Skip to main content
AD Academy
CCNA — Cisco Networking Fundamentals
Beginner14 minLast updated: Topic 2 of 12

Switching, VLAN and Trunk

MAC Table, VLANs, 802.1Q, Access vs. Trunk and STP.

Not read

What you will learn here

  • How a switch learns MAC addresses
  • What a VLAN is and why networks are split
  • Access vs Trunk ports (802.1Q)

Worth reading first:OSI and TCP/IP Model

A Switch learns which MAC addresses are on each port and builds a MAC Address Table. This way, it sends each Frame only to the correct port, instead of to the entire network.

VLAN — Logical segmentation of the network

PC-A and PC-C sit in VLAN 10, PC-B and PC-D in VLAN 20, connected through access ports to switches SW1 and SW2. A trunk port between the switches carries both VLANs tagged with 802.1Q, while the native VLAN travels untagged. Hosts in different VLANs cannot reach each other until a router or L3 switch provides inter-VLAN routing.

Short and clear

  • A VLAN splits one physical switch into several separate logical networks.
  • An access port belongs to a single VLAN — that is where a PC or phone plugs in.
  • A trunk port carries several VLANs at once using an 802.1Q tag on every frame.
  • VLANs cannot talk directly — you need a router or a layer-3 switch.

Real-life exampleIn the office: VLAN 10 for PCs, VLAN 20 for phones, VLAN 99 for management. A guest on the guest VLAN cannot reach corporate servers even on the same physical switch.

  • A VLAN is a 'network within a network' — logical separation without additional cables.
  • Access Port — Belongs to one VLAN, connected to a computer or printer.
  • Trunk Port — Carries several VLANs between Switches, tagged with 802.1Q.
  • Native VLAN — Traffic that passes through the Trunk without a tag (default VLAN 1 — recommended to change).
  • Inter-VLAN Routing — A Router or L3 Switch is required to move between VLANs.
! Create VLAN and configure access port
Switch(config)# vlan 20
Switch(config-vlan)# name USERS
Switch(config)# interface gi0/1
Switch(config-if)# switchport mode access
Switch(config-if)# switchport access vlan 20

! Configure Trunk between switches
Switch(config)# interface gi0/24
Switch(config-if)# switchport mode trunk
Switch(config-if)# switchport trunk allowed vlan 10,20,30

! Checks
Switch# show vlan brief
Switch# show interfaces trunk
Switch# show mac address-table
bash
Architecture and Theory — Under the Hood

A Switch builds a MAC Address Table by learning: every incoming Frame teaches it which MAC address resides on which port. If the destination is unknown — it performs Flooding to all ports in that VLAN. Each VLAN is a separate Broadcast .

VLAN 10 (Sales)      VLAN 20 (IT)
   PC-A ---+            PC-B ---+
           |                    |
        [ SW1 ] === Trunk 802.1Q === [ SW2 ]
           |                    |
        Router / L3 SW  (Inter-VLAN Routing)
text
  • 802.1Q adds a 4-byte tag inside the Frame: TPID (0x8100) + PCP (QoS) + VLAN ID (12 bits = 4094 VLANs).
  • Access Port: removes/adds a tag — the computer doesn't know it's in a VLAN.
  • Trunk Port: carries tagged traffic of several VLANs; the Native VLAN passes untagged.
  • Inter-VLAN Routing: either Router-on-a-Stick (sub-interfaces) or SVI on an L3 Switch.
Practical Configuration (CLI)
! Access Port
SW(config)# vlan 10
SW(config-vlan)# name SALES
SW(config)# interface range gi0/2-10
SW(config-if-range)# switchport mode access
SW(config-if-range)# switchport access vlan 10
SW(config-if-range)# switchport nonegotiate
SW(config-if-range)# spanning-tree portfast

! Trunk between switches
SW(config)# interface gi0/24
SW(config-if)# switchport trunk encapsulation dot1q
SW(config-if)# switchport mode trunk
SW(config-if)# switchport trunk native vlan 999
SW(config-if)# switchport trunk allowed vlan 10,20,30

! Router-on-a-Stick
R(config)# interface gi0/0.10
R(config-subif)# encapsulation dot1Q 10
R(config-subif)# ip address 192.168.10.1 255.255.255.0

! L3 Switch (SVI)
SW(config)# ip routing
SW(config)# interface vlan 10
SW(config-if)# ip address 192.168.10.1 255.255.255.0
bash
Real-world Scenarios in an Organization
  • Department Separation: Sales / IT / HR — each in its own VLAN, and access between them is controlled by an ACL.
  • Voice VLAN: IP phones receive a separate VLAN with high QoS priority.
  • Dedicated VLAN for Management and Servers — do not leave management in VLAN 1.
  • Guest VLAN: Guests receive internet only, without access to the internal network.
Troubleshooting
SW# show vlan brief              ! Is the port in the correct VLAN?
SW# show interfaces trunk        ! Which VLANs are actually passing?
SW# show interfaces gi0/24 switchport
SW# show mac address-table vlan 10
SW# show interfaces status
bash
  • 'Everything is configured but there's no communication' → The VLAN is not in the allowed list of the Trunk.
  • Native VLAN mismatch → CDP message in the log; fix on both sides.
  • There is communication within the VLAN but not between VLANs → Missing Inter-VLAN Routing or incorrect Default Gateway on the client.
  • The port is err-disabled → Usually ; reset with `shutdown / no shutdown`.
Glossary and Quick Command Line
  • show vlan brief / show interfaces trunk — the two most important L2 commands
  • 802.1Q = Tagging Standard | Native VLAN = Untagged
  • VLAN 1 = Default — do not use in production
  • SVI = interface vlan X on an L3 Switch

Check yourself

What is the role of a Trunk Port?

What prevents loops in a switch network?

Was this page helpful?