CCNA Layer 2 Switching - Virtual Local Area Networks

by Leigh Anne Chisholm

  The History of Network Segmentation
  So What Is a VLAN?
  Why Do I Need It? Or DO I Need It?
How VLANs Work
  Configuring a VLAN
  Verifying VLAN Configuration
VLAN Trunking
  Configuring ISL Trunking
  Verifying Trunk Operation
  Removing a VLAN from a Trunk Link
VLAN Trunk Protocol (VTP)
  VTP Pruning
  Configuring VTP
  Verifying VTP Operation
Spanning Tree Protocol and VLANs - Cisco's Solution
  Verifying Spanning Tree Operation
Inter-VLAN Communication


This is the third in a series of Cisco Certified Network Associate (CCNA) LAN Switching White Papers published by CertificationZone. Since the publication of CertificationZone's original CCNA LAN Switching White Paper in May of 2000, Cisco updated its CCNA curriculum, downshifting much of the Advanced Cisco Router Configuration (ACRC) and Cisco LAN Switching Configuration (CLSC) curriculum into the new CCNA 2.0 preparation course -- "Interconnecting Cisco Network Devices." Cisco has expanded its scope, requiring a greater in-depth knowledge of CCNA Bridging and Switching topics, particularly in the areas of "Static VLANs," "Spantree," and "Switching modes/methods." As a direct result of the increased content in these topics, CertificationZone decided a new LAN switching paper was required. Since the scope of the material increased dramatically, it was decided that the CCNA 2.0 LAN Switching tutorial would be divided into two separate publications.

The first of the new CCNA Layer 2 Switching tutorials (published in January of 2001) covered basic Layer 2 bridging and switching technologies, examined Cisco's Catalyst series line of LAN switches, and provided an introduction to installing, configuring, and troubleshooting the Cisco Catalyst 1900 series LAN switch. This paper, the final tutorial in the CCNA 2.0 LAN Switching series looks at the theory and operation of Virtual Local Area Networks (VLANs).

After reading this tutorial, you should be able to:

Together, the two new CertificationZone CCNA LAN Switching tutorials touch on all of the knowledge areas required for the CCNA 2.0 exam. For up-to-date information of what LAN switching knowledge is required to pass the CCNA 2.0 exam, consult Cisco's web site.


Over the years, data networking requirements have changed drastically. Character-based systems have been replaced by graphic-intensive applications. The integration of voice, video, and data has brought new challenges -- and as requirements change, infrastructure support technology has evolved. Ethernet media has moved beyond the original 10 Mbps coaxial cable standard and now supports twisted pair copper media and fiber optics. Network segmentation options have been developed in an effort to resolve today's internetworking challenges -- namely those of bandwidth, security, and quality of service. VLANs are an outgrowth of network segmentation devices.

What is a VLAN? Why do I need it? Or rather, do I need it at all? What functionality does it offer me? What are the drawbacks of implementing VLANs in my network environment?

While VLANs are not strictly an Ethernet technology, the CCNA 2.0 curriculum focuses on VLANs from an Ethernet perspective. For information on implementing VLANs in Token Ring or FDDI environments, refer to Cisco's Web Site or consult Cisco Certified Network Professional or Cisco Certified Internetwork Expert level material.

The answer to all these questions begins with answering the first question, "What is a VLAN?" The definition is simple, but many network administrators fail to understand the benefits and drawbacks of implementing VLANs before they've made the decision to deploy the technology in their network. Far too often, administrators discover after the fact that they've added another layer of complexity to their network, making troubleshooting more difficult, and have not gained the anticipated results. Understanding the role that VLANs play in a network requires an examination of the problems and technologies that have led to the evolution of this technology. By looking at the problems and the technologies that have been developed to solve their respective issues, you can not only answer the question "What is a VLAN?" but will also be able to answer the questions "Why do I need it?" and "DO I (in fact) need it?"

The History of Network Segmentation

It was once said that if you placed an infinite number of monkeys in a room in front of an infinite number of typewriters, they would eventually reproduce the entire works of William Shakespeare. Modernizing the "Infinite Number of Monkeys" theorem requires that the infinite number of monkeys be placed in a room in front of an infinite number of computers each connected via a Local Area Network.

In a straight forward "shared-media" design, it is highly unlikely that the infinite number of monkeys would ever reproduce the entire works of William Shakespeare -- the amount of congestion on the network is likely to pale in comparison to the degree of frustration exhibited by the infinite number of monkeys. The greater the number of monkeys accessing network resources, the greater the demand for access to network media. Decreased network performance inevitably results in decreased productivity as monkeys (or end-users) wait for network-based applications to respond.

On an Ethernet-based LAN, an oversubscribed segment can experience an excessive number of collisions. To control oversubscription, the Ethernet specification establishes restrictions on the maximum number of devices that can exist on a populated Ethernet segment, defines the maximum length of a LAN segment, and limits overall diameter of the LAN topology. Even with strict adherence to these requirements, a local area network can still experience congestion.

The most common method of resolving media problems due to an oversubscription of bandwidth is by segmenting the network using an OSI model Layer 2 device known as "bridge" or "switch". The deployment of a Layer 2 device reduces the number of devices contending for access to network media thereby decreasing the traffic load on the original segment.

A Layer 2 device establishes separate collision domains between connected segments. By creating separate collision domains, multiple "maximum diameter Ethernet LANs" can be interconnected, effectively increasing the number of PCs that can exist within an Ethernet environment and bypassing the problems that restrict the diameter of the network.

Figure 1. Segmenting a Collision Domain

Even with the deployment of Layer 2 devices in a network environment, problems with oversubscription of network media could still exist. While it is possible to control the amount of end-user data on a given segment, Layer 2 devices do not restrict the propagation of broadcast traffic between segments. Broadcast traffic from sources such as Novell's "chatty " IPX protocol or Microsoft's NetBIOS name resolution process, if not readily confined, could monopolize the bandwidth of the entire network.

For example, let's look at "X Y Z Corporation." Their network infrastructure consists of over 2000 PCs configured to use IP, IPX, and NetBEUI. AppleTalk and DECnet are also configured on a handful of systems. Each department within the organization has been configured to function as either a Microsoft Workgroup or domain. The departments configured to operate as Microsoft Workgroups elected to base their server-applications on NetWare servers rather than Windows NT systems. The administration of all NetWare servers is the responsibility of the department, rather than the Information Systems team. Because there is no single authority overseeing the deployment of the NetWare systems, no common IPX network scheme exists, nor is there a corporate standard set for naming systems. It is not uncommon to see multiple frame types configured on each NetWare server and on all NetWare clients.

Although the Information Systems department has deployed a number of bridges within this environment in an attempt to localize network activity, there remains a significant amount of broadcast traffic being sent between Ethernet segments. A single broadcast storm would completely disable the entire network.

The Information Systems department of "X Y Z Corporation" could make an excellent case for increasing the capital expenditures budget to allow for the purchase of several Layer 3 devices known as "routers." A router would not only divide the collision domain into separate segments, but also divide the broadcast domain keeping broadcast traffic local to each connected segment. By reducing the number of broadcasts propagated between LAN segments, the overall traffic load of each segment decreases.

Figure 2. Segmenting a Broadcast Domain

It's not the router that inherently divides the collision domain, but rather it's the physical grouping of devices that limits what broadcasts appear on the LAN media. For the sake of simplicity, assume that "X Y Z Corporation" is now only deploying TCP/IP on its network. If "X Y Z Corporation" were to decide to divide its network into three IP subnets ( mask, mask, and mask and perform "one-arm routing" (meaning that a single router interface would route for the connected subnets), this network design would not stop the propagation of broadcasts between end-systems from different subnets. An example of this type of topology is shown in Figure 3.

Figure 3. Network Layer Segmentation without Broadcast Control

When a PC located on the 3rd floor creates a directed broadcast frame, it uses the IP address To build the Ethernet frame to encapsulate the packet, the PC uses the broadcast MAC address of FF-FF-FF-FF-FF-FF as the destination address.

Each LAN switch will receive a copy of the frame. As a Layer 2 device, each switch is only aware of the Ethernet MAC address information -- it is unable to process IP address information contained within the frame. Each LAN switch will continue to flood the broadcast frame out all ports. The directed broadcast frame will be propagated to all end-systems located in the network, however end-systems located on the first and second floors will ignore the frame because the frame is not recognized as a broadcast destined for it. Thus, the problem of broadcast propagation consuming bandwidth still exists.

Note: The term "one-arm routing" is typically associated with a "router-on-a-stick" configuration. The term "router-on-a-stick" refers to a router with a single interface that performs routing for multiple networks (or subnets). If you were to draw a diagram, it would show a router with a single line coming from one of its interfaces. This depiction might remind you of a lollipop - but instead of candy at the end of the stick, it's a router!

Figure 4. Router on a Stick

If "X Y Z Corporation" chose to physically segment its network by floor, using one subnet per floor, an effective broadcast domain would be created. Layer 2 devices would typically only encounter broadcasts from devices that reside on the local subnet, and propagation of these frames would be desirable.

Figure 5. Network Layer Segmentation with Broadcast Control

So What Is a VLAN?

Figure 6. Virtual Local Area Networks (VLANs)

Why Do I Need It? Or DO I Need It?

Figure 7. Catalyst 1900 Default VLAN Configuration

Configuring a VLAN

Verifying VLAN Configuration

VLAN Trunking

VLAN Trunk Protocol (VTP)

Spanning Tree Protocol and VLANs - Cisco's Solution

Inter-VLAN Communication

