CCNA VLANs and Trunking

VLANs turn one physical switch into many logical ones, and trunks carry those VLANs between switches — the exam tests both the concepts and the configuration gotchas. This guide to CCNA VLANs and trunking covers VLAN concepts and access ports, 802.1Q trunks and the native VLAN, and inter-VLAN routing. Pair it with our free CCNA mock test to lock it in.

VLAN Concepts and Access Ports

A VLAN (Virtual LAN) is a broadcast domain created in software on a switch — devices in different VLANs cannot talk to each other without a router, even though they share the same hardware. VLANs shrink broadcast domains, enforce separation (keeping guests off the staff network, for example), and let one switch serve many logical networks. VLAN IDs 1–4094 are usable; VLAN 1 is the default on every port, and 1002–1005 are reserved legacy ranges you should never use.

An access port belongs to exactly one VLAN and carries untagged frames to end devices — PCs, printers, phones. Configure it with switchport mode access followed by switchport access vlan 10. Create the VLAN itself with vlan 10 then name SALES. Verify with show vlan brief — if a port sits in the wrong VLAN, traffic lands in the wrong broadcast domain and "the network is down" for that user.

IP phones introduce the voice VLAN: one port carries two VLANs, with the PC's data untagged and the phone's traffic tagged. Configure with switchport voice vlan 20 alongside the access VLAN. The exam also expects you to know that unused ports should be shut down or parked in an unused VLAN — an open port in VLAN 1 is an invitation.

Key exam points

  • VLAN = broadcast domain in software. VLAN 1 is default; 1002–1005 reserved; usable range 1–4094.
  • Access ports carry one untagged VLAN to end devices: switchport mode access + switchport access vlan.
  • Voice VLAN lets a phone (tagged) share a port with a PC (untagged).
  • Verify with show vlan brief; park unused ports in a dead VLAN.

Trunks, 802.1Q and the Native VLAN

A trunk is a link between switches (or to a router) that carries traffic for multiple VLANs, tagging each frame with 802.1Q so the far end knows which VLAN it belongs to. The tag is a 4-byte header inserted into the Ethernet frame carrying the 12-bit VLAN ID. The one exception is the native VLAN: its frames cross the trunk untagged, exactly as if it were an access port. Native VLAN defaults to VLAN 1, and both ends of a trunk must agree on it — a native mismatch lets traffic leak between VLANs and logs angry console messages.

Configure a trunk with switchport mode trunk, set the native VLAN with switchport trunk native vlan 99, and prune with switchport trunk allowed vlan 10,20,30. Verify with show interfaces trunk and show interfaces switchport. Best practice: change the native VLAN to an unused VLAN (never VLAN 1, never a user VLAN) to defeat double-tagging VLAN hopping attacks.

DTP (Dynamic Trunking Protocol) negotiates trunking automatically: dynamic desirable actively tries to trunk, dynamic auto only trunks if the other side asks (auto + auto = access, no trunk), while trunk and access are statically set. Disable negotiation on inter-switch links with switchport nonegotiate — negotiated trunks are both a security risk and a source of exam troubleshooting questions.

Key exam points

  • Trunks carry multiple VLANs; 802.1Q tags each frame with a 12-bit VLAN ID.
  • Native VLAN crosses untagged (default VLAN 1); both ends must match — set it to an unused VLAN.
  • DTP: desirable tries, auto waits (auto+auto = access). Use switchport nonegotiate for security.
  • Verify with show interfaces trunk; prune with switchport trunk allowed vlan.

Inter-VLAN Routing

VLANs can't talk to each other at Layer 2 — routing between them needs a Layer 3 device. The classic method is router-on-a-stick: one router interface divided into subinterfaces, one per VLAN, each with 802.1Q encapsulation. The switch side is a trunk; the router routes between subnets as normal. Configuration looks like this:
interface g0/0.10
encapsulation dot1Q 10
ip address 192.168.10.1 255.255.255.0

The modern alternative is multilayer switching using SVIs (Switched Virtual Interfaces): interface vlan 10 with an IP address, plus ip routing enabled on the Layer 3 switch. It's faster (hardware-switched) and removes the single-trunk bottleneck of router-on-a-stick. The exam tests both — know that router-on-a-stick needs subinterfaces with encapsulation, while SVIs need no shutdown and at least one active port in the VLAN (or the SVI stays down).

Troubleshooting inter-VLAN routing follows a checklist: is the trunk up and allowing the VLAN? Does the subinterface/SVI have the right IP and encapsulation? Is the host's default gateway pointing at the router's address in its own VLAN? A host with the wrong gateway can reach its own subnet but nothing else — the single most common exam symptom.

Key exam points

  • Router-on-a-stick: subinterfaces with encapsulation dot1Q, one per VLAN; switch side is a trunk.
  • Multilayer switching: SVIs (interface vlan N) + ip routing — faster, no trunk bottleneck.
  • An SVI stays down with no active access/trunk port carrying that VLAN.
  • First check for inter-VLAN failure: host default gateway and trunk allowed-VLAN list.

Related CCNA study guides

Frequently asked questions

What are the key CCNA exam points for VLAN Concepts and Access Ports?

For the CCNA 200-301 exam, remember: VLAN = broadcast domain in software. VLAN 1 is default; 1002–1005 reserved; usable range 1–4094. Access ports carry one untagged VLAN to end devices: switchport mode access + switchport access vlan. Voice VLAN lets a phone (tagged) share a port with a PC (untagged). Verify with show vlan brief; park unused ports in a dead VLAN.

What are the key CCNA exam points for Trunks, 802.1Q and the Native VLAN?

For the CCNA 200-301 exam, remember: Trunks carry multiple VLANs; 802.1Q tags each frame with a 12-bit VLAN ID. Native VLAN crosses untagged (default VLAN 1); both ends must match — set it to an unused VLAN. DTP: desirable tries, auto waits (auto+auto = access). Use switchport nonegotiate for security. Verify with show interfaces trunk; prune with switchport trunk allowed vlan.

What are the key CCNA exam points for Inter-VLAN Routing?

For the CCNA 200-301 exam, remember: Router-on-a-stick: subinterfaces with encapsulation dot1Q, one per VLAN; switch side is a trunk. Multilayer switching: SVIs (interface vlan N) + ip routing — faster, no trunk bottleneck. An SVI stays down with no active access/trunk port carrying that VLAN. First check for inter-VLAN failure: host default gateway and trunk allowed-VLAN list.

Which key detail about VLAN Concepts and Access Ports should you memorise for the CCNA 200-301 exam?

Access ports carry one untagged VLAN to end devices: switchport mode access + switchport access vlan.

Which key detail about Trunks, 802.1Q and the Native VLAN should you memorise for the CCNA 200-301 exam?

Native VLAN crosses untagged (default VLAN 1); both ends must match — set it to an unused VLAN.