Guided buildcore7 steps~18 min6 devices
One VLAN across two switches
Split four PCs into two VLANs across two switches, then carry both VLANs between the switches over a single tagged trunk.
What you'll be able to do: Two PCs in the same VLAN ping each other through two switches and one shared cable, while a PC in the other VLAN — on that very same cable, in that very same subnet — cannot reach them at all.
Topics: VLANs · Trunking · 802.1Q · Switching
What you'll build
- SW-Floor1 — a switch, the first-floor access switch
- SW-Floor2 — a switch, the second-floor access switch
- PC-A — a pc, a Sales machine on floor 1
- PC-B — a pc, a Sales machine on floor 2
- PC-C — a pc, an Ops machine on floor 1
- PC-D — a pc, an Ops machine on floor 2
Step by step
1. Two switches, one cable between them
Drag two switches onto the canvas and run a single cable from Gi0/1 on one to Gi0/1 on the other. That one link is everything the two floors have in common, and by the end of this build it will be carrying two separate VLANs at once. Name both switches now, because every check from here on resolves a device by the hostname you set, not by the label the canvas hands out.
- Cable SW-Floor1 Gi0/1 ↔ SW-Floor2 Gi0/1
On SW-Floor1 — Name the first-floor switch
enable configure terminal hostname SW-Floor1 endOn SW-Floor2 — Name the second-floor switch
enable configure terminal hostname SW-Floor2 endWhy: A cable between two switches merges them into one switching fabric: with every port in VLAN 1, both chassis form a single broadcast domain, and each switch learns the other's hosts as MAC addresses living behind its uplink port. Everything this build adds is about controlling what crosses that one link.
2. Four hosts, two per floor
Add four PCs and cable each one to an Fa0/x port, two on each switch. Fa0/1 on each switch will end up in Sales and Fa0/2 in Ops, so the pairs that need to talk to each other are deliberately on opposite switches — that is the only way to prove a VLAN really does cross the cable.
- Cable SW-Floor1 Fa0/1 ↔ PC-A Eth0
- Cable SW-Floor1 Fa0/2 ↔ PC-C Eth0
- Cable SW-Floor2 Fa0/1 ↔ PC-B Eth0
- Cable SW-Floor2 Fa0/2 ↔ PC-D Eth0
Why: A VLAN is not tied to a switch: membership follows ports, and one VLAN can have ports on any number of switches as long as the links between them carry it. That is how a single VLAN serves a department spread over several floors or wiring closets.
3. Address all four in one subnet, on purpose
Give every PC an address in 192.168.1.0/24 — yes, all four in the same subnet. Keeping routing out of the picture means that when two of these machines stop being able to reach each other later, the VLAN is the only thing that can possibly have caused it. Ping across the switches now and everything answers, because a switch out of the box puts every port in one flat VLAN 1.
On PC-A — Name and address the first Sales machine
hostname PC-A ipconfig Eth0 192.168.1.10 255.255.255.0On PC-B — Name and address the second Sales machine
hostname PC-B ipconfig Eth0 192.168.1.11 255.255.255.0On PC-C — Name and address the first Ops machine
hostname PC-C ipconfig Eth0 192.168.1.20 255.255.255.0On PC-D — Name and address the second Ops machine
hostname PC-D ipconfig Eth0 192.168.1.21 255.255.255.0Check: run
ipconfigon PC-A and look for192.168.1.10.Why: The ping from PC-A to PC-B crosses both switches, and each learns PC-A's MAC on the port the frame arrived on — SW-Floor1 on Fa0/1, SW-Floor2 on its uplink Gi0/1. A switch never knows how far away a host is; it only knows which of its own ports leads toward it.
4. Declare the VLANs on both switches
A VLAN is a number a switch agrees to keep separate, and each switch keeps its own list. Create VLAN 10 for Sales, VLAN 20 for Ops and VLAN 99 as an empty parking VLAN on both switches — a VLAN that exists on one switch and not the other is the classic reason a trunk appears to swallow traffic. Nothing changes on the wire yet, because no port has been handed to a VLAN so far.
On SW-Floor1 — Build the VLAN database on floor 1
enable configure terminal vlan 10 name Sales exit vlan 20 name Ops exit vlan 99 name Parking exit endOn SW-Floor2 — Build the identical VLAN database on floor 2
enable configure terminal vlan 10 name Sales exit vlan 20 name Ops exit vlan 99 name Parking exit endCheck: run
show vlan briefon SW-Floor1 and look for99 Parking.Why: Each switch keeps its own VLAN database, so a VLAN exists only on the switches where it has been created. VLAN 99 is empty on purpose: it will become the trunk's native VLAN, the one VLAN that crosses the link untagged, and parking that role on a VLAN no user lives in keeps real traffic from ever travelling without a tag.
5. Hand each host port to one VLAN
An access port belongs to exactly one VLAN and sends the host plain untagged frames — the PC has no idea a VLAN exists. Put Fa0/1 in VLAN 10 and Fa0/2 in VLAN 20 on both switches, then ping from PC-A to PC-C. It fails, even though they share a switch and a subnet, and that failure is the whole point of a VLAN.
On SW-Floor1 — Put the floor-1 host ports into Sales and Ops
enable configure terminal interface Fa0/1 switchport mode access switchport access vlan 10 exit interface Fa0/2 switchport mode access switchport access vlan 20 exit endOn SW-Floor2 — Put the floor-2 host ports into Sales and Ops
enable configure terminal interface Fa0/1 switchport mode access switchport access vlan 10 exit interface Fa0/2 switchport mode access switchport access vlan 20 exit endCheck: run
show vlan briefon SW-Floor1 and look foractive Fa0/1.Why: A VLAN boundary is enforced by the switch, not by the hosts: PC-A still considers PC-C local and broadcasts its ARP request, but the switch delivers it only to other ports in VLAN 10. The uplink is still an access port in VLAN 1, so for now it carries neither of the new VLANs — which the next step deals with.
6. Turn the uplink into a trunk
PC-A has also lost PC-B, because the cable between the switches is still an access port in VLAN 1 and a VLAN 10 frame has nowhere to go. A trunk fixes that by tagging each frame with its VLAN number on the way out and stripping the tag on the way in, so many VLANs share one wire. Configure it on both ends — a trunk facing an access port carries nothing. Allow only VLAN 10 and the native VLAN for the moment, so the allowed list has something to prove in the next step.
On SW-Floor1 — Tag the floor-1 end of the uplink
enable configure terminal interface Gi0/1 switchport trunk encapsulation dot1q switchport mode trunk switchport trunk native vlan 99 switchport trunk allowed vlan 10,99 exit endOn SW-Floor2 — Tag the floor-2 end of the same uplink
enable configure terminal interface Gi0/1 switchport trunk encapsulation dot1q switchport mode trunk switchport trunk native vlan 99 switchport trunk allowed vlan 10,99 exit endCheck: run
show interfaces trunkon SW-Floor1 and look forGi0/1 on 802.1q trunking 99.Why: A trunk carries many VLANs over one link by adding each frame's VLAN ID as a tag on the way out and removing it at the far end, which is why both switches must run that link as an 802.1Q trunk. Setting the native VLAN — the one that crosses untagged — to the unused VLAN 99 on both ends keeps any untagged frame out of the VLANs people actually use.
7. Widen the allowed list to carry VLAN 20 as well
Sales works across the floors, but PC-C still cannot find PC-D: VLAN 20 was never on the allowed list, so the trunk drops it. Add it on both ends and Ops comes back without a single change to a PC or a cable. Read the trunk report afterwards — one wire, two VLANs riding it tagged, and Sales and Ops still unable to reach each other despite sharing the subnet, the switches and the cable.
On SW-Floor1 — Let VLAN 20 onto the floor-1 end
enable configure terminal interface Gi0/1 switchport trunk allowed vlan add 20 exit endOn SW-Floor2 — Let VLAN 20 onto the floor-2 end
enable configure terminal interface Gi0/1 switchport trunk allowed vlan add 20 exit endCheck: run
show interfaces trunkon SW-Floor1 and look forGi0/1 10,20,99.Why: The allowed list is a filter applied to each trunk independently: a VLAN missing from it is not carried on that link, however healthy the link is, and each end enforces its own list. Keeping it narrow on purpose is good practice, because broadcasts for a VLAN with no members beyond the trunk have no reason to cross it.
The theory behind it
More in Switching & wireless
- Map the network with CDP and LLDP — Let two switches and a router discover each other, find the router's address from a switch that was never told it, add LLDP, then stop the router announcing itself toward the internet.
- Two departments, one switch — Split a single switch into Sales and Ops with VLANs, and watch the pings between them stop.
- Router on a stick — Split one switch into two VLANs and route between them over a single router port.
- Route between VLANs on the switch — Give one switch an SVI in each VLAN, find out why the VLANs still can't talk, then turn on ip routing — inter-VLAN routing with no router at all.
- Choose your root bridge — Close a loop of three switches, find the port spanning tree blocks on its own, then decide which switch is root — and which one takes over when it fails.
- Two cables, one logical link — Add a second uplink between two switches, watch spanning tree block it, then bundle both into an LACP EtherChannel so they carry traffic together.
Build it for real
The lab walks you through these steps and ticks each one off as your network starts working.
Open in the lab