Network Access // Lesson 02

Trunks &
802.1Q.

VLANs let us create separate Layer 2 networks on a switch. But what happens when VLAN 10 needs to exist on several switches? A trunk lets multiple VLANs share the same physical link.

Trunk ports IEEE 802.1Q VLAN tagging Native VLAN Allowed VLANs Cisco IOS
01 // The problem

Our VLANs need to cross switches.

In the previous lesson we created VLAN 10 and VLAN 20. That works perfectly when all the devices are connected to one switch.

Now imagine we add a second switch. Both switches have users in VLAN 10 and VLAN 20.

We could theoretically use one physical connection for VLAN 10 and another for VLAN 20, but that becomes ridiculous as the number of VLANs grows.

The solution: use a trunk link that can carry traffic for multiple VLANs over one physical connection.
02 // See it

One link. Multiple VLANs.

PC-A VLAN 10

PC-B VLAN 20
SW1 Trunk port
SW2 Trunk port
PC-C VLAN 10

PC-D VLAN 20

PC-A and PC-C can belong to the same VLAN even though they are connected to different switches.

The trunk between SW1 and SW2 carries traffic belonging to both VLAN 10 and VLAN 20 while keeping the VLANs logically separate.

03 // 802.1Q

How does the receiving switch know the VLAN?

This creates an obvious problem.

If frames from several VLANs travel across the same physical link, the receiving switch needs a way to identify which VLAN each frame belongs to.

The standard mechanism used for this is IEEE 802.1Q, commonly called dot1q.

For traffic that is tagged on a trunk, 802.1Q inserts VLAN information into the Ethernet frame.

Destination MAC
Source MAC
802.1Q TAG
VLAN 10
EtherType / Length
Payload
FCS
CCNA association: when you see 802.1Q, think VLAN tagging on Ethernet trunks.
04 // Tagging

Access traffic becomes trunk traffic.

Suppose PC-A is connected to an access port in VLAN 10. The PC itself normally sends an ordinary untagged Ethernet frame.

STEP 01

Frame arrives

PC-A sends an Ethernet frame into an access port assigned to VLAN 10.

STEP 02

Switch knows the VLAN

SW1 associates the incoming frame with VLAN 10 because of the access port configuration.

STEP 03

Cross the trunk

When forwarded over the 802.1Q trunk, the switch identifies the frame as belonging to VLAN 10 using an 802.1Q tag.

SW2 receives the frame, reads the VLAN information and can then forward the traffic within VLAN 10.

05 // Native VLAN

The important exception.

On an 802.1Q trunk, one VLAN is configured as the native VLAN.

Under normal Cisco 802.1Q trunk behaviour, frames belonging to the native VLAN are sent untagged.

By default, the native VLAN on many Cisco switch configurations is VLAN 1, although it can be changed.

Important: the native VLAN should match on both ends of a trunk. A native VLAN mismatch can cause unexpected behaviour and generates warnings on Cisco devices.
Traffic Across an 802.1Q trunk
VLAN 10 Normally tagged with VLAN ID 10
VLAN 20 Normally tagged with VLAN ID 20
Native VLAN Normally sent untagged
06 // Configure

Configure a static trunk.

Suppose GigabitEthernet0/1 connects SW1 to SW2.

On SW1:

SW1> enable
SW1# configure terminal
SW1(config)# interface gigabitEthernet 0/1
SW1(config-if)# switchport mode trunk

And on SW2:

SW2> enable
SW2# configure terminal
SW2(config)# interface gigabitEthernet 0/1
SW2(config-if)# switchport mode trunk
Simple but important: switchport mode trunk statically configures the interface to operate as a Layer 2 trunk.
07 // Allowed VLANs

Control which VLANs cross the trunk.

A trunk does not necessarily need to carry every VLAN that exists on the switch.

We can explicitly define which VLANs are allowed across it.

SW1(config)# interface gigabitEthernet 0/1
SW1(config-if)# switchport trunk allowed vlan 10,20

Now VLANs 10 and 20 are permitted across that trunk.

Troubleshooting favourite: a VLAN may exist correctly on both switches but still fail across the link because it is not in the trunk's allowed VLAN list.
08 // Change the native VLAN

Configure the native VLAN.

The native VLAN can be changed using:

SW1(config)# interface gigabitEthernet 0/1
SW1(config-if)# switchport trunk native vlan 99

The corresponding trunk on SW2 should be configured consistently:

SW2(config)# interface gigabitEthernet 0/1
SW2(config-if)# switchport trunk native vlan 99
Remember the distinction: the native VLAN and the allowed VLAN list are different concepts.
09 // Verify

Use show interfaces trunk.

The star of this lesson is:

SW1# show interfaces trunk

Port        Mode         Encapsulation  Status        Native vlan
Gi0/1       on           802.1q         trunking      99

Port        Vlans allowed on trunk
Gi0/1       10,20

Port        Vlans allowed and active in management domain
Gi0/1       10,20

Port        Vlans in spanning tree forwarding state and not pruned
Gi0/1       10,20

From one command we can quickly check:

Baznetic rule: after configuring a trunk, don't just assume it worked. Run show interfaces trunk.
10 // Verify deeper

Inspect the switchport.

We can also inspect the individual interface:

SW1# show interfaces gigabitEthernet 0/1 switchport

Name: Gi0/1
Switchport: Enabled
Administrative Mode: trunk
Operational Mode: trunk
Trunking Native Mode VLAN: 99
Trunking VLANs Enabled: 10,20

Notice the difference between administrative mode and operational mode.

Administrative mode tells us what we configured. Operational mode tells us what the interface is actually doing.

11 // Access vs trunk

Don't mix them up.

Feature Access port Trunk port
Typical purpose Connect an endpoint Carry VLANs between network devices
VLANs Normally one access VLAN Can carry multiple VLANs
802.1Q tags Endpoint traffic normally untagged Used to identify VLANs across the trunk
Example PC → switch Switch → switch
12 // Troubleshooting

The trunk is up — but the VLAN isn't working.

CHECK 01

Is it actually a trunk?

Use show interfaces trunk and check the operational state.

CHECK 02

Is the VLAN allowed?

Check that the required VLAN appears in the allowed VLAN list.

CHECK 03

Does the VLAN exist?

Use show vlan brief to confirm the VLAN exists and is active where required.

CHECK 04

Native VLAN mismatch?

Check that both sides of the trunk agree on the native VLAN.

13 // Follow the frame

PC-A sends traffic to PC-C.

Both PCs are in VLAN 10 but are connected to different switches.

1. PC-A sends an ordinary Ethernet frame into its VLAN 10 access port on SW1.

2. SW1 associates the frame with VLAN 10.

3. SW1 determines that the frame needs to leave through the trunk toward SW2.

4. On the trunk, the frame is identified as VLAN 10 using 802.1Q tagging, assuming VLAN 10 is not the native VLAN.

5. SW2 receives the trunk frame and recognises that it belongs to VLAN 10.

6. SW2 forwards it toward PC-C through the appropriate VLAN 10 access port.

Crucial point: the trunk allows VLAN 10 to extend across both switches. It does not route traffic between VLAN 10 and VLAN 20.
14 // Exam traps

Things worth remembering.

  • A trunk can carry traffic for multiple VLANs.
  • IEEE 802.1Q is the Ethernet VLAN-tagging standard you should associate with CCNA trunking.
  • An access port and a trunk port serve different purposes.
  • Native VLAN traffic is normally untagged on an 802.1Q trunk.
  • The native VLAN should match at both ends of the trunk.
  • An allowed VLAN list controls which VLANs may traverse a trunk.
  • A VLAN being present on both switches does not automatically mean it is permitted across a restricted trunk.
  • A trunk extends Layer 2 VLAN connectivity. It does not perform inter-VLAN routing.
  • show interfaces trunk is a key verification and troubleshooting command.
15 // Quick reference

Commands to remember.

# Configure static trunk
interface gigabitEthernet 0/1
 switchport mode trunk

# Allow selected VLANs
 switchport trunk allowed vlan 10,20

# Configure native VLAN
 switchport trunk native vlan 99

# Verify trunks
show interfaces trunk

# Inspect one switchport
show interfaces gigabitEthernet 0/1 switchport

# Verify VLANs
show vlan brief
16 // Test yourself

Trunks & 802.1Q quick quiz

1. What is the main purpose of a VLAN trunk?

2. Which standard is associated with VLAN tagging on Ethernet trunks?

3. Which Cisco IOS command statically configures a switchport as a trunk?

4. How is native VLAN traffic normally sent over an 802.1Q trunk?

5. Which command is most useful for quickly viewing active trunk interfaces, native VLANs and allowed VLANs?

6. VLAN 30 exists on SW1 and SW2, but the trunk only allows VLANs 10 and 20. What happens to VLAN 30 traffic across that trunk?

7. Does an 802.1Q trunk provide routing between VLAN 10 and VLAN 20?

Score: 0 / 7