Packet Walk: What Happens When You Ping Across VLANs
One ping across two VLANs touches ARP, 802.1Q tags, routing tables, and MAC rewriting. Follow a packet hop by hop — and learn where each stage can break.
The setup
PC1 lives in VLAN 10 (192.168.10.50/24) and PC2 in VLAN 20 (192.168.20.50/24). A router-on-a-stick (or L3 switch) does inter-VLAN routing: gateway 192.168.10.1 on VLAN 10, 192.168.20.1 on VLAN 20. You type ping 192.168.20.50 on PC1. Walk with the packet.
Step 1: The host does the subnet math
PC1 ANDs the destination with its own mask and discovers 192.168.20.0/24 ≠ 192.168.10.0/24 — so the destination is remote. Rule: for remote destinations, send the frame to your default gateway's MAC address, with the packet's destination IP remaining 192.168.20.50.
If PC1's ARP table lacks the gateway, it broadcasts ARP "who has 192.168.10.1?" on VLAN 10, and the router replies. Then the ICMP echo request leaves — source IP PC1, destination IP PC2, source MAC PC1, destination MAC router's VLAN-10 interface.
Step 2: The switch tags it
PC1's access port admits the frame into VLAN 10 untagged. To reach the router through the trunk, the switch adds the VLAN 10 tag. Tagged frame crosses the trunk; the router's subinterface for VLAN 10 pops the tag and hands the IP packet to the router's forwarding plane.
Step 3: The router forwards
The router looks up 192.168.20.50: longest-prefix match says VLAN 20 subinterface. It builds a new frame — source MAC = router's VLAN-20 MAC, destination MAC = PC2's (ARP again if needed), 802.1Q tag VLAN 20 — and sends it down the trunk. The switch strips the tag at PC2's access port. Echo reply reverses the whole sequence.
Where this breaks (the real reason to learn it)
| Symptom | Suspect | One command |
|---|---|---|
| "Destination host unreachable" instantly | No route / no gateway configured | ip route / route print |
| Ping fails, gateway ARP incomplete | VLAN mismatch on trunk, or native VLAN disagreement | show interfaces trunk |
| Same-VLAN works, cross-VLAN fails | No IP routing on L3 switch; subinterface down | show ip interface brief / show vlan |
| SVI is down/down | L3 switch: every VLAN needs at least one up/access port (or trunk allowing it) | show ip interface brief |
| ARP resolves, still 100% loss | PC firewall dropping ICMP — the classic | capture on the target host |
Make it muscle memory
Build this exact topology in Packet Tracer or GNS3, then break one thing at a time and predict the symptom before you ping. When your predictions beat your test results, you have the mental model interviewers probe for: the packet is always telling you the truth; you just have to know where to look.
- Your host decides local-vs-routed first: same-subnet goes to ARP, remote goes to the gateway MAC.
- Switches add/remove 802.1Q tags; routers rewrite MAC headers but keep IP addresses.
- The common failures: missing gateway, VLAN mismatch, and an SVI with no active ports.
- A packet walk predicts exactly which capture will show the problem.