Guided buildcore7 steps~15 min5 devices
Two departments, one switch
Split a single switch into Sales and Ops with VLANs, and watch the pings between them stop.
What you'll be able to do: Sales desks talk to Sales desks and Ops desks talk to Ops desks, on the same switch, with nothing able to cross between them until a router is added.
Topics: VLANs · Broadcast domains · Access ports · Layer 2 segmentation
What you'll build
- SW-Floor1 — a switch, the floor switch every desk plugs into
- PC-Sales-A — a pc, the first Sales desk
- PC-Sales-B — a pc, the second Sales desk
- PC-Ops-A — a pc, the first Ops desk
- PC-Ops-B — a pc, the second Ops desk
Step by step
1. Place the switch and name it
Drag one switch onto the canvas. The canvas gives it a placeholder name, so the first thing you type is a hostname of your own — every later step and every check refers to this device as SW-Floor1, and a named device is the only way to tell two switches apart in a console tab.
On SW-Floor1 — Name the switch
enable configure terminal hostname SW-Floor1 endCheck: run
show running-configon SW-Floor1 and look forhostname SW-Floor1.Why: A hostname is how a device identifies itself beyond its own console: discovery protocols like LLDP announce it to neighbours, and logs and people refer to the box by it. Setting it first means everything that happens afterwards is recorded against the right name.
2. Plug in the two Sales desks
Drag two PCs on and run a copper cable from each one's Eth0 to a switch port. Switch ports need no configuration to carry traffic — they come up as soon as they see a neighbour, which is why an unconfigured switch is a working network out of the box.
- Cable PC-Sales-A Eth0 ↔ SW-Floor1 Fa0/1
- Cable PC-Sales-B Eth0 ↔ SW-Floor1 Fa0/2
Check: run
show interfaces statuson SW-Floor1 and look forFa0/2 connected 1 auto 100 fastethernet.Why: Every port on an unconfigured switch already belongs to VLAN 1, which is why the Vlan column of `show interfaces status` reads 1 before you have typed anything. A factory switch is therefore one VLAN and one broadcast domain across all of its ports — the starting point this build is about to divide.
3. Address the Sales pair
Name each PC and give it an address in 192.168.1.0/24. Two hosts in one subnet on one switch need nothing else to reach each other — no gateway, no routes — so the ping succeeds the moment the second address lands.
On PC-Sales-A — Name the first Sales desk and address it
hostname PC-Sales-A ipconfig Eth0 192.168.1.11 255.255.255.0On PC-Sales-B — Name the second Sales desk and address it
hostname PC-Sales-B ipconfig Eth0 192.168.1.12 255.255.255.0On PC-Sales-A — Check that one Sales desk reaches the other
ping 192.168.1.12Check: run
ipconfigon PC-Sales-A and look forIPv4 Address. . . . . . . . . . : 192.168.1.11.Why: Two hosts talk directly only when two things are true at once: their masks put them in the same subnet, and the network puts them in the same broadcast domain, so that ARP can find one from the other. Right now both are true; the rest of this build pulls the two apart to show that each one matters on its own.
4. Add the Ops desks to the same flat network
Ops gets the same treatment: two PCs, two cables, two addresses in the same 192.168.1.0/24. Now ping from Sales to Ops. It works, and that is the problem — a switch with default settings is one broadcast domain, so every desk reaches every other desk and hears every broadcast, whichever department it belongs to.
- Cable PC-Ops-A Eth0 ↔ SW-Floor1 Fa0/3
- Cable PC-Ops-B Eth0 ↔ SW-Floor1 Fa0/4
On PC-Ops-A — Name the first Ops desk and address it
hostname PC-Ops-A ipconfig Eth0 192.168.1.21 255.255.255.0On PC-Ops-B — Name the second Ops desk and address it
hostname PC-Ops-B ipconfig Eth0 192.168.1.22 255.255.255.0On PC-Sales-A — Prove there is nothing between the two departments yet
ping 192.168.1.21 ping 192.168.1.22Check: run
show vlan briefon SW-Floor1 and look for1 default active Fa0/1, Fa0/2, Fa0/3, Fa0/4,.Why: A broadcast domain is every device that receives a broadcast sent by any one of them. On a flat switch that is every port, so nothing at layer 2 separates the departments, and as the domain grows every ARP request and every other broadcast interrupts more hosts that have no interest in it.
5. Create the two VLANs
A VLAN is a separate broadcast domain living inside one switch. Create two of them and name them, so the next engineer reading the configuration knows what VLAN 10 is for. Nothing moves yet — a new VLAN starts empty, and the Ports column after this step proves it.
On SW-Floor1 — Add VLAN 10 and VLAN 20 to the switch's VLAN database
enable configure terminal vlan 10 name Sales exit vlan 20 name Ops exit endCheck: run
show vlan briefon SW-Floor1 and look for10 Sales active.Why: Creating a VLAN only adds an entry to the switch's VLAN database: a number, a name and a state. Membership is a property of each port and is assigned separately, so the switch now knows the new broadcast domain exists even though nothing lives in it yet.
6. Move the Sales desks into VLAN 10
An access port belongs to exactly one VLAN and carries that VLAN's traffic untagged, which is what an ordinary PC expects. Put Fa0/1 and Fa0/2 into VLAN 10, then run the two pings again: Sales to Sales still works, Sales to Ops stops. No address changed, so the only thing in the way is the VLAN boundary.
On SW-Floor1 — Make the two Sales ports access ports in VLAN 10
enable configure terminal interface Fa0/1 switchport mode access switchport access vlan 10 exit interface Fa0/2 switchport mode access switchport access vlan 10 exit endOn PC-Sales-A — One ping still works, the other now fails
ping 192.168.1.12 ping 192.168.1.21Check: run
show vlan briefon SW-Floor1 and look for10 Sales active Fa0/1, Fa0/2.Why: A switch delivers a frame only to ports in the VLAN it arrived in, and that includes broadcasts. PC-Sales-A still believes 192.168.1.21 is local and sends an ARP request for it, but the request stays inside VLAN 10 and never reaches the Ops ports, so no reply comes back and the ping dies before a single echo is sent.
7. Finish the split: Ops gets its own VLAN and its own subnet
Leaving Ops in VLAN 1 happens to work, but VLAN 1 is where every unconfigured port lands, so any desk plugged in anywhere would join Ops by accident. Move Fa0/3 and Fa0/4 into VLAN 20, then re-address Ops into 192.168.2.0/24: you have already proved the wall is the VLAN, and one broadcast domain per subnet is the shape a router needs before it can carry traffic between them.
On SW-Floor1 — Make the two Ops ports access ports in VLAN 20
enable configure terminal interface Fa0/3 switchport mode access switchport access vlan 20 exit interface Fa0/4 switchport mode access switchport access vlan 20 exit endOn PC-Ops-A — Re-address the first Ops desk into the Ops subnet
ipconfig Eth0 192.168.2.21 255.255.255.0On PC-Ops-B — Re-address the second Ops desk into the Ops subnet
ipconfig Eth0 192.168.2.22 255.255.255.0On PC-Ops-A — Ops still reaches Ops, and Sales stays out of reach
ping 192.168.2.22 ping 192.168.1.11Check: run
show vlan briefon SW-Floor1 and look for20 Ops active Fa0/3, Fa0/4.Why: The rule is one VLAN, one subnet, because hosts decide whether to use a gateway by comparing subnets. While Sales and Ops shared 192.168.1.0/24, each side considered the other local and ARPed for it directly, so even with a router attached no packet between them would ever have been handed to it.
The theory behind it
More in Switching & wireless
- Map the network with CDP and LLDP — Let two switches and a router discover each other, find the router's address from a switch that was never told it, add LLDP, then stop the router announcing itself toward the internet.
- One VLAN across two switches — Split four PCs into two VLANs across two switches, then carry both VLANs between the switches over a single tagged trunk.
- Router on a stick — Split one switch into two VLANs and route between them over a single router port.
- Route between VLANs on the switch — Give one switch an SVI in each VLAN, find out why the VLANs still can't talk, then turn on ip routing — inter-VLAN routing with no router at all.
- Choose your root bridge — Close a loop of three switches, find the port spanning tree blocks on its own, then decide which switch is root — and which one takes over when it fails.
- Two cables, one logical link — Add a second uplink between two switches, watch spanning tree block it, then bundle both into an LACP EtherChannel so they carry traffic together.
Build it for real
The lab walks you through these steps and ticks each one off as your network starts working.
Open in the lab