Local Area Networks / Laboratory
LABORATORY 03

VLANs, trunks and inter-VLAN routing

Duration: 2 hours Platform: the workbench in this page, or Packet Tracer Background: laboratories 1–2, lecture 4 PDF: download the notes RO versiunea română

A single physical switch becomes three networks that cannot hear one another, then two switches send all their traffic down a single cable, and at the end a router joins them back - under control, through subinterfaces. This exercise is the moment at which a network stops being a heap of cables and becomes a design.

1The problem VLANs solve

A company has three departments spread over two floors. Each floor has one switch. Accounts is not allowed to see the traffic of production, and visitors are not allowed to see anything.

Without VLANs you have exactly two solutions and both are poor: either you buy a separate switch for each department, on each floor - six switches instead of two -, or you pull cables from one end of the building to the other. The VLAN is the third answer: the same physical switch behaves as several independent switches, and membership is decided in the configuration, not in the cabling.

VLAN
A virtual local area network. Every port of the switch is assigned to a VLAN, and the switch refuses to switch frames between different VLANs. Two computers in neighbouring ports, but in different VLANs, are as isolated as if they were in different buildings.
access port
A port that belongs to a single VLAN and on which untagged - ordinary - frames travel. This is where computers are attached, which neither know nor need to know anything about VLANs.
trunk port
A port that carries frames from several VLANs at once, on the same cable. So that they do not get mixed up, every frame receives a 4-byte tag with the number of the VLAN - the 802.1Q standard. This is where switches are attached to one another, and the switch to the router.
native VLAN
The only VLAN that travels untagged on a trunk. It exists for historical reasons, it is a classic source of attacks, and for that reason an empty VLAN, containing no host at all, is deliberately chosen.
What we do today, in three sentences We divide a switch into three VLANs and prove that the isolation works. We join the switches with trunks and prove that the same VLAN is heard across two switches, while different VLANs still are not. At the end we put a router above them, so that the departments can talk to one another - but only through it, where we can control what passes.

2Equipment needed

QtyEquipmentModelPacket Tracer categoryWhat it is for here
3Switch2960Network Devices → SwitchesSW-A (floor 1), SW-B (floor 2), SW-CORE
1Router4331Network Devices → Routersrouting between the VLANs
6ComputerPC-PTEnd Devices → End DevicesPC1 … PC6, two for each department
6Straight cableCopper Straight-ThroughConnectionshosts → switches, switch → router
2Crossover cableCopper Cross-OverConnectionsSW-A ↔ SW-CORE, SW-B ↔ SW-CORE

For the optional section with a layer 3 switch you also need a 3560 switch (from Network Devices → Switches as well), which replaces SW-CORE. For the Spanning Tree section, a third crossover cable, between SW-A and SW-B.

The cable rule, briefly Switch ↔ switch means cross-over. Switch ↔ router and host ↔ switch mean straight-through. In the workbench in this page the cables are already correctly in place; in Packet Tracer you choose them yourselves.

3The topology and the plan

R1G0/0/0 · 3 subinterfaces 802.1Q trunk SW-CORE2960 · G0/1 to R1 trunktrunk SW-Afloor 1 SW-Bfloor 2 PC1 PC2 PC3 PC4 PC5 PC6 VLAN 10 VLAN 20 VLAN 30
Fig. 1 - Three departments spread over two floors. Each floor has a switch, but the departments do not coincide with the floors - exactly the situation for which VLANs were invented.
VLANNameNetworkGatewayHosts
10ADMIN192.168.10.0/24192.168.10.1PC1 (.11), PC4 (.14)
20PRODUCTIE192.168.20.0/24192.168.20.1PC2 (.12), PC5 (.15)
30OASPETI192.168.30.0/24192.168.30.1PC3 (.13), PC6 (.16)
99NATIV--none - the native VLAN, deliberately empty
999NEFOLOSIT--the unused ports
SwitchAccess portsTrunk ports
SW-AFa0/1 → VLAN 10, Fa0/2 → VLAN 20, Fa0/3 → VLAN 30G0/1 to SW-CORE
SW-BFa0/1 → VLAN 10, Fa0/2 → VLAN 20, Fa0/3 → VLAN 30G0/1 to SW-CORE
SW-COREnoneG0/1 to R1, G0/2 to SW-A, G0/3 to SW-B
Notice a useful symmetry SW-A and SW-B have exactly the same configuration. You will type them identically, which means you can copy it - and, in practice, this is precisely how the work is done: it is written once, checked, then applied to the rest.

4The workbench

The topology of figure 1, cabled, with the addresses of the hosts already in place. The rest you configure yourselves, following the steps of sections 5-7. The objectives on the right tick themselves off.

5Step 1: creating the VLANs

  1. Check the starting point

    Before any configuration, issue a ping from PC1 towards PC4:

    on PC1
    ping 192.168.10.14
    

    It works. All six hosts are, for the moment, in a single layer 2 network - VLAN 1, the default one. Remember the result: in five minutes it will no longer work, and that is the point.

  2. Create the VLANs - on all three switches
    identical on SW-A, SW-B and SW-CORE
    Switch> enable
    Switch# configure terminal
    Switch(config)# vlan 10
    Switch(config-vlan)# name ADMIN
    Switch(config-vlan)# vlan 20
    Switch(config-vlan)# name PRODUCTIE
    Switch(config-vlan)# vlan 30
    Switch(config-vlan)# name OASPETI
    Switch(config-vlan)# vlan 99
    Switch(config-vlan)# name NATIV
    Switch(config-vlan)# vlan 999
    Switch(config-vlan)# name NEFOLOSIT
    Switch(config-vlan)# exit
    

    There is no need to leave config-vlan mode in between: the command vlan 20 works directly from inside VLAN 10.

    SW-CORE included, although it has no host A switch cannot switch the traffic of a VLAN it does not have configured locally, even if it merely transits it. A VLAN missing on an intermediate switch is the number one cause of trouble in this exercise - and one of the most frequent in real networks.
  3. Assign the access ports
    on SW-A - identical on SW-B
    SW-A(config)# interface fastEthernet 0/1
    SW-A(config-if)# switchport mode access
    SW-A(config-if)# switchport access vlan 10
    SW-A(config-if)# switchport nonegotiate
    SW-A(config-if)# spanning-tree portfast
    SW-A(config-if)# exit
    
    SW-A(config)# interface fastEthernet 0/2
    SW-A(config-if)# switchport mode access
    SW-A(config-if)# switchport access vlan 20
    SW-A(config-if)# switchport nonegotiate
    SW-A(config-if)# exit
    
    SW-A(config)# interface fastEthernet 0/3
    SW-A(config-if)# switchport mode access
    SW-A(config-if)# switchport access vlan 30
    SW-A(config-if)# switchport nonegotiate
    SW-A(config-if)# end
    

    What each line does:

    CommandIts effect
    switchport mode accessdeclares the port a user port, not a link between switches
    switchport access vlan 10moves it into VLAN 10
    switchport nonegotiateturns off DTP, so the port cannot be tricked into becoming a trunk (the switch spoofing attack of lecture 12)
    spanning-tree portfastthe port comes into service at once, without the 30 seconds of STP waiting
  4. Verify the isolation - this is where the result shows
    on SW-A
    SW-A# show vlan brief
    

    You must see exactly this:

    what should appear
    VLAN Name                             Status    Ports
    ---- -------------------------------- --------- ------------------------------
    1    default                          active    G0/1, G0/2
    10   ADMIN                            active    Fa0/1
    20   PRODUCTIE                        active    Fa0/2
    30   OASPETI                          active    Fa0/3
    99   NATIV                            active
    999  NEFOLOSIT                        active
    

    Now test, from PC1:

    on PC1
    ping 192.168.20.12
    ping 192.168.10.14
    

    Both must fail. The first, because PC2 is in another VLAN. The second, because PC4 is on another switch and the trunk does not exist yet. The failure is the proof that you configured correctly.

    Question

    PC1 and PC2 are attached to the same physical switch, at two neighbouring ports. Why do they not hear each other?

    See the answer

    Because the switch refuses to switch between ports in different VLANs. Even if it had the MAC address of PC2 in its table, it would not use it: the MAC table is indexed by VLAN as well. The two hosts are in distinct broadcast domains, and from the point of view of layer 2 it is as though they were attached to entirely separate switches.

    In addition, they also have addresses from different IP networks, so they would not even attempt a direct ARP - they would send the frame towards the gateway, which does not yet exist.

6Step 2: the trunk links

  1. Configure the trunks

    Three switches, four link ports. All of them receive the same configuration:

    on SW-A, the port towards SW-CORE
    SW-A(config)# interface gigabitEthernet 0/1
    SW-A(config-if)# switchport mode trunk
    SW-A(config-if)# switchport trunk native vlan 99
    SW-A(config-if)# switchport trunk allowed vlan 10,20,30,99
    SW-A(config-if)# switchport nonegotiate
    SW-A(config-if)# end
    

    Repeat identically on:

    • SW-B, port G0/1
    • SW-CORE, port G0/2 (towards SW-A)
    • SW-CORE, port G0/3 (towards SW-B)
    • SW-CORE, port G0/1 (towards R1) - yes, this one too: the router receives tagged frames
    The two disciplined settings switchport trunk allowed vlan: left at its default, a trunk link carries all 4094 possible VLANs. By declaring the list explicitly you reduce useless traffic and limit what an attacker can inject.
    switchport trunk native vlan 99: the native VLAN must be an empty one. If it stayed VLAN 1, a host in VLAN 1 could carry out the double tagging attack of lecture 12.
  2. Verify
    on SW-A
    SW-A# show interfaces trunk
    
    what should appear
    Port        Mode         Encapsulation  Status        Native vlan
    G0/1        on           802.1q         trunking      99
    
    Port        Vlans allowed on trunk
    G0/1        10,20,30,99
    

    If Status shows not-trunking, the port has no active link: check the cable or the far end. If Native vlan differs between the two ends of the same link, IOS displays a warning in the console - do not ignore it, it is exactly the vulnerability you are trying to close.

  3. Test the isolation again
    on PC1
    ping 192.168.10.14
    ping 192.168.20.15
    
    TestExpected resultWhy
    PC1 → PC4worksthe same VLAN 10, although on different switches: the frame crossed the trunk, tagged
    PC1 → PC5failsthe trunk carries both VLANs, but does not mix them

    This is the central idea of the exercise, in a single sentence: a trunk carries several VLANs without joining them.

  4. Look at the 802.1Q tag

    In the workbench in this page: issue ping 192.168.10.14 from PC1 and look at the Path of the last packet table. The column absent on the access port and present on the trunk is the tag itself - the segments between switches carry VLAN 10, those towards the hosts carry nothing.

    In Packet Tracer: in Simulation, filtered on ICMP and ARP, click the envelope on the trunk link and open Outbound PDU Details. You will see, in the structure of the Ethernet frame, an additional 4-byte field, with TPID 0x8100 and VLAN ID 10. Compare with the same frame on an access port: there the tag does not exist. This is, literally, the whole difference between an access port and a trunk port.

7Step 3: router-on-a-stick

The three VLANs are now three completely separate networks. The ADMIN department must nonetheless reach the resources in PRODUCTIE. We need a layer 3 device - but the router has a single free interface, and we have three networks.

The solution: subinterfaces. The same physical interface is divided logically into three, each with its own address and its own VLAN tag.

  1. Configure the subinterfaces on R1
    on R1
    Router> enable
    Router# configure terminal
    Router(config)# hostname R1
    
    R1(config)# interface gigabitEthernet 0/0/0
    R1(config-if)# no ip address
    R1(config-if)# no shutdown
    R1(config-if)# exit
    
    R1(config)# interface gigabitEthernet 0/0/0.10
    R1(config-subif)# description Gateway VLAN 10 ADMIN
    R1(config-subif)# encapsulation dot1Q 10
    R1(config-subif)# ip address 192.168.10.1 255.255.255.0
    R1(config-subif)# exit
    
    R1(config)# interface gigabitEthernet 0/0/0.20
    R1(config-subif)# encapsulation dot1Q 20
    R1(config-subif)# ip address 192.168.20.1 255.255.255.0
    R1(config-subif)# exit
    
    R1(config)# interface gigabitEthernet 0/0/0.30
    R1(config-subif)# encapsulation dot1Q 30
    R1(config-subif)# ip address 192.168.30.1 255.255.255.0
    R1(config-subif)# exit
    
    R1(config)# interface gigabitEthernet 0/0/0.99
    R1(config-subif)# encapsulation dot1Q 99 native
    R1(config-subif)# end
    
    R1# copy running-config startup-config
    
    Three mistakes that are made every single time 1. no shutdown is issued on the physical interface. If it stays shut down, every subinterface is dead, however correctly configured. Try it: issue shutdown on G0/0/0 and watch all the objectives go out at once.
    2. The physical interface receives no IP address - the addresses sit on the subinterfaces.
    3. The number of the subinterface (.10) has no meaning whatsoever for the device; what matters is encapsulation dot1Q 10. Use the same number all the same - it will save you an hour of troubleshooting six months from now.
  2. Verify the complete routing
    on R1
    R1# show ip interface brief
    R1# show ip route
    

    Exactly three connected routes must appear in the routing table, marked C, one for each VLAN. If only two appear, one of the subinterfaces has no address or has the wrong tag.

    on PC1
    ping 192.168.10.1
    ping 192.168.20.12
    ping 192.168.30.13
    tracert 192.168.30.16
    

    tracert will show exactly one intermediate hop: the gateway. Traffic between two VLANs goes up to the router and comes back down on the same wire - hence the name "router on a stick".

  3. Measure the bottleneck

    All the traffic between all the VLANs passes twice down the same G0/0/0 cable: once up, once down. In a real network, this is the limit of the architecture - and the reason why the following section exists.

    In Packet Tracer, run massive pings simultaneously from PC1 and PC4 (ping -n 200 -l 1400) towards hosts in another VLAN and compare the times with those obtained when you run alone.

8The modern variant: a layer 3 switch

Replace SW-CORE with a 3560 switch and remove the router entirely. The routing is now done in hardware, on the backplane of the switch, with no cable involved at all. In the workbench in this page, the same demonstration is made by enabling routing on SW-CORE itself.

on SW-CORE
SW-CORE(config)# ip routing

SW-CORE(config)# interface vlan 10
SW-CORE(config-if)# ip address 192.168.10.1 255.255.255.0
SW-CORE(config-if)# no shutdown
SW-CORE(config-if)# exit

SW-CORE(config)# interface vlan 20
SW-CORE(config-if)# ip address 192.168.20.1 255.255.255.0
SW-CORE(config-if)# no shutdown
SW-CORE(config-if)# exit

SW-CORE(config)# interface vlan 30
SW-CORE(config-if)# ip address 192.168.30.1 255.255.255.0
SW-CORE(config-if)# no shutdown
SW-CORE(config-if)# end

SW-CORE# show ip route
Do not do both at once If you leave both the router and the SVIs configured, the three gateways will exist in two places - duplicate IP addresses. In the workbench in this page, first take out the cable of R1 from the Cables panel, or issue shutdown on its physical interface.
Router-on-a-stick
  • Works with any router, even an old one
  • The router can also do NAT, VPN, complex ACLs
  • Simple configuration, easy to explain
Layer 3 switch with SVIs
  • Routing in hardware, no bottleneck
  • Consumes no cable and no port
  • More expensive equipment; more limited security features than a router

Test the same pings as before. The functional result is identical, but the traffic never leaves the switch any more - check with tracert, where the intermediate hop remains a single one, but is the switch itself.

9Spanning Tree, observed

Add a direct link between SW-A and SW-B, configured as a trunk as well. In the workbench in this page: pick SW-A, from the Cables panel press connect on port G0/2 and choose SW-B : G0/2. You have created a physical loop between the three switches - exactly the situation of lecture 4.

observing the tree
SW-A# show spanning-tree
SW-CORE# show spanning-tree
  1. Identify which switch has become the root bridge - it appears with the note This bridge is the root. With no configuration at all, the smallest MAC address decides, therefore as a rule the oldest device in the network. Rarely the one you would have chosen.
  2. Find the port in the BLK state, with the role Altn. That is the cable that STP has taken out of service in order to break the loop. The link exists physically, but carries nothing.
  3. Check that the ping between PC1 and PC4 still works: the loop was neutralized without any loss of connectivity.
  4. Force the root onto the switch in the centre, where it suits you to have it:
the root, set explicitly
SW-CORE(config)# spanning-tree vlan 10,20,30,99 root primary
SW-A(config)# spanning-tree vlan 10,20,30,99 root secondary

Run show spanning-tree on SW-CORE again: it is now the root, and the blocked port has moved. The command root primary does nothing magical - it sets the priority to 24576, a value smaller than the default (32768), and the smaller priority wins the election.

Experiment, in Packet Tracer

Disconnect the cable between SW-CORE and SW-A. Time how long it takes until the ping between PC1 and PC4 starts working again, through the backup link.

What you should observe

About 30–50 seconds with classic STP: max age (20 s) plus the transitions through listening and learning (2 × 15 s). Then enable the rapid mode and repeat the measurement:

on every switch
Switch(config)# spanning-tree mode rapid-pvst

Convergence drops to a few seconds. This is exactly why no modern network runs classic 802.1D any more.

10Four faults to diagnose

Provoke them one at a time, in the workbench. Each time note which command showed you the problem - that is what stays useful after the laboratory.

FaultHow you produce itSymptomThe command that reveals it
VLAN missing on the transit switchon SW-CORE: no vlan 20VLAN 10 and 30 work across the trunk, VLAN 20 does notshow vlan brief on SW-CORE
VLAN removed from the allowed liston SW-A G0/1: switchport trunk allowed vlan 10,30,99PC2 no longer reaches anywhere outside the switchshow interfaces trunk
Port left in VLAN 1on SW-B: no switchport access vlan 10 on Fa0/1PC4 disappears from its network, but the cable is greenshow vlan brief on SW-B
Wrong tag on a subinterfaceon R1: encapsulation dot1Q 25 instead of 20VLAN 20 has no gateway; the others workshow running-config on R1
The common pattern All four faults produce the same general symptom - "one VLAN does not work, the others do" - and none of them shows in the state of the cables. When you hear this symptom, the order of checking is always the same: does the VLAN exist on every switch along the way? Is the access port in the right VLAN? Is the VLAN allowed on each trunk? Does the subinterface of the router have the right tag?

11Assignments

  • Build the topology and configure the five VLANs on all the switches
  • Demonstrate the isolation between VLANs before configuring the router
  • Configure the trunks with native VLAN 99 and an explicit list of allowed VLANs
  • Capture and document an 802.1Q tag from Simulation mode
  • Configure router-on-a-stick and demonstrate complete connectivity between all three VLANs
  • Achieve the same function with a 3560 switch and SVIs; compare the path of the packet in the two variants
  • Add the loop, observe STP and force the root onto SW-CORE
  • Provoke the four faults of section 10 and note, for each, the diagnostic command

12Going further

The guests are not allowed inside

VLAN 30 is for visitors. The company policy requires: visitors have access to the Internet, but to no internal resource. In this laboratory you do not have the Internet yet, so simulate it with a server placed in a VLAN 40, 192.168.40.0/24.

Requirements:

  1. PC3 and PC6 (VLAN 30) must reach the server in VLAN 40
  2. PC3 and PC6 must not reach any host in VLAN 10 or 20
  3. The hosts in VLAN 10 and 20 must reach everywhere, including the hosts in VLAN 30

Point 3 is the interesting part: traffic from ADMIN towards OASPETI must pass, but the reverse must not. Think about what kind of access list you need and in which direction it is applied. State the exact rule in words and justify where you place it - the configuration itself you will do in laboratory 6.

See the hint

A standard list is not enough: it filters by source only, and the source is the same (VLAN 30) both in the permitted traffic (towards VLAN 40) and in the forbidden traffic (towards VLAN 10 and 20). You need an extended list, which can see the destination as well.

The rule would read: "deny IP traffic with the source in 192.168.30.0/24 and the destination in 192.168.10.0/24 or 192.168.20.0/24; permit the rest". The correct placement is on the G0/0/0.30 subinterface, direction in - that is, as close as possible to the source, so that the forbidden traffic does not even reach the router.

Point 3 works automatically with this placement: traffic from ADMIN towards OASPETI comes in on G0/0/0.10, where the list is not applied, so it is not filtered.

13Self-check questions

14Deliverables

DeliverableFormatWeight
The Packet Tracer file with working VLANs, trunks and inter-VLAN routing.pkt35 %
The capture of the 802.1Q tag, with commentarydocument15 %
The four faults, with symptom and diagnostic commanddocument20 %
The comparison router-on-a-stick / layer 3 switch, with the path of the packet in bothdocument15 %
Going further: the rule stated in words, with the placement justifieddocument15 %