VLAN segmentation is a core topic in the CCNA Network Access domain. Understanding how access ports, trunk ports, and VLAN membership interact — and what breaks when a host lands in the wrong VLAN — builds the reasoning skills the exam tests repeatedly.
How Access Ports and Trunks Work Together
In this basic data-VLAN example, an access port associates incoming untagged endpoint traffic with its configured VLAN. The switch maintains that VLAN association; this description does not require every switch to insert an 802.1Q tag internally. A trunk port, by contrast, carries frames from multiple VLANs between switches or between a switch and a router. It uses 802.1Q tagging so the receiving device knows which VLAN each frame belongs to.
The practical implication: two hosts can share the same physical switch and the same trunk uplink, yet be completely isolated from each other if they belong to different VLANs. Ordinary Layer 2 forwarding does not connect different VLAN broadcast domains. Communication between their IP subnets requires inter-VLAN routing, such as a router or a Layer 3 switch, with the necessary addressing and permissions.
Study Example: One Host in the Wrong VLAN
Consider this study example. A small office has two VLANs: VLAN 10 for the sales team and VLAN 20 for the finance team. Switch SW1 connects to Switch SW2 through a trunk link that carries both VLANs. A finance workstation is physically patched into SW1, but the access port is mistakenly configured for VLAN 10 instead of VLAN 20.
The finance workstation gets a Layer 2 path only to other VLAN 10 devices — the sales hosts. It cannot reach any finance server on VLAN 20, even though those servers are just one hop away on SW2. No trunk misconfiguration exists; the trunk carries both VLANs correctly. The access-port assignment is the known mismatch in this example. Correcting it restores the intended VLAN membership; the workstation’s IP configuration, gateway and applicable controls must also fit that VLAN before end-to-end connectivity can be expected.
This scenario highlights something important: when a host cannot reach peers that should be in the same department, checking the access VLAN on its switch port is a logical first step before investigating trunks or routing.
For additional scenarios built around this same logic, the free CCNA practice questions bank at Every Exam Prep includes Network Access questions covering VLAN behavior, port modes, and related switching concepts — work through those to test your reasoning.
Practice Question
Host A is in VLAN 10 on SW1. Host B is in VLAN 20 on SW2. The trunk between SW1 and SW2 allows both VLANs. Assume there is no inter-VLAN routing and the hosts use addresses in their respective VLAN subnets. Host A cannot ping Host B.
What is the most likely reason?
- A: The trunk is blocking VLAN 20 frames.
- B: Layer 2 alone cannot route between different VLANs; inter-VLAN routing is missing.
- C: Host A’s access port must be configured as a trunk port.
- D: 802.1Q tagging is not supported between two Cisco switches.
Correct answer: B
Hosts in different VLANs are in different Layer 2 broadcast domains. Even with a perfectly functioning trunk, frames cannot cross VLAN boundaries without a Layer 3 routing process. A router-on-a-stick configuration or a Layer 3 switch with routed SVIs would solve this. Option A is plausible, but the scenario explicitly states both VLANs are allowed on the trunk. Option C is wrong because end devices use access ports, not trunk ports. Option D is incorrect because 802.1Q is the standard inter-switch tagging protocol Cisco switches support.
Keep a paper log of questions you answer incorrectly, noting the specific concept that tripped you up — access port behavior, trunk pruning, or inter-VLAN routing. The CCNA cheat sheet at Every Exam Prep offers a broader review of switching and other exam domains and includes a PDF download for offline reference.
Official exam reference: Cisco CCNA exam topics. These study examples are independently written.
