All guided builds

Guided buildcore7 steps~15 min5 devices

Two departments, one switch

Split a single switch into Sales and Ops with VLANs, and watch the pings between them stop.

What you'll be able to do: Sales desks talk to Sales desks and Ops desks talk to Ops desks, on the same switch, with nothing able to cross between them until a router is added.

Topics: VLANs · Broadcast domains · Access ports · Layer 2 segmentation

What you'll build

Step by step

  1. 1. Place the switch and name it

    Drag one switch onto the canvas. The canvas gives it a placeholder name, so the first thing you type is a hostname of your own — every later step and every check refers to this device as SW-Floor1, and a named device is the only way to tell two switches apart in a console tab.

    On SW-Floor1 — Name the switch

    enable
    configure terminal
    hostname SW-Floor1
    end

    Check: run show running-config on SW-Floor1 and look for hostname SW-Floor1.

    Why: A hostname is how a device identifies itself beyond its own console: discovery protocols like LLDP announce it to neighbours, and logs and people refer to the box by it. Setting it first means everything that happens afterwards is recorded against the right name.

  2. 2. Plug in the two Sales desks

    Drag two PCs on and run a copper cable from each one's Eth0 to a switch port. Switch ports need no configuration to carry traffic — they come up as soon as they see a neighbour, which is why an unconfigured switch is a working network out of the box.

    • Cable PC-Sales-A Eth0 ↔ SW-Floor1 Fa0/1
    • Cable PC-Sales-B Eth0 ↔ SW-Floor1 Fa0/2

    Check: run show interfaces status on SW-Floor1 and look for Fa0/2 connected 1 auto 100 fastethernet.

    Why: Every port on an unconfigured switch already belongs to VLAN 1, which is why the Vlan column of `show interfaces status` reads 1 before you have typed anything. A factory switch is therefore one VLAN and one broadcast domain across all of its ports — the starting point this build is about to divide.

  3. 3. Address the Sales pair

    Name each PC and give it an address in 192.168.1.0/24. Two hosts in one subnet on one switch need nothing else to reach each other — no gateway, no routes — so the ping succeeds the moment the second address lands.

    On PC-Sales-A — Name the first Sales desk and address it

    hostname PC-Sales-A
    ipconfig Eth0 192.168.1.11 255.255.255.0

    On PC-Sales-B — Name the second Sales desk and address it

    hostname PC-Sales-B
    ipconfig Eth0 192.168.1.12 255.255.255.0

    On PC-Sales-A — Check that one Sales desk reaches the other

    ping 192.168.1.12

    Check: run ipconfig on PC-Sales-A and look for IPv4 Address. . . . . . . . . . : 192.168.1.11.

    Why: Two hosts talk directly only when two things are true at once: their masks put them in the same subnet, and the network puts them in the same broadcast domain, so that ARP can find one from the other. Right now both are true; the rest of this build pulls the two apart to show that each one matters on its own.

  4. 4. Add the Ops desks to the same flat network

    Ops gets the same treatment: two PCs, two cables, two addresses in the same 192.168.1.0/24. Now ping from Sales to Ops. It works, and that is the problem — a switch with default settings is one broadcast domain, so every desk reaches every other desk and hears every broadcast, whichever department it belongs to.

    • Cable PC-Ops-A Eth0 ↔ SW-Floor1 Fa0/3
    • Cable PC-Ops-B Eth0 ↔ SW-Floor1 Fa0/4

    On PC-Ops-A — Name the first Ops desk and address it

    hostname PC-Ops-A
    ipconfig Eth0 192.168.1.21 255.255.255.0

    On PC-Ops-B — Name the second Ops desk and address it

    hostname PC-Ops-B
    ipconfig Eth0 192.168.1.22 255.255.255.0

    On PC-Sales-A — Prove there is nothing between the two departments yet

    ping 192.168.1.21
    ping 192.168.1.22

    Check: run show vlan brief on SW-Floor1 and look for 1 default active Fa0/1, Fa0/2, Fa0/3, Fa0/4,.

    Why: A broadcast domain is every device that receives a broadcast sent by any one of them. On a flat switch that is every port, so nothing at layer 2 separates the departments, and as the domain grows every ARP request and every other broadcast interrupts more hosts that have no interest in it.

  5. 5. Create the two VLANs

    A VLAN is a separate broadcast domain living inside one switch. Create two of them and name them, so the next engineer reading the configuration knows what VLAN 10 is for. Nothing moves yet — a new VLAN starts empty, and the Ports column after this step proves it.

    On SW-Floor1 — Add VLAN 10 and VLAN 20 to the switch's VLAN database

    enable
    configure terminal
    vlan 10
    name Sales
    exit
    vlan 20
    name Ops
    exit
    end

    Check: run show vlan brief on SW-Floor1 and look for 10 Sales active.

    Why: Creating a VLAN only adds an entry to the switch's VLAN database: a number, a name and a state. Membership is a property of each port and is assigned separately, so the switch now knows the new broadcast domain exists even though nothing lives in it yet.

  6. 6. Move the Sales desks into VLAN 10

    An access port belongs to exactly one VLAN and carries that VLAN's traffic untagged, which is what an ordinary PC expects. Put Fa0/1 and Fa0/2 into VLAN 10, then run the two pings again: Sales to Sales still works, Sales to Ops stops. No address changed, so the only thing in the way is the VLAN boundary.

    On SW-Floor1 — Make the two Sales ports access ports in VLAN 10

    enable
    configure terminal
    interface Fa0/1
    switchport mode access
    switchport access vlan 10
    exit
    interface Fa0/2
    switchport mode access
    switchport access vlan 10
    exit
    end

    On PC-Sales-A — One ping still works, the other now fails

    ping 192.168.1.12
    ping 192.168.1.21

    Check: run show vlan brief on SW-Floor1 and look for 10 Sales active Fa0/1, Fa0/2.

    Why: A switch delivers a frame only to ports in the VLAN it arrived in, and that includes broadcasts. PC-Sales-A still believes 192.168.1.21 is local and sends an ARP request for it, but the request stays inside VLAN 10 and never reaches the Ops ports, so no reply comes back and the ping dies before a single echo is sent.

  7. 7. Finish the split: Ops gets its own VLAN and its own subnet

    Leaving Ops in VLAN 1 happens to work, but VLAN 1 is where every unconfigured port lands, so any desk plugged in anywhere would join Ops by accident. Move Fa0/3 and Fa0/4 into VLAN 20, then re-address Ops into 192.168.2.0/24: you have already proved the wall is the VLAN, and one broadcast domain per subnet is the shape a router needs before it can carry traffic between them.

    On SW-Floor1 — Make the two Ops ports access ports in VLAN 20

    enable
    configure terminal
    interface Fa0/3
    switchport mode access
    switchport access vlan 20
    exit
    interface Fa0/4
    switchport mode access
    switchport access vlan 20
    exit
    end

    On PC-Ops-A — Re-address the first Ops desk into the Ops subnet

    ipconfig Eth0 192.168.2.21 255.255.255.0

    On PC-Ops-B — Re-address the second Ops desk into the Ops subnet

    ipconfig Eth0 192.168.2.22 255.255.255.0

    On PC-Ops-A — Ops still reaches Ops, and Sales stays out of reach

    ping 192.168.2.22
    ping 192.168.1.11

    Check: run show vlan brief on SW-Floor1 and look for 20 Ops active Fa0/3, Fa0/4.

    Why: The rule is one VLAN, one subnet, because hosts decide whether to use a gateway by comparing subnets. While Sales and Ops shared 192.168.1.0/24, each side considered the other local and ARPed for it directly, so even with a router attached no packet between them would ever have been handed to it.

The theory behind it

Build it for real

The lab walks you through these steps and ticks each one off as your network starts working.

Open in the lab
Two departments, one switch — step-by-step network lab · NetForge-AI