← All labs Lab 4 · Packet Tracer

802.1Q trunks

Static trunk, native VLAN and allowed VLANs

Level: Intermediate Time: 25 min Domain 2.0 Network Access

Scenario

Sales (VLAN 10) and HR (VLAN 20) have people on two switches joined by G0/1. The VLANs and access ports are done, but the link between the switches is in access mode and only carries VLAN 1: PC1 can't reach PC2 even though they're in the same VLAN.

Turn G0/1 into a static trunk on both switches. For security, create VLAN 99 (NATIVA) and use it as the native VLAN, and allow only VLANs 10, 20 and 99. Verify with show interfaces trunk.

Topology

SW1SW2PC1PC3PC2PC4Gi0/1Gi0/1Fa0Fa0/1Fa0Fa0/2Fa0Fa0/1Fa0Fa0/2

Devices and cabling

FromToCable
SW1 Gi0/1SW2 Gi0/1Crossover
PC1 Fa0SW1 Fa0/1Straight-through
PC3 Fa0SW1 Fa0/2Straight-through
PC2 Fa0SW2 Fa0/1Straight-through
PC4 Fa0SW2 Fa0/2Straight-through

If in doubt, the automatic connection cable (the lightning bolt) picks the right one. Rule: straight-through between different devices (PC or router to switch) and crossover between alike ones.

Addressing

DeviceInterfaceAddressMaskDefault gateway
PC1SW1 Fa0/1 · VLAN 10192.168.10.11255.255.255.0—
PC2SW2 Fa0/1 · VLAN 10192.168.10.12255.255.255.0—
PC3SW1 Fa0/2 · VLAN 20192.168.20.11255.255.255.0—
PC4SW2 Fa0/2 · VLAN 20192.168.20.12255.255.255.0—

Starting configuration

In the app this is already done. In Packet Tracer, before you start, enter each device with enable and configure terminal and type (or paste) these lines.

SW1hostname SW1 no ip domain-lookup vlan 10 name VENTAS vlan 20 name RRHH interface fa0/1 switchport mode access switchport access vlan 10 interface fa0/2 switchport mode access switchport access vlan 20
SW2hostname SW2 no ip domain-lookup vlan 10 name VENTAS vlan 20 name RRHH interface fa0/1 switchport mode access switchport access vlan 10 interface fa0/2 switchport mode access switchport access vlan 20

PCs and servers (Desktop › IP Configuration)

Tasks

What must end up working. In the app, each one ticks itself off as soon as you get it.

  1. VLAN 99 NATIVA created on SW1 and SW2
  2. SW1 G0/1 as a static trunk
  3. SW2 G0/1 as a static trunk
  4. Native VLAN 99 on both ends
  5. Only VLANs 10, 20 and 99 allowed
  6. PC1 reaches PC2 and PC3 reaches PC4 over the trunk
  7. Checked with show interfaces trunk
In Packet Tracer
  • Join both switches on G0/1 with a crossover cable (or the automatic one). The PCs use straight-through cables.
  • The starting configuration (VLANs 10 and 20 and the access ports) must be done on both switches.
Hints
  • VLAN 99 NATIVA created on SW1 and SW2: On each switch: vlan 99 → name NATIVA
  • SW1 G0/1 as a static trunk: interface g0/1 → switchport mode trunk
  • SW2 G0/1 as a static trunk: Don't rely on DTP negotiation: configure SW2 too
  • Native VLAN 99 on both ends: switchport trunk native vlan 99 on SW1 and SW2. If they don't match, CDP reports a native VLAN mismatch.
  • Only VLANs 10, 20 and 99 allowed: switchport trunk allowed vlan 10,20,99 on both switches
  • PC1 reaches PC2 and PC3 reaches PC4 over the trunk: From PC1: ping 192.168.10.12. From PC3: ping 192.168.20.12
  • Checked with show interfaces trunk: show interfaces trunk

Step-by-step solution

Try it on your own first: you learn much more by typing the commands yourself.

Show the solution

1Create the native VLAN SW1

The native VLAN travels untagged across the trunk. Using a dedicated VLAN with no devices (instead of VLAN 1) prevents double-tagging attacks.

SW1enable configure terminal vlan 99 name NATIVA exit

2Configure the trunk SW1

Static trunk, native 99 and only the VLANs you need.

SW1interface g0/1 switchport mode trunk switchport trunk native vlan 99 switchport trunk allowed vlan 10,20,99 end

3Repeat the same on SW2 SW2

With SW1 on trunk, SW2 would negotiate the trunk through DTP, but the native and allowed VLANs must match on both ends.

SW2enable configure terminal vlan 99 name NATIVA exit interface g0/1 switchport mode trunk switchport trunk native vlan 99 switchport trunk allowed vlan 10,20,99 end

Verification

Mode "on" means a static trunk, Native vlan 99 and the allowed list 10,20,99. Check the same on SW2.

SW1SW1#show interfaces trunk Port Mode Encapsulation Status Native vlan Gi0/1 on 802.1q trunking 99 Port Vlans allowed on trunk Gi0/1 10,20,99 Port Vlans allowed and active in management domain Gi0/1 10,20,99 Port Vlans in spanning tree forwarding state and not pruned Gi0/1 10,20,99

PC1 and PC2 are on different switches: if the ping replies, VLAN 10 is crossing the trunk.

PC1C:\>ping 192.168.10.12 Pinging 192.168.10.12 with 32 bytes of data: Reply from 192.168.10.12: bytes=32 time<1ms TTL=128 Reply from 192.168.10.12: bytes=32 time<1ms TTL=128 Reply from 192.168.10.12: bytes=32 time<1ms TTL=128 Reply from 192.168.10.12: bytes=32 time<1ms TTL=128 Ping statistics for 192.168.10.12: Packets: Sent = 4, Received = 4, Lost = 0 (0% loss), Approximate round trip times in milli-seconds: Minimum = 0ms, Maximum = 0ms, Average = 0ms

Common mistakes

Practice this lab on your phone

RoutingLab has this lab with a simulated IOS terminal: abbreviations, ? help, the same error messages and objectives that check themselves. The first two labs are free.

Get RoutingLab