EASYTUTORGUIDE

Practical tutorials, tools, courses, digital skills, and business promotion.

Free Learning

Chapter 9 — VLANs and Trunking

Learn Networking from very beginner to advanced through a complete course.

Beginner FriendlyExamplesPracticeProjects
Estimated reading time: 1 minute0% read

Chapter 9 — VLANs and Trunking

A VLAN lets you divide one physical switch network into multiple logical networks. VLANs are very important in Networking because they improve security, organization, performance, and broadcast control.

This chapter explains VLANs, VLAN IDs, access ports, trunk ports, 802.1Q tagging, native VLANs, voice VLANs, default VLANs, inter-VLAN routing, router-on-a-stick, Layer 3 switching, segmentation, configuration concepts, and troubleshooting .

9.1 What Is a VLAN?

VLAN stands for:

Virtual Local Area Network

A VLAN creates a logical network inside a switch.

Without VLANs

             PC1
              |
PC2 ---- Switch ---- PC3
              |
             PC4

All devices may belong to one broadcast domain.

With VLANs

             Switch
             /    \
        VLAN 10   VLAN 20
          Sales      HR

Even though the devices use the same physical switch, they are logically separated.

Think:

VLAN = virtual separation inside a switch

9.2 Why VLANs Are Used

VLANs provide several important benefits.

Security

You can separate departments.

Example

VLAN 10
Accounting

VLAN 20
Guests

Guest users should not automatically have direct access to accounting systems.

Broadcast control

Broadcast traffic stays inside its VLAN.

This reduces unnecessary broadcast traffic.

Organization

Devices can be grouped by:

  • Department
  • Function
  • Security level
  • Location
  • Device type

Flexibility

Two users can belong to the same VLAN even if they connect to different switches.

9.3 VLAN IDs

Each VLAN is identified by a number called the:

VLAN ID

Common examples:

VLAN 10
VLAN 20
VLAN 30

VLAN IDs used with 802.1Q are generally in the range:

1–4094

Example

VLAN 10 = Sales

VLAN 20 = HR

VLAN 30 = IT

The numbers themselves do not automatically have special meanings. Administrators assign them.

9.4 Access Ports

An access port normally carries traffic for one VLAN.

Example

PC
 |
Access Port
 |
Switch

Suppose the port is assigned to VLAN 10.

Switch Port 5

VLAN 10

Any normal untagged traffic arriving from the PC is associated with VLAN 10.

Typical devices on access ports

  • Desktop computers
  • Printers
  • Servers
  • Cameras
  • End-user devices
Access port = one VLAN for an endpoint

9.5 Trunk Ports

A trunk port carries traffic for multiple VLANs.

Example

Switch A ===== Trunk ===== Switch B

The trunk may carry:

  • VLAN 10
  • VLAN 20
  • VLAN 30
  • VLAN 40

over the same physical connection.

Why trunks are useful

Without a trunk, you might need separate physical links for every VLAN.

With a trunk:

One physical link can carry many VLANs

Common trunk connections

  • Switch to switch
  • Switch to router
  • Switch to firewall
  • Switch to wireless controller
  • Switch to virtualization host

9.6 IEEE 802.1Q

The standard commonly used for Ethernet VLAN tagging is:

IEEE 802.1Q
Remember

802.1Q = VLAN tagging

A trunk uses tags so receiving devices know which VLAN a frame belongs to.

9.7 VLAN Tagging

When a frame travels over an 802.1Q trunk, VLAN information is inserted into the Ethernet frame.

Original Ethernet Frame

+----------------------+
| Ethernet Header      |
| Data                 |
+----------------------+

On a trunk

+----------------------+
| Ethernet Header      |
| 802.1Q VLAN Tag      |
| Data                 |
+----------------------+

The tag can indicate:

VLAN ID = 20

The receiving switch knows:

"This frame belongs to VLAN 20."

9.8 Native VLAN

On an 802.1Q trunk, one VLAN can be designated as the:

Native VLAN

Traffic belonging to the native VLAN is commonly sent untagged over the trunk.

Example

Trunk carries:

VLAN 10 tagged
VLAN 20 tagged
VLAN 30 tagged
VLAN 99 native/untagged

Important problem

Both ends of the trunk should agree on the native VLAN.

Switch A
Native VLAN 99

Switch B
Native VLAN 10

This is a:

Native VLAN mismatch

It can cause:

  • Connectivity problems
  • Security concerns
  • Unexpected VLAN behavior

9.9 Voice VLAN

A voice VLAN is a VLAN specifically used for IP phone traffic.

Example

IP Phone
   |
   +---- PC
   |
Switch Port

A single switch port may support:

Data VLAN 10

Voice VLAN 20

The PC belongs to VLAN 10.

The phone's voice traffic belongs to VLAN 20.

Why separate voice?

It helps with:

  • QoS
  • Security
  • Organization
  • Troubleshooting
  • Voice traffic prioritization

9.10 Default VLAN

Many switches have a default VLAN.

Traditionally:

VLAN 1

is the default VLAN on many switch platforms.

New switch ports may initially belong to VLAN 1.

Security consideration

Enterprise administrators often avoid using VLAN 1 for normal production user traffic when possible.

Why?

Because default configurations are predictable and separating management/user traffic can improve security.

9.11 Inter-VLAN Routing

Devices in different VLANs are in different Layer 2 broadcast domains.

Example

PC A
VLAN 10

PC B
VLAN 20

They cannot communicate directly through normal Layer 2 switching.

They need a Layer 3 device.

This process is called:

Inter-VLAN routing

Example

VLAN 10
   |
   |
Layer 3 Device
   |
   |
VLAN 20

The Layer 3 device could be:

  • Router
  • Layer 3 switch
  • Firewall

9.12 Router-on-a-Stick

Router-on-a-stick allows one physical router interface to route between multiple VLANs.

Example

Router
  |
Trunk
  |
Switch
 /    \
VLAN10 VLAN20

The router interface is divided logically into:

Subinterfaces

Example

Router interface G0/0

G0/0.10 → VLAN 10

G0/0.20 → VLAN 20

Each subinterface may have an IP address that acts as the default gateway for that VLAN.

Example

VLAN 10

Network:
192.168.10.0/24

Gateway:
192.168.10.1


VLAN 20

Network:
192.168.20.0/24

Gateway:
192.168.20.1

9.13 Layer 3 Switching

A Layer 3 switch can perform inter-VLAN routing without requiring an external router for every VLAN.

Example

VLAN 10
    \
     \
Layer 3 Switch
     /
    /
VLAN 20

The switch may create logical Layer 3 interfaces for VLANs.

These are commonly called:

SVIs — Switch Virtual Interfaces

Example

Interface VLAN 10
192.168.10.1

Interface VLAN 20
192.168.20.1

The Layer 3 switch routes traffic between the VLANs.

9.14 VLAN Segmentation

VLANs are an important form of network segmentation.

Example organization

VLAN 10
Employees

VLAN 20
Servers

VLAN 30
Guests

VLAN 40
Security Cameras

VLAN 50
VoIP Phones

This keeps different types of traffic separated.

Important security point

VLANs help with segmentation, but they are not a complete security solution by themselves.

You may also need:

  • ACLs
  • Firewalls
  • Authentication
  • Network access control
  • Routing policies

9.15 VLAN Configuration Concepts

You should understand the general configuration process even if the exact commands vary by vendor.

Step 1 — Create VLAN

Create VLAN 10

Name: SALES

Step 2 — Assign access port

Port 5

Mode: Access

VLAN: 10

Step 3 — Configure trunk

Port 24

Mode: Trunk

Allowed VLANs:

10,20,30

Step 4 — Configure Layer 3 gateway

For VLAN 10:
192.168.10.1

For VLAN 20:
192.168.20.1

Step 5 — Verify

Check:

  • VLAN exists
  • Correct ports assigned
  • Trunk works
  • VLAN allowed
  • Gateway correct
  • Routing works

9.16 VLAN Troubleshooting

VLAN problems are very common in Networking scenarios.

Important issues include:

  • Wrong access VLAN
  • VLAN does not exist
  • Trunk not configured
  • VLAN not allowed on trunk
  • Native VLAN mismatch
  • Wrong IP subnet
  • Wrong default gateway
  • Inter-VLAN routing missing
  • Voice VLAN misconfiguration

Troubleshooting Example 1 — Wrong VLAN

Suppose:

PC should be:

VLAN 10

Switch port is:

VLAN 20

The PC may receive an address from the wrong network or fail to access expected resources.

Fix:

Assign the port to the correct VLAN.

Troubleshooting Example 2 — VLAN Missing from Trunk

Suppose:

Switch A
VLANs 10,20,30

Switch B
VLANs 10,20,30

But trunk allows only:

VLAN 10,20

VLAN 30 traffic cannot cross the trunk.

Switch A ===== trunk ===== Switch B
                  |
             VLAN 30 blocked

Fix:

Add VLAN 30 to the allowed VLAN list.

Troubleshooting Example 3 — Native VLAN Mismatch

Switch A native VLAN = 99

Switch B native VLAN = 1

This may produce warnings and unexpected traffic handling.

Fix:

Configure the same native VLAN on both trunk ends.

Troubleshooting Example 4 — No Inter-VLAN Routing

PC A:

VLAN 10

192.168.10.50


PC B:

VLAN 20

192.168.20.50

They cannot communicate.

If there is no Layer 3 device routing between the VLANs, this is expected.

Fix:

Configure inter-VLAN routing.

Troubleshooting Example 5 — Wrong Default Gateway

PC IP:

192.168.10.50

Gateway:

192.168.20.1

The gateway belongs to the wrong VLAN/subnet.

Correct might be:

192.168.10.1

How VLAN Traffic Works

Suppose:

PC A
VLAN 10

Switch A

PC B
VLAN 10

Switch B

The switches are connected by a trunk.

PC A
 |
Switch A
 |
802.1Q Trunk
 |
Switch B
 |
PC B

Switch A adds VLAN information to the frame on the trunk.

Conceptually:

Frame

VLAN ID = 10

Switch B receives it and knows the frame belongs to VLAN 10.

When forwarding it to PC B through an access port, the tag is normally removed.

Access Port vs Trunk Port

This distinction is very important.

Feature Access Port Trunk Port
Number of VLANs Usually one Multiple
Typical connection PC/printer Switch/router
Tagging Usually untagged to endpoint 802.1Q tagging
Purpose Endpoint connection Carry VLANs between network devices

Chapter 9 Practice Questions

Question 1

What does VLAN stand for?

A. Virtual Local Area Network

B. Variable Local Access Network

C. Virtual Link Access Node

D. Verified Local Area Node

Correct answer: A — Virtual Local Area Network

A VLAN creates logical separation inside a switched network.

Question 2

What is one major benefit of VLANs?

A. They eliminate all routers

B. They provide logical segmentation

C. They remove MAC addresses

D. They turn copper into fiber

Correct answer: B — They provide logical segmentation

VLANs help separate departments, device types, and security zones.

Question 3

What happens to Layer 2 broadcast traffic between separate VLANs?

A. It automatically crosses every VLAN

B. It normally stays inside its VLAN

C. It becomes TCP

D. It becomes encrypted automatically

Correct answer: B — It normally stays inside its VLAN

Each VLAN represents a separate Layer 2 broadcast domain.

Question 4

What identifies a VLAN?

A. VLAN ID

B. TCP port

C. MAC OUI

D. DNS suffix

Correct answer: A — VLAN ID

Each VLAN is identified by a VLAN ID.

Question 5

What is the general 802.1Q VLAN ID range?

A. 1–255

B. 1–1024

C. 1–4094

D. 1–65535

Correct answer: C — 1–4094

VLAN IDs associated with 802.1Q are generally in the range 1–4094.

Question 6

What does an access port normally carry?

A. One VLAN

B. Every VLAN automatically

C. Only routing protocols

D. Only voice traffic

Correct answer: A — One VLAN

An access port normally associates an endpoint with one VLAN.

Question 7

Which device is commonly connected to an access port?

A. Desktop PC

B. Switch-to-switch trunk only

C. WAN provider core only

D. Routing table

Correct answer: A — Desktop PC

Access ports commonly connect PCs, printers, cameras, servers, and other endpoints.

Question 8

What is the main purpose of a trunk port?

A. Carry multiple VLANs

B. Carry one host only

C. Disable VLANs

D. Convert TCP to UDP

Correct answer: A — Carry multiple VLANs

A trunk allows many VLANs to share one physical connection.

Question 9

Which standard is commonly used for VLAN tagging?

A. 802.3

B. 802.11

C. 802.1Q

D. 802.1X only

Correct answer: C — 802.1Q

IEEE 802.1Q is the standard commonly used for VLAN tagging on trunks.

Question 10

Why does an 802.1Q trunk tag frames?

A. To identify which VLAN the frame belongs to

B. To assign TCP ports

C. To encrypt every frame

D. To assign DNS names

Correct answer: A — To identify which VLAN the frame belongs to

The VLAN tag allows receiving switches and devices to identify the VLAN associated with a frame.

Question 11

How is native VLAN traffic commonly carried on an 802.1Q trunk?

A. Untagged

B. Double-encrypted

C. As TCP only

D. As multicast only

Correct answer: A — Untagged

Native VLAN traffic is commonly transmitted untagged on the trunk.

Question 12

Switch A uses native VLAN 99 and Switch B uses native VLAN 10. What problem exists?

A. Duplex mismatch

B. Native VLAN mismatch

C. IP conflict

D. DNS loop

Correct answer: B — Native VLAN mismatch

Both ends of a trunk should normally agree on the native VLAN.

Question 13

What is a voice VLAN used for?

A. IP phone traffic

B. Database traffic only

C. DNS only

D. Router firmware only

Correct answer: A — IP phone traffic

Voice VLANs separate VoIP traffic for organization, security, QoS, and prioritization.

Question 14

Which VLAN is traditionally the default on many switches?

A. VLAN 0

B. VLAN 1

C. VLAN 10

D. VLAN 4094

Correct answer: B — VLAN 1

VLAN 1 is traditionally the default VLAN on many switch platforms.

Question 15

What is required for devices in VLAN 10 and VLAN 20 to communicate?

A. Layer 3 routing

B. Only Layer 2 switching

C. A hub

D. CSMA/CD

Correct answer: A — Layer 3 routing

Different VLANs are separate Layer 2 broadcast domains, so a Layer 3 device must route between them.

Question 16

What is inter-VLAN routing?

A. Routing traffic between VLANs

B. Tagging one access port

C. Disabling VLANs

D. Converting frames to DNS records

Correct answer: A — Routing traffic between VLANs

Inter-VLAN routing lets hosts in different VLANs communicate.

Question 17

What does router-on-a-stick use?

A. One physical router interface with subinterfaces

B. One router for every PC

C. No trunk connection

D. Only Layer 2 switching

Correct answer: A — One physical router interface with subinterfaces

Router-on-a-stick uses one trunk-connected physical interface divided into logical subinterfaces.

Question 18

In router-on-a-stick, what may act as the default gateway for each VLAN?

A. Router subinterface IP

B. MAC address only

C. DNS hostname

D. Access port number

Correct answer: A — Router subinterface IP

Each VLAN subinterface can have an IP address used as that VLAN's gateway.

Question 19

What does SVI stand for?

A. Switch Virtual Interface

B. Secure VLAN Identifier

C. Switched Virtual Internet

D. System VLAN Interface

Correct answer: A — Switch Virtual Interface

Layer 3 switches can use SVIs as logical Layer 3 interfaces for VLANs.

Question 20

Which device can perform inter-VLAN routing using SVIs?

A. Layer 3 switch

B. Hub

C. Patch panel

D. Repeater

Correct answer: A — Layer 3 switch

A Layer 3 switch can create SVIs and route traffic between VLANs.

Question 21

Are VLANs alone a complete security solution?

A. Yes

B. No

C. Only with VLAN 1

D. Only on unmanaged switches

Correct answer: B — No

VLANs help with segmentation, but security may also require ACLs, firewalls, authentication, NAC, and routing policies.

Question 22

Which is a correct first step when configuring a VLAN?

A. Create the VLAN

B. Delete all switch ports

C. Disable routing permanently

D. Change every MAC address

Correct answer: A — Create the VLAN

The general process begins by creating the VLAN and then assigning ports.

Question 23

A PC should belong to VLAN 10, but its switch port is assigned to VLAN 20. What is the likely problem?

A. Wrong access VLAN

B. Duplex mismatch

C. DNS failure

D. Bad TCP flag

Correct answer: A — Wrong access VLAN

The switch port should be assigned to the VLAN expected for that endpoint.

Question 24

A trunk allows VLANs 10 and 20, but VLAN 30 must cross it. Why does VLAN 30 fail?

A. VLAN 30 is not allowed on the trunk

B. VLAN 30 must use UDP

C. VLAN 30 must be native

D. VLAN 30 needs a new MAC format

Correct answer: A — VLAN 30 is not allowed on the trunk

Add VLAN 30 to the trunk's allowed VLAN list.

Question 25

PC A is in VLAN 10 and PC B is in VLAN 20. No Layer 3 routing is configured. Can they communicate normally?

A. Yes, automatically

B. No

C. Only through broadcast

D. Only through CSMA/CD

Correct answer: B — No

Hosts in different VLANs require inter-VLAN routing.

Question 26

A PC has IP address 192.168.10.50 but gateway 192.168.20.1. What is wrong?

A. Gateway belongs to the wrong subnet/VLAN

B. MAC address is too long

C. VLAN tagging is impossible

D. The PC needs VLAN 1

Correct answer: A — Gateway belongs to the wrong subnet/VLAN

A host in the 192.168.10.0/24 network would normally use a gateway from that subnet, such as 192.168.10.1.

Question 27

When a VLAN 10 frame moves over an 802.1Q trunk, what identifies it as VLAN 10 traffic?

A. VLAN tag

B. TCP window

C. DNS record

D. ARP timeout

Correct answer: A — VLAN tag

The 802.1Q tag identifies the VLAN associated with the frame.

Question 28

What normally happens to the VLAN tag when a frame leaves a switch toward a normal endpoint through an access port?

A. It is normally removed

B. It becomes an IP address

C. It becomes a TCP port

D. It is always doubled

Correct answer: A — It is normally removed

Normal endpoints on access ports usually receive untagged Ethernet traffic.

Question 29

Which statement correctly compares access and trunk ports?

A. Access ports usually carry one VLAN; trunks carry multiple VLANs.

B. Access ports carry every VLAN; trunks carry one VLAN.

C. Both always carry only VLAN 1.

D. Neither carries VLAN traffic.

Correct answer: A — Access ports usually carry one VLAN; trunks carry multiple VLANs.

Question 30

Two switches must transport VLANs 10, 20, and 30 over one physical Ethernet link. What should be configured?

A. An 802.1Q trunk

B. Three separate DNS servers

C. Half-duplex Ethernet

D. A Telnet connection

Correct answer: A — An 802.1Q trunk

A trunk allows multiple VLANs to travel across one physical link. 802.1Q tags identify which VLAN each frame belongs to.

Exam memory: Access port = usually one VLAN. Trunk port = multiple VLANs. 802.1Q = VLAN tagging. Different VLANs require Layer 3 routing to communicate.

Chapter 9 Final Exam Memory Sheet

VLAN

Virtual Local Area Network

Logical separation inside a switch


--------------------------------


WHY VLANS?

Security
Broadcast control
Organization
Flexibility
Segmentation


--------------------------------


VLAN ID

Identifies a VLAN

General 802.1Q range:

1–4094


--------------------------------


ACCESS PORT

Usually one VLAN

Typical devices:

PC
Printer
Server
Camera


--------------------------------


TRUNK PORT

Carries multiple VLANs

Typical links:

Switch ↔ Switch
Switch ↔ Router
Switch ↔ Firewall


--------------------------------


802.1Q

VLAN tagging


--------------------------------


NATIVE VLAN

Commonly untagged on trunk

Both trunk ends should agree


Native VLAN mismatch
=
possible connectivity/security problems


--------------------------------


VOICE VLAN

Separate IP phone traffic

Helps with:

QoS
Security
Organization
Prioritization


--------------------------------


DEFAULT VLAN

Often VLAN 1


--------------------------------


INTER-VLAN ROUTING

Required for communication
between different VLANs

Possible Layer 3 devices:

Router
Layer 3 switch
Firewall


--------------------------------


ROUTER-ON-A-STICK

One physical router interface

Multiple subinterfaces

Example:

G0/0.10 → VLAN 10
G0/0.20 → VLAN 20


--------------------------------


SVI

Switch Virtual Interface

Used by Layer 3 switches


--------------------------------


VLAN SEGMENTATION

Examples:

Employees
Servers
Guests
Cameras
VoIP Phones


VLANs alone are not
a complete security solution


--------------------------------


COMMON VLAN PROBLEMS

Wrong access VLAN
VLAN missing
Trunk missing
VLAN not allowed
Native VLAN mismatch
Wrong subnet
Wrong gateway
Missing inter-VLAN routing
Voice VLAN misconfiguration


--------------------------------


ACCESS VS TRUNK

Access:

Usually one VLAN
Endpoint connection
Usually untagged


Trunk:

Multiple VLANs
Network-device connection
802.1Q tagged


--------------------------------


IMPORTANT EXAM MEMORY

802.1Q
= VLAN tagging

Access port
= usually one VLAN

Trunk port
= multiple VLANs

Different VLANs
= different broadcast domains

Different VLANs need
Layer 3 routing to communicate

Chapter 9 complete.

A modern course built to help learners study step by step with clarity, comfort, and confidence.