Practice Exams:

VLAN Trunks, SVIs, and Inter-VLAN Routing on Cisco Networks

Networking & Network Engineering

When a user can see a local printer but cannot reach a server in another department, the problem may have nothing to do with DNS or the server. A VLAN might not exist on an upstream switch, an 802.1Q trunk might filter the needed tag, or a switched virtual interface might be down despite an apparently correct IP address. These faults are easy to conceal when someone checks only a port's green status light. CCNA troubleshooting becomes more reliable when every physical link, Layer 2 membership decision and Layer 3 routing boundary is tested separately.

On this page
  1. Start with the broadcast domain and the expected path
  2. Configure edge ports without accidentally making them trunks
  3. Understand exactly what 802.1Q carries between switches
  4. Choose between router-on-a-stick and Layer 3 switching
  5. Diagnose connectivity in an order that isolates the failing layer
  6. Connect VLAN operations to CCNA v1.1 and the announced v2.0

Start with the broadcast domain and the expected path

A virtual LAN defines a Layer 2 broadcast domain. Devices in the same VLAN can normally exchange Ethernet frames without a router if switching and security policies allow it. Devices in different VLANs require Layer 3 forwarding, regardless of whether their IP addresses look similar or their access ports connect to the same chassis. That is why a diagram should identify both VLAN IDs and IP prefixes: neither substitutes for the other.

Imagine employee laptops on VLAN 10 (192.0.2.0/24) and printers on VLAN 20 (198.51.100.0/24) in an illustrative lab. The clients on VLAN 10 must reach a router or Layer 3 switch gateway to access VLAN 20. A switch that only bridges frames will not move an IP packet from one broadcast domain to another. When a troubleshooting request says “the VLAN is configured,” verify the specific meaning: is the VLAN created, is the access port assigned, is the trunk carrying it, and is the routed gateway available?

MAC learning also matters. A switch learns source MAC addresses on incoming frames and associates them with ports in a VLAN’s forwarding table. It floods unknown unicast and broadcast traffic only within the relevant Layer 2 domain under normal conditions. If an uplink is blocking under Spanning Tree or VLAN 20 is pruned, the switch will not forward the expected frames even though both ports are physically up. A route test is premature until the link and VLAN path have been checked.

Configure edge ports without accidentally making them trunks

An access port carries one data VLAN for a conventional workstation. A voice deployment may use a separate voice VLAN in addition to the access data VLAN, and an access point or virtualized server may require a more specialized trunk arrangement. The administrator must learn what the connected device actually sends. A port connected to a desk computer should not be left accepting unexpected VLAN negotiations just because it was convenient during initial installation.

A simplified Cisco IOS access-port configuration can set switchport mode access and switchport access vlan 10. The commands are only the start of a working design. Check that VLAN 10 exists, that the port is enabled and non-errdisabled, that the endpoint’s cabling is sound, and that power-over-Ethernet requirements have been met for devices that need it. On a phone with a downstream PC, the voice VLAN configuration and phone discovery behavior can create symptoms that look like a misconfigured data VLAN.

Useful verification starts with show interfaces status, show vlan brief and the switchport details for the interface. A port in VLAN 1 because of a default setting will not reach a gateway on VLAN 10. If the interface is shut down for a security violation, moving the VLAN does not remove the condition. Record the port’s operational mode, access VLAN, voice VLAN and error indicators before changing anything. The result should explain the entire link state rather than produce an isolated screenshot of the running configuration.

Understand exactly what 802.1Q carries between switches

A trunk carries traffic for multiple VLANs across one physical or logical link by inserting an 802.1Q VLAN tag where appropriate. An ordinary Cisco configuration may use switchport mode trunk and a deliberate allowed list such as switchport trunk allowed vlan 10,20. The trunk’s administrative setting alone is not proof that the peer is forwarding those tags. One side may disagree about mode or allowed VLANs, or a VLAN might be absent locally.

The native VLAN deserves separate attention. By default, traffic belonging to the trunk’s native VLAN is often sent untagged on conventional 802.1Q trunks, although tagging behavior is configurable on some platforms. If the two ends disagree on the native VLAN, untagged traffic can be classified into different broadcast domains. This is both an operational hazard and a security concern. Do not ‘solve’ a mismatch by declaring every VLAN native; align the design on both sides and verify it in actual interface status.

show interfaces trunk is a practical starting point because it distinguishes the trunking interfaces, native VLAN, allowed VLANs and VLANs actively forwarding. A VLAN’s appearance in an allowed list does not mean it is active and forwarding under every condition. Check the VLAN database and Spanning Tree forwarding state as well. A trunk can carry VLAN 10 perfectly while silently filtering VLAN 20, making employee applications work while the printers fail. That narrow failure pattern is evidence, not an inconsistency.

Choose between router-on-a-stick and Layer 3 switching

Inter-VLAN routing can be performed through router subinterfaces, where each subinterface corresponds to an 802.1Q VLAN, or through switched virtual interfaces (SVIs) on a Layer 3 switch. Router-on-a-stick places multiple tagged VLANs across a shared physical router connection. An illustrative subinterface might use encapsulation dot1Q 20 followed by an IP address in the VLAN 20 subnet. The design is useful for small labs, but it concentrates inter-VLAN traffic on that router link.

An SVI is a logical Layer 3 interface associated with a VLAN. A switch may have interface vlan 20 and ip address 198.51.100.1 255.255.255.0; it also needs Layer 3 routing enabled when forwarding between VLANs and must meet the platform’s operational conditions for the SVI to be up. Merely entering an IP address in an SVI configuration is not enough. VLAN 20 must exist and, on many platforms, have at least one relevant active forwarding port for line protocol to rise. Check show ip interface brief and the route table rather than assuming an SVI is usable because it appears in the configuration.

Hosts need the correct default gateway and a route back to their subnet. If the VLAN 20 printer has a static address but points to the VLAN 10 SVI, access from another VLAN may fail even when the switch routes toward VLAN 20. The gateway for a host should be an IP address that is reachable on the host’s own Layer 2 segment and subnet. If the application requires name resolution, test the printer by address before changing DNS records.

Diagnose connectivity in an order that isolates the failing layer

A reproducible path test checks the client interface, then its access VLAN, then the trunk, then the source SVI and finally the destination VLAN and host. A failure to ping the source VLAN gateway often indicates a local Layer 2, IP or access-policy problem. If the source gateway answers but another SVI cannot be reached, check route installation, interface status and filtering. If both gateways answer but the destination host does not, inspect the destination VLAN, host firewall and return path rather than repeatedly changing the source trunk.

A packet capture at an appropriate point can show whether frames are tagged on an uplink, whether ARP resolves the gateway, and whether ICMP reaches the destination. Use captures carefully: an endpoint capture usually does not display the 802.1Q tag removed by an access switch port, so absence of a tag in that capture proves nothing about trunk configuration. A span or dedicated tap with correct configuration provides different visibility. Combine observations with the switch’s own counters, MAC table and route output to avoid drawing a conclusion from one incomplete source.

For a controlled lab, deliberately remove VLAN 20 from a trunk’s allowed list, observe the symptom and restore it. Then disable the VLAN 20 SVI while leaving the trunk healthy and compare the difference. Finally, keep both working but configure a host with the wrong gateway. These controlled changes teach the distinction between a VLAN path fault, a router interface fault and a host addressing fault, the core of useful troubleshooting.

Connect VLAN operations to CCNA v1.1 and the announced v2.0

The current CCNA v1.1 blueprint requires configuring and verifying VLANs, access ports, voice VLANs, 802.1Q trunks, native VLAN behavior and inter-VLAN connectivity. The announced February 2027 v2.0 objectives move toward configuring infrastructure links, SVIs, VLAN attributes and troubleshooting basic Layer 2/Layer 3 operations. That shift does not eliminate the foundation. It changes what the candidate must be able to demonstrate when a design is broken.

A study plan should involve at least two switches, two VLANs and a routed boundary, with an actual change-control record describing the expected result. The IPv4 subnet and gateway calculations establish whether each device belongs to the correct network, while the CCNA 200-301 exam scope determines how deeply to practice each configuration. Refer to Cisco’s v1.1 exam objectives and v2.0 blueprint for the exact verbs and topics on the test date.

The strongest evidence of skill is not a screenshot of a configured VLAN. It is a short explanation demonstrating where the frame was admitted, whether the tag crossed each link, which gateway routed the resulting packet and where the return path went. Once those questions are answered, VLAN troubleshooting becomes a series of testable observations rather than a search for the right command to copy.

Related Posts

• Unlocking the Cisco 350-401 ENCOR Certification – A Gateway to Network Architecture Mastery

• Understanding the Cisco 300-420 Exam and the Foundations of Enterprise Network Design

• Cisco 200-301: Subnetting Gets Easier When You Stop Memorizing Tables

• Cisco 350-401: OSPF at Enterprise Scale

• Cisco 350-401: SD-WAN Policy Turns Intent Into Path Selection

• Cisco 350-701: From Alert to Containment

• Cisco 350-501: BGP Policy Is the Control Plane of the Internet

• Cisco 200-301: VLAN Trunks Without Native VLAN Confusion

• Cisco 200-301: Wireless LAN Controllers

• Cisco 350-401: BGP Path Selection in Practice