IntermediatePublished 2026-06-25
Native VLAN & Trunk Mismatch: Detection and Recovery
Bundle lab
Configure VLANs and 802.1Q trunks across two access switches with a router-on-a-stick gateway. Intentionally misconfigure the native VLAN and trunk allow-list to observe loss of intra-VLAN connectivity, detect the mismatch using switch warnings and show commands, and then remediate to restore user reachability. Validates VLAN segmentation, trunking symmetry, and troubleshooting skills for CCNA candidates.
Learning objectives
- Create VLANs for users and management and assign access ports
- Build and harden 802.1Q trunks with an explicit allowed VLAN list and a non-default native VLAN
- Detect native VLAN mismatches using syslog/CDP warnings and show commands
- Identify and correct missing VLANs on trunk allow-lists
- Validate intra-VLAN reachability end-to-end and document the fix
Troubleshooting focus
- CDP logs a native VLAN mismatch: compare the native VLAN on both trunk ends with
show cdp neighbors detail. They must be identical (999); fix the side that differs. - CLIENT10 cannot reach CLIENT20: run
show interfaces trunk. If VLAN 20 is absent from "Vlans in spanning tree forwarding state and not pruned", add it to the allowed list on both trunk ends. - A host cannot reach its own gateway: check the access port's VLAN with
show vlan briefand ensure PortFast is enabled on that port. - The VLAN gateways do not respond: confirm the router parent interface has no IP, the subinterfaces are up/up with dot1Q encapsulation, and the switch trunk carries those VLANs.
- You cannot reach the switch SVIs in VLAN 30: ensure the SVI is up/up, VLAN 30 is allowed on both trunks, and
ip default-gatewayis set on each switch.
Topology
Subscribe to preview this lab's topology.
See plansGrade your work
How this lab is graded
- Build it your way. Where a lab lets you choose a value — a VLAN name, an interface description — grading checks that you configured it, not which name you picked. Names that another line has to reference, like an ACL applied with
access-class, are stated in the guide and do have to match. - Addresses, modes and protocol keywords are exact. An IP address, a subnet mask,
switchport mode trunk, an encapsulation — these carry the meaning of the lab, so they are graded as written in the guide. - Grading reads your saved configuration. Export the lab from CML after you have configured it, and make sure anything you set is in the running-config — a change that only exists in a terminal session never reaches the grader.
- You can submit as many times as you like. Your best score stands, and each attempt tells you which checks passed so you can work the gaps.
- Scored something you believe is correct? Use Report an issue on this page — that is exactly how the grading fixes in the changelog got found.
Create a free account to submit your lab for grading.
Create a free accountFound a problem with this lab?
Please sign in to report a problem — tying it to your attempts lets us reproduce and fix it faster.