VLANs deliberately separate Layer 2 networks. A trunk can carry those VLANs between switches, but it does not allow one VLAN to communicate with another. For that, we need Layer 3 routing.
Consider two hosts:
IP address: 192.168.10.10/24
Gateway: 192.168.10.1
IP address: 192.168.20.10/24
Gateway: 192.168.20.1
These hosts are in different IP networks and different VLANs. A Layer 2 switch cannot simply bridge traffic from VLAN 10 into VLAN 20.
PC-A wants to send traffic to 192.168.20.10. Using its own IP address and subnet mask, it determines that the destination is not on its local subnet.
Instead of trying to deliver the packet directly to PC-B, PC-A sends the traffic toward its default gateway.
Each VLAN connects to a separate physical router interface. It works, but requires lots of interfaces and cabling.
One physical router interface carries multiple VLANs using an 802.1Q trunk and logical subinterfaces.
A multilayer switch can route internally between VLANs using switched virtual interfaces.
The switch-to-router link is configured as an 802.1Q trunk. The router then creates a logical subinterface for each VLAN.
Each subinterface can have an IP address that acts as the default gateway for hosts in that VLAN.
Suppose Gi0/1 connects SW1 to the router.
The switch interface needs to carry VLANs 10 and 20.
SW1> enable
SW1# configure terminal
SW1(config)# interface gigabitEthernet 0/1
SW1(config-if)# switchport mode trunk
SW1(config-if)# switchport trunk allowed vlan 10,20
SW1(config-if)# no shutdown
This should look familiar from Lesson 02: the router-facing switchport is carrying multiple VLANs, so it is a trunk.
Assume the router connects using GigabitEthernet0/0.
First enable the physical interface:
R1> enable
R1# configure terminal
R1(config)# interface gigabitEthernet 0/0
R1(config-if)# no shutdown
Now create a subinterface for VLAN 10:
R1(config)# interface gigabitEthernet 0/0.10
R1(config-subif)# encapsulation dot1Q 10
R1(config-subif)# ip address 192.168.10.1 255.255.255.0
And VLAN 20:
R1(config)# interface gigabitEthernet 0/0.20
R1(config-subif)# encapsulation dot1Q 20
R1(config-subif)# ip address 192.168.20.1 255.255.255.0
encapsulation dot1Q 10 associates that subinterface with
802.1Q VLAN 10.
| VLAN | Network | Router interface | Host gateway |
|---|---|---|---|
| 10 | 192.168.10.0/24 | Gi0/0.10 | 192.168.10.1 |
| 20 | 192.168.20.0/24 | Gi0/0.20 | 192.168.20.1 |
PC-A uses 192.168.10.1 as its gateway, while PC-B uses 192.168.20.1.
The router has an interface in both IP networks, which allows it to route packets between them.
1. PC-A wants to reach 192.168.20.10.
2. PC-A recognises that 192.168.20.10 is outside its 192.168.10.0/24 subnet.
3. PC-A sends the packet in an Ethernet frame addressed toward its default gateway.
4. SW1 forwards the VLAN 10 traffic toward R1 over the trunk.
5. R1 receives it on the VLAN 10 subinterface and examines the destination IP address.
6. R1's routing table identifies 192.168.20.0/24 as a connected network through the VLAN 20 subinterface.
7. R1 builds a new Layer 2 frame for the outgoing VLAN 20 segment and forwards the packet back across the trunk.
8. SW1 forwards the frame within VLAN 20 toward PC-B.
A very useful first command is:
R1# show ip interface brief
Interface IP-Address OK? Method Status Protocol
GigabitEthernet0/0 unassigned YES unset up up
GigabitEthernet0/0.10 192.168.10.1 YES manual up up
GigabitEthernet0/0.20 192.168.20.1 YES manual up up
The routing table should also contain both directly connected networks:
R1# show ip route connected
C 192.168.10.0/24 is directly connected, GigabitEthernet0/0.10
C 192.168.20.0/24 is directly connected, GigabitEthernet0/0.20
And don't forget the switch side:
SW1# show interfaces trunk
A multilayer switch can perform both Layer 2 switching and Layer 3 routing. Instead of sending inter-VLAN traffic to an external router, we can create switched virtual interfaces (SVIs).
An SVI is a logical Layer 3 interface associated with a VLAN.
First create the VLANs if required:
SW1(config)# vlan 10
SW1(config-vlan)# name STAFF
SW1(config-vlan)# exit
SW1(config)# vlan 20
SW1(config-vlan)# name GUEST
Now create the SVIs:
SW1(config)# interface vlan 10
SW1(config-if)# ip address 192.168.10.1 255.255.255.0
SW1(config-if)# no shutdown
SW1(config)# interface vlan 20
SW1(config-if)# ip address 192.168.20.1 255.255.255.0
SW1(config-if)# no shutdown
On a Layer 3 switch, enable IPv4 routing:
SW1(config)# ip routing
ip routing enables IPv4 routing.
| Feature | Router-on-a-stick | Layer 3 switch |
|---|---|---|
| Layer 3 device | External router | Multilayer switch |
| Gateway interfaces | Router subinterfaces | SVIs |
| VLAN transport | 802.1Q trunk to router | Routing can occur internally |
| Key command | encapsulation dot1Q | interface vlan + ip routing |
| Physical router links | One trunk can serve many VLANs | No external router required for local inter-VLAN routing |
Configuring interface vlan 10 does not necessarily mean the
SVI will immediately become operational.
In a typical Cisco switching scenario, the VLAN must exist and the switch needs an active Layer 2 port in that VLAN (or a trunk carrying it) for the SVI line protocol to come up, assuming the SVI itself is not shut down.
SW1# show ip interface brief
Interface IP-Address OK? Method Status Protocol
Vlan10 192.168.10.1 YES manual up up
Vlan20 192.168.20.1 YES manual up up
Check the IP address, subnet mask and especially the default gateway.
Use show vlan brief to verify access ports and VLAN existence.
For router-on-a-stick, verify that the required VLANs are allowed across the switch-to-router trunk.
Check that each router subinterface has the correct
encapsulation dot1Q VLAN ID.
Use show ip interface brief and look for interfaces that are
down or administratively down.
On a multilayer switch, confirm that Layer 3 routing is enabled with
ip routing.
encapsulation dot1Q 10 associates a router subinterface
with VLAN 10.
interface vlan 10 creates/configures an SVI — it does not
configure a physical switchport.
ip routing enables IPv4 routing.
# Switch trunk toward router
interface gigabitEthernet 0/1
switchport mode trunk
switchport trunk allowed vlan 10,20
# Router-on-a-stick
interface gigabitEthernet 0/0.10
encapsulation dot1Q 10
ip address 192.168.10.1 255.255.255.0
interface gigabitEthernet 0/0.20
encapsulation dot1Q 20
ip address 192.168.20.1 255.255.255.0
# Layer 3 switch SVI
interface vlan 10
ip address 192.168.10.1 255.255.255.0
no shutdown
# Enable IPv4 routing on multilayer switch
ip routing
# Verification
show vlan brief
show interfaces trunk
show ip interface brief
show ip route
Now that our switches and routers are connected, let's learn how network devices discover their directly connected neighbours using Cisco Discovery Protocol and the standards-based Link Layer Discovery Protocol.