VLANs, Trunks, and Spanning Tree — Switching Fundamentals
A VLAN is a broadcast domain. A trunk carries many of them. Spanning tree keeps the redundant ones from burning the building down. The three ideas that run every LAN.
Why VLANs exist
Picture a 48-port switch with finance, engineering, and printers all plugged in. Without VLANs, every broadcast from one printer interrupts every host on the switch — and everyone's traffic mingles. A VLAN (virtual LAN) carves the switch into isolated broadcast domains: same hardware, separate L2 worlds. Hosts in VLAN 10 can talk to each other at Layer 2; to reach VLAN 20 they must go through a router (or Layer 3 switch).
Access ports and trunk ports
Switch ports play two roles:
| Port type | Purpose | How frames look |
|---|---|---|
| Access | One VLAN, to an end device | Untagged — the host never sees VLANs |
| Trunk | Many VLANs, switch-to-switch or switch-to-router | Tagged with 802.1Q, except the native VLAN |
The 802.1Q tag is a 4-byte header inserted into the Ethernet frame: a 2-byte TPID (0x8100 says "tagged frame"), and a 2-byte TCI carrying the 12-bit VLAN ID (1–4094 usable) plus priority bits. Tags get stripped when frames exit an access port — hosts stay blissfully unaware.
The native VLAN trap
Every trunk has one native VLAN whose traffic crosses untagged. If both ends of a link disagree about which VLAN that is, frames from VLAN A arrive at the other side in VLAN B — a silent misdelivery, notoriously hard to spot because pings within a VLAN still work when a link fails over.
switchport mode trunk / switchport mode access. Cisco's DTP auto-negotiation is a VLAN-hopping attack waiting for a curious neighbor.Why spanning tree exists
Redundant links are how networks survive failures. They are also loops — and a loop on a switch fabric is extinction-level: a broadcast frame circles forever, multiplies at every switch, and the storm takes down the whole VLAN in seconds. MAC address tables flap between ports, CPU spikes, and the network is effectively dead.
Spanning Tree Protocol (STP) solves it by electing a root bridge and computing a loop-free tree: every redundant link ends up forwarding or deliberately blocked. Blocked ports wake up when something fails — redundancy you can actually use.
Root election and port roles
Bridges elect the root by the lowest bridge ID (priority + MAC address; default priority 32768). Then every other bridge picks its shortest path to the root; the port on the shortest path is its root port, each segment elects one designated port to forward, and everything else gets blocked.
"Shortest" uses cumulative path cost, which shrinks as links get faster (modern values): 10 Mbps = 100, 100 Mbps = 19, 1 Gbps = 4, 10 Gbps = 2.
Classic STP walks ports through Blocking → Listening → Learning → Forwarding with ~15-second timers — roughly 30–50 seconds of darkness after a topology change. Rapid STP (802.1w, and inside modern MSTP/PVST+) converges in seconds by negotiating link by link with proposal/agreement handshakes, and adds alternate and backup port roles.
! pick your root and backup-root ON PURPOSE — lowest MAC wins otherwise
spanning-tree vlan 10 priority 4096
spanning-tree vlan 10 priority 8192 ! on the backup root
! edge ports: skip the 30s wait, die if anyone talks STP back
interface range Gi1/0/1 - 24
spanning-tree portfast
spanning-tree bpduguard enable
! never let a downstream switch become root
interface Gi1/0/25
spanning-tree guard root
The checklist that saves real LANs
- Place the root. If you did not configure priority, your root bridge is whoever has the lowest MAC — often a closet switch. Set it explicitly.
- Portfast only on edge ports. Loops downstream of portfast are unprotected by the 30-second safety delay — BPDU guard is the seatbelt.
- Verify after changes:
show spanning-tree vlan 10 [brief|detail]— find "Root ID" and make sure it is who you expect; watch the "Number of topology changes" counter for flapping. - RSTP minimum in 2026. Run rapid per-VLAN or MSTP; nobody waits 50 seconds for convergence on purpose anymore.
- VLANs divide one switch into separate broadcast domains — isolation without more hardware.
- 802.1Q trunks multiplex VLANs; native VLAN mismatch is a classic silent failure.
- STP elects a root bridge and blocks redundant links to prevent broadcast storms.
- Use RSTP edge ports and BPDU guard in real deployments.