VLANs let a switched network create multiple Layer 2 broadcast domains on the same physical infrastructure. Trunks let those VLANs cross links between switches and other VLAN-aware devices. The two concepts are tightly connected, and the Cisco 200-301 CCNA expects candidates to understand both the configuration and the forwarding logic behind them.
The important shift is to stop thinking of a switch as one flat network. A switch can carry many logical networks, each identified by a VLAN ID. Ports, frames, MAC address learning, spanning tree, inter-VLAN routing, and security behavior all depend on that segmentation.
What a VLAN changes
Without VLAN segmentation, all access ports in the same Layer 2 domain participate in the same broadcast environment. A VLAN separates that environment logically. Devices in VLAN 10 and VLAN 20 can be connected to the same physical switch but remain in different Layer 2 broadcast domains.
An access port normally belongs to one data VLAN. Frames from an ordinary endpoint arrive untagged, and the switch associates them with the configured access VLAN. The switch learns source MAC addresses in the context of that VLAN and only floods unknown or broadcast traffic within the same VLAN.
This matters because the same MAC address table is logically partitioned by VLAN context. A frame destined for a host in another VLAN is not simply switched across the same Layer 2 domain. It must be routed by a Layer 3 device or switched virtual interface.
Voice VLANs add another common access-port pattern. An IP phone and attached workstation can share a physical switch port while voice and data belong to different VLANs. The exam focus is the concept and basic configuration behavior rather than advanced voice architecture.
Trunks carry multiple VLANs
A trunk link is used when more than one VLAN must traverse the same physical interface. IEEE 802.1Q tagging inserts VLAN information into Ethernet frames so the receiving device knows which VLAN each frame belongs to. The switch can therefore multiplex traffic from many logical networks across one link.
The native VLAN is the special case. On a standard 802.1Q trunk, native-VLAN traffic is normally sent untagged unless the platform is configured otherwise. Both ends of the trunk should agree on the native VLAN; mismatches can create confusing connectivity and security problems.
Candidates should be comfortable reading trunk state and recognizing the difference between a port that is operationally trunking and one that is merely configured with an intended trunk mode. They should also understand that a trunk can restrict which VLANs are allowed across it. Carrying every VLAN everywhere is rarely a good design.
The site’s explanation of trunking in computer networks provides a broader conceptual view, while CCNA study should focus specifically on 802.1Q behavior, VLAN membership, and verification.
VLANs and subnets are related but different
A VLAN is a Layer 2 segmentation construct. An IP subnet is a Layer 3 addressing construct. In most enterprise designs, one VLAN maps to one IP subnet, which makes the two appear interchangeable, but they solve different problems.
The distinction is important for troubleshooting. If two hosts are in the same IP subnet but accidentally connected to different VLANs, they may be unable to resolve each other at Layer 2. If they are in the same VLAN but configured with incompatible IP subnets, Layer 2 forwarding may work while IP communication fails.
The existing comparison of subnets and VLANs is useful here because it prevents a common exam mistake: assuming that changing a VLAN ID somehow changes an IP prefix automatically. It does not. VLAN membership and IP addressing must be designed coherently.
Inter-VLAN communication requires routing
Hosts in different VLANs need a Layer 3 boundary between them. That routing can be provided by a router with subinterfaces, a multilayer switch with switched virtual interfaces, or another Layer 3 gateway design. The CCNA candidate should recognize why routing is required and how the default gateway relates to the host’s VLAN.
In a router-on-a-stick design, a trunk connects the switch to a router interface. Router subinterfaces are associated with VLAN IDs and provide Layer 3 gateways. The design is easy to understand but can create a throughput bottleneck because multiple VLANs share one physical router link.
Multilayer switches commonly use SVIs instead. Each VLAN that needs local Layer 3 routing can have an interface VLAN with an IP address. The switch routes between those VLAN interfaces when IP routing is enabled. This is more scalable for many campus designs.
For exam questions, verify both sides of the boundary. A correctly configured trunk does not help if the SVI is down or the endpoint has the wrong default gateway. Likewise, a correct gateway address cannot compensate for an access port placed in the wrong VLAN.
VLAN design affects spanning tree
Redundant trunks can carry the same VLAN across multiple paths, which is why spanning tree becomes part of the conversation. The Layer 2 topology for a VLAN needs a loop-free forwarding path. Depending on the spanning-tree mode, different VLANs can have different logical topologies and root-bridge choices.
This is one reason VLAN design should not be separated from redundancy design. If the root bridge is poorly placed, traffic can take inefficient paths. If trunks allow unnecessary VLANs, the spanning-tree domain and broadcast scope can become larger than required.
The CCNA level does not require enterprise-scale campus design mastery, but it does expect candidates to connect the topics. VLANs, trunks, EtherChannel, and spanning tree are parts of one Layer 2 system rather than isolated command sets.
Troubleshoot from Layer 1 upward
When a VLAN does not work, start with the physical and interface state. Is the link up? Is the access port in the expected VLAN? Is the VLAN created and active? If the path crosses switches, is the interswitch interface actually trunking? Is the VLAN allowed on the trunk? Do both sides agree on native VLAN behavior?
Then check Layer 3. Does the endpoint have an address from the correct subnet? Is the default gateway correct? Is the SVI or router subinterface up? Is routing enabled where needed?
Useful verification output includes access VLAN assignment, trunk status, allowed VLANs, MAC address learning, SVI state, and IP configuration. Learn to interpret the output instead of memorizing a single “show” command for each topic. The exam can present partial output and ask you to infer the fault.
Security starts with limiting scope
VLANs are not a complete security boundary, but sensible segmentation reduces unnecessary reachability and broadcast exposure. Trunks should carry only the VLANs that need to traverse the link. User access ports should not be left in unexpected trunk states. Native VLAN choices and unused ports should follow the organization’s hardening approach.
More advanced threats such as VLAN hopping exist, but the CCNA lesson is broader: secure Layer 2 design starts by making port roles explicit. An endpoint port should behave like an endpoint port. An infrastructure trunk should carry the VLANs required for its purpose, not every VLAN by default.
Build a forwarding mental model
For each question, picture the frame. Which VLAN does it enter? Where is the source MAC learned? Is the destination local to that VLAN? If the frame crosses a trunk, how is VLAN identity preserved? If the IP destination is in another subnet, where does routing occur?
This mental model is more durable than command memorization. It also prepares you for the broader network engineering certification topics where VLAN segmentation interacts with security, wireless, virtualization, and software-defined networking.
Within the Cisco enterprise certification family, VLANs remain foundational. More advanced Cisco material adds larger campus designs, policy, overlays, and automation, but the basic logic is the same: identify the Layer 2 domain, preserve or change that identity intentionally, and route only when crossing a Layer 3 boundary.
Recognize the failure patterns that trunks create
Trunk problems often create selective failures rather than a total outage. If VLAN 10 is allowed across an interswitch trunk but VLAN 20 is not, users in VLAN 10 may work normally while VLAN 20 appears broken only when traffic must cross that link. This is why “the link is up” is not sufficient evidence that the trunk is correct.
A native VLAN mismatch can be equally deceptive. Tagged VLAN traffic may continue to work while untagged control or native traffic behaves unexpectedly. The switch can also generate warnings that point directly to the inconsistency. Reading those messages is more useful than repeatedly bouncing the interface.
Another pattern is a port placed into access mode on one side and trunk mode on the other. The physical link may stay up, but VLAN handling no longer matches. Similar symptoms can appear when the expected VLAN does not exist in the local VLAN database or when an SVI remains down because no active port is associated with the VLAN.
For exam troubleshooting, build a checklist around state rather than commands: port role, access VLAN, trunk encapsulation behavior, allowed VLANs, native VLAN, VLAN existence, MAC learning, SVI state, and gateway configuration. The command used to display each item is secondary to knowing what evidence you need.