IntermediatePublished 2026-06-30
CCNA: Pruning the Allowed VLAN List on Trunks
Bundle lab
Hands-on CCNA lab focusing on 802.1Q trunk allow-lists. Build a realistic three-switch campus with two user hosts in VLAN 10. First bring up trunks carrying all VLANs by default, then implement an explicit allowed VLAN list and prune a non-used VLAN. Intentionally remove VLAN 10 from one trunk to observe an outage, verify with Linux pings and IOS show commands, and restore service by fixing the allow-list. Reinforce native VLAN alignment and compare default vs explicit trunk policy.
Learning objectives
- Create VLANs and map access ports correctly for end hosts
- Build 802.1Q trunks and compare default all-VLAN behavior to an explicit allow-list
- Curate each trunk's VLAN allow-list (adding, removing, or excepting VLANs as needed) to control trunk transport
- Align native VLAN on both ends and harden trunks with nonegotiate
- Verify trunk/allowed sets and diagnose an allow-list outage with show interfaces trunk and end-host pings
Troubleshooting focus
- Detect a missing VLAN on a trunk allow-list causing inter-switch isolation of that VLAN
- Identify native VLAN mismatches and their symptoms
- Catch host ports placed in the wrong access VLAN during onboarding
Topology
Subscribe to preview this lab's topology.
See plansGrade your work
How this lab is graded
- Build it your way. Where a lab lets you choose a value — a VLAN name, an interface description — grading checks that you configured it, not which name you picked. Names that another line has to reference, like an ACL applied with
access-class, are stated in the guide and do have to match. - Addresses, modes and protocol keywords are exact. An IP address, a subnet mask,
switchport mode trunk, an encapsulation — these carry the meaning of the lab, so they are graded as written in the guide. - Grading reads your saved configuration. Export the lab from CML after you have configured it, and make sure anything you set is in the running-config — a change that only exists in a terminal session never reaches the grader.
- You can submit as many times as you like. Your best score stands, and each attempt tells you which checks passed so you can work the gaps.
- Scored something you believe is correct? Use Report an issue on this page — that is exactly how the grading fixes in the changelog got found.
Create a free account to submit your lab for grading.
Create a free accountFound a problem with this lab?
Please sign in to report a problem — tying it to your attempts lets us reproduce and fix it faster.