We can recreate this exact switch-trunking lab in Cisco Packet
Tracer. The key concept is:
Access ports connect end devices to one
VLAN. Trunk port carries multiple VLANs between switches.
One small
correction in the image: the SW2 configuration appears to show vlan 18 and
vlan 38, but based on the topology it should be VLAN 10, 20, and 30.
why a company needs trunking.
Let's forget Packet Tracer for a moment and look at an actual corporate
office.
Imagine your Cubic office
Suppose an
office has 200 employees and one switch has 48 ports.
The company doesn't
want every device to be in the same network.
They may create:
- VLAN 10 → Employees
- VLAN 20 → IT/Servers
- VLAN 30 → Guest Wi-Fi
- VLAN 40 → CCTV
- VLAN 50 → Voice/IP Phones
So physically you might have:
Now comes the important question:
Why do we need a TRUNK?
Imagine SW1 and SW2 are on different floors.
But users on both floors need access to the same VLANs.
For example:
SW1 SW2 Employee VLAN 10 ─────────── VLAN 10 IT VLAN 20 ─────────── VLAN 20 Guest VLAN 30 ─────────── VLAN 30 Voice VLAN 40 ─────────── VLAN 40
Do we need four physical cables?
SW1 ================= SW2 VLAN 10 SW1 ================= SW2 VLAN 20 SW1 ================= SW2 VLAN 30 SW1 ================= SW2 VLAN 40
That would be inefficient.
Instead, we use one trunk link:
That's the main reason for trunking.
1. Create the topology
In Packet Tracer, add:
2 × 2960 switches
4 × PCs
Arrange
them:
More precisely:
Connections
Device Port Device Port Type
PC1 FastEthernet0 SW1 Fa0/1 Copper Straight-Through
PC2 FastEthernet0 SW1 Fa0/2 Copper Straight-Through
SW1 Fa0/24 SW2 Fa0/24 Copper Cross-Over*
PC3 FastEthernet0 SW2 Fa0/1 Copper Straight-Through
PC4 FastEthernet0 SW2 Fa0/2 Copper Straight-Through
www.kumaratuljaiswal.in
2. Create VLANs on SW1
Click SW1 → CLI.
enable configure terminal vlan 10 name VLAN10 exit vlan 20 name VLAN20 exit vlan 30 name VLAN30 exit
So SW1 now has:
- VLAN 10
- VLAN 20
- VLAN 30
3. Configure PC1 port as VLAN 10
PC1 is connected to SW1 Fa0/1.
This means:
interface fa0/1 switchport mode access switchport access vlan 10 exit
|
Fa0/1
|
VLAN 10
4. Configure PC2 port as VLAN 20
interface fa0/2 switchport mode access switchport access vlan 20 exit
Now:
PC1 → VLAN 10
PC2 → VLAN 20
5. Configure SW1-to-SW2 as a trunk
This is the most important part.
On SW1:
interface fa0/24 switchport mode trunk switchport trunk allowed vlan 10,20 exit
Notice:
allowed vlan 10,20
We are not
allowing VLAN 30.
Therefore:
- VLAN 10 → Allowed
- VLAN 20 → Allowed
- VLAN 30 → Blocked
6. Configure SW2
Go to SW2 → CLI.
Create the same VLANs:
enable configure terminal vlan 10 name VLAN10 exit vlan 20 name VLAN20 exit vlan 30 name VLAN30 exit
7. Configure PC3 as VLAN 10
PC3 is connected to SW2 Fa0/1:
interface fa0/1 switchport mode access switchport access vlan 10 exit
8. Configure PC4 as VLAN 20
interface fa0/2 switchport mode access switchport access vlan 20 exit
9. Configure SW2 trunk
interface fa0/24 switchport mode trunk switchport trunk allowed vlan 10,20 exit
Now both sides of the trunk agree:
SW1 Fa0/24
||
||
802.1Q TRUNK
||
SW2 Fa0/24
Allowed VLANs:
10
20
VLAN 30:
NOT ALLOWED
10. Configure PC IP addresses
Go to each PC:
PC → Desktop → IP Configuration
PC1
- IP Address: 192.168.10.10
- Subnet Mask: 255.255.255.0
PC2
- IP Address: 192.168.20.10
- Subnet Mask: 255.255.255.0
PC3
- IP Address: 192.168.10.20
- Subnet Mask: 255.255.255.0
PC4
- IP Address: 192.168.20.20
- Subnet Mask: 255.255.255.0
You don't need a default gateway for this particular lab because we're
only testing Layer-2 communication within the same VLAN.
11. Test the important part
From PC1:
- ping 192.168.10.20
Expected:
- Reply from 192.168.10.20
Why?
PC1 VLAN 10 ↓ SW1 ↓ TRUNK ↓ SW2 ↓ VLAN 10 ↓ PC3
So PC1 → PC3 should work.
Now from PC2:
ping
192.168.20.20
Expected:
Reply from
192.168.20.20
Because both are VLAN 20.
12. Test between different VLANs
From PC1:
ping
192.168.20.20
This should fail.
Why?
PC1 →
VLAN 10
X
VLAN 20
A Layer-2 switch does not route
between VLAN 10 and VLAN 20. You would need a router or Layer-3 switch for
inter-VLAN routing.
13. Verify the VLANs
On SW1:
- show vlan brief
You should see something similar to:
VLAN Name Status Ports 10 VLAN10 active Fa0/1 20 VLAN20 active Fa0/2 30 VLAN30 active
On SW2:
- show vlan brief
You should see
10 VLAN10 active Fa0/1 20 VLAN20 active Fa0/2 30 VLAN30 active
14. Verify the trunk
On either switch:
- show interfaces trunk
You should see Fa0/24 as a trunk.
Most importantly, the allowed VLAN list should contain:
10,20
and not 30.
You can also check:
- show interfaces fa0/24 switchport
Look for:
Administrative Mode: trunk
Operational Mode: trunk
and the allowed VLANs.
The three tests you should remember for your System Engineer interview
| Test | Expected | | ------------- | ------------------------------------- | | PC1 → PC3 | ✅ Works — same VLAN 10 | | PC2 → PC4 | ✅ Works — same VLAN 20 | | PC1 → PC2/PC4 | ❌ Fails — different VLANs, no routing |
And the important interview explanation is:
“I configured Fa0/1 and Fa0/2 as access ports for VLAN 10 and VLAN 20. I configured the inter-switch Fa0/24 link as an 802.1Q trunk and restricted the allowed VLANs to 10 and 20. VLAN 30 exists on the switches but is not permitted across the trunk.”







0 comments:
Post a Comment
For Any Tech Updates, Hacking News, Internet, Computer, Technology and related to IT Field Articles Follow Our Blog.