Guided buildcore8 steps~18 min4 devices
Router on a stick
Split one switch into two VLANs and route between them over a single router port.
What you'll be able to do: Two PCs in different VLANs can ping each other, and every packet between them rides one cable up to the router, gets routed, and comes back tagged for the other VLAN.
Topics: VLANs · Trunking · Inter-VLAN routing · Subinterfaces
What you'll build
- Edge — a router, the router that joins the two VLANs
- SW-Floor1 — a switch, the access switch both PCs plug into
- PC-Sales — a pc, a workstation in the sales VLAN
- PC-Ops — a pc, a workstation in the operations VLAN
Step by step
1. Place the access switch
Drag a switch onto the canvas and give it a name. A hostname is not cosmetic: it is how you tell two consoles apart at a glance, and every command you run from here on is stamped with it in the prompt.
On SW-Floor1 — Enter privileged mode, then configuration mode, and name the switch
enable configure terminal hostname SW-Floor1 endCheck: run
show running-configon SW-Floor1 and look forhostname SW-Floor1.Why: Everything you type lands in the running configuration, the live copy the device is working from, and `show running-config` reads it back. Checking a change there, rather than trusting what you remember typing, is the habit that catches a command that landed in the wrong mode or on the wrong device.
2. Cut the switch into two VLANs
A switch out of the box is one flat broadcast domain: every port can reach every other port. Creating VLAN 10 and VLAN 20 turns it into two logical switches that happen to share a chassis, and nothing crosses between them without a router.
On SW-Floor1 — Define the two VLANs in the switch's VLAN database
enable configure terminal vlan 10 name SALES exit vlan 20 name OPS exit endCheck: run
show vlan briefon SW-Floor1 and look for10 SALES.Why: VLAN numbers are what switches and trunks actually use; names like SALES exist for people. The number is the identity stamped into each frame's 802.1Q tag, so it must match on every device that carries the VLAN, while a name is only a local label.
3. Put the first PC in VLAN 10
Drag a PC in and cable it to Fa0/1, then declare that port an access port in VLAN 10. An access port carries one VLAN and strips every tag, so the PC has no idea VLANs exist — which is the point.
- Cable PC-Sales Eth0 ↔ SW-Floor1 Fa0/1
On SW-Floor1 — Hand Fa0/1 to VLAN 10 as an untagged access port
enable configure terminal interface Fa0/1 switchport mode access switchport access vlan 10 no shutdown endOn PC-Sales — Name the PC and give it an address in the sales subnet
hostname PC-Sales ipconfig Eth0 192.168.10.10 255.255.255.0 192.168.10.1Check: run
show vlan briefon SW-Floor1 and look for10 SALES active Fa0/1.Why: An access port assigns a VLAN to whatever arrives on it: the PC sends an ordinary untagged frame, and the switch files it under VLAN 10 on the way in. VLAN membership is therefore decided by which port a device plugs into, not by anything configured on the device itself.
4. Put the second PC in VLAN 20
Repeat on Fa0/2, but in VLAN 20 and in a different subnet. Two VLANs almost always means two subnets: the VLAN keeps the frames apart at layer 2, and the subnet is what tells each PC that the other one is somebody else's problem.
- Cable PC-Ops Eth0 ↔ SW-Floor1 Fa0/2
On SW-Floor1 — Hand Fa0/2 to VLAN 20 as an untagged access port
enable configure terminal interface Fa0/2 switchport mode access switchport access vlan 20 no shutdown endOn PC-Ops — Name the PC and give it an address in the operations subnet
hostname PC-Ops ipconfig Eth0 192.168.20.10 255.255.255.0 192.168.20.1Check: run
show vlan briefon SW-Floor1 and look for20 OPS active Fa0/2.Why: Matching the third octet to the VLAN number — 192.168.10.0/24 for VLAN 10, 192.168.20.0/24 for VLAN 20 — is a convention, not a rule, but it lets anyone reading an address know its VLAN at a glance. What is a rule is one subnet per VLAN, because hosts only use their gateway for destinations outside their own subnet.
5. Hang the router off one switch port
Two VLANs need two gateways, and a small router has only two Ethernet ports to spare. Cable Gi0/0 to the switch's Gi0/1 and bring it up with no address at all — the physical port becomes a pipe, and the addresses go on the subinterfaces you add next. That single cable is the stick the whole design is named after.
- Cable Edge Gi0/0 ↔ SW-Floor1 Gi0/1
On Edge — Name the router and bring the physical uplink up without an address
enable configure terminal hostname Edge interface Gi0/0 no ip address no shutdown exit endCheck: run
show ip interface briefon Edge and look forGi0/0 unassigned YES manual up.Why: On a router on a stick the physical port is plumbing: it carries every frame on the link, and each subinterface you add next claims the frames tagged with its own VLAN. The parent must still be enabled, because a subinterface can only be as up as the port it rides on.
6. Give VLAN 10 a gateway: the first subinterface
A subinterface is a second, virtual interface that lives on a physical port and owns one VLAN's worth of addressing. `encapsulation dot1Q 10` is the part that matters: it tells Gi0/0.10 to accept frames carrying the VLAN 10 tag and to stamp that tag on everything it sends. The address 192.168.10.1 then becomes the gateway every sales host already points at.
On Edge — Create the VLAN 10 subinterface and make it the sales gateway
enable configure terminal interface Gi0/0.10 encapsulation dot1Q 10 ip address 192.168.10.1 255.255.255.0 no shutdown exit endCheck: run
show ip routeon Edge and look forC 192.168.10.0/24 is directly connected, Gi0/0.10.Why: 802.1Q inserts a 4-byte tag into the Ethernet header, and 12 bits of it carry the VLAN ID — once a frame leaves its access port, that number is the only thing that says which VLAN it belongs to. Hosts never see the tag, because access ports add and remove it at the edge; only trunks and devices such as this router read it.
7. Give VLAN 20 a gateway on the same port
Add a second subinterface on the same physical port, tagged for VLAN 20 and addressed in the operations subnet. The router now holds two directly connected networks and can route between them, which is the whole job of the box — one port, two gateways, two subnets in the routing table.
On Edge — Create the VLAN 20 subinterface and make it the operations gateway
enable configure terminal interface Gi0/0.20 encapsulation dot1Q 20 ip address 192.168.20.1 255.255.255.0 no shutdown exit endCheck: run
show ip routeon Edge and look forC 192.168.20.0/24 is directly connected, Gi0/0.20.Why: Inter-VLAN routing is ordinary routing: the router sees two connected networks and forwards between them, unaware that both arrive on the same cable. Each routed packet goes up the link tagged for one VLAN and comes back down tagged for the other, so the one cable carries every inter-VLAN packet twice — the design's main limit as traffic grows.
8. Trunk the uplink and watch the VLANs meet
The switch port facing the router is still an access port in VLAN 1, so it strips the tags the router needs and drops the rest. Turning Gi0/1 into an 802.1Q trunk makes it carry VLAN 10 and VLAN 20 side by side, each frame labelled, and inter-VLAN routing starts working the moment you press enter. Ping from PC-Sales to 192.168.20.10 and the reply comes back in two hops: up to the router, and back down in the other VLAN.
On SW-Floor1 — Turn the router-facing port into a tagged trunk carrying both VLANs
enable configure terminal interface Gi0/1 switchport mode trunk switchport trunk allowed vlan 10,20 no shutdown endCheck: run
show interfaces trunkon SW-Floor1 and look forGi0/1 on 802.1q trunking 1.Why: A trunk is the only kind of switch port that belongs to several VLANs at once, and it can only do that by keeping each frame's 802.1Q tag on the wire so the far end knows where the frame belongs. The tags are what let one cable, one router port and one switch port serve two broadcast domains without ever mixing them.
The theory behind it
More in Switching & wireless
- Map the network with CDP and LLDP — Let two switches and a router discover each other, find the router's address from a switch that was never told it, add LLDP, then stop the router announcing itself toward the internet.
- Two departments, one switch — Split a single switch into Sales and Ops with VLANs, and watch the pings between them stop.
- One VLAN across two switches — Split four PCs into two VLANs across two switches, then carry both VLANs between the switches over a single tagged trunk.
- Route between VLANs on the switch — Give one switch an SVI in each VLAN, find out why the VLANs still can't talk, then turn on ip routing — inter-VLAN routing with no router at all.
- Choose your root bridge — Close a loop of three switches, find the port spanning tree blocks on its own, then decide which switch is root — and which one takes over when it fails.
- Two cables, one logical link — Add a second uplink between two switches, watch spanning tree block it, then bundle both into an LACP EtherChannel so they carry traffic together.
Build it for real
The lab walks you through these steps and ticks each one off as your network starts working.
Open in the lab