A 48-port switch solves collisions, but it leaves 48 computers in a single broadcast domain, with no separation between departments and no fallback path if a cable fails. This lecture presents the four tools that turn a pile of switches into a designed network: the VLAN, the trunk link, Spanning Tree and link aggregation.
1Recap4 min
- A switch learns from the source MAC address, forwards by the destination MAC address and floods when it does not know where the recipient is.
- A switch separates collision domains (one per port) but extends the broadcast domain - all its ports form a single one.
- A broadcast frame is flooded on every port, whatever the CAM table contains.
- Layer 2 has no TTL. Remember this - it is the key to the whole second half of this lecture.
Learning outcomes
- Explain what problem a VLAN solves and why a router is not enough
- Distinguish an access port from a trunk port and read an 802.1Q tag
- Explain the role of the native VLAN and its security risk
- Compare the two solutions for routing between VLANs
- Explain why a loop at layer 2 is fatal while one at layer 3 is not
- Run the STA algorithm step by step on a given topology
- Configure an aggregated link and know which modes combine with which
2What goes wrong in a flat LAN7 min
Take a concrete example. A company has three departments - accounts, production and a visitor area - spread across three floors, with one switch per floor, all connected together. With no logical separation, five problems arise at once.
| Problem | How it shows up | What we would want |
|---|---|---|
| Security | any host can try to reach any other; broadcasts arrive everywhere, visitors included, and may contain information useful to an attacker | blocking direct access between departments |
| Efficiency | a single broadcast is processed by every host in the company; in a network with many switches the impact becomes costly | limiting the broadcast domains |
| Administration | policies apply per switch, but the departments are mixed up across floors | policies per department, regardless of physical location |
| Quality (QoS) | IP telephones and video calls compete with file downloads for the same bandwidth | separate traffic, with its own priority |
| Cost | physical separation would require extra switches and cabling | a software solution on top of the existing equipment |
A broadcast frame is not merely "one more frame". Every host in the domain receives it, carries it up to the operating system and processes it - even if it then decides that it is none of its business. This is real work, done by every computer, for every broadcast.
In a network with 500 hosts, the ordinary protocols (ARP, DHCP, service discovery, network announcements) produce enough broadcast traffic to consume, permanently, a visible slice of every host's processor. And if a loop appears, as we shall see below, the network dies within a second.
Why not a router?
The question is a fair one: we know from the last lecture that a router separates broadcast domains. The answer has four parts:
- Routers are significantly more expensive per port than switches.
- They process layer 3, and so introduce greater latency.
- They consume one interface per segment, and routers have few interfaces.
- Most important: a router separates by cabling, but the hosts of the same department may be physically scattered throughout the building. You would have to rewire the building at every reorganisation.
3The definition of a VLAN9 min
Internally, each switch associates a VLAN ID with every port. On Cisco equipment all ports initially belong to VLAN 1. A port belonging to a single VLAN is called an access port; for the host attached to it, VLAN membership is entirely transparent - nothing is configured on the computer, and the user has no way of finding out.
A VLAN that "does not get there" is, in nine cases out of ten, a VLAN missing on an intermediate switch. It is the first thing to check in any problem of this kind.
4Access ports and trunk links11 min
So far we have worked with a single switch. What happens when VLANs must pass from one switch to another?
The problem
The first idea is to use one cable per VLAN: three VLANs, three cables, three ports consumed at each end. The solution works perfectly - and is entirely unusable. Ten VLANs would mean ten ports occupied on every switch merely for interconnection, plus ten cables to pull.
The solution: the trunk link
A trunk port carries the traffic of several VLANs over the same wire. Each frame receives a tag saying which VLAN it belongs to. This is where switches connect to one another.
Both ends of a trunk link must be configured as trunk ports, and the set of VLANs allowed on it is configurable - by default, all of them.
The 802.1Q tag
The concrete question remains: if switch 1 sends a frame from VLAN 10 over the trunk, how does switch 2 know which VLAN to place it in? The answer is that 4 extra bytes are inserted into the Ethernet frame, immediately after the source address.
The exceptions are virtualisation servers and IP telephones, which are deliberately configured as trunk ports, because they must place traffic into several VLANs themselves.
5The native VLAN5 min
Every trunk link has a special VLAN, called the native VLAN, whose frames travel untagged - in ordinary Ethernet format, as though the trunk did not exist.
The reason is historical: compatibility with equipment that does not understand 802.1Q and would otherwise discard every frame on the trunk. The two ends must have the same native VLAN configured; otherwise traffic from one VLAN lands, silently and with no error message whatever, in another VLAN.
The practical recommendation, valid in any real network: set the native VLAN to an unused VLAN, one with no hosts in it.
Topology: SW1 - SW0 - SW2, joined by trunks with native VLAN 10. Host A is on SW1 in VLAN 10, host B on SW2 in VLAN 10, hosts C and D on SW0 in VLAN 20. Host A sends a broadcast. Whom does it reach, and in what format does it travel over the links?
See the solution
It reaches B alone. A broadcast propagates exclusively within the sender's VLAN, and C and D are in VLAN 20. The path is A → SW1 → SW0 → SW2 → B.
On both trunk links the frame travels untagged, in standard Ethernet format - because VLAN 10 is precisely the native VLAN of the trunks.
Had the native VLAN been 1, the same frame would have travelled 802.1Q-tagged with VLAN ID 10. That is the only difference, but it causes confusion in the examination every time.
6Routing between VLANs13 min
VLANs isolate - that is their job. Sometimes, however, we genuinely do want the production department to reach the accounts server. In a controlled way, but to reach it.
Being distinct broadcast domains, two VLANs cannot communicate without a layer 3 device. There are two classic solutions and one modern one.
The classic solution: one interface per VLAN
The router is given one physical interface per VLAN, and each interface connects to an access port in that VLAN. Traffic comes in on one interface and goes out on another, the router performing ordinary routing between its connected networks.
The router-on-a-stick solution
A single physical router interface connects to a trunk port on the switch and is divided logically into subinterfaces, one per VLAN. Each subinterface receives an IP address of its own and is told that traffic arrives 802.1Q-tagged with a particular VLAN ID.
- Works with any router, even an old one
- One cable, one port
- The router can do NAT, VPN and complex ACLs at the same time
- Scales well with the number of VLANs
- Routing in hardware, on the backplane - no bottleneck at all
- Consumes neither a cable nor a port
- More expensive equipment
- More limited security features than a router
Router-on-a-stick remains relevant for small networks, for existing equipment and - above all - because it is the clearest illustration of what the 802.1Q tag does. You will configure it in laboratory 3.
7Redundancy and the problem of loops9 min
If the link between two switches fails, the hosts behind them stop communicating. The obvious solution is a backup link. The obvious solution, however, produces a physical loop - and a physical loop in a switched network produces three simultaneous effects, all of them catastrophic.
traceroute - but the network
stays usable.The Ethernet header has no equivalent of the TTL whatever. That is the only difference, but it is decisive - and the reason STP had to be invented.
8Spanning Tree: roles and costs11 min
The idea of the STP protocol (Spanning Tree Protocol, IEEE 802.1D) is simple and elegant: we accept the physical loop, because we need the redundancy, but we logically block one of the ports in it. If the main link fails, the blocked port is reopened.
The algorithm used is called the STA (Spanning Tree Algorithm) and is, in essence, the computation of a spanning tree over the graph of switches - a classic problem of graph theory, applied in real time, by devices that do not know one another.
The four roles
| Role | Who has it | What the port does |
|---|---|---|
| Root bridge | the switch with the lowest Bridge ID in the network | all of its ports are designated |
| Root port (RP) | exactly one on every non-root switch | the best path towards the root; it sends and receives data |
| Designated port (DP) | exactly one on every link | it sends and receives data |
| Blocked port (BLK) | everything that remains | it neither sends nor receives data, but keeps listening to BPDUs |
If it fell completely silent, it would have no way of finding out that the main link had failed. By continuing to listen to the STP messages (called BPDUs), it notices the silence on the main path and can reopen itself.
The blocked port is, in other words, a sentry: it lets nothing through, but it watches constantly and is ready to open the gate.
Bridge ID: who becomes the root
Every switch has a unique 64-bit identifier: 16 bits of priority (32768 by default) followed by 48 bits of MAC address. The comparison is lexicographic: priority first, and the MAC address in case of a tie.
The typical result: the root of the tree turns out to be a dusty access switch in a cupboard, and all the traffic between the modern backbone switches passes through it. The network works, but far below its capacity, and the cause is practically invisible unless you know what to look for.
That is why, in a real network, the root is set explicitly.
Link costs
| Bandwidth | Classic STP cost | Cost in the extended scale |
|---|---|---|
| 10 Mbps | 100 | 2,000,000 |
| 100 Mbps | 19 | 200,000 |
| 1 Gbps | 4 | 20,000 |
| 10 Gbps | 2 | 2,000 |
The cost of a path is the sum of the costs of the links traversed. Notice that the values are not linear: a 10 Mbps link costs 25 times as much as a 1 Gbps one, although it is 100 times slower. The scale was chosen empirically, and at modern speeds it has become too compressed - hence the extended variant.
- Leave everything at its default. Who becomes the root? Why? (Look at the MAC addresses.)
- Lower the priority of switch D to 4096. The tree reorganises itself entirely around it - this is exactly how an administrator forces the root.
- Return to equal priorities and change the speed of link A–C to 10 Mbps. Watch the blocked port move: the path has become expensive, so STP picks a different route.
- Make two links identical in speed and cost. How is the tie broken? (By Bridge ID.)
9The four steps of the algorithm9 min
Switches exchange messages called BPDUs (Bridge Protocol Data Unit), sent every 2 seconds on
every port, to the multicast address 01:80:C2:00:00:00. A BPDU carries four pieces of
information: the ID of the known root, the cost to reach it, the sender's own ID and the port ID.
- Electing the root. Every switch starts out believing it is the root. When it receives a BPDU with a lower Bridge ID, it changes its mind and propagates that one onward. After a few seconds everybody agrees on who the root is.
- Electing the root ports. Every non-root switch chooses exactly one port: the one with the lowest cumulative cost to the root. On a tie in cost, the neighbour's Bridge ID decides, then the Port ID.
- Electing the designated ports. On every link there must be exactly one designated port: that of the switch with the lower cost to the root; on a tie, the one with the lower Bridge ID. The root always has only designated ports.
- Blocking the rest. Any port that is neither a root port nor a designated port goes into the blocking state.
Five switches have the following Bridge IDs. Which becomes the root?
| Switch | Priority | MAC address |
|---|---|---|
| A | 16384 | 00E0.A3C9.6AB8 |
| B | 32768 | 0001.97DA.86E8 |
| C | 8192 | 00D0.BC0C.844D |
| D | 16384 | 0003.E496.C80E |
| E | 8192 | 0060.2F07.EB2B |
See the solution
Priority is compared first. The lowest is 8192, so only C and E remain in the running. Switch B, although it has the lowest MAC address of all, is eliminated at once - its priority is 32768.
Between C and E the MAC address decides: 00D0... against 0060....
The comparison is made byte by byte, from the left: the first byte is 00 in both; the
second is D0 = 208 for C and 60 = 96 for E. So E wins.
The root is E. The classic trap is to look at the MAC address first - priority is always compared first.
10Port states and convergence time6 min
A port does not go straight from "blocked" to "working". It passes through a series of states, each with its own role.
| State | Forwards data | Learns MAC addresses | Processes BPDUs | Duration |
|---|---|---|---|---|
| Disabled | no | no | no | the port is administratively shut |
| Blocking | no | no | receives only | up to 20 s (max age) |
| Listening | no | no | sends and receives | 15 s (forward delay) |
| Learning | no | yes | sends and receives | 15 s (forward delay) |
| Forwarding | yes | yes | sends and receives | final state |
If the port went straight into forwarding, the CAM table would be empty and the switch would flood all traffic - at precisely the most delicate moment, immediately after a topology change.
The learning state gives it 15 seconds to fill its table by listening to the traffic, without forwarding anything. By the time it moves to forwarding, it already knows where every host is.
For a user who has merely switched on a computer and is waiting for the port to come up, nearly a minute of silence is unacceptable - and generates a support ticket. Hence the fast variants in the next section, plus the PortFast mechanism, which skips the transitions on ports where there is certainly no other switch.
11The modern variants of STP4 min
| Variant | Standard | What it brings |
|---|---|---|
| STP | 802.1D | the original; convergence up to 50 s; a single tree for all VLANs |
| RSTP | 802.1w | convergence within seconds; new port roles (alternate, backup) |
| PVST+ | Cisco | one tree per VLAN - allows redundant links to be used simultaneously |
| Rapid-PVST+ | Cisco | the combination of the two above; the usual choice in a Cisco network |
| MSTP | 802.1s | groups VLANs into a few tree instances - scales better than one tree per VLAN |
With a separate tree per VLAN, you can have VLAN 10 use the left-hand link and VLAN 20 the right-hand one. Both links carry traffic, the redundancy remains, and the available bandwidth doubles. That is exactly why these variants appeared.
12EtherChannel: several cables, one link9 min
STP solves loops by blocking ports - which means an expensive link sits unused. Link aggregation solves the same problem differently: several physical links are combined into a single logical interface, which STP sees as one link.
There is no longer a loop, so nothing gets blocked, and the bandwidth adds up.
- The bandwidth adds up: four 1 Gbps links become one logical 4 Gbps link
- Configuration is done once, on the logical interface
- Redundancy without STP convergence time - losing a member does not interrupt the link
- Traffic distribution between members (load balancing)
- At most 8 physical interfaces in a group
- All members must have the same speed, the same duplex, the same mode (access or trunk), the same set of allowed VLANs and the same native VLAN
- Distribution is done per flow, not per frame: a single session never exceeds the bandwidth of one member
If the switch sent frames alternately over each link, they could arrive at the destination in a different order from the one they left in - the links do not have perfectly identical latencies. The reordering would damage TCP performance far more than the extra bandwidth would help.
So the switch computes a hash from the source and destination addresses and sends all the frames of one conversation over the same link. The practical consequence: a single file copy between two servers will never exceed 1 Gbps on a 4 Gbps channel. Aggregated bandwidth helps many simultaneous conversations, not a single one.
The negotiation protocols
| PAgP | LACP | |
|---|---|---|
| Origin | Cisco proprietary | IEEE 802.3ad, later 802.1AX |
| Active mode | desirable | active |
| Passive mode | auto | passive |
| No negotiation | on - recommended between equipment from different manufacturers | |
The combination rule is the same for both protocols and is worth memorising through its logic
rather than from the table: at least one end must initiate. Two passive ends will never form a
channel, because both are waiting. And on combines with nothing but on,
because it sends no negotiation packet at all - the other end has nothing to hear.
13Common mistakes4 min
- "I created the VLAN on the end switches, so it is done" Every switch the traffic passes through must have the VLAN configured locally, even if it has no hosts in it. For any VLAN that "does not get there", check the intermediate switches first.
- "The native VLAN does not matter, it is just a setting" If the two ends of a trunk have different native VLANs, traffic from one VLAN lands silently in another - with no error message at all. Set the same native VLAN at both ends, and choose an unused one.
- "I put the IP address on the router's physical interface, for router-on-a-stick"
The addresses belong on the subinterfaces. The physical interface gets only
no shutdown. If you leave it shut, every subinterface is dead, however correctly they are configured. Physical: enabled only. Logical: address and encapsulation. - "STP slows the network down, let us turn it off" The most expensive decision available. Without STP, the first accidental loop - a cable plugged in wrongly by somebody in a hurry - brings the whole network down. Do not disable STP. Move to Rapid-PVST+ and enable PortFast on access ports.
- "I joined two switches with four cables, so I have 4 Gbps" Without EtherChannel configured, STP will block three of them - you have 1 Gbps and three decorative cables. Aggregation must be configured explicitly, at both ends.
14Summary and glossary4 min
- The VLAN divides a physical switch into several broadcast domains, defined by ports and independent of the cabling.
- The trunk carries several VLANs over a single cable, using the 802.1Q tag. The native VLAN travels untagged - and must therefore be chosen with care.
- Communication between VLANs requires a layer 3 device: a router with subinterfaces or a layer 3 switch with SVIs.
- A loop at layer 2 is fatal, because there is no TTL. STP solves it by logically blocking a port.
- EtherChannel turns several cables into a single logical link - bandwidth added up, with no loop and nothing blocked.
15Self-check questions6 min
16Further reading and bibliography2 min
We have segmented the local network and made it resilient to faults. What we have not solved is communication between different networks, on a global scale - and for that, MAC addresses, flat and local, are of no use whatever. The next lecture introduces hierarchical addressing and layer 3.
In laboratory 3 you configure exactly the VLANs, the trunk and the router-on-a-stick from here, then provoke a loop and time how long STP convergence takes.
- IEEE 802.1Q - VLANs and frame tagging
- IEEE 802.1D and 802.1w - Spanning Tree and the rapid variant
- IEEE 802.1s - Multiple Spanning Tree
- IEEE 802.1AX - link aggregation
- Cisco - the VLAN, STP and EtherChannel configuration guides in the Catalyst documentation