IntermediatePublished 2026-06-25
Voice & Data VLANs: Access + Trunk Allowed Lists
Bundle lab
Configure a two-switch access layer with data and voice VLANs on access ports and an 802.1Q trunk between switches. Add a router-on-a-stick gateway for VLAN 10/20. Verify VLAN placement, trunk status, and observe a connectivity failure caused by an allow-list misconfiguration on the inter-switch trunk—then correct it to restore intra-VLAN reachability.
Learning objectives
- Create and name VLANs for data and voice segmentation
- Configure access ports with both a data VLAN and a voice VLAN
- Build and harden 802.1Q trunks (native VLAN and allowed VLANs)
- Implement router-on-a-stick as the default gateway for user/voice VLANs
- Verify VLAN membership and trunk status with show commands
- Diagnose and fix trunk allow-list issues that break VLAN transport
Troubleshooting focus
- Detect missing VLANs in a trunk’s allowed list when same-VLAN hosts can’t talk across switches
- Spot access-port VLAN/voice-VLAN mismatches using show vlan / show interfaces switchport
- Identify native VLAN mismatches on a trunk that trigger STP/l2 issues or control-plane leaks
- Recognize when DTP negotiation is disabled but trunk mode wasn’t explicitly set on both ends
- Use end-host pings to triangulate which trunk/path is failing
Topology
Subscribe to preview this lab's topology.
See plansGrade your work
How this lab is graded
- Build it your way. Where a lab lets you choose a value — a VLAN name, an interface description — grading checks that you configured it, not which name you picked. Names that another line has to reference, like an ACL applied with
access-class, are stated in the guide and do have to match. - Addresses, modes and protocol keywords are exact. An IP address, a subnet mask,
switchport mode trunk, an encapsulation — these carry the meaning of the lab, so they are graded as written in the guide. - Grading reads your saved configuration. Export the lab from CML after you have configured it, and make sure anything you set is in the running-config — a change that only exists in a terminal session never reaches the grader.
- You can submit as many times as you like. Your best score stands, and each attempt tells you which checks passed so you can work the gaps.
- Scored something you believe is correct? Use Report an issue on this page — that is exactly how the grading fixes in the changelog got found.
Create a free account to submit your lab for grading.
Create a free accountFound a problem with this lab?
Please sign in to report a problem — tying it to your attempts lets us reproduce and fix it faster.