Question 1
What does VLAN stand for?
A. Virtual Local Area Network
B. Variable Local Access Network
C. Virtual Link Access Node
D. Verified Local Area Node
A VLAN creates logical separation inside a switched network.
Learn Networking from very beginner to advanced through a complete course.
A VLAN lets you divide one physical switch network into multiple logical networks. VLANs are very important in Networking because they improve security, organization, performance, and broadcast control.
This chapter explains VLANs, VLAN IDs, access ports, trunk ports, 802.1Q tagging, native VLANs, voice VLANs, default VLANs, inter-VLAN routing, router-on-a-stick, Layer 3 switching, segmentation, configuration concepts, and troubleshooting .
VLAN stands for:
Virtual Local Area Network
A VLAN creates a logical network inside a switch.
PC1
|
PC2 ---- Switch ---- PC3
|
PC4
All devices may belong to one broadcast domain.
Switch
/ \
VLAN 10 VLAN 20
Sales HR
Even though the devices use the same physical switch, they are logically separated.
Think:
VLAN = virtual separation inside a switch
VLANs provide several important benefits.
You can separate departments.
VLAN 10
Accounting
VLAN 20
Guests
Guest users should not automatically have direct access to accounting systems.
Broadcast traffic stays inside its VLAN.
This reduces unnecessary broadcast traffic.
Devices can be grouped by:
Two users can belong to the same VLAN even if they connect to different switches.
Each VLAN is identified by a number called the:
VLAN ID
Common examples:
VLAN 10
VLAN 20
VLAN 30
VLAN IDs used with 802.1Q are generally in the range:
1–4094
VLAN 10 = Sales
VLAN 20 = HR
VLAN 30 = IT
The numbers themselves do not automatically have special meanings. Administrators assign them.
An access port normally carries traffic for one VLAN.
PC
|
Access Port
|
Switch
Suppose the port is assigned to VLAN 10.
Switch Port 5
VLAN 10
Any normal untagged traffic arriving from the PC is associated with VLAN 10.
Access port = one VLAN for an endpoint
A trunk port carries traffic for multiple VLANs.
Switch A ===== Trunk ===== Switch B
The trunk may carry:
over the same physical connection.
Without a trunk, you might need separate physical links for every VLAN.
With a trunk:
One physical link can carry many VLANs
The standard commonly used for Ethernet VLAN tagging is:
IEEE 802.1Q
802.1Q = VLAN tagging
A trunk uses tags so receiving devices know which VLAN a frame belongs to.
When a frame travels over an 802.1Q trunk, VLAN information is inserted into the Ethernet frame.
+----------------------+
| Ethernet Header |
| Data |
+----------------------+
+----------------------+
| Ethernet Header |
| 802.1Q VLAN Tag |
| Data |
+----------------------+
The tag can indicate:
VLAN ID = 20
The receiving switch knows:
"This frame belongs to VLAN 20."
On an 802.1Q trunk, one VLAN can be designated as the:
Native VLAN
Traffic belonging to the native VLAN is commonly sent untagged over the trunk.
Trunk carries:
VLAN 10 tagged
VLAN 20 tagged
VLAN 30 tagged
VLAN 99 native/untagged
Both ends of the trunk should agree on the native VLAN.
Switch A
Native VLAN 99
Switch B
Native VLAN 10
This is a:
Native VLAN mismatch
It can cause:
A voice VLAN is a VLAN specifically used for IP phone traffic.
IP Phone
|
+---- PC
|
Switch Port
A single switch port may support:
Data VLAN 10
Voice VLAN 20
The PC belongs to VLAN 10.
The phone's voice traffic belongs to VLAN 20.
It helps with:
Many switches have a default VLAN.
Traditionally:
VLAN 1
is the default VLAN on many switch platforms.
New switch ports may initially belong to VLAN 1.
Enterprise administrators often avoid using VLAN 1 for normal production user traffic when possible.
Why?
Because default configurations are predictable and separating management/user traffic can improve security.
Devices in different VLANs are in different Layer 2 broadcast domains.
PC A
VLAN 10
PC B
VLAN 20
They cannot communicate directly through normal Layer 2 switching.
They need a Layer 3 device.
This process is called:
Inter-VLAN routing
VLAN 10
|
|
Layer 3 Device
|
|
VLAN 20
The Layer 3 device could be:
Router-on-a-stick allows one physical router interface to route between multiple VLANs.
Router
|
Trunk
|
Switch
/ \
VLAN10 VLAN20
The router interface is divided logically into:
Subinterfaces
Router interface G0/0
G0/0.10 → VLAN 10
G0/0.20 → VLAN 20
Each subinterface may have an IP address that acts as the default gateway for that VLAN.
VLAN 10
Network:
192.168.10.0/24
Gateway:
192.168.10.1
VLAN 20
Network:
192.168.20.0/24
Gateway:
192.168.20.1
A Layer 3 switch can perform inter-VLAN routing without requiring an external router for every VLAN.
VLAN 10
\
\
Layer 3 Switch
/
/
VLAN 20
The switch may create logical Layer 3 interfaces for VLANs.
These are commonly called:
SVIs — Switch Virtual Interfaces
Interface VLAN 10
192.168.10.1
Interface VLAN 20
192.168.20.1
The Layer 3 switch routes traffic between the VLANs.
VLANs are an important form of network segmentation.
VLAN 10
Employees
VLAN 20
Servers
VLAN 30
Guests
VLAN 40
Security Cameras
VLAN 50
VoIP Phones
This keeps different types of traffic separated.
VLANs help with segmentation, but they are not a complete security solution by themselves.
You may also need:
You should understand the general configuration process even if the exact commands vary by vendor.
Create VLAN 10
Name: SALES
Port 5
Mode: Access
VLAN: 10
Port 24
Mode: Trunk
Allowed VLANs:
10,20,30
For VLAN 10:
192.168.10.1
For VLAN 20:
192.168.20.1
Check:
VLAN problems are very common in Networking scenarios.
Important issues include:
Suppose:
PC should be:
VLAN 10
Switch port is:
VLAN 20
The PC may receive an address from the wrong network or fail to access expected resources.
Fix:
Assign the port to the correct VLAN.
Suppose:
Switch A
VLANs 10,20,30
Switch B
VLANs 10,20,30
But trunk allows only:
VLAN 10,20
VLAN 30 traffic cannot cross the trunk.
Switch A ===== trunk ===== Switch B
|
VLAN 30 blocked
Fix:
Add VLAN 30 to the allowed VLAN list.
Switch A native VLAN = 99
Switch B native VLAN = 1
This may produce warnings and unexpected traffic handling.
Fix:
Configure the same native VLAN on both trunk ends.
PC A:
VLAN 10
192.168.10.50
PC B:
VLAN 20
192.168.20.50
They cannot communicate.
If there is no Layer 3 device routing between the VLANs, this is expected.
Fix:
Configure inter-VLAN routing.
PC IP:
192.168.10.50
Gateway:
192.168.20.1
The gateway belongs to the wrong VLAN/subnet.
Correct might be:
192.168.10.1
Suppose:
PC A
VLAN 10
Switch A
PC B
VLAN 10
Switch B
The switches are connected by a trunk.
PC A
|
Switch A
|
802.1Q Trunk
|
Switch B
|
PC B
Switch A adds VLAN information to the frame on the trunk.
Conceptually:
Frame
VLAN ID = 10
Switch B receives it and knows the frame belongs to VLAN 10.
When forwarding it to PC B through an access port, the tag is normally removed.
This distinction is very important.
| Feature | Access Port | Trunk Port |
|---|---|---|
| Number of VLANs | Usually one | Multiple |
| Typical connection | PC/printer | Switch/router |
| Tagging | Usually untagged to endpoint | 802.1Q tagging |
| Purpose | Endpoint connection | Carry VLANs between network devices |
What does VLAN stand for?
A. Virtual Local Area Network
B. Variable Local Access Network
C. Virtual Link Access Node
D. Verified Local Area Node
A VLAN creates logical separation inside a switched network.
What is one major benefit of VLANs?
A. They eliminate all routers
B. They provide logical segmentation
C. They remove MAC addresses
D. They turn copper into fiber
VLANs help separate departments, device types, and security zones.
What happens to Layer 2 broadcast traffic between separate VLANs?
A. It automatically crosses every VLAN
B. It normally stays inside its VLAN
C. It becomes TCP
D. It becomes encrypted automatically
Each VLAN represents a separate Layer 2 broadcast domain.
What identifies a VLAN?
A. VLAN ID
B. TCP port
C. MAC OUI
D. DNS suffix
Each VLAN is identified by a VLAN ID.
What is the general 802.1Q VLAN ID range?
A. 1–255
B. 1–1024
C. 1–4094
D. 1–65535
VLAN IDs associated with 802.1Q are generally in the range 1–4094.
What does an access port normally carry?
A. One VLAN
B. Every VLAN automatically
C. Only routing protocols
D. Only voice traffic
An access port normally associates an endpoint with one VLAN.
Which device is commonly connected to an access port?
A. Desktop PC
B. Switch-to-switch trunk only
C. WAN provider core only
D. Routing table
Access ports commonly connect PCs, printers, cameras, servers, and other endpoints.
What is the main purpose of a trunk port?
A. Carry multiple VLANs
B. Carry one host only
C. Disable VLANs
D. Convert TCP to UDP
A trunk allows many VLANs to share one physical connection.
Which standard is commonly used for VLAN tagging?
A. 802.3
B. 802.11
C. 802.1Q
D. 802.1X only
IEEE 802.1Q is the standard commonly used for VLAN tagging on trunks.
Why does an 802.1Q trunk tag frames?
A. To identify which VLAN the frame belongs to
B. To assign TCP ports
C. To encrypt every frame
D. To assign DNS names
The VLAN tag allows receiving switches and devices to identify the VLAN associated with a frame.
How is native VLAN traffic commonly carried on an 802.1Q trunk?
A. Untagged
B. Double-encrypted
C. As TCP only
D. As multicast only
Native VLAN traffic is commonly transmitted untagged on the trunk.
Switch A uses native VLAN 99 and Switch B uses native VLAN 10. What problem exists?
A. Duplex mismatch
B. Native VLAN mismatch
C. IP conflict
D. DNS loop
Both ends of a trunk should normally agree on the native VLAN.
What is a voice VLAN used for?
A. IP phone traffic
B. Database traffic only
C. DNS only
D. Router firmware only
Voice VLANs separate VoIP traffic for organization, security, QoS, and prioritization.
Which VLAN is traditionally the default on many switches?
A. VLAN 0
B. VLAN 1
C. VLAN 10
D. VLAN 4094
VLAN 1 is traditionally the default VLAN on many switch platforms.
What is required for devices in VLAN 10 and VLAN 20 to communicate?
A. Layer 3 routing
B. Only Layer 2 switching
C. A hub
D. CSMA/CD
Different VLANs are separate Layer 2 broadcast domains, so a Layer 3 device must route between them.
What is inter-VLAN routing?
A. Routing traffic between VLANs
B. Tagging one access port
C. Disabling VLANs
D. Converting frames to DNS records
Inter-VLAN routing lets hosts in different VLANs communicate.
What does router-on-a-stick use?
A. One physical router interface with subinterfaces
B. One router for every PC
C. No trunk connection
D. Only Layer 2 switching
Router-on-a-stick uses one trunk-connected physical interface divided into logical subinterfaces.
In router-on-a-stick, what may act as the default gateway for each VLAN?
A. Router subinterface IP
B. MAC address only
C. DNS hostname
D. Access port number
Each VLAN subinterface can have an IP address used as that VLAN's gateway.
What does SVI stand for?
A. Switch Virtual Interface
B. Secure VLAN Identifier
C. Switched Virtual Internet
D. System VLAN Interface
Layer 3 switches can use SVIs as logical Layer 3 interfaces for VLANs.
Which device can perform inter-VLAN routing using SVIs?
A. Layer 3 switch
B. Hub
C. Patch panel
D. Repeater
A Layer 3 switch can create SVIs and route traffic between VLANs.
Are VLANs alone a complete security solution?
A. Yes
B. No
C. Only with VLAN 1
D. Only on unmanaged switches
VLANs help with segmentation, but security may also require ACLs, firewalls, authentication, NAC, and routing policies.
Which is a correct first step when configuring a VLAN?
A. Create the VLAN
B. Delete all switch ports
C. Disable routing permanently
D. Change every MAC address
The general process begins by creating the VLAN and then assigning ports.
A PC should belong to VLAN 10, but its switch port is assigned to VLAN 20. What is the likely problem?
A. Wrong access VLAN
B. Duplex mismatch
C. DNS failure
D. Bad TCP flag
The switch port should be assigned to the VLAN expected for that endpoint.
A trunk allows VLANs 10 and 20, but VLAN 30 must cross it. Why does VLAN 30 fail?
A. VLAN 30 is not allowed on the trunk
B. VLAN 30 must use UDP
C. VLAN 30 must be native
D. VLAN 30 needs a new MAC format
Add VLAN 30 to the trunk's allowed VLAN list.
PC A is in VLAN 10 and PC B is in VLAN 20. No Layer 3 routing is configured. Can they communicate normally?
A. Yes, automatically
B. No
C. Only through broadcast
D. Only through CSMA/CD
Hosts in different VLANs require inter-VLAN routing.
A PC has IP address 192.168.10.50 but gateway 192.168.20.1. What is wrong?
A. Gateway belongs to the wrong subnet/VLAN
B. MAC address is too long
C. VLAN tagging is impossible
D. The PC needs VLAN 1
A host in the 192.168.10.0/24 network would normally use a gateway from that subnet, such as 192.168.10.1.
When a VLAN 10 frame moves over an 802.1Q trunk, what identifies it as VLAN 10 traffic?
A. VLAN tag
B. TCP window
C. DNS record
D. ARP timeout
The 802.1Q tag identifies the VLAN associated with the frame.
What normally happens to the VLAN tag when a frame leaves a switch toward a normal endpoint through an access port?
A. It is normally removed
B. It becomes an IP address
C. It becomes a TCP port
D. It is always doubled
Normal endpoints on access ports usually receive untagged Ethernet traffic.
Which statement correctly compares access and trunk ports?
A. Access ports usually carry one VLAN; trunks carry multiple VLANs.
B. Access ports carry every VLAN; trunks carry one VLAN.
C. Both always carry only VLAN 1.
D. Neither carries VLAN traffic.
Two switches must transport VLANs 10, 20, and 30 over one physical Ethernet link. What should be configured?
A. An 802.1Q trunk
B. Three separate DNS servers
C. Half-duplex Ethernet
D. A Telnet connection
A trunk allows multiple VLANs to travel across one physical link. 802.1Q tags identify which VLAN each frame belongs to.
Exam memory: Access port = usually one VLAN. Trunk port = multiple VLANs. 802.1Q = VLAN tagging. Different VLANs require Layer 3 routing to communicate.
VLAN
Virtual Local Area Network
Logical separation inside a switch
--------------------------------
WHY VLANS?
Security
Broadcast control
Organization
Flexibility
Segmentation
--------------------------------
VLAN ID
Identifies a VLAN
General 802.1Q range:
1–4094
--------------------------------
ACCESS PORT
Usually one VLAN
Typical devices:
PC
Printer
Server
Camera
--------------------------------
TRUNK PORT
Carries multiple VLANs
Typical links:
Switch ↔ Switch
Switch ↔ Router
Switch ↔ Firewall
--------------------------------
802.1Q
VLAN tagging
--------------------------------
NATIVE VLAN
Commonly untagged on trunk
Both trunk ends should agree
Native VLAN mismatch
=
possible connectivity/security problems
--------------------------------
VOICE VLAN
Separate IP phone traffic
Helps with:
QoS
Security
Organization
Prioritization
--------------------------------
DEFAULT VLAN
Often VLAN 1
--------------------------------
INTER-VLAN ROUTING
Required for communication
between different VLANs
Possible Layer 3 devices:
Router
Layer 3 switch
Firewall
--------------------------------
ROUTER-ON-A-STICK
One physical router interface
Multiple subinterfaces
Example:
G0/0.10 → VLAN 10
G0/0.20 → VLAN 20
--------------------------------
SVI
Switch Virtual Interface
Used by Layer 3 switches
--------------------------------
VLAN SEGMENTATION
Examples:
Employees
Servers
Guests
Cameras
VoIP Phones
VLANs alone are not
a complete security solution
--------------------------------
COMMON VLAN PROBLEMS
Wrong access VLAN
VLAN missing
Trunk missing
VLAN not allowed
Native VLAN mismatch
Wrong subnet
Wrong gateway
Missing inter-VLAN routing
Voice VLAN misconfiguration
--------------------------------
ACCESS VS TRUNK
Access:
Usually one VLAN
Endpoint connection
Usually untagged
Trunk:
Multiple VLANs
Network-device connection
802.1Q tagged
--------------------------------
IMPORTANT EXAM MEMORY
802.1Q
= VLAN tagging
Access port
= usually one VLAN
Trunk port
= multiple VLANs
Different VLANs
= different broadcast domains
Different VLANs need
Layer 3 routing to communicate
Chapter 9 complete.
A modern course built to help learners study step by step with clarity, comfort, and confidence.