Build Department VLANs
Department VLAN Lab
One access switch · four isolated broadcast domains · port map follows the supplied lab
Lab objective
A company has Sales, Marketing, Finance and IT users connected to one access switch. Your job is to separate the departments into four VLANs exactly as shown in the topology. At the end, hosts in the same VLAN should communicate at Layer 2; hosts in different VLANs should not communicate because this lab intentionally has no Layer-3 gateway.
VLAN and addressing plan
| Department | VLAN | Subnet from supplied lab | Switch ports | Example hosts |
|---|---|---|---|---|
| Sales | 10 | 192.168.10.0/27 | E0/0-E0/1 | PC1 .10, PC2 .11 |
| Marketing | 20 | 192.168.20.0/26 | E0/2-E0/3 | PC3 .10, PC4 .11 |
| Finance | 30 | 192.168.30.0/27 | E1/0-E1/2 | PC5 .10, PC6 .11, PC7 .12 |
| IT | 40 | 192.168.40.0/28 | E1/3, E2/0-E2/1 | PC8 .10, PC9 .11, PC10 .12 |
The VLAN IDs, department names, subnet sizes and port grouping follow the supplied CCNA lab. Example host IPs are AddySec choices inside those subnets.
Before configuration
On SW1, confirm the access interfaces are up. Then check the current VLAN database.
SW1> enable
SW1# show interfaces status
SW1# show vlan brief
Step 1 — Create the VLANs
SW1# configure terminal
SW1(config)# vlan 10
SW1(config-vlan)# name SALES
SW1(config-vlan)# exit
SW1(config)# vlan 20
SW1(config-vlan)# name MRKT
SW1(config-vlan)# exit
SW1(config)# vlan 30
SW1(config-vlan)# name FINANCE
SW1(config-vlan)# exit
SW1(config)# vlan 40
SW1(config-vlan)# name IT
SW1(config-vlan)# exit
Step 2 — Assign access ports
SW1(config)# interface range ethernet 0/0-1
SW1(config-if-range)# switchport mode access
SW1(config-if-range)# switchport access vlan 10
SW1(config-if-range)# exit
SW1(config)# interface range ethernet 0/2-3
SW1(config-if-range)# switchport mode access
SW1(config-if-range)# switchport access vlan 20
SW1(config-if-range)# exit
SW1(config)# interface range ethernet 1/0-2
SW1(config-if-range)# switchport mode access
SW1(config-if-range)# switchport access vlan 30
SW1(config-if-range)# exit
SW1(config)# interface ethernet 1/3
SW1(config-if)# switchport mode access
SW1(config-if)# switchport access vlan 40
SW1(config-if)# exit
SW1(config)# interface range ethernet 2/0-1
SW1(config-if-range)# switchport mode access
SW1(config-if-range)# switchport access vlan 40
SW1(config-if-range)# end
Step 3 — Configure PCs
Give each PC an address from its department subnet. Do not configure a default gateway yet. This makes the isolation test easier to understand.
Step 4 — Verify switch state
SW1# show vlan brief
SW1# show running-config | section interface
You should see every access interface under the intended VLAN.
Step 5 — Test the design
From PC1, ping PC2: should work. From PC1, ping PC3: should fail. That failure is expected: VLAN 10 and VLAN 20 are separate broadcast domains and no router/L3 SVI exists yet.
Break it
Move PC2’s port E0/1 into VLAN 20. Predict the result before testing. Then use show vlan brief to prove the mistake and restore E0/1 to VLAN 10.
What you should be able to explain
Why can two hosts on the same physical switch fail to communicate? Because the switch can logically separate them into different Layer-2 broadcast domains.
Reference
Based on the VLAN tasks, VLAN IDs, subnet ranges and access-port assignments in the supplied CCNA All LABS material. Wording, host examples, verification flow and break/fix exercise are AddySec original content.