Network Access // Lesson 01

VLANs.

One physical switch does not have to mean one network. VLANs let us logically divide a switched LAN into separate Layer 2 broadcast domains — giving us segmentation without needing a separate switch for every network.

Broadcast domains VLAN IDs Access ports Cisco IOS Verification
01 // The idea

What is a VLAN?

A Virtual Local Area Network (VLAN) is a logical segmentation of a Layer 2 network.

Without VLANs, devices connected to the same switched LAN normally belong to the same Layer 2 broadcast domain. A broadcast such as an ARP request can therefore be flooded through that broadcast domain.

VLANs allow us to split the switch into multiple logical Layer 2 networks. Devices in VLAN 10 are in a different broadcast domain from devices in VLAN 20, even if they are connected to the same physical switch.

Key idea: each VLAN represents a separate Layer 2 broadcast domain.
02 // Why use them?

One switch. Multiple networks.

01

Segmentation

Separate groups of devices without buying physically separate switches.

02

Broadcast control

A Layer 2 broadcast remains inside its VLAN rather than being flooded into every other VLAN.

03

Organisation

Users, phones, servers, management devices and other systems can be placed into logical networks based on their purpose.

03 // See it

A switch with two VLANs

Imagine four computers connected to the same physical switch. Two ports belong to VLAN 10 and two belong to VLAN 20.

PC-A VLAN 10
PC-B VLAN 10
SW1 Layer 2 Switch
PC-C VLAN 20
PC-D VLAN 20

If PC-A sends a Layer 2 broadcast, SW1 can flood that broadcast to the appropriate ports in VLAN 10. It does not flood that frame into VLAN 20.

Likewise, broadcasts originating in VLAN 20 remain in VLAN 20.

Exam mindset: VLANs separate Layer 2 broadcast domains. Communication between VLANs requires a Layer 3 function, which we'll cover in the inter-VLAN routing lesson.
04 // VLAN IDs

Identifying a VLAN

VLANs are identified using a numeric VLAN ID.

VLAN Example purpose
10 Staff
20 Guest devices
30 VoIP phones
99 Network management

The numbers above are simply examples. The VLAN ID does not inherently mean "staff", "voice" or "management" — that meaning comes from the network design and configuration.

Normal and extended VLAN ranges

On Cisco switches you will commonly encounter:

  • 1–1005 — normal-range VLANs.
  • 1006–4094 — extended-range VLANs.

VLAN IDs are carried using a 12-bit VLAN identifier in an IEEE 802.1Q tag. The values 0 and 4095 are reserved, leaving usable VLAN IDs 1 through 4094.

05 // Access ports

Putting a device into a VLAN

A port connected to an ordinary endpoint such as a desktop computer is typically configured as an access port.

An access port belongs to one access VLAN and normally carries ordinary Ethernet frames to and from the endpoint without an 802.1Q VLAN tag. The switch internally associates traffic arriving on that port with the configured VLAN.

PC Normal Ethernet
Gi0/1 Access VLAN 10
VLAN 10 Broadcast domain
Access port: typically connects an endpoint to one VLAN.

Trunk port: can carry traffic for multiple VLANs. That's the next lesson.
06 // Configure

Create VLANs in Cisco IOS

Let's create two VLANs and give them useful names.

Switch> enable
Switch# configure terminal

Switch(config)# vlan 10
Switch(config-vlan)# name STAFF
Switch(config-vlan)# exit

Switch(config)# vlan 20
Switch(config-vlan)# name GUEST
Switch(config-vlan)# exit

At this point VLANs 10 and 20 exist on the switch, but we haven't yet assigned our endpoint ports to them.

07 // Configure

Configure an access port

Suppose a staff PC is connected to interface GigabitEthernet0/1. We want that interface to belong to VLAN 10.

Switch(config)# interface gigabitEthernet 0/1
Switch(config-if)# switchport mode access
Switch(config-if)# switchport access vlan 10
Switch(config-if)# no shutdown

Now configure another interface for a guest device in VLAN 20:

Switch(config)# interface gigabitEthernet 0/2
Switch(config-if)# switchport mode access
Switch(config-if)# switchport access vlan 20
Switch(config-if)# no shutdown
Useful habit: explicitly configuring switchport mode access makes the intended port role clear rather than relying on dynamic behaviour or defaults.
08 // Verify

Never trust the config. Verify it.

One of the most useful VLAN commands is:

Switch# show vlan brief

VLAN Name                             Status    Ports
---- -------------------------------- --------- -----------------------
1    default                          active    Gi0/3, Gi0/4
10   STAFF                            active    Gi0/1
20   GUEST                            active    Gi0/2

This quickly tells us:

For a specific interface, another useful command is:

Switch# show interfaces gigabitEthernet 0/1 switchport

Name: Gi0/1
Switchport: Enabled
Administrative Mode: static access
Operational Mode: static access
Access Mode VLAN: 10 (STAFF)
CCNA habit: learn the verification command alongside the configuration command. Being able to configure something is only half the job.
09 // Switching behaviour

MAC addresses are learned per VLAN

A switch learns source MAC addresses as Ethernet frames arrive. VLAN membership is part of the switching context, so the MAC address table associates learned addresses with a VLAN and interface.

Switch# show mac address-table

          Mac Address Table
-------------------------------------------

Vlan    Mac Address       Type        Ports
----    -----------       --------    -----
  10    0011.2233.4455    DYNAMIC     Gi0/1
  20    00aa.bbcc.ddee    DYNAMIC     Gi0/2

When forwarding a frame, the switch considers the destination MAC address within the relevant VLAN.

Remember: a Layer 2 switch can switch traffic between ports in the same VLAN. It does not perform ordinary Layer 3 routing between separate VLANs unless Layer 3 functionality is configured on a capable device.
10 // Troubleshooting

Why can't these two PCs communicate?

CHECK 01

Wrong VLAN

The interface may have been accidentally assigned to a different VLAN. Use show vlan brief.

CHECK 02

VLAN missing

Confirm the required VLAN exists on the switch.

CHECK 03

Port state

Check that the interface is operational and has not been administratively shut down.

CHECK 04

Different VLANs

Hosts in different VLANs require Layer 3 routing if they need to communicate with each other.

11 // Exam traps

Things worth remembering

  • A VLAN is a Layer 2 broadcast domain.
  • Devices can be in the same VLAN even when connected to different switches, provided the Layer 2 network is configured to carry that VLAN.
  • Being connected to the same physical switch does not mean two devices must be in the same VLAN.
  • An access port is normally associated with one access VLAN.
  • Traffic between different VLANs requires Layer 3 routing.
  • VLAN names are useful labels; forwarding behaviour is based on the VLAN configuration/ID, not the descriptive name.
  • show vlan brief is one of your most useful verification commands.
12 // Quick reference

Commands to remember

# Create VLAN
vlan 10
 name STAFF

# Configure access port
interface gigabitEthernet 0/1
 switchport mode access
 switchport access vlan 10

# Verify VLANs
show vlan brief

# Verify switchport
show interfaces gigabitEthernet 0/1 switchport

# View learned MAC addresses
show mac address-table
13 // Test yourself

VLAN quick quiz

1. What does a VLAN create?

2. Which command assigns an access interface to VLAN 20?

3. Which command is particularly useful for quickly checking VLAN membership?

4. PC-A is in VLAN 10 and PC-B is in VLAN 20. What is required for them to communicate?

5. Which statement about an access port is correct?

6. A broadcast arrives on an access port in VLAN 10. Which statement is correct?

7. What is the highest usable IEEE 802.1Q VLAN ID?

Score: 0 / 7