VLAN Works Locally but Fails Across the Second Switch

intermediate
LAB TOPOLOGY

Department VLAN Lab

One access switch · four isolated broadcast domains · port map follows the supplied lab

VLAN 10 · SALES · 192.168.10.0/27VLAN 20 · MARKETING · 192.168.20.0/26VLAN 30 · FINANCE · 192.168.30.0/27VLAN 40 · IT · 192.168.40.0/28VLAN 10NICE0/0VLAN 10NICE0/1VLAN 20NICE0/2VLAN 20NICE0/3VLAN 30NICE1/0VLAN 30NICE1/1VLAN 30NICE1/2VLAN 40NICE1/3VLAN 40NICE2/0VLAN 40NICE2/1PC1SALES192.168.10.10/27PC2SALES192.168.10.11/27PC3MRKT192.168.20.10/26PC4MRKT192.168.20.11/26SW1L2 ACCESS SWITCHPC5FINANCE192.168.30.10/27PC6FINANCE192.168.30.11/27PC7FINANCE192.168.30.12/27PC8IT192.168.40.10/28PC9IT192.168.40.11/28PC10IT192.168.40.12/28
Topology note:VLAN IDs, subnet sizes and switch-port assignments follow the supplied VLAN lab. Host IPs are example usable addresses inside those exact subnets.

Symptom

PC1 on SW1 and PC2 on SW2 are both meant to be in VLAN 10. Each access port is correct, but the PCs cannot ping across the inter-switch link.

Investigation path

1. Prove endpoint state. Confirm both IPs and masks belong to the same subnet.

2. Prove access VLAN state.

SW1# show vlan brief
SW2# show vlan brief

3. Inspect the inter-switch link.

SW1# show interfaces trunk
SW2# show interfaces trunk

If VLAN 10 is missing from the allowed/active forwarding list, you have a strong lead.

4. Check MAC learning.

SW1# show mac address-table dynamic vlan 10
SW2# show mac address-table dynamic vlan 10

Root cause example

SW2’s uplink was left in access mode. VLAN 10 frames cannot traverse the link as the design expects.

Fix and proof

Correct both ends as trunks, verify VLAN 10 is carried, clear dynamic MAC entries if needed, and ping again. The important skill is the order: endpoint → access VLAN → trunk → MAC learning.