (PC-Eng-N).
On SW-North — List each VLAN and the ports in it
enable show vlan briefCheck: run
show vlan briefon SW-North and look for10 SALES active Fa0/1.Why: A VLAN is a separate broadcast domain, so the server's ARP replies never reach a host in another VLAN — even one plugged in a port away. The server's port sits in SALES while PC-Eng-N's port sits in ENG: same subnet on paper, two different networks on the wire.
3. Move the server's port into the engineering VLAN
Put Fa0/1 into VLAN 20 and retest from PC-Eng-N. The server and the host have not changed at all — only the port between them.
On SW-North — Reassign the server's access port to VLAN 20
enable configure terminal interface Fa0/1 switchport access vlan 20 endOn PC-Eng-N — Retest the server
ping 192.168.20.5Check: run
show vlan briefon SW-North and look for20 ENG active Fa0/1, Fa0/2.Why: An access port belongs to exactly one VLAN and the host behind it never knows which. Fixing the membership on the switch fixes the host, without touching its address.
4. The south desk is still cut off — follow the frame onto the trunk
PC-Eng-S still fails. Check its own port first, then the trunk from BOTH ends: `show interfaces trunk` lists the VLANs each end allows. A trunk can read `trunking` and still refuse a VLAN.
On PC-Eng-S — Retest from the south desk
ping 192.168.20.5On SW-South — Check the desk's port, then the south end of the trunk
enable show vlan brief show interfaces trunkOn SW-North — Check the north end of the same trunk
enable show interfaces trunkCheck: run
show interfaces trunkon SW-South and look forGi0/1 10.Why: The south desk's port is correctly in VLAN 20, which rules the host's own port out. Both trunk ends are up and trunking, which rules out the cable and the trunk mode. What is left is the allowed list: the north end allows 10 and 20, the south end allows only 10, so every VLAN 20 frame is dropped at the south end in both directions.
5. Let VLAN 20 onto the south end of the trunk
Add VLAN 20 to SW-South's allowed list — add it, do not replace the list — and retest from the south desk.
On SW-South — Append VLAN 20 to the trunk's allowed list
enable configure terminal interface Gi0/1 switchport trunk allowed vlan add 20 endOn PC-Eng-S — Retest across the trunk
ping 192.168.20.5 ping 192.168.20.11Check: run
show interfaces trunkon SW-South and look forGi0/1 10,20.Why: The allowed list is a filter each end applies on its own. With both ends now agreeing on 10 and 20, VLAN 20 frames are tagged across the link and delivered on the far side — and VLAN 10 carries on exactly as before.
6. Prove it from the server's side
Ping the south desk from the server, then read SW-North's MAC address table: the south desk's MAC now appears learned on the trunk port Gi0/1, in VLAN 20 — proof that VLAN 20 frames really cross the link.
On Build-Server — Test the path in the other direction
ping 192.168.20.12On SW-North — See which port each engineering MAC was learned on
enable show mac address-tableCheck: run
show mac address-tableon SW-North and look forDYNAMIC Gi0/1.Why: A switch learns a source MAC on the port the frame arrived on. An engineering MAC learned on the trunk port, in VLAN 20, can only have come across the trunk — the direct evidence that the allowed list now carries the VLAN.
The theory behind it
More in Troubleshooting
- Fix the broken office — Nobody in a two-desk office can reach the intranet server. Find the two faults and fix them, one layer at a time.
- Fix the desks DHCP forgot — The clinic's desks come up with no address. Find why the DHCP server never hears them — then why their leases still go nowhere.
- Fix the NAT that translates nothing — The shop's desks and tills cannot reach the internet, yet the router itself can. Find why nothing leaves translated.
- Fix the OSPF adjacencies — Three routers run OSPF and nothing converges. Find the area mismatch and the network statement that matches nothing.
- Fix the branch that fails four ways — A branch depot has lost head office, and two of its hosts have faults of their own. Find all four, one layer at a time.
Build it for real
The lab walks you through these steps and ticks each one off as your network starts working.
Open in the lab