Network Implementation 20% Lesson 6 of 14

Lesson 2.2.1 — VLANs, VLAN Database & SVIs

Avatar Of Asad IjazAsad Ijaz ·Sep 18, 2026 ·7 min read
43% through domain
Illustration Of A Switch Divided Into Colored Zones Like Rooms In A Floor Plan, Each Holding A Device Icon

Domain 2.0 | Network Implementation — 20% of exam

Learning Objectives

By the end of this lesson, you will be able to:

  • Explain what a VLAN is and why it creates a separate broadcast domain independent of physical wiring
  • Describe how the VLAN database is used to create VLANs and assign switch ports to them
  • Distinguish an access port from a trunk port in terms of VLAN membership
  • Explain the purpose of a switched virtual interface (SVI) and how it enables inter-VLAN routing on a Layer 3 switch
  • Identify the default VLAN and recognize common VLAN configuration mistakes

Key Terms

TermDefinition
VLAN (Virtual LAN)A logical grouping of switch ports into a separate broadcast domain, independent of physical location or wiring
VLAN DatabaseThe switch’s internal table of created VLANs, each identified by a VLAN ID and optional name
Access PortA switch port assigned to exactly one VLAN, used to connect end devices like PCs and printers
SVI (Switched Virtual Interface)A virtual Layer 3 interface configured directly on a switch, representing a VLAN and enabling inter-VLAN routing
Broadcast DomainThe set of devices that receive a broadcast frame sent by any one device in that same domain
Default VLANVLAN 1, the VLAN every switch port belongs to out of the box before any manual VLAN configuration

Explanation

What a VLAN Actually Is

The previous lesson introduced VLANs briefly to explain why subinterfaces and router-on-a-stick exist in the first place. This lesson is where VLANs actually get explained properly, since they’re the foundation for everything else in this objective.

A VLAN (Virtual LAN) groups switch ports into a logical network that behaves as its own separate broadcast domain, regardless of where those ports physically sit. Two devices plugged into the same physical switch can be on completely different VLANs, and two devices on opposite ends of a building, connected to different switches, can be on the exact same VLAN — the grouping is entirely logical, defined by configuration, not by cabling.

This is a meaningful upgrade over the traditional flat topologies covered in Module 1, where every device on a switch shared one single broadcast domain by default. On a large flat network, a single broadcast frame — an ARP request, for instance — gets flooded to every connected device, which wastes bandwidth and doesn’t scale as a network grows. VLANs solve this by letting an administrator carve one physical switch (or a whole stack of switches) into multiple, isolated logical networks.

Why VLANs Exist: Segmentation Without Rewiring

Before VLANs, separating departments or traffic types into different broadcast domains meant physically wiring them to entirely separate switches. VLANs remove that constraint. A single switch, or an entire campus of switches, can host VLAN 10 for the Sales department, VLAN 20 for Engineering, and VLAN 30 for Voice traffic, all sharing the same physical infrastructure but never seeing each other’s broadcast traffic — and, without a router involved, never able to communicate with each other at all, which is exactly the security and containment benefit VLANs are prized for.

This same logical-separation idea is why VLANs pair so naturally with the core infrastructure devices discussed back in Module 1 — a modern switch’s real value comes from this kind of software-defined segmentation, not just from moving frames between ports.

The VLAN Database: Where VLANs Live

Before any port can be assigned to a VLAN, the VLAN itself has to exist in the switch’s VLAN database — an internal table listing every VLAN ID configured on that switch, along with an optional descriptive name.

SW1(config)# vlan 10
SW1(config-vlan)# name SALES

SW1(config)# vlan 20
SW1(config-vlan)# name ENGINEERING

Once a VLAN exists in the database, it can be assigned to one or more switch ports. Creating the VLAN and assigning a port to it are two separate steps — a common early mistake is assigning a port to a VLAN number that was never actually created in the database, which leaves the port in a nonfunctional state even though the command appeared to succeed.

Diagram Showing Vlans Created In The Vlan Database And Then Assigned To Specific Switch Ports
How Vlans Are Created In The Database Before Being Assigned To Individual Switch Ports

How VLANs Are Created In The Database Before Being Assigned To Individual Switch Ports

Access Ports: Assigning a Single VLAN to a Port

Most switch ports connecting to end devices — a PC, a printer, an access point — are configured as access ports, meaning each one belongs to exactly one VLAN. Frames arriving on an access port are untagged; the switch itself tracks which VLAN that port (and therefore that frame) belongs to internally.

SW1(config)# interface GigabitEthernet0/5
SW1(config-if)# switchport mode access
SW1(config-if)# switchport access vlan 10

This is different from the trunk ports covered in the previous lesson, which carry traffic for multiple VLANs simultaneously, with each frame tagged to identify its VLAN. An access port is single-VLAN and untagged; a trunk port is multi-VLAN and (mostly) tagged. Getting this distinction backwards — configuring an access port where a trunk is needed, or vice versa — is one of the most common real-world switch misconfigurations.

Diagram Comparing An Access Port Carrying One Untagged Vlan Against A Trunk Port Carrying Multiple Tagged Vlans
How Access Ports Carry One Untagged Vlan While Trunk Ports Carry Multiple Tagged Vlans

How Access Ports Carry One Untagged VLAN While Trunk Ports Carry Multiple Tagged VLANs

The Default VLAN and Why It Matters

Every switch port belongs to VLAN 1, the default VLAN, right out of the box — before any administrator has created or assigned anything. This is also, by default, the same VLAN typically used as the native VLAN on trunk links, which is exactly the concept discussed in the previous lesson’s native VLAN section.

Leaving every port on VLAN 1 defeats the entire purpose of segmentation, and it’s also a security consideration: VLAN 1 traffic is frequently targeted in VLAN-hopping attack techniques precisely because it’s the universal default. Most production network designs deliberately move end-device traffic off VLAN 1 and onto purpose-specific VLANs, sometimes leaving VLAN 1 unused entirely except as a required native VLAN placeholder.

SVIs: Routing Without Leaving the Switch

A switched virtual interface (SVI) is a virtual Layer 3 interface configured directly on a switch, representing one specific VLAN. Unlike a subinterface, which lives on a router and requires an external trunk link to reach the switch, an SVI lives inside the switch itself — no external cable, no dot1Q encapsulation statement, no separate router needed.

SW1(config)# interface Vlan10
SW1(config-if)# ip address 192.168.10.1 255.255.255.0
SW1(config-if)# no shutdown

SW1(config)# ip routing

That final ip routing command matters: creating SVIs alone doesn’t make a switch route between VLANs. The switch also needs Layer 3 routing explicitly enabled — without it, the SVIs exist and can be pinged, but the switch won’t forward traffic between them.

Because the routing happens internally, on switching hardware built for wire-speed forwarding, a Layer 3 switch using SVIs generally routes between VLANs with lower latency and higher throughput than sending everything out to a router-on-a-stick and back, which is exactly the tradeoff the previous lesson’s comparison covered.

Access Port vs. Trunk vs. SVI: Keeping the Roles Straight

It’s worth being precise about which of these three concepts does what, since the exam likes to test the distinction:

ConceptLives OnPurpose
Access PortSwitchConnects one end device to exactly one VLAN
Trunk PortSwitch (or router-facing link)Carries multiple VLANs, tagged, between switches or to a router
SVISwitchA Layer 3, routable interface representing one VLAN, enabling inter-VLAN routing on the switch itself

An access port and an SVI for the same VLAN aren’t the same thing and don’t compete with each other — the access port is where end devices physically plug in on that VLAN, while the SVI is the Layer 3 gateway address for that VLAN as a whole.

Diagram Comparing Inter-Vlan Routing Done Internally Via Svis On A Layer 3 Switch Against Router-On-A-Stick Using An External Router
Where Inter-Vlan Routing Actually Happens: Inside A Layer 3 Switch Via Svis, Versus An External Router

Recognition-Level Verification Concepts

A few patterns are worth recognizing on sight:

  • A switchport mode access plus switchport access vlan <ID> pairing identifies a port dedicated to a single VLAN.
  • An interface Vlan<ID> configuration with an IP address, on a switch rather than a router, is an SVI.
  • A port left unconfigured, with no explicit VLAN assignment, defaults to VLAN 1.
  • The presence (or absence) of ip routing on a switch determines whether its SVIs can actually route between VLANs, not just respond to pings on their own subnet.

Common Exam Traps

  • Creating a VLAN in the database and assigning a port to it are two separate steps. Assigning a port to a VLAN number that doesn’t yet exist in the VLAN database leaves that port nonfunctional.
  • Access ports are single-VLAN and untagged; trunk ports are multi-VLAN and tagged. Mixing these up when reading a configuration or troubleshooting a connectivity issue is one of the most common mistakes in this topic.
  • VLAN 1 is the default for every port and often the default native VLAN too — don’t assume a device is on a specific, deliberately chosen VLAN just because it’s working; it might simply never have been moved off VLAN 1.
  • Creating an SVI does not automatically enable inter-VLAN routing. The switch also needs ip routing enabled globally, or the SVIs will sit there without actually forwarding traffic between VLANs.
  • An SVI is not the same thing as an access port on that VLAN. One is the Layer 3 gateway for the VLAN; the other is where individual devices physically connect.

Lesson 2.2.1 Practice Quiz — VLANs, VLAN Database & SVIs

17 questions covering VLAN fundamentals, the VLAN database, access vs. trunk ports, the default VLAN, and SVIs.

N10-009 · Domain 2.2
Question 1Plain
What is a VLAN?
A VLAN logically separates switch ports into their own broadcast domain, regardless of the physical wiring or location of those ports.
Question 2Plain
What must happen before a switch port can be successfully assigned to a VLAN?
A VLAN must exist in the switch's VLAN database before any port can be meaningfully assigned to it — assigning a port to a nonexistent VLAN leaves it nonfunctional.
Question 3Plain
Which VLAN do all switch ports belong to by default, out of the box?
VLAN 1 is the default VLAN every switch port belongs to before any manual configuration.
Question 4Choose Two
Which two statements about access ports are correct? (Choose two.)
Access ports belong to exactly one VLAN and carry that VLAN's traffic untagged. Carrying multiple VLANs and requiring dot1Q encapsulation both describe trunk ports, not access ports.
Question 5Choose Two
Which two things are required for a Layer 3 switch to actually route traffic between VLANs using SVIs? (Choose two.)
SVIs need their own IP addresses and the switch needs "ip routing" enabled globally. Dot1Q encapsulation and an external router are router-on-a-stick concepts, not part of SVI-based routing on a switch.
Question 6Choose Two
Which two statements about VLAN 1 are correct? (Choose two.)
VLAN 1 is both the default port VLAN and the typical default native VLAN on trunks. It can still be used (it's simply best practice to move end-device traffic off it), and it has no special requirement for router-on-a-stick.
Question 7Scenario
An administrator runs "switchport access vlan 15" on a port, but VLAN 15 was never created with a "vlan 15" command in global configuration. What is the most likely result?
Assigning a port to a VLAN that hasn't been created in the VLAN database leaves that port nonfunctional, even though the assignment command itself appears to succeed.
Question 8Scenario
A single desktop PC needs to be connected to the switch and placed on the Sales VLAN (VLAN 10) only. Which configuration is appropriate?
A single end device belonging to one VLAN should connect to an access port assigned to that VLAN — the standard, simplest configuration for this scenario.
Question 9Scenario
A network team wants their Layer 3 switch to route between VLANs 10 and 20 without adding a separate physical router. What must they configure?
SVIs for each VLAN, combined with ip routing enabled on the switch, let a Layer 3 switch route between VLANs entirely internally — no external router needed.
Question 10Scenario
SVIs are configured with correct IP addresses for VLAN 10 and VLAN 20, and each subnet's own hosts can ping their own SVI. However, hosts on VLAN 10 cannot reach hosts on VLAN 20. What is the most likely cause?
Each SVI working on its own subnet but not routing between subnets is the classic symptom of "ip routing" not being enabled globally — the SVIs exist but the switch isn't actually performing Layer 3 forwarding between them.
Question 11Scenario
A security audit finds that every port on a switch is still on the default VLAN with no segmentation applied. What is the primary concern this raises?
Leaving everything on the default VLAN 1 defeats the purpose of segmentation and is a known security risk, since VLAN 1 is frequently targeted in VLAN-hopping attack techniques.
Question 12Exhibit
Based on this configuration, what has been created?
SW1(config)# vlan 40 SW1(config-vlan)# name GUEST-WIFI
This is the VLAN database creation step — VLAN 40 now exists with the name GUEST-WIFI, but no port has been assigned to it yet.
Question 13Exhibit
Based on this configuration, which VLAN is this port assigned to, and in what mode?
SW1(config)# interface FastEthernet0/12 SW1(config-if)# switchport mode access SW1(config-if)# switchport access vlan 20
"switchport mode access" plus "switchport access vlan 20" explicitly configures this port as an access port dedicated to VLAN 20 only.
Question 14Exhibit
Based on this output, which ports belong to VLAN 10?
SW1# show vlan brief VLAN Name Status Ports ---- ------------- -------- ------------------------------- 1 default active Gi0/1, Gi0/2 10 SALES active Gi0/3, Gi0/4, Gi0/5 20 ENGINEERING active Gi0/6, Gi0/7
The VLAN 10 (SALES) row lists Gi0/3, Gi0/4, and Gi0/5 as its member ports in this show vlan brief output.
Question 15Exhibit
Given this configuration on a switch with no other relevant global commands, why might inter-VLAN routing fail even though the SVIs appear correctly configured?
SW1(config)# interface Vlan10 SW1(config-if)# ip address 192.168.10.1 255.255.255.0 SW1(config-if)# no shutdown SW1(config)# interface Vlan20 SW1(config-if)# ip address 192.168.20.1 255.255.255.0 SW1(config-if)# no shutdown
Both SVIs are configured and enabled with valid, distinct subnets — but without "ip routing" enabled globally, the switch will not actually forward traffic between them.
Question 16Exhibit
A port was assigned to VLAN 25, but this output shows VLAN 25 in an unusual state. What does this indicate?
SW1# show vlan brief VLAN Name Status Ports ---- --------- ---------- ----- 25 VLAN0025 act/unsup Gi0/9
The default auto-generated name "VLAN0025" suggests this VLAN was created (often automatically, by assigning a port to it) without an administrator explicitly naming or fully verifying it — worth double-checking during an audit.
Question 17Exhibit
Comparing these two port configurations, which one is the trunk and which is the access port?
interface Gi0/1 switchport mode trunk switchport trunk allowed vlan 10,20,30 interface Gi0/2 switchport mode access switchport access vlan 10
Gi0/1's "switchport mode trunk" with an allowed VLAN list confirms it as the trunk; Gi0/2's "switchport mode access" with a single VLAN confirms it as the access port.
📝

Summary

A VLAN logically groups switch ports into a separate broadcast domain, independent of physical wiring or location.

VLANs must be created in the switch's VLAN database before any port can be assigned to them.

Access ports belong to exactly one VLAN and carry untagged traffic; trunk ports carry multiple VLANs, each tagged with its VLAN ID.

VLAN 1 is the default VLAN every port belongs to out of the box, and it's typically also the default native VLAN on trunks — leaving traffic on VLAN 1 defeats the purpose of segmentation and carries security risks.

An SVI is a virtual Layer 3 interface configured directly on a switch, representing one VLAN and enabling inter-VLAN routing without an external router — but only once ip routing is enabled on the switch.

Access ports, trunk ports, and SVIs each play a distinct, non-overlapping role in how a VLAN-segmented network actually moves traffic.

Avatar Of Asad Ijaz

Lead Networking Architect and Editor at NetworkUstad. BS in Computer Networks and Security, CCNP and CCNA certified, with 11+ years of experience in enterprise network design, implementation, and troubleshooting. Writes practical tutorials on routing, IPv4 management, network automation, and security fundamentals.