Topic

802.1Q practice labs

34 hands-on 802.1Q scenarios you build in your own Cisco Modeling Labs instance and grade against the answer key. 802.1Q configuration and troubleshooting practice for CCNA and CCNP.

Two VLANs, a trunk, and a router to join them — the reference wiring for VLANs, Trunking & Inter-VLAN Routing, not a specific lab.

Included with a subscription

BeginnerDailyLocked

CCNA Break/Fix: The Trunk That Carries Only Some VLANs

A compact two-switch, two-host CML lab focused on troubleshooting an 802.1Q trunk. One VLAN traverses the trunk, another does not. Learners must read trunk state on both ends, compare against the intended design, and correct the mismatch without disrupting the working VLAN. Includes a second subtle trunk hygiene fault (native VLAN mismatch) that must be standardized.

CCNA35 min4 objectives

IntermediateLocked

Layer-2 Trunk EtherChannel Carrying Multiple VLANs

Build a two-link LACP EtherChannel between SW1 and SW2 and convert the Port-channel into an 802.1Q trunk that explicitly carries VLANs 40 and 41. Validate end-to-end host reachability across VLAN 40 and confirm the trunk’s allowed VLAN list and switchport mode on the logical port-channel. Emphasis: deterministic EtherChannel configuration on member interfaces, correct trunking on the Port-channel, and verification with IOS show commands.

CCNA55 min5 objectives

IntermediateDailyLocked

Inter-VLAN Routing: Router-on-a-Stick Across a Branch

Deploy router-on-a-stick inter-VLAN routing across a compact branch topology with a distribution and access switch, a hardened 802.1Q trunk, and two user VLANs. Configure VLANs and access/trunk ports, build router subinterfaces, verify end-to-end user reachability, and troubleshoot trunk/native-VLAN/subinterface mismatches.

CCNA55 min5 objectives

IntermediateLocked

Multi-Dept Campus Inter-VLAN with Router-on-a-Stick

Design and implement a three-department campus edge using a single router-on-a-stick to provide inter-VLAN routing for Sales (VLAN 10), Engineering (VLAN 20), and Servers (VLAN 30). Map the addressing plan directly to router subinterfaces and build an 802.1Q trunk on the access switch. Verify end-to-end reachability and troubleshoot an allow-list drift scenario.

CCNA55 min5 objectives

IntermediateLocked

Scaling to Three VLANs: Adding a Department

Extend a working two-VLAN router-on-a-stick design to a third VLAN (Guest) without breaking Sales and Engineering. Add one router subinterface, one switch VLAN + access port, and update the switch trunk’s allowed-VLAN list safely using 'add' so existing VLANs remain transported.

CCNA55 min5 objectives

BeginnerLocked

Switch Trunk and Access Ports for Router-on-a-Stick

Configure the Layer-2 switch side of a router-on-a-stick design. A single IOS router already provides inter-VLAN routing on Ethernet0/0.10 (10.0.10.1/24) and Ethernet0/0.20 (10.0.20.1/24). Bring up VLAN transport by creating VLANs on the switch, assigning host access ports, and converting the router-facing link into an 802.1Q trunk that carries VLANs 10 and 20. Validate with show commands on the switch and with cross-VLAN pings from the hosts.

CCNA30 min4 objectives

AdvancedLocked

Router-on-a-Stick Troubleshooting Capstone

Advanced CCNA capstone: diagnose and repair a fully-broken three-VLAN router-on-a-stick deployment. One iol-xe router uplinks by 802.1Q trunk to a pure layer-2 ioll2-xe switch, with three alpine PCs on their own access VLANs (10 Sales, 20 Voice, 30 CCTV); after a recent switch and router change, inter-VLAN connectivity is broken or intermittent across all three VLANs. Trace VLAN intent end-to-end from each host through the trunk to the router's subinterfaces, repair whatever faults you find, and verify with end-host pings/traceroutes and IOS show commands.

CCNA68 min5 objectives

BeginnerLocked

dot1Q Subinterfaces: The Router Side

Practice creating 802.1Q subinterfaces on a single router uplink to deliver inter-VLAN routing using router-on-a-stick. The Layer-2 switch is already fully configured with VLAN 10 and VLAN 20, access ports for two hosts, and a working 802.1Q trunk to the router. Your job: leave the router's physical Ethernet0/0 unnumbered and add exactly two subinterfaces with the correct encapsulation tags and gateway IPs so hosts can reach their gateways and each other.

CCNA35 min4 objectives

IntermediateLocked

Native VLAN on a Router-on-a-Stick Trunk

Build and verify inter-VLAN routing using router-on-a-stick with a native (untagged) VLAN on the trunk. Configure one router (subinterfaces only), one Layer-2 access switch (VLANs, access ports, and a single 802.1Q trunk), and two end hosts in different VLANs. The management VLAN 99 rides untagged as the trunk's native VLAN, so the router subinterface must use 'encapsulation dot1Q 99 native' and the switch trunk must match 'switchport trunk native vlan 99'. Verify from Linux hosts and IOS 'show' commands, then practice troubleshooting common native-VLAN faults.

CCNA50 min4 objectives

IntermediateLocked

Three-VLAN Router-on-a-Stick: Build, Harden & Verify

Build and verify a three-VLAN router-on-a-stick design: one IOS router provides inter-VLAN routing via 802.1Q subinterfaces to a single Layer-2 access switch, with three Alpine hosts in VLANs 10, 20, and 30. The starter environment does not yet forward traffic correctly between all three VLANs, so you will apply a disciplined router-switch-host verification method to diagnose and fix the problem, then briefly break and restore one VLAN's connectivity before finishing with an enterprise-clean, hardened trunk.

CCNA68 min5 objectives

AdvancedLocked

802.1Q Trunking Troubleshooting Capstone

Advanced CCNA switching capstone centered on restoring end-to-end VLAN 20 transport across three Layer-2 switches using 802.1Q trunks. The starter ships intentionally broken: after a simulated maintenance window, two Alpine hosts in VLAN 20 can no longer reach each other across the inter-switch trunks. Learners diagnose with show interfaces trunk, show interfaces switchport, and show vlan brief, then identify and correct the trunking faults in the right order and verify with host pings.

CCNA55 min5 objectives

IntermediateLocked

A Policy-Correct Multi-VLAN Trunk

Build a single 802.1Q trunk between two Layer-2 switches that correctly carries three VLANs with an explicit allow-list and a dedicated non-default native VLAN. Place hosts in Users (VLAN 10) across both switches and a server in Servers (VLAN 20). Verify that the trunk allows VLANs 10, 20, and 99, that the native VLAN matches on both ends, and that same-VLAN hosts communicate across the trunk. Then intentionally break and restore the configuration to practice troubleshooting trunk allow-lists, native VLAN alignment, and host VLAN placement.

CCNA47 min5 objectives

IntermediateLocked

CCNA: Pruning the Allowed VLAN List on Trunks

Hands-on CCNA lab focusing on 802.1Q trunk allow-lists. Build a realistic three-switch campus with two user hosts in VLAN 10. First bring up trunks carrying all VLANs by default, then implement an explicit allowed VLAN list and prune a non-used VLAN. Intentionally remove VLAN 10 from one trunk to observe an outage, verify with Linux pings and IOS show commands, and restore service by fixing the allow-list. Reinforce native VLAN alignment and compare default vs explicit trunk policy.

CCNA48 min5 objectives

BeginnerFree2026-06-30

802.1Q Trunk Fundamentals: Static Trunk and VLANs

Build a static 802.1Q trunk between two Layer-2 switches to carry VLANs 10 and 20. Map hosts to access ports, verify trunk encapsulation and allowed VLANs, demonstrate same-VLAN reachability across the trunk, and confirm inter-VLAN isolation. Then simulate an allow-list drift fault, diagnose with show commands, and restore service.

CCNA45 min5 objectives

Free with an account

IntermediateLocked

Port Security: Static Secure MAC Binding

Troubleshoot a Layer-2 forwarding fault that breaks a user VLAN between access/distribution switches, then implement static secure MAC binding on the client-facing access port. You will restore end-to-end VLAN 20 reachability and enforce a single authorized MAC on the user port using port-security with violation restrict.

CCNA55 min5 objectives

AdvancedLocked

Trunk Verification & Diagnosing a Silent VLAN

An advanced CCNA switching lab focused on verifying 802.1Q trunks and diagnosing a silent VLAN after a switch refresh. The topology uses three layer-2 switches (a distribution switch between two access closets) and two Alpine hosts, and users in VLAN 20 at one closet cannot reach their VLAN 20 peers at the other closet across the trunk path. Learners use show interfaces trunk, show interfaces switchport, and show vlan brief to locate the break and restore predictable Layer-2 forwarding without adding any Layer-3 configuration.

CCNA55 min5 objectives

BeginnerLocked

Trunking Basics: Access Ports vs Trunk Ports

Hands-on CCNA switching lab contrasting single-VLAN access ports with 802.1Q trunks. You begin with the inter-switch link configured as a plain access port, so only one VLAN reaches the router-on-a-stick gateway while the other cannot. You will diagnose the connectivity problem, convert the link into a properly hardened 802.1Q trunk, and validate that both VLANs regain access to their gateway.

CCNA55 min5 objectives

IntermediateLocked

CCNA: Native VLAN & Untagged Traffic on 802.1Q

Hands-on CCNA switching lab focused on the native VLAN and tagging behavior on 802.1Q trunks. Users in one VLAN currently cannot reach their peers across a switch-to-switch trunk; you will standardize the native VLAN away from VLAN 1 to a dedicated parking VLAN, diagnose and correct the trunk configuration, verify the untagged VLAN on both ends, and confirm same-VLAN host reachability across the trunk.

CCNA55 min6 objectives

IntermediateLocked

Native VLAN Mismatch: Diagnosing a Broken Trunk with CDP

Diagnose and remediate a trunk misconfiguration between an access switch and a distribution switch so that same-VLAN hosts across two access switches can communicate end-to-end. Use CDP and trunk verification commands to investigate the fault and restore proper trunk operation, without introducing any Layer-3 routing.

CCNA45 min5 objectives

IntermediateLocked

CCNA VLAN Trunking 7: Trunking Across Three Switches

Build an end-to-end 802.1Q path across three Cisco IOS Layer-2 switches so VLAN 10 transports user traffic from an access port on the left switch to an access port on the right switch through a middle switch. Harden trunks (native VLAN 999, nonegotiate) and verify with show interfaces trunk. Then intentionally break the allow-list to see the outage and restore service.

CCNA45 min5 objectives

IntermediateLocked

VLAN Trunking 6: DTP and Trunk Hardening

Hands-on DTP negotiation and trunk hardening across a 3-switch path. You will observe dynamic trunking behavior (auto vs desirable), fix an allow-list drift that blocks user VLAN transport, and then harden the trunks to static with nonegotiate and a non-default native VLAN. End-to-end host reachability in the same VLAN proves success.

CCNA55 min6 objectives

AdvancedDailyLocked

Branch Layer 2 Capstone: Build, Verify & Fix VLANs and Trunks

Advanced Layer-2 capstone, run as a fault hunt. A branch was cut over last night: one user VLAN has no gateway, another user sits in the wrong subnet, the management VLAN is unreachable from the distribution switch, and a port that should lock to one MAC no longer does. Nothing was recorded. You get symptoms and the required end state — no fault list. Faults span the router and both switches, and more than one of them presents as 'the trunk is broken'.

CCNA75 min5 objectives

IntermediateLocked

Port Membership & Trunking: VLAN Assignment + Verification

Hands-on CCNA VLAN and trunking lab: assign access ports by interface range, build and harden 802.1Q trunks, set a dedicated native VLAN, correct a misassigned user port, and verify VLAN membership. Includes a cross-switch path with a router-on-a-stick gateway, tests from real hosts, and troubleshooting of trunk allow-lists and native VLAN mismatches.

CCNA70 min6 objectives

AdvancedLocked

Multi-VLAN Segmentation: 3 VLANs & Trunk Alignment

Hands-on CCNA campus switching lab with two Layer-2 switches and three VLANs (Users 10, Servers 20, Management 99) extended over a single 802.1Q trunk. Learners deploy VLANs and access ports, harden the trunk (native VLAN 999, explicit allow-list, nonegotiate), and validate isolation. The lab ships with a trunk-carried outage: VLAN 10 traffic reaches its gateway successfully, but VLAN 20 traffic does not. You will diagnose from end hosts, confirm switch states, and correct the trunk so that same-VLAN traffic to the gateway SVI succeeds while inter-VLAN forwarding remains absent.

CCNA75 min5 objectives

Practicing 802.1Q trunking on Cisco Modeling Labs

Why it matters, and what these labs cover.

802.1Q trunking is what lets more than one VLAN cross a single link, so it sits underneath nearly every campus design: switch-to-switch uplinks, router-on-a-stick, and the port-channels between distribution switches. The mechanics are easy to state, a 4-byte tag identifies the VLAN and one VLAN per trunk (the native VLAN) crosses untagged, and the failure modes are what actually cost people points. A VLAN missing from the allowed list produces no error message anywhere; the trunk is up, the VLAN is up, and traffic simply does not arrive. A native VLAN mismatch keeps forwarding while quietly bridging two VLANs together. You catch those by learning to read the columns of show interfaces trunk on both ends of a link, which is a skill that only develops with a CLI in front of you.

These labs build trunks on real Cisco IOS in Cisco Modeling Labs. You will set switchport trunk encapsulation dot1q where the platform requires it, force the mode with switchport mode trunk rather than leaving DTP to negotiate, lock negotiation down with switchport nonegotiate, restrict the link with switchport trunk allowed vlan 10,20,99, extend it safely with the add keyword instead of replacing the whole list, and move the native VLAN off VLAN 1 with switchport trunk native vlan 99. Verification is show interfaces trunk for the mode, native VLAN, and the allowed versus allowed-and-active columns, show interfaces switchport to confirm negotiation of trunking is off, and show vlan brief to prove the VLAN exists on both switches. Fault labs give you a native VLAN mismatch and its CDP log message, an allowed list that was overwritten instead of appended, and two ends left on dynamic auto so the link never trunks at all. Your uploaded config is graded requirement by requirement against the answer key.

Frequently asked questions

Should I let DTP negotiate the trunk or hard-set it?

Hard-set both ends with switchport mode trunk, then add switchport nonegotiate. Dynamic desirable actively asks the neighbor to trunk and dynamic auto only responds, so two auto ends never form a trunk and the link silently stays an access port. Disabling DTP on a link you have already forced to trunk also removes the switch-spoofing VLAN-hopping vector at no cost.

What actually breaks when the native VLAN does not match?

Each switch places the other side untagged frames into its own native VLAN, so traffic from two different VLANs merges at Layer 2. The trunk keeps forwarding, which is why it is easy to miss. CDP logs a native VLAN mismatch and per-VLAN spanning tree can go inconsistent on that link. The fix is to compare the native VLAN column of show interfaces trunk on both switches and set them to the same unused VLAN.

What do I need to run these trunking labs?

Your own Cisco Modeling Labs instance and nothing else. Each topology is a YAML package on CML free-tier switch images, so a two-switch trunk with hosts on either side costs nothing beyond CML itself, and the show interfaces trunk output you read is genuine IOS rather than a simulator approximation of it.

Learn 802.1Q

Study the theory behind these labs — the concept explainer and step-by-step guides.

Looking for something else? Browse the full lab archive, narrow it to self-standing labs, or see today's daily lab.