All guided builds

Troubleshooting labcore6 steps~15 min5 devices

Fix the VLAN that stops at the trunk

Engineering's server is unreachable and the south desk is cut off completely. Find the wrong VLAN and the trunk that drops it.

What you'll be able to do: Every engineering host reaches the build server across both switches, and you can tell a port in the wrong VLAN from a trunk that refuses a VLAN using nothing but `show vlan brief` and `show interfaces trunk`.

Topics: Troubleshooting · VLANs · Trunking · Access ports

The network you're handed

Step by step

  1. 1. Scope the outage before touching anything

    Engineering says the build server is down. Test from both desks: PC-Eng-N sits on the same switch as the server, PC-Eng-S is on the far side of the trunk. Then check the addressing — every host should be in 192.168.20.0/24.

    On PC-Eng-N — Test the server from the desk on the same switch

    ping 192.168.20.5
    ipconfig

    On PC-Eng-S — Test the server and the other desk from across the trunk

    ping 192.168.20.5
    ping 192.168.20.11

    Check: run ipconfig on PC-Eng-N and look for IPv4 Address. . . . . . . . . . : 192.168.20.11.

    Why: All three hosts share one subnet, so none of them uses a gateway and no router is involved — the fault is at layer 1 or layer 2. And because PC-Eng-N cannot reach a server on its OWN switch, at least one fault has nothing to do with the trunk. Start with the smallest broken piece: two ports on SW-North.

  2. 2. Read the north switch's VLAN table

    Two hosts in the same subnet on the same switch can only fail to talk if something separates them at layer 2. `show vlan brief` lists every VLAN with the access ports in it — find Fa0/1 (the server) and Fa0/2 (PC-Eng-N).

    On SW-North — List each VLAN and the ports in it

    enable
    show vlan brief

    Check: run show vlan brief on SW-North and look for 10 SALES active Fa0/1.

    Why: A VLAN is a separate broadcast domain, so the server's ARP replies never reach a host in another VLAN — even one plugged in a port away. The server's port sits in SALES while PC-Eng-N's port sits in ENG: same subnet on paper, two different networks on the wire.

  3. 3. Move the server's port into the engineering VLAN

    Put Fa0/1 into VLAN 20 and retest from PC-Eng-N. The server and the host have not changed at all — only the port between them.

    On SW-North — Reassign the server's access port to VLAN 20

    enable
    configure terminal
    interface Fa0/1
    switchport access vlan 20
    end

    On PC-Eng-N — Retest the server

    ping 192.168.20.5

    Check: run show vlan brief on SW-North and look for 20 ENG active Fa0/1, Fa0/2.

    Why: An access port belongs to exactly one VLAN and the host behind it never knows which. Fixing the membership on the switch fixes the host, without touching its address.

  4. 4. The south desk is still cut off — follow the frame onto the trunk

    PC-Eng-S still fails. Check its own port first, then the trunk from BOTH ends: `show interfaces trunk` lists the VLANs each end allows. A trunk can read `trunking` and still refuse a VLAN.

    On PC-Eng-S — Retest from the south desk

    ping 192.168.20.5

    On SW-South — Check the desk's port, then the south end of the trunk

    enable
    show vlan brief
    show interfaces trunk

    On SW-North — Check the north end of the same trunk

    enable
    show interfaces trunk

    Check: run show interfaces trunk on SW-South and look for Gi0/1 10.

    Why: The south desk's port is correctly in VLAN 20, which rules the host's own port out. Both trunk ends are up and trunking, which rules out the cable and the trunk mode. What is left is the allowed list: the north end allows 10 and 20, the south end allows only 10, so every VLAN 20 frame is dropped at the south end in both directions.

  5. 5. Let VLAN 20 onto the south end of the trunk

    Add VLAN 20 to SW-South's allowed list — add it, do not replace the list — and retest from the south desk.

    On SW-South — Append VLAN 20 to the trunk's allowed list

    enable
    configure terminal
    interface Gi0/1
    switchport trunk allowed vlan add 20
    end

    On PC-Eng-S — Retest across the trunk

    ping 192.168.20.5
    ping 192.168.20.11

    Check: run show interfaces trunk on SW-South and look for Gi0/1 10,20.

    Why: The allowed list is a filter each end applies on its own. With both ends now agreeing on 10 and 20, VLAN 20 frames are tagged across the link and delivered on the far side — and VLAN 10 carries on exactly as before.

  6. 6. Prove it from the server's side

    Ping the south desk from the server, then read SW-North's MAC address table: the south desk's MAC now appears learned on the trunk port Gi0/1, in VLAN 20 — proof that VLAN 20 frames really cross the link.

    On Build-Server — Test the path in the other direction

    ping 192.168.20.12

    On SW-North — See which port each engineering MAC was learned on

    enable
    show mac address-table

    Check: run show mac address-table on SW-North and look for DYNAMIC Gi0/1.

    Why: A switch learns a source MAC on the port the frame arrived on. An engineering MAC learned on the trunk port, in VLAN 20, can only have come across the trunk — the direct evidence that the allowed list now carries the VLAN.

The theory behind it

Build it for real

The lab walks you through these steps and ticks each one off as your network starts working.

Open in the lab
Fix the VLAN that stops at the trunk — step-by-step network lab · NetForge-AI