Network Implementation 20% Lesson 5 of 14

Lesson 2.1.5 — Subinterfaces and Router-on-a-Stick

Avatar Of Asad IjazAsad Ijaz ·Sep 17, 2026 ·6 min read
36% through domain
Illustration Of One Cable Splitting Into Several Colored Streams Each Leading To A Separate Network Icon

Domain 2.0 | Network Implementation — 20% of exam

Learning Objectives

By the end of this lesson, you will be able to:

  • Explain why devices on separate VLANs need a router to communicate, and why that traditionally required one physical interface per VLAN
  • Define a subinterface and explain how it lets one physical interface service multiple VLANs
  • Describe the router-on-a-stick design and the role of an 802.1Q trunk in making it work
  • Read and interpret a subinterface configuration, including VLAN tagging and IP addressing
  • Compare router-on-a-stick to Layer 3 switching as an inter-VLAN routing method

Key Terms

TermDefinition
SubinterfaceA logical division of a single physical interface, each configured with its own IP address and VLAN association
Router-on-a-StickA design where a single physical router interface, divided into subinterfaces, routes traffic between multiple VLANs over one trunk link
802.1Q TrunkA link that carries traffic for multiple VLANs, with each frame tagged to identify which VLAN it belongs to
Native VLANThe one VLAN on an 802.1Q trunk whose traffic is sent untagged by default
Inter-VLAN RoutingThe process of routing traffic between devices on different VLANs, which requires a Layer 3 device since VLANs are separate broadcast domains

Explanation

Why Devices on Different VLANs Need a Router

This lesson previews a concept that Module 2’s switching lessons will cover in full: a VLAN groups switch ports into separate logical broadcast domains, even if they’re physically connected to the same switch. Two hosts on different VLANs are, from a Layer 2 perspective, on completely separate networks — a switch alone can’t move traffic between them. Something has to route between VLANs the same way it would route between any two separate networks, and that means a Layer 3 device has to get involved.

The most basic way to do this is to give the router one physical interface (and one cable) per VLAN, with each interface configured on that VLAN’s subnet. It works, but it doesn’t scale — a network with ten VLANs would need ten physical router interfaces and ten cables running to the switch, burning through router ports fast.

What a Subinterface Actually Is

A subinterface solves the scaling problem by logically dividing one physical interface into multiple virtual interfaces, each with its own IP address and its own VLAN association. Instead of ten physical ports, a router can use a single physical interface — say GigabitEthernet0/0 — divided into GigabitEthernet0/0.10, GigabitEthernet0/0.20, GigabitEthernet0/0.30, and so on, one per VLAN.

This connects directly to the core infrastructure devices lesson from Module 1: a subinterface doesn’t change what a router does conceptually — it’s still routing between subnets — it just lets one physical port carry traffic for many logical networks at once.

The Router-on-a-Stick Design

Router-on-a-stick is the name for this whole design: one physical link (the “stick”) runs between the switch and the router, carrying traffic for every VLAN that needs inter-VLAN routing, and the router’s subinterfaces sort that traffic out on the other end.

For this to work, the single physical link has to be configured as an 802.1Q trunk on the switch side. A trunk tags each frame with a VLAN ID as it crosses the link, so that even though multiple VLANs share the same physical wire, the router (and the switch) always know which VLAN a given frame belongs to.

Diagram Showing A Single Trunk Link And Router Subinterfaces Handling Three Separate Vlans
How A Single Trunk Link Lets One Router Interface Route Between Multiple Vlans

How A Single Trunk Link Lets One Router Interface Route Between Multiple VLANs

A basic router-on-a-stick configuration looks like this:

R1(config)# interface GigabitEthernet0/0.10
R1(config-subif)# encapsulation dot1Q 10
R1(config-subif)# ip address 192.168.10.1 255.255.255.0

R1(config)# interface GigabitEthernet0/0.20
R1(config-subif)# encapsulation dot1Q 20
R1(config-subif)# ip address 192.168.20.1 255.255.255.0

Each subinterface is bound to the physical interface (GigabitEthernet0/0) but behaves like an independent Layer 3 interface: it has its own subnet, its own IP address, and it participates in routing exactly as a separate physical interface would. The encapsulation dot1Q 10 line is what ties that specific subinterface to VLAN 10’s tagged traffic — without it, the subinterface has no way to know which frames on the shared physical link belong to it.

Diagram Showing Tagged Vlan Frames On A Trunk Sorted To Matching Router Subinterfaces By Vlan Id
How Tagged Frames On The Trunk Are Sorted To The Matching Subinterface By Vlan Id

How Tagged Frames On The Trunk Are Sorted To The Matching Subinterface By VLAN ID

Native VLAN Considerations

On an 802.1Q trunk, exactly one VLAN is designated the native VLAN, and traffic for that VLAN is sent untagged by default — a legacy behavior from when trunking was first standardized, kept for backward compatibility with older equipment that doesn’t understand tags at all. If a subinterface is meant to handle the native VLAN, its configuration needs the encapsulation dot1Q <vlan> native keyword to tell the router to expect untagged frames for that specific VLAN.

A mismatched native VLAN — where the switch and router disagree on which VLAN is untagged — is a classic real-world (and exam) troubleshooting scenario: traffic on that VLAN either goes nowhere, or worse, leaks between VLANs in ways that are hard to spot without careful trunk verification.

Router-on-a-Stick vs. Layer 3 Switching

Router-on-a-stick isn’t the only way to route between VLANs, and it’s not always the best one. Many enterprise switches are Layer 3 switches, capable of doing inter-VLAN routing internally using switched virtual interfaces (SVIs) — a concept the next module section covers in depth. A Layer 3 switch skips the trunk-to-a-separate-router step entirely, routing between VLANs at wire speed inside the switch itself.

Diagram Comparing Router-On-A-Stick Using An External Router Against Inter-Vlan Routing Done Inside A Layer 3 Switch
Comparing A Trunk-To-Router Design Against Inter-Vlan Routing Done Inside A Layer 3 Switch

Comparing A Trunk-To-Router Design Against Inter-VLAN Routing Done Inside A Layer 3 Switch

Router-on-a-stick still shows up in smaller networks, lab environments, and situations where a dedicated router is already doing other jobs (like the NAT/PAT and dynamic routing work covered earlier in this module) and adding VLAN routing to it is more practical than provisioning a separate Layer 3 switch. But for anything beyond modest traffic volumes, a Layer 3 switch is generally the more scalable and lower-latency choice, since it avoids funneling every inter-VLAN packet down one shared physical link.

Where This Fits: Closing Out Objective 2.1

This lesson closes out N10-009 objective 2.1 (routing technologies). Across these five lessons, you’ve gone from static routes and route selection, through dynamic routing protocols, address translation, gateway redundancy, and now subinterfaces — the full set of tools a router uses to move traffic between networks. The next set of lessons shifts to objective 2.2, switching technologies, starting with VLANs themselves — the very concept this lesson had to introduce early, just to explain why subinterfaces exist in the first place.

Recognition-Level Verification Concepts

A few patterns are worth recognizing on sight:

  • A physical interface name followed by a dot and a number (like GigabitEthernet0/0.10) always indicates a subinterface.
  • An encapsulation dot1Q <VLAN> line inside a subinterface configuration tells you exactly which VLAN that subinterface handles.
  • A single physical link carrying multiple VLANs, tagged per frame, is an 802.1Q trunk — the prerequisite for router-on-a-stick to function at all.
  • The native keyword appearing after a VLAN number in an encapsulation command flags that subinterface as handling untagged native VLAN traffic.

Common Exam Traps

  • A subinterface is not a separate physical port. It’s a logical division of one physical interface — don’t confuse the two when reading a topology diagram or configuration.
  • Router-on-a-stick requires the switch-side link to be a trunk, not an access port. Without 802.1Q trunking configured on the switch, VLAN tags never reach the router, and subinterfaces have nothing to sort.
  • Native VLAN traffic is untagged by default — this is easy to forget and a common source of trunk mismatches when the switch and router disagree on which VLAN is native.
  • Router-on-a-stick and Layer 3 switching solve the same problem differently. Don’t assume every inter-VLAN routing scenario uses subinterfaces — many modern designs use SVIs on a Layer 3 switch instead.
  • Every subinterface needs its own encapsulation dot1Q statement. Forgetting it (or assigning the same VLAN number to two subinterfaces) is a frequent configuration mistake in this scenario.

Lesson 2.1.5 Practice Quiz — Subinterfaces and Router-on-a-Stick

17 questions covering subinterfaces, 802.1Q trunking, router-on-a-stick, native VLAN, and Layer 3 switching.

N10-009 · Domain 2.1
Question 1Plain
What is a subinterface?
A subinterface is a logical division of a single physical interface, letting one physical port handle multiple VLANs, each with its own IP addressing.
Question 2Plain
For router-on-a-stick to function, how must the switch-side link be configured?
Router-on-a-stick requires the switch-side link to be an 802.1Q trunk, so VLAN tags reach the router for its subinterfaces to sort.
Question 3Plain
By default, how is native VLAN traffic sent across an 802.1Q trunk?
The native VLAN's traffic is sent untagged by default on an 802.1Q trunk — a legacy behavior kept for backward compatibility.
Question 4Choose Two
Which two statements about router-on-a-stick are correct? (Choose two.)
Router-on-a-stick uses one physical trunk link and subinterfaces with dot1Q encapsulation to sort VLAN traffic — the entire point is to avoid needing one port per VLAN. SVIs are a Layer 3 switch concept, not part of router-on-a-stick.
Question 5Choose Two
Which two are required in a correct subinterface configuration for VLAN 10? (Choose two.)
Each subinterface needs its own encapsulation statement identifying its VLAN and its own IP address. The "native" keyword is only needed if that specific VLAN is the trunk's native VLAN, not on every subinterface.
Question 6Choose Two
Which two statements about Layer 3 switching for inter-VLAN routing are correct? (Choose two.)
A Layer 3 switch uses SVIs to route between VLANs internally, without needing a separate router or trunk — and it generally scales better than router-on-a-stick, not worse.
Question 7Scenario
A small office has three VLANs and wants a single existing router to handle inter-VLAN routing without purchasing additional router interfaces. Which design fits?
Router-on-a-stick lets one physical interface, divided into subinterfaces, handle all three VLANs over a single trunk — exactly what avoids needing more physical ports.
Question 8Scenario
A trunk is correctly configured on the switch, but hosts on VLAN 20 still can't reach their default gateway through the router's subinterface. The subinterface has a correct IP address but is missing one line of configuration. What is most likely missing?
Without the encapsulation dot1Q statement, the subinterface has no way to associate itself with VLAN 20's tagged traffic, even with a valid IP address configured.
Question 9Scenario
The switch designates VLAN 1 as the native VLAN, but the router's subinterface for VLAN 1 lacks the "native" keyword in its encapsulation statement. What should be done to fix this mismatch?
Since VLAN 1 is the switch's native VLAN, its traffic arrives untagged. The router's subinterface for that VLAN needs the "native" keyword so it correctly expects untagged frames instead of looking for a VLAN tag that will never arrive.
Question 10Scenario
A growing enterprise needs to route between a dozen VLANs with maximum throughput and minimal added latency. Which approach is generally preferred over router-on-a-stick at this scale?
At larger scale, a Layer 3 switch routing internally via SVIs avoids funneling all inter-VLAN traffic through one shared trunk link, offering better throughput and lower latency than router-on-a-stick.
Question 11Scenario
A physical interface Gi0/1 is divided into Gi0/1.5 (encapsulation dot1Q 5) and Gi0/1.15 (encapsulation dot1Q 15), connected to a switch trunk carrying both VLANs. What design is this?
Two subinterfaces on one physical interface, each tied to a different VLAN via dot1Q encapsulation, over a single trunk link, is the definition of router-on-a-stick.
Question 12Exhibit
Based on this configuration, which VLAN does this subinterface serve?
R1(config)# interface GigabitEthernet0/0.30 R1(config-subif)# encapsulation dot1Q 30 R1(config-subif)# ip address 192.168.30.1 255.255.255.0
The "encapsulation dot1Q 30" line explicitly ties this subinterface to VLAN 30, regardless of the subinterface's own numeric suffix (.30) or IP address.
Question 13Exhibit
Based on this switch trunk output, which VLANs are allowed across this trunk?
SW1# show interfaces trunk Port Mode Encapsulation Status Native vlan Gi0/1 on 802.1q trunking 1 Port Vlans allowed on trunk Gi0/1 10,20,30
The "Vlans allowed on trunk" line explicitly lists 10, 20, and 30 as the VLANs permitted across this trunk; the native VLAN (1) is separate from that allowed list.
Question 14Exhibit
Based on this log message, what is the underlying problem?
%CDP-4-NATIVE_VLAN_MISMATCH: Native VLAN mismatch discovered on GigabitEthernet0/1 (1), with SW2 GigabitEthernet0/2 (99).
This CDP message flags that one side of the trunk considers VLAN 1 native while the other considers VLAN 99 native — a mismatch that can cause untagged traffic to land on the wrong VLAN.
Question 15Exhibit
What is wrong with this subinterface configuration?
R1(config)# interface GigabitEthernet0/0.10 R1(config-subif)# encapsulation dot1Q 10 R1(config-subif)# ip address 192.168.10.1 255.255.255.0 R1(config)# interface GigabitEthernet0/0.20 R1(config-subif)# encapsulation dot1Q 10 R1(config-subif)# ip address 192.168.20.1 255.255.255.0
Both subinterfaces use "encapsulation dot1Q 10," meaning both are configured for VLAN 10 despite their differing subinterface numbers and IP subnets — a common copy-paste misconfiguration.
Question 16Exhibit
Based on this configuration, which native VLAN behavior does this subinterface expect?
R1(config)# interface GigabitEthernet0/0.1 R1(config-subif)# encapsulation dot1Q 1 native R1(config-subif)# ip address 192.168.1.1 255.255.255.0
The "native" keyword after the VLAN number tells the router this subinterface handles the trunk's native VLAN, which arrives untagged rather than tagged like the other VLANs.
Question 17Exhibit
Based on this configuration taken from a switch, what design does this represent, as opposed to router-on-a-stick?
SW1(config)# interface Vlan10 SW1(config-if)# ip address 192.168.10.1 255.255.255.0 SW1(config-if)# no shutdown
An "interface Vlan10" configured directly on a switch, with its own IP address, is a switched virtual interface (SVI) — the Layer 3 switching alternative to router-on-a-stick, with no dot1Q encapsulation or physical trunk-to-router link involved.
📝

Summary

Devices on different VLANs can't communicate without a Layer 3 device routing between them, since VLANs are separate broadcast domains.

A subinterface is a logical division of one physical interface, each with its own IP address and VLAN association, avoiding the need for one physical port per VLAN.

Router-on-a-stick uses a single 802.1Q trunk link between a switch and a router, with the router's subinterfaces sorting tagged frames by VLAN ID.

The native VLAN on a trunk is sent untagged by default, and a mismatch between switch and router native VLAN settings is a common troubleshooting scenario.

Layer 3 switches offer an alternative to router-on-a-stick, performing inter-VLAN routing internally via SVIs rather than funneling all traffic through one trunk to a separate router.

This lesson completes N10-009 objective 2.1 (routing technologies); the next lessons move into objective 2.2, switching technologies, starting with VLANs.

Avatar Of Asad Ijaz

Lead Networking Architect and Editor at NetworkUstad. BS in Computer Networks and Security, CCNP and CCNA certified, with 11+ years of experience in enterprise network design, implementation, and troubleshooting. Writes practical tutorials on routing, IPv4 management, network automation, and security fundamentals.