All guided builds

Guided buildcore8 steps~18 min4 devices

Router on a stick

Split one switch into two VLANs and route between them over a single router port.

What you'll be able to do: Two PCs in different VLANs can ping each other, and every packet between them rides one cable up to the router, gets routed, and comes back tagged for the other VLAN.

Topics: VLANs · Trunking · Inter-VLAN routing · Subinterfaces

What you'll build

Step by step

  1. 1. Place the access switch

    Drag a switch onto the canvas and give it a name. A hostname is not cosmetic: it is how you tell two consoles apart at a glance, and every command you run from here on is stamped with it in the prompt.

    On SW-Floor1 — Enter privileged mode, then configuration mode, and name the switch

    enable
    configure terminal
    hostname SW-Floor1
    end

    Check: run show running-config on SW-Floor1 and look for hostname SW-Floor1.

    Why: Everything you type lands in the running configuration, the live copy the device is working from, and `show running-config` reads it back. Checking a change there, rather than trusting what you remember typing, is the habit that catches a command that landed in the wrong mode or on the wrong device.

  2. 2. Cut the switch into two VLANs

    A switch out of the box is one flat broadcast domain: every port can reach every other port. Creating VLAN 10 and VLAN 20 turns it into two logical switches that happen to share a chassis, and nothing crosses between them without a router.

    On SW-Floor1 — Define the two VLANs in the switch's VLAN database

    enable
    configure terminal
    vlan 10
    name SALES
    exit
    vlan 20
    name OPS
    exit
    end

    Check: run show vlan brief on SW-Floor1 and look for 10 SALES.

    Why: VLAN numbers are what switches and trunks actually use; names like SALES exist for people. The number is the identity stamped into each frame's 802.1Q tag, so it must match on every device that carries the VLAN, while a name is only a local label.

  3. 3. Put the first PC in VLAN 10

    Drag a PC in and cable it to Fa0/1, then declare that port an access port in VLAN 10. An access port carries one VLAN and strips every tag, so the PC has no idea VLANs exist — which is the point.

    • Cable PC-Sales Eth0 ↔ SW-Floor1 Fa0/1

    On SW-Floor1 — Hand Fa0/1 to VLAN 10 as an untagged access port

    enable
    configure terminal
    interface Fa0/1
    switchport mode access
    switchport access vlan 10
    no shutdown
    end

    On PC-Sales — Name the PC and give it an address in the sales subnet

    hostname PC-Sales
    ipconfig Eth0 192.168.10.10 255.255.255.0 192.168.10.1

    Check: run show vlan brief on SW-Floor1 and look for 10 SALES active Fa0/1.

    Why: An access port assigns a VLAN to whatever arrives on it: the PC sends an ordinary untagged frame, and the switch files it under VLAN 10 on the way in. VLAN membership is therefore decided by which port a device plugs into, not by anything configured on the device itself.

  4. 4. Put the second PC in VLAN 20

    Repeat on Fa0/2, but in VLAN 20 and in a different subnet. Two VLANs almost always means two subnets: the VLAN keeps the frames apart at layer 2, and the subnet is what tells each PC that the other one is somebody else's problem.

    • Cable PC-Ops Eth0 ↔ SW-Floor1 Fa0/2

    On SW-Floor1 — Hand Fa0/2 to VLAN 20 as an untagged access port

    enable
    configure terminal
    interface Fa0/2
    switchport mode access
    switchport access vlan 20
    no shutdown
    end

    On PC-Ops — Name the PC and give it an address in the operations subnet

    hostname PC-Ops
    ipconfig Eth0 192.168.20.10 255.255.255.0 192.168.20.1

    Check: run show vlan brief on SW-Floor1 and look for 20 OPS active Fa0/2.

    Why: Matching the third octet to the VLAN number — 192.168.10.0/24 for VLAN 10, 192.168.20.0/24 for VLAN 20 — is a convention, not a rule, but it lets anyone reading an address know its VLAN at a glance. What is a rule is one subnet per VLAN, because hosts only use their gateway for destinations outside their own subnet.

  5. 5. Hang the router off one switch port

    Two VLANs need two gateways, and a small router has only two Ethernet ports to spare. Cable Gi0/0 to the switch's Gi0/1 and bring it up with no address at all — the physical port becomes a pipe, and the addresses go on the subinterfaces you add next. That single cable is the stick the whole design is named after.

    • Cable Edge Gi0/0 ↔ SW-Floor1 Gi0/1

    On Edge — Name the router and bring the physical uplink up without an address

    enable
    configure terminal
    hostname Edge
    interface Gi0/0
    no ip address
    no shutdown
    exit
    end

    Check: run show ip interface brief on Edge and look for Gi0/0 unassigned YES manual up.

    Why: On a router on a stick the physical port is plumbing: it carries every frame on the link, and each subinterface you add next claims the frames tagged with its own VLAN. The parent must still be enabled, because a subinterface can only be as up as the port it rides on.

  6. 6. Give VLAN 10 a gateway: the first subinterface

    A subinterface is a second, virtual interface that lives on a physical port and owns one VLAN's worth of addressing. `encapsulation dot1Q 10` is the part that matters: it tells Gi0/0.10 to accept frames carrying the VLAN 10 tag and to stamp that tag on everything it sends. The address 192.168.10.1 then becomes the gateway every sales host already points at.

    On Edge — Create the VLAN 10 subinterface and make it the sales gateway

    enable
    configure terminal
    interface Gi0/0.10
    encapsulation dot1Q 10
    ip address 192.168.10.1 255.255.255.0
    no shutdown
    exit
    end

    Check: run show ip route on Edge and look for C 192.168.10.0/24 is directly connected, Gi0/0.10.

    Why: 802.1Q inserts a 4-byte tag into the Ethernet header, and 12 bits of it carry the VLAN ID — once a frame leaves its access port, that number is the only thing that says which VLAN it belongs to. Hosts never see the tag, because access ports add and remove it at the edge; only trunks and devices such as this router read it.

  7. 7. Give VLAN 20 a gateway on the same port

    Add a second subinterface on the same physical port, tagged for VLAN 20 and addressed in the operations subnet. The router now holds two directly connected networks and can route between them, which is the whole job of the box — one port, two gateways, two subnets in the routing table.

    On Edge — Create the VLAN 20 subinterface and make it the operations gateway

    enable
    configure terminal
    interface Gi0/0.20
    encapsulation dot1Q 20
    ip address 192.168.20.1 255.255.255.0
    no shutdown
    exit
    end

    Check: run show ip route on Edge and look for C 192.168.20.0/24 is directly connected, Gi0/0.20.

    Why: Inter-VLAN routing is ordinary routing: the router sees two connected networks and forwards between them, unaware that both arrive on the same cable. Each routed packet goes up the link tagged for one VLAN and comes back down tagged for the other, so the one cable carries every inter-VLAN packet twice — the design's main limit as traffic grows.

  8. 8. Trunk the uplink and watch the VLANs meet

    The switch port facing the router is still an access port in VLAN 1, so it strips the tags the router needs and drops the rest. Turning Gi0/1 into an 802.1Q trunk makes it carry VLAN 10 and VLAN 20 side by side, each frame labelled, and inter-VLAN routing starts working the moment you press enter. Ping from PC-Sales to 192.168.20.10 and the reply comes back in two hops: up to the router, and back down in the other VLAN.

    On SW-Floor1 — Turn the router-facing port into a tagged trunk carrying both VLANs

    enable
    configure terminal
    interface Gi0/1
    switchport mode trunk
    switchport trunk allowed vlan 10,20
    no shutdown
    end

    Check: run show interfaces trunk on SW-Floor1 and look for Gi0/1 on 802.1q trunking 1.

    Why: A trunk is the only kind of switch port that belongs to several VLANs at once, and it can only do that by keeping each frame's 802.1Q tag on the wire so the far end knows where the frame belongs. The tags are what let one cable, one router port and one switch port serve two broadcast domains without ever mixing them.

The theory behind it

Build it for real

The lab walks you through these steps and ticks each one off as your network starts working.

Open in the lab
Router on a stick — step-by-step network lab · NetForge-AI