IntermediatePublished 2026-06-30
A Policy-Correct Multi-VLAN Trunk
Bundle lab
Build a single 802.1Q trunk between two Layer-2 switches that correctly carries three VLANs with an explicit allow-list and a dedicated non-default native VLAN. Place hosts in Users (VLAN 10) across both switches and a server in Servers (VLAN 20). Verify that the trunk allows VLANs 10, 20, and 99, that the native VLAN matches on both ends, and that same-VLAN hosts communicate across the trunk. Then intentionally break and restore the configuration to practice troubleshooting trunk allow-lists, native VLAN alignment, and host VLAN placement.
Learning objectives
- Create VLANs and map access ports to the correct VLANs on Layer-2 switches
- Configure a static 802.1Q trunk with an explicit allowed VLAN list and a non-default native VLAN
- Verify trunk status, allowed VLANs, and native VLAN symmetry using show interfaces trunk
- Validate end-host placement and intra-VLAN connectivity across a trunk
- Troubleshoot common trunk issues: omitted VLANs on allow-lists, native VLAN mismatches, and wrong access VLANs
Troubleshooting focus
- A native VLAN mismatch causes unexpected untagged/Native traffic behavior and warnings
- A required VLAN omitted from the trunk allow-list breaks cross-switch reachability for that VLAN
- An access port assigned to the wrong VLAN strands a host in the wrong broadcast domain
Topology
Subscribe to preview this lab's topology.
See plansGrade your work
How this lab is graded
- Build it your way. Where a lab lets you choose a value — a VLAN name, an interface description — grading checks that you configured it, not which name you picked. Names that another line has to reference, like an ACL applied with
access-class, are stated in the guide and do have to match. - Addresses, modes and protocol keywords are exact. An IP address, a subnet mask,
switchport mode trunk, an encapsulation — these carry the meaning of the lab, so they are graded as written in the guide. - Grading reads your saved configuration. Export the lab from CML after you have configured it, and make sure anything you set is in the running-config — a change that only exists in a terminal session never reaches the grader.
- You can submit as many times as you like. Your best score stands, and each attempt tells you which checks passed so you can work the gaps.
- Scored something you believe is correct? Use Report an issue on this page — that is exactly how the grading fixes in the changelog got found.
Create a free account to submit your lab for grading.
Create a free accountFound a problem with this lab?
Please sign in to report a problem — tying it to your attempts lets us reproduce and fix it faster.