A single physical switch becomes three networks that cannot hear one another, then two switches send all their traffic down a single cable, and at the end a router joins them back - under control, through subinterfaces. This exercise is the moment at which a network stops being a heap of cables and becomes a design.
1The problem VLANs solve
A company has three departments spread over two floors. Each floor has one switch. Accounts is not allowed to see the traffic of production, and visitors are not allowed to see anything.
Without VLANs you have exactly two solutions and both are poor: either you buy a separate switch for each department, on each floor - six switches instead of two -, or you pull cables from one end of the building to the other. The VLAN is the third answer: the same physical switch behaves as several independent switches, and membership is decided in the configuration, not in the cabling.
2Equipment needed
| Qty | Equipment | Model | Packet Tracer category | What it is for here |
|---|---|---|---|---|
| 3 | Switch | 2960 | Network Devices → Switches | SW-A (floor 1), SW-B (floor 2), SW-CORE |
| 1 | Router | 4331 | Network Devices → Routers | routing between the VLANs |
| 6 | Computer | PC-PT | End Devices → End Devices | PC1 … PC6, two for each department |
| 6 | Straight cable | Copper Straight-Through | Connections | hosts → switches, switch → router |
| 2 | Crossover cable | Copper Cross-Over | Connections | SW-A ↔ SW-CORE, SW-B ↔ SW-CORE |
For the optional section with a layer 3 switch you also need a 3560 switch (from
Network Devices → Switches as well), which replaces SW-CORE. For the Spanning Tree section, a third
crossover cable, between SW-A and SW-B.
3The topology and the plan
| VLAN | Name | Network | Gateway | Hosts |
|---|---|---|---|---|
| 10 | ADMIN | 192.168.10.0/24 | 192.168.10.1 | PC1 (.11), PC4 (.14) |
| 20 | PRODUCTIE | 192.168.20.0/24 | 192.168.20.1 | PC2 (.12), PC5 (.15) |
| 30 | OASPETI | 192.168.30.0/24 | 192.168.30.1 | PC3 (.13), PC6 (.16) |
| 99 | NATIV | - | - | none - the native VLAN, deliberately empty |
| 999 | NEFOLOSIT | - | - | the unused ports |
| Switch | Access ports | Trunk ports |
|---|---|---|
| SW-A | Fa0/1 → VLAN 10, Fa0/2 → VLAN 20, Fa0/3 → VLAN 30 | G0/1 to SW-CORE |
| SW-B | Fa0/1 → VLAN 10, Fa0/2 → VLAN 20, Fa0/3 → VLAN 30 | G0/1 to SW-CORE |
| SW-CORE | none | G0/1 to R1, G0/2 to SW-A, G0/3 to SW-B |
4The workbench
The topology of figure 1, cabled, with the addresses of the hosts already in place. The rest you configure yourselves, following the steps of sections 5-7. The objectives on the right tick themselves off.
5Step 1: creating the VLANs
- Check the starting point
Before any configuration, issue a ping from PC1 towards PC4:
on PC1ping 192.168.10.14
It works. All six hosts are, for the moment, in a single layer 2 network - VLAN 1, the default one. Remember the result: in five minutes it will no longer work, and that is the point.
- Create the VLANs - on all three switches
identical on SW-A, SW-B and SW-CORE
Switch> enable Switch# configure terminal Switch(config)# vlan 10 Switch(config-vlan)# name ADMIN Switch(config-vlan)# vlan 20 Switch(config-vlan)# name PRODUCTIE Switch(config-vlan)# vlan 30 Switch(config-vlan)# name OASPETI Switch(config-vlan)# vlan 99 Switch(config-vlan)# name NATIV Switch(config-vlan)# vlan 999 Switch(config-vlan)# name NEFOLOSIT Switch(config-vlan)# exit
There is no need to leave
config-vlanmode in between: the commandvlan 20works directly from inside VLAN 10.SW-CORE included, although it has no host A switch cannot switch the traffic of a VLAN it does not have configured locally, even if it merely transits it. A VLAN missing on an intermediate switch is the number one cause of trouble in this exercise - and one of the most frequent in real networks. - Assign the access ports
on SW-A - identical on SW-B
SW-A(config)# interface fastEthernet 0/1 SW-A(config-if)# switchport mode access SW-A(config-if)# switchport access vlan 10 SW-A(config-if)# switchport nonegotiate SW-A(config-if)# spanning-tree portfast SW-A(config-if)# exit SW-A(config)# interface fastEthernet 0/2 SW-A(config-if)# switchport mode access SW-A(config-if)# switchport access vlan 20 SW-A(config-if)# switchport nonegotiate SW-A(config-if)# exit SW-A(config)# interface fastEthernet 0/3 SW-A(config-if)# switchport mode access SW-A(config-if)# switchport access vlan 30 SW-A(config-if)# switchport nonegotiate SW-A(config-if)# end
What each line does:
Command Its effect switchport mode accessdeclares the port a user port, not a link between switches switchport access vlan 10moves it into VLAN 10 switchport nonegotiateturns off DTP, so the port cannot be tricked into becoming a trunk (the switch spoofing attack of lecture 12) spanning-tree portfastthe port comes into service at once, without the 30 seconds of STP waiting - Verify the isolation - this is where the result shows
on SW-A
SW-A# show vlan brief
You must see exactly this:
what should appearVLAN Name Status Ports ---- -------------------------------- --------- ------------------------------ 1 default active G0/1, G0/2 10 ADMIN active Fa0/1 20 PRODUCTIE active Fa0/2 30 OASPETI active Fa0/3 99 NATIV active 999 NEFOLOSIT active
Now test, from PC1:
on PC1ping 192.168.20.12 ping 192.168.10.14
Both must fail. The first, because PC2 is in another VLAN. The second, because PC4 is on another switch and the trunk does not exist yet. The failure is the proof that you configured correctly.
QuestionPC1 and PC2 are attached to the same physical switch, at two neighbouring ports. Why do they not hear each other?
See the answer
Because the switch refuses to switch between ports in different VLANs. Even if it had the MAC address of PC2 in its table, it would not use it: the MAC table is indexed by VLAN as well. The two hosts are in distinct broadcast domains, and from the point of view of layer 2 it is as though they were attached to entirely separate switches.
In addition, they also have addresses from different IP networks, so they would not even attempt a direct ARP - they would send the frame towards the gateway, which does not yet exist.
6Step 2: the trunk links
- Configure the trunks
Three switches, four link ports. All of them receive the same configuration:
on SW-A, the port towards SW-CORESW-A(config)# interface gigabitEthernet 0/1 SW-A(config-if)# switchport mode trunk SW-A(config-if)# switchport trunk native vlan 99 SW-A(config-if)# switchport trunk allowed vlan 10,20,30,99 SW-A(config-if)# switchport nonegotiate SW-A(config-if)# end
Repeat identically on:
- SW-B, port
G0/1 - SW-CORE, port
G0/2(towards SW-A) - SW-CORE, port
G0/3(towards SW-B) - SW-CORE, port
G0/1(towards R1) - yes, this one too: the router receives tagged frames
The two disciplined settingsswitchport trunk allowed vlan: left at its default, a trunk link carries all 4094 possible VLANs. By declaring the list explicitly you reduce useless traffic and limit what an attacker can inject.
switchport trunk native vlan 99: the native VLAN must be an empty one. If it stayed VLAN 1, a host in VLAN 1 could carry out the double tagging attack of lecture 12. - SW-B, port
- Verify
on SW-A
SW-A# show interfaces trunk
what should appearPort Mode Encapsulation Status Native vlan G0/1 on 802.1q trunking 99 Port Vlans allowed on trunk G0/1 10,20,30,99
If Status shows
not-trunking, the port has no active link: check the cable or the far end. If Native vlan differs between the two ends of the same link, IOS displays a warning in the console - do not ignore it, it is exactly the vulnerability you are trying to close. - Test the isolation again
on PC1
ping 192.168.10.14 ping 192.168.20.15
Test Expected result Why PC1 → PC4 works the same VLAN 10, although on different switches: the frame crossed the trunk, tagged PC1 → PC5 fails the trunk carries both VLANs, but does not mix them This is the central idea of the exercise, in a single sentence: a trunk carries several VLANs without joining them.
- Look at the 802.1Q tag
In the workbench in this page: issue
ping 192.168.10.14from PC1 and look at the Path of the last packet table. The column absent on the access port and present on the trunk is the tag itself - the segments between switches carry VLAN 10, those towards the hosts carry nothing.In Packet Tracer: in Simulation, filtered on ICMP and ARP, click the envelope on the trunk link and open Outbound PDU Details. You will see, in the structure of the Ethernet frame, an additional 4-byte field, with
TPID 0x8100andVLAN ID 10. Compare with the same frame on an access port: there the tag does not exist. This is, literally, the whole difference between an access port and a trunk port.
7Step 3: router-on-a-stick
The three VLANs are now three completely separate networks. The ADMIN department must nonetheless reach the resources in PRODUCTIE. We need a layer 3 device - but the router has a single free interface, and we have three networks.
The solution: subinterfaces. The same physical interface is divided logically into three, each with its own address and its own VLAN tag.
- Configure the subinterfaces on R1
on R1
Router> enable Router# configure terminal Router(config)# hostname R1 R1(config)# interface gigabitEthernet 0/0/0 R1(config-if)# no ip address R1(config-if)# no shutdown R1(config-if)# exit R1(config)# interface gigabitEthernet 0/0/0.10 R1(config-subif)# description Gateway VLAN 10 ADMIN R1(config-subif)# encapsulation dot1Q 10 R1(config-subif)# ip address 192.168.10.1 255.255.255.0 R1(config-subif)# exit R1(config)# interface gigabitEthernet 0/0/0.20 R1(config-subif)# encapsulation dot1Q 20 R1(config-subif)# ip address 192.168.20.1 255.255.255.0 R1(config-subif)# exit R1(config)# interface gigabitEthernet 0/0/0.30 R1(config-subif)# encapsulation dot1Q 30 R1(config-subif)# ip address 192.168.30.1 255.255.255.0 R1(config-subif)# exit R1(config)# interface gigabitEthernet 0/0/0.99 R1(config-subif)# encapsulation dot1Q 99 native R1(config-subif)# end R1# copy running-config startup-config
Three mistakes that are made every single time 1.no shutdownis issued on the physical interface. If it stays shut down, every subinterface is dead, however correctly configured. Try it: issueshutdownonG0/0/0and watch all the objectives go out at once.
2. The physical interface receives no IP address - the addresses sit on the subinterfaces.
3. The number of the subinterface (.10) has no meaning whatsoever for the device; what matters isencapsulation dot1Q 10. Use the same number all the same - it will save you an hour of troubleshooting six months from now. - Verify the complete routing
on R1
R1# show ip interface brief R1# show ip route
Exactly three connected routes must appear in the routing table, marked
C, one for each VLAN. If only two appear, one of the subinterfaces has no address or has the wrong tag.on PC1ping 192.168.10.1 ping 192.168.20.12 ping 192.168.30.13 tracert 192.168.30.16
tracertwill show exactly one intermediate hop: the gateway. Traffic between two VLANs goes up to the router and comes back down on the same wire - hence the name "router on a stick". - Measure the bottleneck
All the traffic between all the VLANs passes twice down the same G0/0/0 cable: once up, once down. In a real network, this is the limit of the architecture - and the reason why the following section exists.
In Packet Tracer, run massive pings simultaneously from PC1 and PC4 (
ping -n 200 -l 1400) towards hosts in another VLAN and compare the times with those obtained when you run alone.
8The modern variant: a layer 3 switch
Replace SW-CORE with a 3560 switch and remove the router entirely. The routing is now done in hardware, on the backplane of the switch, with no cable involved at all. In the workbench in this page, the same demonstration is made by enabling routing on SW-CORE itself.
SW-CORE(config)# ip routing SW-CORE(config)# interface vlan 10 SW-CORE(config-if)# ip address 192.168.10.1 255.255.255.0 SW-CORE(config-if)# no shutdown SW-CORE(config-if)# exit SW-CORE(config)# interface vlan 20 SW-CORE(config-if)# ip address 192.168.20.1 255.255.255.0 SW-CORE(config-if)# no shutdown SW-CORE(config-if)# exit SW-CORE(config)# interface vlan 30 SW-CORE(config-if)# ip address 192.168.30.1 255.255.255.0 SW-CORE(config-if)# no shutdown SW-CORE(config-if)# end SW-CORE# show ip route
shutdown on its physical interface.- Works with any router, even an old one
- The router can also do NAT, VPN, complex ACLs
- Simple configuration, easy to explain
- Routing in hardware, no bottleneck
- Consumes no cable and no port
- More expensive equipment; more limited security features than a router
Test the same pings as before. The functional result is identical, but the traffic never leaves the
switch any more - check with tracert, where the intermediate hop remains a single one, but is
the switch itself.
9Spanning Tree, observed
Add a direct link between SW-A and SW-B, configured as a trunk as well. In the workbench in this page:
pick SW-A, from the Cables panel press connect on port G0/2 and choose
SW-B : G0/2. You have created a physical loop between the three switches - exactly the
situation of lecture 4.
SW-A# show spanning-tree SW-CORE# show spanning-tree
- Identify which switch has become the root bridge - it appears with the note
This bridge is the root. With no configuration at all, the smallest MAC address decides, therefore as a rule the oldest device in the network. Rarely the one you would have chosen. - Find the port in the
BLKstate, with the roleAltn. That is the cable that STP has taken out of service in order to break the loop. The link exists physically, but carries nothing. - Check that the ping between PC1 and PC4 still works: the loop was neutralized without any loss of connectivity.
- Force the root onto the switch in the centre, where it suits you to have it:
SW-CORE(config)# spanning-tree vlan 10,20,30,99 root primary SW-A(config)# spanning-tree vlan 10,20,30,99 root secondary
Run show spanning-tree on SW-CORE again: it is now the root, and the blocked port has moved.
The command root primary does nothing magical - it sets the priority to 24576, a value smaller
than the default (32768), and the smaller priority wins the election.
Disconnect the cable between SW-CORE and SW-A. Time how long it takes until the ping between PC1 and PC4 starts working again, through the backup link.
What you should observe
About 30–50 seconds with classic STP: max age (20 s) plus the transitions through listening and learning (2 × 15 s). Then enable the rapid mode and repeat the measurement:
Switch(config)# spanning-tree mode rapid-pvst
Convergence drops to a few seconds. This is exactly why no modern network runs classic 802.1D any more.
10Four faults to diagnose
Provoke them one at a time, in the workbench. Each time note which command showed you the problem - that is what stays useful after the laboratory.
| Fault | How you produce it | Symptom | The command that reveals it |
|---|---|---|---|
| VLAN missing on the transit switch | on SW-CORE: no vlan 20 | VLAN 10 and 30 work across the trunk, VLAN 20 does not | show vlan brief on SW-CORE |
| VLAN removed from the allowed list | on SW-A G0/1: switchport trunk allowed vlan 10,30,99 | PC2 no longer reaches anywhere outside the switch | show interfaces trunk |
| Port left in VLAN 1 | on SW-B: no switchport access vlan 10 on Fa0/1 | PC4 disappears from its network, but the cable is green | show vlan brief on SW-B |
| Wrong tag on a subinterface | on R1: encapsulation dot1Q 25 instead of 20 | VLAN 20 has no gateway; the others work | show running-config on R1 |
11Assignments
- Build the topology and configure the five VLANs on all the switches
- Demonstrate the isolation between VLANs before configuring the router
- Configure the trunks with native VLAN 99 and an explicit list of allowed VLANs
- Capture and document an 802.1Q tag from Simulation mode
- Configure router-on-a-stick and demonstrate complete connectivity between all three VLANs
- Achieve the same function with a 3560 switch and SVIs; compare the path of the packet in the two variants
- Add the loop, observe STP and force the root onto SW-CORE
- Provoke the four faults of section 10 and note, for each, the diagnostic command
12Going further
VLAN 30 is for visitors. The company policy requires: visitors have access to the Internet, but to no
internal resource. In this laboratory you do not have the Internet yet, so simulate it with a server
placed in a VLAN 40, 192.168.40.0/24.
Requirements:
- PC3 and PC6 (VLAN 30) must reach the server in VLAN 40
- PC3 and PC6 must not reach any host in VLAN 10 or 20
- The hosts in VLAN 10 and 20 must reach everywhere, including the hosts in VLAN 30
Point 3 is the interesting part: traffic from ADMIN towards OASPETI must pass, but the reverse must not. Think about what kind of access list you need and in which direction it is applied. State the exact rule in words and justify where you place it - the configuration itself you will do in laboratory 6.
See the hint
A standard list is not enough: it filters by source only, and the source is the same (VLAN 30) both in the permitted traffic (towards VLAN 40) and in the forbidden traffic (towards VLAN 10 and 20). You need an extended list, which can see the destination as well.
The rule would read: "deny IP traffic with the source in 192.168.30.0/24 and the destination in
192.168.10.0/24 or 192.168.20.0/24; permit the rest". The correct placement is on the
G0/0/0.30 subinterface, direction in - that is, as close as possible to the
source, so that the forbidden traffic does not even reach the router.
Point 3 works automatically with this placement: traffic from ADMIN towards OASPETI comes in on
G0/0/0.10, where the list is not applied, so it is not filtered.
13Self-check questions
14Deliverables
| Deliverable | Format | Weight |
|---|---|---|
| The Packet Tracer file with working VLANs, trunks and inter-VLAN routing | .pkt | 35 % |
| The capture of the 802.1Q tag, with commentary | document | 15 % |
| The four faults, with symptom and diagnostic command | document | 20 % |
| The comparison router-on-a-stick / layer 3 switch, with the path of the packet in both | document | 15 % |
| Going further: the rule stated in words, with the placement justified | document | 15 % |