Packet Path/

VLANs, Trunks, and Spanning Tree — Switching Fundamentals

A VLAN is a broadcast domain. A trunk carries many of them. Spanning tree keeps the redundant ones from burning the building down. The three ideas that run every LAN.

Switching · Beginner · 13 min · September 30, 2026

Illustration of two switches with color-coded VLAN segments and a spanning-tree arc

Why VLANs exist

Picture a 48-port switch with finance, engineering, and printers all plugged in. Without VLANs, every broadcast from one printer interrupts every host on the switch — and everyone's traffic mingles. A VLAN (virtual LAN) carves the switch into isolated broadcast domains: same hardware, separate L2 worlds. Hosts in VLAN 10 can talk to each other at Layer 2; to reach VLAN 20 they must go through a router (or Layer 3 switch).

Access ports and trunk ports

Switch ports play two roles:

Port typePurposeHow frames look
AccessOne VLAN, to an end deviceUntagged — the host never sees VLANs
TrunkMany VLANs, switch-to-switch or switch-to-routerTagged with 802.1Q, except the native VLAN

The 802.1Q tag is a 4-byte header inserted into the Ethernet frame: a 2-byte TPID (0x8100 says "tagged frame"), and a 2-byte TCI carrying the 12-bit VLAN ID (1–4094 usable) plus priority bits. Tags get stripped when frames exit an access port — hosts stay blissfully unaware.

The native VLAN trap

Every trunk has one native VLAN whose traffic crosses untagged. If both ends of a link disagree about which VLAN that is, frames from VLAN A arrive at the other side in VLAN B — a silent misdelivery, notoriously hard to spot because pings within a VLAN still work when a link fails over.

Never ship thisKeep user traffic off the default VLAN 1, make native VLANs match on both ends of every trunk, and set modes explicitly: switchport mode trunk / switchport mode access. Cisco's DTP auto-negotiation is a VLAN-hopping attack waiting for a curious neighbor.

Why spanning tree exists

Redundant links are how networks survive failures. They are also loops — and a loop on a switch fabric is extinction-level: a broadcast frame circles forever, multiplies at every switch, and the storm takes down the whole VLAN in seconds. MAC address tables flap between ports, CPU spikes, and the network is effectively dead.

Spanning Tree Protocol (STP) solves it by electing a root bridge and computing a loop-free tree: every redundant link ends up forwarding or deliberately blocked. Blocked ports wake up when something fails — redundancy you can actually use.

Root election and port roles

Bridges elect the root by the lowest bridge ID (priority + MAC address; default priority 32768). Then every other bridge picks its shortest path to the root; the port on the shortest path is its root port, each segment elects one designated port to forward, and everything else gets blocked.

"Shortest" uses cumulative path cost, which shrinks as links get faster (modern values): 10 Mbps = 100, 100 Mbps = 19, 1 Gbps = 4, 10 Gbps = 2.

Classic STP walks ports through Blocking → Listening → Learning → Forwarding with ~15-second timers — roughly 30–50 seconds of darkness after a topology change. Rapid STP (802.1w, and inside modern MSTP/PVST+) converges in seconds by negotiating link by link with proposal/agreement handshakes, and adds alternate and backup port roles.

! pick your root and backup-root ON PURPOSE — lowest MAC wins otherwise
spanning-tree vlan 10 priority 4096
spanning-tree vlan 10 priority 8192   ! on the backup root

! edge ports: skip the 30s wait, die if anyone talks STP back
interface range Gi1/0/1 - 24
 spanning-tree portfast
 spanning-tree bpduguard enable

! never let a downstream switch become root
interface Gi1/0/25
 spanning-tree guard root

The checklist that saves real LANs

Key takeaways

Keep reading