Sales (VLAN 10) and HR (VLAN 20) have people on two switches joined by G0/1. The VLANs and access ports are done, but the link between the switches is in access mode and only carries VLAN 1: PC1 can't reach PC2 even though they're in the same VLAN.
Turn G0/1 into a static trunk on both switches. For security, create VLAN 99 (NATIVA) and use it as the native VLAN, and allow only VLANs 10, 20 and 99. Verify with show interfaces trunk.
Topology
Devices and cabling
SW1, SW2·2960-24TT
PC1, PC2, PC3, PC4·PC-PT
From
To
Cable
SW1Gi0/1
SW2Gi0/1
Crossover
PC1Fa0
SW1Fa0/1
Straight-through
PC3Fa0
SW1Fa0/2
Straight-through
PC2Fa0
SW2Fa0/1
Straight-through
PC4Fa0
SW2Fa0/2
Straight-through
If in doubt, the automatic connection cable (the lightning bolt) picks the right one. Rule: straight-through between different devices (PC or router to switch) and crossover between alike ones.
Addressing
Device
Interface
Address
Mask
Default gateway
PC1
SW1 Fa0/1 · VLAN 10
192.168.10.11
255.255.255.0
—
PC2
SW2 Fa0/1 · VLAN 10
192.168.10.12
255.255.255.0
—
PC3
SW1 Fa0/2 · VLAN 20
192.168.20.11
255.255.255.0
—
PC4
SW2 Fa0/2 · VLAN 20
192.168.20.12
255.255.255.0
—
Starting configuration
In the app this is already done. In Packet Tracer, before you start, enter each device with enable and configure terminal and type (or paste) these lines.
SW1hostname SW1
no ip domain-lookup
vlan 10
name VENTAS
vlan 20
name RRHH
interface fa0/1
switchport mode access
switchport access vlan 10
interface fa0/2
switchport mode access
switchport access vlan 20
SW2hostname SW2
no ip domain-lookup
vlan 10
name VENTAS
vlan 20
name RRHH
interface fa0/1
switchport mode access
switchport access vlan 10
interface fa0/2
switchport mode access
switchport access vlan 20
PCs and servers (Desktop › IP Configuration)
PC1: IP 192.168.10.11, mask 255.255.255.0
PC2: IP 192.168.10.12, mask 255.255.255.0
PC3: IP 192.168.20.11, mask 255.255.255.0
PC4: IP 192.168.20.12, mask 255.255.255.0
Tasks
What must end up working. In the app, each one ticks itself off as soon as you get it.
VLAN 99 NATIVA created on SW1 and SW2
SW1 G0/1 as a static trunk
SW2 G0/1 as a static trunk
Native VLAN 99 on both ends
Only VLANs 10, 20 and 99 allowed
PC1 reaches PC2 and PC3 reaches PC4 over the trunk
Checked with show interfaces trunk
In Packet Tracer
Join both switches on G0/1 with a crossover cable (or the automatic one). The PCs use straight-through cables.
The starting configuration (VLANs 10 and 20 and the access ports) must be done on both switches.
Hints
VLAN 99 NATIVA created on SW1 and SW2: On each switch: vlan 99 → name NATIVA
SW1 G0/1 as a static trunk: interface g0/1 → switchport mode trunk
SW2 G0/1 as a static trunk: Don't rely on DTP negotiation: configure SW2 too
Native VLAN 99 on both ends: switchport trunk native vlan 99 on SW1 and SW2. If they don't match, CDP reports a native VLAN mismatch.
Only VLANs 10, 20 and 99 allowed: switchport trunk allowed vlan 10,20,99 on both switches
PC1 reaches PC2 and PC3 reaches PC4 over the trunk: From PC1: ping 192.168.10.12. From PC3: ping 192.168.20.12
Checked with show interfaces trunk: show interfaces trunk
Step-by-step solution
Try it on your own first: you learn much more by typing the commands yourself.
Show the solution
1Create the native VLAN SW1
The native VLAN travels untagged across the trunk. Using a dedicated VLAN with no devices (instead of VLAN 1) prevents double-tagging attacks.
SW1enable
configure terminal
vlan 99
name NATIVA
exit
2Configure the trunk SW1
Static trunk, native 99 and only the VLANs you need.
Mode "on" means a static trunk, Native vlan 99 and the allowed list 10,20,99. Check the same on SW2.
SW1SW1#show interfaces trunk
Port Mode Encapsulation Status Native vlan
Gi0/1 on 802.1q trunking 99
Port Vlans allowed on trunk
Gi0/1 10,20,99
Port Vlans allowed and active in management domain
Gi0/1 10,20,99
Port Vlans in spanning tree forwarding state and not pruned
Gi0/1 10,20,99
PC1 and PC2 are on different switches: if the ping replies, VLAN 10 is crossing the trunk.
PC1C:\>ping 192.168.10.12
Pinging 192.168.10.12 with 32 bytes of data:
Reply from 192.168.10.12: bytes=32 time<1ms TTL=128
Reply from 192.168.10.12: bytes=32 time<1ms TTL=128
Reply from 192.168.10.12: bytes=32 time<1ms TTL=128
Reply from 192.168.10.12: bytes=32 time<1ms TTL=128
Ping statistics for 192.168.10.12:
Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 0ms, Maximum = 0ms, Average = 0ms
Common mistakes
A different native VLAN on each end: untagged traffic ends up in another VLAN and CDP reports a native VLAN mismatch.
Forgetting to create VLAN 99: the trunk allows it, but the switch doesn't have it.
Practice this lab on your phone
RoutingLab has this lab with a simulated IOS terminal: abbreviations, ? help, the same error messages and objectives that check themselves. The first two labs are free.