All guided builds

Guided buildcore7 steps~18 min6 devices

One VLAN across two switches

Split four PCs into two VLANs across two switches, then carry both VLANs between the switches over a single tagged trunk.

What you'll be able to do: Two PCs in the same VLAN ping each other through two switches and one shared cable, while a PC in the other VLAN — on that very same cable, in that very same subnet — cannot reach them at all.

Start this build in the lab 6 devices — needs any paid plan (the free canvas fits 5).

Topics: VLANs · Trunking · 802.1Q · Switching

What you'll build

Step by step

  1. 1. Two switches, one cable between them

    Drag two switches onto the canvas and run a single cable from Gi0/1 on one to Gi0/1 on the other. That one link is everything the two floors have in common, and by the end of this build it will be carrying two separate VLANs at once. Name both switches now, because every check from here on resolves a device by the hostname you set, not by the label the canvas hands out.

    • Cable SW-Floor1 Gi0/1 ↔ SW-Floor2 Gi0/1

    On SW-Floor1 — Name the first-floor switch

    enable
    configure terminal
    hostname SW-Floor1
    end

    On SW-Floor2 — Name the second-floor switch

    enable
    configure terminal
    hostname SW-Floor2
    end

    Why: A cable between two switches merges them into one switching fabric: with every port in VLAN 1, both chassis form a single broadcast domain, and each switch learns the other's hosts as MAC addresses living behind its uplink port. Everything this build adds is about controlling what crosses that one link.

  2. 2. Four hosts, two per floor

    Add four PCs and cable each one to an Fa0/x port, two on each switch. Fa0/1 on each switch will end up in Sales and Fa0/2 in Ops, so the pairs that need to talk to each other are deliberately on opposite switches — that is the only way to prove a VLAN really does cross the cable.

    • Cable SW-Floor1 Fa0/1 ↔ PC-A Eth0
    • Cable SW-Floor1 Fa0/2 ↔ PC-C Eth0
    • Cable SW-Floor2 Fa0/1 ↔ PC-B Eth0
    • Cable SW-Floor2 Fa0/2 ↔ PC-D Eth0

    Why: A VLAN is not tied to a switch: membership follows ports, and one VLAN can have ports on any number of switches as long as the links between them carry it. That is how a single VLAN serves a department spread over several floors or wiring closets.

  3. 3. Address all four in one subnet, on purpose

    Give every PC an address in 192.168.1.0/24 — yes, all four in the same subnet. Keeping routing out of the picture means that when two of these machines stop being able to reach each other later, the VLAN is the only thing that can possibly have caused it. Ping across the switches now and everything answers, because a switch out of the box puts every port in one flat VLAN 1.

    On PC-A — Name and address the first Sales machine

    hostname PC-A
    ipconfig Eth0 192.168.1.10 255.255.255.0

    On PC-B — Name and address the second Sales machine

    hostname PC-B
    ipconfig Eth0 192.168.1.11 255.255.255.0

    On PC-C — Name and address the first Ops machine

    hostname PC-C
    ipconfig Eth0 192.168.1.20 255.255.255.0

    On PC-D — Name and address the second Ops machine

    hostname PC-D
    ipconfig Eth0 192.168.1.21 255.255.255.0

    Check: run ipconfig on PC-A and look for 192.168.1.10.

    Why: The ping from PC-A to PC-B crosses both switches, and each learns PC-A's MAC on the port the frame arrived on — SW-Floor1 on Fa0/1, SW-Floor2 on its uplink Gi0/1. A switch never knows how far away a host is; it only knows which of its own ports leads toward it.

  4. 4. Declare the VLANs on both switches

    A VLAN is a number a switch agrees to keep separate, and each switch keeps its own list. Create VLAN 10 for Sales, VLAN 20 for Ops and VLAN 99 as an empty parking VLAN on both switches — a VLAN that exists on one switch and not the other is the classic reason a trunk appears to swallow traffic. Nothing changes on the wire yet, because no port has been handed to a VLAN so far.

    On SW-Floor1 — Build the VLAN database on floor 1

    enable
    configure terminal
    vlan 10
    name Sales
    exit
    vlan 20
    name Ops
    exit
    vlan 99
    name Parking
    exit
    end

    On SW-Floor2 — Build the identical VLAN database on floor 2

    enable
    configure terminal
    vlan 10
    name Sales
    exit
    vlan 20
    name Ops
    exit
    vlan 99
    name Parking
    exit
    end

    Check: run show vlan brief on SW-Floor1 and look for 99 Parking.

    Why: Each switch keeps its own VLAN database, so a VLAN exists only on the switches where it has been created. VLAN 99 is empty on purpose: it will become the trunk's native VLAN, the one VLAN that crosses the link untagged, and parking that role on a VLAN no user lives in keeps real traffic from ever travelling without a tag.

  5. 5. Hand each host port to one VLAN

    An access port belongs to exactly one VLAN and sends the host plain untagged frames — the PC has no idea a VLAN exists. Put Fa0/1 in VLAN 10 and Fa0/2 in VLAN 20 on both switches, then ping from PC-A to PC-C. It fails, even though they share a switch and a subnet, and that failure is the whole point of a VLAN.

    On SW-Floor1 — Put the floor-1 host ports into Sales and Ops

    enable
    configure terminal
    interface Fa0/1
    switchport mode access
    switchport access vlan 10
    exit
    interface Fa0/2
    switchport mode access
    switchport access vlan 20
    exit
    end

    On SW-Floor2 — Put the floor-2 host ports into Sales and Ops

    enable
    configure terminal
    interface Fa0/1
    switchport mode access
    switchport access vlan 10
    exit
    interface Fa0/2
    switchport mode access
    switchport access vlan 20
    exit
    end

    Check: run show vlan brief on SW-Floor1 and look for active Fa0/1.

    Why: A VLAN boundary is enforced by the switch, not by the hosts: PC-A still considers PC-C local and broadcasts its ARP request, but the switch delivers it only to other ports in VLAN 10. The uplink is still an access port in VLAN 1, so for now it carries neither of the new VLANs — which the next step deals with.

  6. 6. Turn the uplink into a trunk

    PC-A has also lost PC-B, because the cable between the switches is still an access port in VLAN 1 and a VLAN 10 frame has nowhere to go. A trunk fixes that by tagging each frame with its VLAN number on the way out and stripping the tag on the way in, so many VLANs share one wire. Configure it on both ends — a trunk facing an access port carries nothing. Allow only VLAN 10 and the native VLAN for the moment, so the allowed list has something to prove in the next step.

    On SW-Floor1 — Tag the floor-1 end of the uplink

    enable
    configure terminal
    interface Gi0/1
    switchport trunk encapsulation dot1q
    switchport mode trunk
    switchport trunk native vlan 99
    switchport trunk allowed vlan 10,99
    exit
    end

    On SW-Floor2 — Tag the floor-2 end of the same uplink

    enable
    configure terminal
    interface Gi0/1
    switchport trunk encapsulation dot1q
    switchport mode trunk
    switchport trunk native vlan 99
    switchport trunk allowed vlan 10,99
    exit
    end

    Check: run show interfaces trunk on SW-Floor1 and look for Gi0/1 on 802.1q trunking 99.

    Why: A trunk carries many VLANs over one link by adding each frame's VLAN ID as a tag on the way out and removing it at the far end, which is why both switches must run that link as an 802.1Q trunk. Setting the native VLAN — the one that crosses untagged — to the unused VLAN 99 on both ends keeps any untagged frame out of the VLANs people actually use.

  7. 7. Widen the allowed list to carry VLAN 20 as well

    Sales works across the floors, but PC-C still cannot find PC-D: VLAN 20 was never on the allowed list, so the trunk drops it. Add it on both ends and Ops comes back without a single change to a PC or a cable. Read the trunk report afterwards — one wire, two VLANs riding it tagged, and Sales and Ops still unable to reach each other despite sharing the subnet, the switches and the cable.

    On SW-Floor1 — Let VLAN 20 onto the floor-1 end

    enable
    configure terminal
    interface Gi0/1
    switchport trunk allowed vlan add 20
    exit
    end

    On SW-Floor2 — Let VLAN 20 onto the floor-2 end

    enable
    configure terminal
    interface Gi0/1
    switchport trunk allowed vlan add 20
    exit
    end

    Check: run show interfaces trunk on SW-Floor1 and look for Gi0/1 10,20,99.

    Why: The allowed list is a filter applied to each trunk independently: a VLAN missing from it is not carried on that link, however healthy the link is, and each end enforces its own list. Keeping it narrow on purpose is good practice, because broadcasts for a VLAN with no members beyond the trunk have no reason to cross it.

The theory behind it

Build it for real

The lab walks you through these steps and ticks each one off as your network starts working.

Open in the lab
One VLAN across two switches — step-by-step network lab · NetForge-AI