← All labs Lab 3 · Packet Tracer

VLANs and access ports

Create and name VLANs and assign ports with interface range

Level: Beginner Time: 25 min Domain 2.0 Network Access

Scenario

The office has two departments on the same switch: Sales and HR. Today everything is in VLAN 1 and anyone can see the other's broadcast traffic.

Create VLAN 10 (VENTAS) and VLAN 20 (RRHH). Put ports Fa0/1 to Fa0/10 in access mode on VLAN 10 and Fa0/11 to Fa0/20 on VLAN 20. Ports Fa0/21 to Fa0/24 are unused: shut them down.

Use interface range instead of going port by port and verify the result with show vlan brief.

Topology

SW1PC1PC2PC3PC4Fa0Fa0/1Fa0Fa0/2Fa0Fa0/11Fa0Fa0/12

Devices and cabling

FromToCable
PC1 Fa0SW1 Fa0/1Straight-through
PC2 Fa0SW1 Fa0/2Straight-through
PC3 Fa0SW1 Fa0/11Straight-through
PC4 Fa0SW1 Fa0/12Straight-through

If in doubt, the automatic connection cable (the lightning bolt) picks the right one. Rule: straight-through between different devices (PC or router to switch) and crossover between alike ones.

Addressing

DeviceInterfaceAddressMaskDefault gateway
PC1Fa0/1 · VLAN 10192.168.10.11255.255.255.0—
PC2Fa0/2 · VLAN 10192.168.10.12255.255.255.0—
PC3Fa0/11 · VLAN 20192.168.20.11255.255.255.0—
PC4Fa0/12 · VLAN 20192.168.20.12255.255.255.0—

Starting configuration

In the app this is already done. In Packet Tracer, before you start, enter each device with enable and configure terminal and type (or paste) these lines.

SW1hostname SW1 no ip domain-lookup

PCs and servers (Desktop › IP Configuration)

Tasks

What must end up working. In the app, each one ticks itself off as soon as you get it.

  1. VLAN 10 named VENTAS
  2. VLAN 20 named RRHH
  3. Fa0/1–Fa0/10: access on VLAN 10
  4. Fa0/11–Fa0/20: access on VLAN 20
  5. Fa0/21–Fa0/24 shut down
  6. Each pair of PCs talks inside its VLAN
  7. Checked with show vlan brief
In Packet Tracer
  • Use straight-through cables from each PC to the switch. On a 2960, ports come up enabled and in VLAN 1.
Hints
  • VLAN 10 named VENTAS: vlan 10 → name VENTAS
  • VLAN 20 named RRHH: vlan 20 → name RRHH
  • Fa0/1–Fa0/10: access on VLAN 10: interface range fa0/1 - 10 → switchport mode access → switchport access vlan 10
  • Fa0/11–Fa0/20: access on VLAN 20: interface range fa0/11 - 20 → switchport mode access → switchport access vlan 20
  • Fa0/21–Fa0/24 shut down: interface range fa0/21 - 24 → shutdown. An unused port that's shut is one less way in.
  • Each pair of PCs talks inside its VLAN: PC1–PC2 on VLAN 10 and PC3–PC4 on VLAN 20. Try it with ping from PC1 and PC3.
  • Checked with show vlan brief: show vlan brief

Step-by-step solution

Try it on your own first: you learn much more by typing the commands yourself.

Show the solution

1Create and name the VLANs SW1

vlan 10 creates the VLAN and enters its mode; name sets its name. Typing vlan 20 from inside VLAN 10 jumps to the new one.

SW1enable configure terminal vlan 10 name VENTAS vlan 20 name RRHH exit

2Assign the Sales ports SW1

interface range configures several ports at once. switchport mode access pins the port as an access port so it doesn't negotiate a trunk.

SW1interface range fa0/1 - 10 switchport mode access switchport access vlan 10

3Assign the HR ports SW1

SW1interface range fa0/11 - 20 switchport mode access switchport access vlan 20

4Shut down the unused ports SW1

A free port left on is an open door for anyone who plugs something in. Shutting them is a security best practice.

SW1interface range fa0/21 - 24 shutdown end

Verification

Each VLAN must list its ports. Ports that don't show up anywhere are either trunks or assigned to a VLAN that doesn't exist.

SW1SW1#show vlan brief VLAN Name Status Ports ---- -------------------------------- --------- ------------------------------- 1 default active Fa0/21, Fa0/22, Fa0/23, Fa0/24 Gi0/1, Gi0/2 10 VENTAS active Fa0/1, Fa0/2, Fa0/3, Fa0/4 Fa0/5, Fa0/6, Fa0/7, Fa0/8 Fa0/9, Fa0/10 20 RRHH active Fa0/11, Fa0/12, Fa0/13, Fa0/14 Fa0/15, Fa0/16, Fa0/17, Fa0/18 Fa0/19, Fa0/20 1002 fddi-default act/unsup 1003 token-ring-default act/unsup 1004 fddinet-default act/unsup 1005 trnet-default act/unsup

PC1 reaches PC2 because they share a VLAN and a network. Between different VLANs you'd need a router or a layer 3 switch.

PC1C:\>ping 192.168.10.12 Pinging 192.168.10.12 with 32 bytes of data: Reply from 192.168.10.12: bytes=32 time<1ms TTL=128 Reply from 192.168.10.12: bytes=32 time<1ms TTL=128 Reply from 192.168.10.12: bytes=32 time<1ms TTL=128 Reply from 192.168.10.12: bytes=32 time<1ms TTL=128 Ping statistics for 192.168.10.12: Packets: Sent = 4, Received = 4, Lost = 0 (0% loss), Approximate round trip times in milli-seconds: Minimum = 0ms, Maximum = 0ms, Average = 0ms

Common mistakes

Practice this lab on your phone

RoutingLab has this lab with a simulated IOS terminal: abbreviations, ? help, the same error messages and objectives that check themselves. The first two labs are free.

Get RoutingLab