VLANs let us create separate Layer 2 networks on a switch. But what happens when VLAN 10 needs to exist on several switches? A trunk lets multiple VLANs share the same physical link.
In the previous lesson we created VLAN 10 and VLAN 20. That works perfectly when all the devices are connected to one switch.
Now imagine we add a second switch. Both switches have users in VLAN 10 and VLAN 20.
We could theoretically use one physical connection for VLAN 10 and another for VLAN 20, but that becomes ridiculous as the number of VLANs grows.
PC-A and PC-C can belong to the same VLAN even though they are connected to different switches.
The trunk between SW1 and SW2 carries traffic belonging to both VLAN 10 and VLAN 20 while keeping the VLANs logically separate.
This creates an obvious problem.
If frames from several VLANs travel across the same physical link, the receiving switch needs a way to identify which VLAN each frame belongs to.
The standard mechanism used for this is IEEE 802.1Q, commonly called dot1q.
For traffic that is tagged on a trunk, 802.1Q inserts VLAN information into the Ethernet frame.
Suppose PC-A is connected to an access port in VLAN 10. The PC itself normally sends an ordinary untagged Ethernet frame.
PC-A sends an Ethernet frame into an access port assigned to VLAN 10.
SW1 associates the incoming frame with VLAN 10 because of the access port configuration.
When forwarded over the 802.1Q trunk, the switch identifies the frame as belonging to VLAN 10 using an 802.1Q tag.
SW2 receives the frame, reads the VLAN information and can then forward the traffic within VLAN 10.
On an 802.1Q trunk, one VLAN is configured as the native VLAN.
Under normal Cisco 802.1Q trunk behaviour, frames belonging to the native VLAN are sent untagged.
By default, the native VLAN on many Cisco switch configurations is VLAN 1, although it can be changed.
| Traffic | Across an 802.1Q trunk |
|---|---|
| VLAN 10 | Normally tagged with VLAN ID 10 |
| VLAN 20 | Normally tagged with VLAN ID 20 |
| Native VLAN | Normally sent untagged |
Suppose GigabitEthernet0/1 connects SW1 to SW2.
On SW1:
SW1> enable
SW1# configure terminal
SW1(config)# interface gigabitEthernet 0/1
SW1(config-if)# switchport mode trunk
And on SW2:
SW2> enable
SW2# configure terminal
SW2(config)# interface gigabitEthernet 0/1
SW2(config-if)# switchport mode trunk
switchport mode trunk statically configures the interface
to operate as a Layer 2 trunk.
A trunk does not necessarily need to carry every VLAN that exists on the switch.
We can explicitly define which VLANs are allowed across it.
SW1(config)# interface gigabitEthernet 0/1
SW1(config-if)# switchport trunk allowed vlan 10,20
Now VLANs 10 and 20 are permitted across that trunk.
The native VLAN can be changed using:
SW1(config)# interface gigabitEthernet 0/1
SW1(config-if)# switchport trunk native vlan 99
The corresponding trunk on SW2 should be configured consistently:
SW2(config)# interface gigabitEthernet 0/1
SW2(config-if)# switchport trunk native vlan 99
The star of this lesson is:
SW1# show interfaces trunk
Port Mode Encapsulation Status Native vlan
Gi0/1 on 802.1q trunking 99
Port Vlans allowed on trunk
Gi0/1 10,20
Port Vlans allowed and active in management domain
Gi0/1 10,20
Port Vlans in spanning tree forwarding state and not pruned
Gi0/1 10,20
From one command we can quickly check:
show interfaces trunk.
We can also inspect the individual interface:
SW1# show interfaces gigabitEthernet 0/1 switchport
Name: Gi0/1
Switchport: Enabled
Administrative Mode: trunk
Operational Mode: trunk
Trunking Native Mode VLAN: 99
Trunking VLANs Enabled: 10,20
Notice the difference between administrative mode and operational mode.
Administrative mode tells us what we configured. Operational mode tells us what the interface is actually doing.
| Feature | Access port | Trunk port |
|---|---|---|
| Typical purpose | Connect an endpoint | Carry VLANs between network devices |
| VLANs | Normally one access VLAN | Can carry multiple VLANs |
| 802.1Q tags | Endpoint traffic normally untagged | Used to identify VLANs across the trunk |
| Example | PC → switch | Switch → switch |
Use show interfaces trunk and check the operational state.
Check that the required VLAN appears in the allowed VLAN list.
Use show vlan brief to confirm the VLAN exists and is active
where required.
Check that both sides of the trunk agree on the native VLAN.
Both PCs are in VLAN 10 but are connected to different switches.
1. PC-A sends an ordinary Ethernet frame into its VLAN 10 access port on SW1.
2. SW1 associates the frame with VLAN 10.
3. SW1 determines that the frame needs to leave through the trunk toward SW2.
4. On the trunk, the frame is identified as VLAN 10 using 802.1Q tagging, assuming VLAN 10 is not the native VLAN.
5. SW2 receives the trunk frame and recognises that it belongs to VLAN 10.
6. SW2 forwards it toward PC-C through the appropriate VLAN 10 access port.
show interfaces trunk is a key verification and
troubleshooting command.
# Configure static trunk
interface gigabitEthernet 0/1
switchport mode trunk
# Allow selected VLANs
switchport trunk allowed vlan 10,20
# Configure native VLAN
switchport trunk native vlan 99
# Verify trunks
show interfaces trunk
# Inspect one switchport
show interfaces gigabitEthernet 0/1 switchport
# Verify VLANs
show vlan brief
VLAN 10 and VLAN 20 are deliberately separated at Layer 2. Next we'll learn how routers and Layer 3 switches allow those networks to communicate using router-on-a-stick and switched virtual interfaces.