The office has two departments on the same switch: Sales and HR. Today everything is in VLAN 1 and anyone can see the other's broadcast traffic.
Create VLAN 10 (VENTAS) and VLAN 20 (RRHH). Put ports Fa0/1 to Fa0/10 in access mode on VLAN 10 and Fa0/11 to Fa0/20 on VLAN 20. Ports Fa0/21 to Fa0/24 are unused: shut them down.
Use interface range instead of going port by port and verify the result with show vlan brief.
Topology
Devices and cabling
SW1·2960-24TT
PC1, PC2, PC3, PC4·PC-PT
From
To
Cable
PC1Fa0
SW1Fa0/1
Straight-through
PC2Fa0
SW1Fa0/2
Straight-through
PC3Fa0
SW1Fa0/11
Straight-through
PC4Fa0
SW1Fa0/12
Straight-through
If in doubt, the automatic connection cable (the lightning bolt) picks the right one. Rule: straight-through between different devices (PC or router to switch) and crossover between alike ones.
Addressing
Device
Interface
Address
Mask
Default gateway
PC1
Fa0/1 · VLAN 10
192.168.10.11
255.255.255.0
—
PC2
Fa0/2 · VLAN 10
192.168.10.12
255.255.255.0
—
PC3
Fa0/11 · VLAN 20
192.168.20.11
255.255.255.0
—
PC4
Fa0/12 · VLAN 20
192.168.20.12
255.255.255.0
—
Starting configuration
In the app this is already done. In Packet Tracer, before you start, enter each device with enable and configure terminal and type (or paste) these lines.
SW1hostname SW1
no ip domain-lookup
PCs and servers (Desktop › IP Configuration)
PC1: IP 192.168.10.11, mask 255.255.255.0
PC2: IP 192.168.10.12, mask 255.255.255.0
PC3: IP 192.168.20.11, mask 255.255.255.0
PC4: IP 192.168.20.12, mask 255.255.255.0
Tasks
What must end up working. In the app, each one ticks itself off as soon as you get it.
VLAN 10 named VENTAS
VLAN 20 named RRHH
Fa0/1–Fa0/10: access on VLAN 10
Fa0/11–Fa0/20: access on VLAN 20
Fa0/21–Fa0/24 shut down
Each pair of PCs talks inside its VLAN
Checked with show vlan brief
In Packet Tracer
Use straight-through cables from each PC to the switch. On a 2960, ports come up enabled and in VLAN 1.
Hints
VLAN 10 named VENTAS: vlan 10 → name VENTAS
VLAN 20 named RRHH: vlan 20 → name RRHH
Fa0/1–Fa0/10: access on VLAN 10: interface range fa0/1 - 10 → switchport mode access → switchport access vlan 10
Fa0/11–Fa0/20: access on VLAN 20: interface range fa0/11 - 20 → switchport mode access → switchport access vlan 20
Fa0/21–Fa0/24 shut down: interface range fa0/21 - 24 → shutdown. An unused port that's shut is one less way in.
Each pair of PCs talks inside its VLAN: PC1–PC2 on VLAN 10 and PC3–PC4 on VLAN 20. Try it with ping from PC1 and PC3.
Checked with show vlan brief: show vlan brief
Step-by-step solution
Try it on your own first: you learn much more by typing the commands yourself.
Show the solution
1Create and name the VLANs SW1
vlan 10 creates the VLAN and enters its mode; name sets its name. Typing vlan 20 from inside VLAN 10 jumps to the new one.
SW1enable
configure terminal
vlan 10
name VENTAS
vlan 20
name RRHH
exit
2Assign the Sales ports SW1
interface range configures several ports at once. switchport mode access pins the port as an access port so it doesn't negotiate a trunk.
PC1 reaches PC2 because they share a VLAN and a network. Between different VLANs you'd need a router or a layer 3 switch.
PC1C:\>ping 192.168.10.12
Pinging 192.168.10.12 with 32 bytes of data:
Reply from 192.168.10.12: bytes=32 time<1ms TTL=128
Reply from 192.168.10.12: bytes=32 time<1ms TTL=128
Reply from 192.168.10.12: bytes=32 time<1ms TTL=128
Reply from 192.168.10.12: bytes=32 time<1ms TTL=128
Ping statistics for 192.168.10.12:
Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 0ms, Maximum = 0ms, Average = 0ms
Common mistakes
Assigning the port to a VLAN that doesn't exist: IOS creates it with a warning ("% Access VLAN does not exist. Creating vlan 30"), but with the default name.
Leaving ports in dynamic mode: if someone plugs in a switch, a trunk could form.
Practice this lab on your phone
RoutingLab has this lab with a simulated IOS terminal: abbreviations, ? help, the same error messages and objectives that check themselves. The first two labs are free.