Runbook 02 — VLAN and Trunk Troubleshooting
Runbook Information
Section titled “Runbook Information”| Item | Details |
|---|---|
| Runbook | 02 |
| Runbook Name | VLAN and Trunk Troubleshooting |
| Track | CompTIA Network+ |
| Type | Network Operations Runbook |
| Primary Role | Network Technician / Network Administrator |
| Difficulty | Intermediate |
| Use Case | VLAN segmentation and trunk connectivity incidents |
| Primary Tools | Switch CLI, Ping, Traceroute, ARP, MAC Address Table, Wireshark, Syslog, SNMP |
| Primary Technologies | Ethernet, VLANs, IEEE 802.1Q, Access Ports, Trunks |
| Outcome | Identify, isolate, remediate, verify, escalate, and document Layer 2 connectivity faults |
Runbook Objective: Provide a structured procedure for investigating VLAN and trunk connectivity incidents without making unnecessary configuration changes. The objective is to determine whether the failure exists at the endpoint, access port, VLAN database, trunk, allowed VLAN list, native VLAN configuration, MAC-learning process, or upstream network path.
When to Use This Runbook
Section titled “When to Use This Runbook”Use this runbook when:
Users in one VLAN cannot communicate.
One department has lost network access.
Devices receive addresses from the wrong network.
A VLAN works on one switch but not another.
A VLAN cannot cross an inter-switch link.
Some VLANs work across a trunk while others fail.
Newly created VLANs do not work.
A switch replacement causes selective connectivity failures.
Wireless users connect but cannot reach their VLAN gateway.
A trunk is operational but selected users remain unreachable.Typical incidents include:
-
incorrect access VLAN
-
missing VLAN
-
disabled VLAN
-
incorrect access-port configuration
-
trunk failure
-
incorrect trunk encapsulation
-
missing allowed VLAN
-
native VLAN mismatch
-
incorrect native VLAN
-
VLAN pruning
-
MAC-learning problems
-
inter-switch connectivity problems
-
Layer 2 loops
-
configuration drift
1. Understand the Layer 2 Path
Section titled “1. Understand the Layer 2 Path”Before troubleshooting, determine the expected Layer 2 path.
Example:
CLIENT01 ↓Access Port ↓VLAN 10 ↓SW02 ↓802.1Q Trunk ↓SW01 ↓GatewayFor communication to succeed:
Access Port +VLAN +Trunk +Allowed VLAN +MAC Learning +Gateway Pathmust all operate correctly.
2. Troubleshooting Principle
Section titled “2. Troubleshooting Principle”Follow:
Symptom ↓Scope ↓Access Port ↓VLAN ↓MAC Learning ↓Trunk ↓Allowed VLAN ↓Upstream Path ↓Root Cause ↓Remediation ↓VerificationDo not immediately:
Delete VLANs
Recreate Trunks
Reset Switches
Allow All VLANs
Reboot SwitchesThese actions can hide the original problem.
3. Record the Incident
Section titled “3. Record the Incident”Document:
Incident ID:
Date:
Time:
Reported By:
Affected Users:
Affected VLAN:
Affected Switch:
Affected Interfaces:
Business Impact:
Recent Changes:Example:
Incident ID:INC-VLAN-2041
Affected:Finance Department
VLAN:10
Switch:SW02
Problem:Finance users cannot reach their default gateway.
Impact:25 users affected.4. Record the Exact Symptom
Section titled “4. Record the Exact Symptom”Avoid:
VLAN is broken.Prefer:
Clients connected to VLAN 10 on SW02 cannot reach10.10.10.1.
VLAN 20 clients on the same switch remain operational.This immediately suggests:
Selective VLAN Failurerather than:
Complete Switch Failure5. Determine Scope
Section titled “5. Determine Scope”Ask:
One Device?
One Port?
One VLAN?
One Switch?
Multiple Switches?
All VLANs?
One Trunk?
Entire Site?Create:
| Test | Result |
|---|---|
| Same VLAN / Same Switch | |
| Same VLAN / Different Switch | |
| Different VLAN / Same Switch | |
| Different VLAN / Different Switch |
6. Check Recent Changes
Section titled “6. Check Recent Changes”Review:
VLAN Creation
VLAN Deletion
Port Assignment Changes
Trunk Configuration
Allowed VLAN Changes
Native VLAN Changes
Switch Replacement
Firmware Upgrade
Configuration RestoreRecord:
Change ID:
Engineer:
Time:
Affected Device:7. Establish Expected VLAN Architecture
Section titled “7. Establish Expected VLAN Architecture”Example:
| VLAN | Name | Network | Purpose |
|---|---|---|---|
| 10 | USERS | 10.10.10.0/24 |
Corporate users |
| 20 | ENGINEERING | 10.10.20.0/24 |
Engineering |
| 30 | SERVERS | 10.10.30.0/24 |
Servers |
| 40 | MANAGEMENT | 10.10.40.0/24 |
Infrastructure |
| 50 | CORP-WIFI | 10.10.50.0/24 |
Wireless |
| 60 | GUEST | 10.10.60.0/24 |
Guest |
Do not troubleshoot without knowing:
What VLAN Should This Device Be In?8. Identify the Endpoint
Section titled “8. Identify the Endpoint”Collect:
Hostname:
IP Address:
Subnet Mask:
Default Gateway:
MAC Address:
Switch:
Switch Port:
Expected VLAN:Windows:
ipconfig /allLinux:
ip addr9. Check Physical Connectivity
Section titled “9. Check Physical Connectivity”Verify:
NIC Enabled
Cable Connected
Link LED
Switch Port Up
Correct Speed
Correct DuplexOn the switch:
show interfaces statusIf the port is:
DOWNresolve Layer 1 before continuing with VLAN troubleshooting.
10. Verify the Access Port
Section titled “10. Verify the Access Port”Identify the endpoint interface.
Example:
CLIENT01 ↓SW02 Gi0/10Run:
show interfaces Gi0/10 switchportVerify:
Administrative Mode:static access
Operational Mode:static access
Access VLAN:1011. Check VLAN Membership
Section titled “11. Check VLAN Membership”Run:
show vlan briefExpected:
VLAN 10Name: USERSStatus: active
Gi0/10→ VLAN 10Compare:
Expected VLANvsActual VLAN12. Decision Point — Wrong Access VLAN
Section titled “12. Decision Point — Wrong Access VLAN”Suppose:
Expected:VLAN 10
Actual:VLAN 20Likely root cause:
Incorrect Access-Port AssignmentDo not troubleshoot routing before correcting the Layer 2 configuration.
13. Verify VLAN Exists
Section titled “13. Verify VLAN Exists”Run:
show vlan briefConfirm the VLAN exists on every required switch.
Example:
SW01:VLAN 10 present
SW02:VLAN 10 present
SW03:VLAN 10 present14. Decision Point — VLAN Missing
Section titled “14. Decision Point — VLAN Missing”If:
SW01:VLAN 10 exists
SW02:VLAN 10 missingdevices connected to SW02 cannot correctly participate in VLAN 10.
Determine why the VLAN is missing before recreating it.
15. Verify VLAN Status
Section titled “15. Verify VLAN Status”Confirm:
Status:activeDo not assume that existence alone means the VLAN is operational.
16. Check MAC Address Learning
Section titled “16. Check MAC Address Learning”Run:
show mac address-tableLocate the endpoint MAC.
Expected:
MAC Address ↓VLAN 10 ↓Gi0/10Record:
MAC:
VLAN:
Interface:
Type:17. Decision Point — MAC Not Learned
Section titled “17. Decision Point — MAC Not Learned”If the switch does not learn the endpoint MAC, investigate:
Cable
NIC
Port State
Access VLAN
Port Security
Endpoint TrafficGenerate controlled traffic:
ping <DEFAULT-GATEWAY>Then check the MAC table again.
18. Check for MAC Learning on Wrong Port
Section titled “18. Check for MAC Learning on Wrong Port”If the MAC appears on an unexpected interface:
Expected:Gi0/10
Actual:Gi0/24investigate:
Incorrect Cabling
Topology Documentation
Loop
Unexpected Intermediate Device19. Test the Default Gateway
Section titled “19. Test the Default Gateway”From the endpoint:
ping 10.10.10.1If:
Gateway:UNREACHABLEbut the endpoint configuration is correct, continue investigating the Layer 2 path.
20. Identify the Required Trunk
Section titled “20. Identify the Required Trunk”Example:
CLIENT01 ↓SW02 ↓Gi0/1 ↓802.1Q Trunk ↓SW01Determine every trunk the VLAN must traverse.
21. Check Trunk State
Section titled “21. Check Trunk State”Run:
show interfaces trunkVerify:
Port
Mode
Encapsulation
Status
Native VLANExpected:
Status:trunking22. Decision Point — Trunk Not Formed
Section titled “22. Decision Point — Trunk Not Formed”If the expected link is not trunking, inspect both ends.
Check:
SW01 Interface Configuration
SW02 Interface ConfigurationA trunk requires compatible configuration.
23. Compare Both Ends
Section titled “23. Compare Both Ends”Document:
| Parameter | SW01 | SW02 |
|---|---|---|
| Interface | ||
| Mode | ||
| Trunk Status | ||
| Native VLAN | ||
| Allowed VLANs |
Configuration mismatches are easier to identify when compared side-by-side.
24. Check Allowed VLANs
Section titled “24. Check Allowed VLANs”Run:
show interfaces trunkLook for:
Vlans allowed on trunkExample:
10,20,30,4025. Decision Point — VLAN Missing from Allowed List
Section titled “25. Decision Point — VLAN Missing from Allowed List”Suppose:
Required:VLAN 10
Allowed:20,30,40The physical trunk may remain:
UPwhile VLAN 10 traffic fails.
This produces:
Selective VLAN Outage26. Compare Required and Allowed VLANs
Section titled “26. Compare Required and Allowed VLANs”Create:
| VLAN | Required | SW01 Allowed | SW02 Allowed | Result |
|---|---|---|---|---|
| 10 | Yes | |||
| 20 | Yes | |||
| 30 | Yes | |||
| 40 | Yes | |||
| 50 | No/Yes |
27. Do Not Solve by Allowing Everything
Section titled “27. Do Not Solve by Allowing Everything”Avoid immediately configuring:
Allow All VLANsInstead allow:
Only Required VLANsThis preserves segmentation and reduces unnecessary Layer 2 exposure.
28. Check Active VLANs on the Trunk
Section titled “28. Check Active VLANs on the Trunk”Review:
Vlans allowed and active in management domainA VLAN may be allowed but unavailable because it does not exist locally.
Therefore:
Allowed≠Active29. Check Forwarding VLANs
Section titled “29. Check Forwarding VLANs”Review:
Vlans in spanning tree forwarding state and not prunedThis helps determine whether the VLAN is actually forwarding across the trunk.
30. Check Native VLAN
Section titled “30. Check Native VLAN”Run:
show interfaces trunkCompare the native VLAN on both sides.
Example:
SW01:Native VLAN 99
SW02:Native VLAN 1This is:
Native VLAN Mismatch31. Understand Native VLAN Behavior
Section titled “31. Understand Native VLAN Behavior”In standard 802.1Q operation:
Tagged Frames→ VLAN Identifier PresentNative VLAN traffic may be transmitted untagged depending on platform configuration.
A mismatch can cause:
Unexpected Traffic Placement
Connectivity Problems
Security Risk
Protocol Warnings32. Review Syslog for Native VLAN Warnings
Section titled “32. Review Syslog for Native VLAN Warnings”Search for events such as:
Native VLAN mismatchRecord:
Timestamp:
Local Interface:
Local VLAN:
Neighbor:
Neighbor VLAN:33. Check Spanning Tree
Section titled “33. Check Spanning Tree”Where supported:
show spanning-treeor:
show spanning-tree vlan 10Verify the required interface state.
Possible states include:
Forwarding
Blocking / Discardingdepending on the implementation.
34. Do Not Disable STP to Restore Connectivity
Section titled “34. Do Not Disable STP to Restore Connectivity”Never treat:
Spanning Tree Blockingas automatically incorrect.
STP may be preventing:
Layer 2 LoopUnderstand the topology before making changes.
35. Look for Layer 2 Loops
Section titled “35. Look for Layer 2 Loops”Symptoms can include:
High Broadcast Traffic
MAC Address Flapping
High CPU
Network Instability
Packet Loss
Severe Performance Degradation36. Check for MAC Flapping
Section titled “36. Check for MAC Flapping”Review switch logs and MAC tables.
A MAC repeatedly appearing on multiple ports may indicate:
Layer 2 Loop
Incorrect Cabling
Unexpected Switching Device37. Check Interface Counters
Section titled “37. Check Interface Counters”Run:
show interfaces <interface>Inspect:
Input Errors
Output Errors
CRC Errors
Drops
Runts
Giants
CollisionsDo not confuse physical degradation with VLAN misconfiguration.
38. Test Same-VLAN Connectivity
Section titled “38. Test Same-VLAN Connectivity”Test two devices:
CLIENT0110.10.10.20and:
CLIENT0210.10.10.21Both should be in VLAN 10.
Test:
ping 10.10.10.2139. Interpret Same-VLAN Failure
Section titled “39. Interpret Same-VLAN Failure”If same-VLAN devices cannot communicate, investigate:
Access VLAN
Switch Port
Trunk
MAC Learning
Host Firewall
Physical ConnectivityRouting is generally not required for communication within the same subnet.
40. Test Across Switches
Section titled “40. Test Across Switches”Place:
CLIENT01→ SW02and:
CLIENT02→ SW03in the same VLAN.
If they communicate on the same switch but fail across switches, investigate:
Inter-Switch Trunks41. Use Controlled Comparison
Section titled “41. Use Controlled Comparison”Example:
CLIENT01 → CLIENT02Same SwitchSUCCESS
CLIENT01 → CLIENT03Different SwitchFAILUREThis strongly suggests the problem exists:
Between Switches42. Check VLAN Tagging with Wireshark
Section titled “42. Check VLAN Tagging with Wireshark”Where capture location supports VLAN visibility, use:
vlanor:
vlan.id == 10Remember that endpoint captures may not display tags because access ports typically deliver untagged Ethernet frames.
43. Understand Where to Capture
Section titled “43. Understand Where to Capture”For VLAN-tag analysis, capture near:
Trunk Links
SPAN / Mirror Ports
Virtual Switches
Hypervisor Interfacesrather than relying only on endpoint captures.
44. Check ARP Behavior
Section titled “44. Check ARP Behavior”From CLIENT01:
arp -aThen:
ping 10.10.10.1Inspect whether the gateway MAC is learned.
45. Decision Point — ARP Failure
Section titled “45. Decision Point — ARP Failure”If CLIENT01 repeatedly sends:
Who has 10.10.10.1?without receiving a response, investigate:
VLAN Path
Gateway Interface
Trunk
Allowed VLAN
Layer 2 Connectivity46. Capture ARP
Section titled “46. Capture ARP”Wireshark filter:
arpLook for:
ARP Requestfollowed by:
ARP ReplyNo reply can provide valuable Layer 2 evidence.
47. Check Gateway VLAN Interface
Section titled “47. Check Gateway VLAN Interface”If Layer 2 appears healthy, verify the gateway interface.
Examples:
SVIor:
Router SubinterfaceCheck:
show ip interface brief48. Verify Router-on-a-Stick Configuration
Section titled “48. Verify Router-on-a-Stick Configuration”Where used:
RTR01 |802.1Q Trunk |SW01Each routed subinterface should correspond to the correct VLAN.
Conceptually:
VLAN 10→ 10.10.10.1
VLAN 20→ 10.10.20.149. Verify VLAN Encapsulation Mapping
Section titled “49. Verify VLAN Encapsulation Mapping”An incorrect mapping such as:
Gateway:10.10.10.1
802.1Q VLAN:20can prevent VLAN 10 clients from reaching their gateway.
50. Distinguish Layer 2 from Layer 3
Section titled “50. Distinguish Layer 2 from Layer 3”If:
Same VLAN Communication:WORKING
Default Gateway:UNREACHABLEinvestigate:
Gateway Interface
Router Trunk
SVI
Router Subinterfacerather than access switching alone.
51. Investigate Wireless VLAN Mapping
Section titled “51. Investigate Wireless VLAN Mapping”For wireless incidents:
SSID ↓VLAN Mapping ↓AP Uplink ↓Switch TrunkExample:
GHC-CORP→ VLAN 5052. Check AP Switch Port
Section titled “52. Check AP Switch Port”Determine whether AP01 requires:
Access Portor:
Trunkdepending on the wireless architecture.
Multiple SSIDs mapped to multiple VLANs commonly require tagged VLAN transport.
53. Verify Wireless VLANs Across the Path
Section titled “53. Verify Wireless VLANs Across the Path”Check:
AP01 ↓Access Switch ↓Core Switch ↓GatewayVerify VLAN 50 exists and is permitted everywhere required.
54. Investigate Management VLAN Problems
Section titled “54. Investigate Management VLAN Problems”If network devices cannot be managed, verify:
Management VLAN
Management IP
Switch Management Interface
Default Gateway
Trunk Path
ACLDo not confuse:
Data Plane Workingwith:
Management Plane Working55. Check Configuration Drift
Section titled “55. Check Configuration Drift”Compare:
Running Configurationagainst:
Known-Good ConfigurationFocus on:
VLAN Definitions
Access Ports
Trunk Ports
Allowed VLANs
Native VLANs
SVIs
Management VLAN56. Review Configuration Changes
Section titled “56. Review Configuration Changes”Where available:
show running-configCompare with backups or change-management records.
Look for:
interface configuration changes
switchport mode changes
switchport access vlan changes
switchport trunk allowed vlan changes
native VLAN changes57. Build a Theory Matrix
Section titled “57. Build a Theory Matrix”| Theory | Evidence For | Evidence Against | Test | Result |
|---|---|---|---|---|
| Wrong access VLAN | ||||
| VLAN missing | ||||
| Trunk down | ||||
| VLAN not allowed | ||||
| Native VLAN mismatch | ||||
| STP issue | ||||
| Gateway VLAN issue | ||||
| Physical fault |
58. Fault Isolation Example
Section titled “58. Fault Isolation Example”Suppose:
CLIENT01↓Valid IPAccess Port↓VLAN 10MAC Learned↓CorrectSW02 VLAN 10↓PresentSW02 → SW01 Trunk↓UPbut:
Allowed VLANs↓20,30,40Root cause:
VLAN 10 Missing from Allowed VLAN List59. Create the Root Cause Statement
Section titled “59. Create the Root Cause Statement”Example:
Finance users connected to SW02 lost access to thenetwork because VLAN 10 was removed from the allowedVLAN list on the SW02-to-SW01 trunk.
The trunk remained operational, but VLAN 10 framescould no longer traverse the inter-switch link.60. Document the Proposed Remediation
Section titled “60. Document the Proposed Remediation”Before making changes:
Current Configuration:
Expected Configuration:
Proposed Change:
Affected Interface:
Affected VLAN:
Risk:
Rollback Plan:61. Implement the Minimum Change
Section titled “61. Implement the Minimum Change”If the issue is:
VLAN 10 Missingrestore only the required VLAN according to the approved configuration.
Do not unnecessarily:
Reset Entire Trunk
Delete/Recreate VLAN Database
Reload Switch62. Verify the Configuration
Section titled “62. Verify the Configuration”After remediation:
show vlan briefshow interfaces trunkshow mac address-tableConfirm expected Layer 2 state.
63. Retest the Original Symptom
Section titled “63. Retest the Original Symptom”From CLIENT01:
ping 10.10.10.1Then test the required enterprise services.
64. Test Same-VLAN Communication
Section titled “64. Test Same-VLAN Communication”Verify:
CLIENT01 ↓CLIENT02works as expected.
65. Test Inter-VLAN Communication
Section titled “65. Test Inter-VLAN Communication”Where permitted:
CLIENT01 ↓Gateway ↓SERVER01Confirm routing still works after the Layer 2 remediation.
66. Verify Other VLANs
Section titled “66. Verify Other VLANs”A trunk modification can affect multiple networks.
Test:
VLAN 10
VLAN 20
VLAN 30
VLAN 40according to the network design.
67. Verify Monitoring
Section titled “67. Verify Monitoring”Check:
Switch Availability
Interface Status
Trunk Status
Packet Loss
Interface ErrorsEnsure monitoring returns to baseline.
68. Review Syslog After Remediation
Section titled “68. Review Syslog After Remediation”Look for:
Interface Changes
Trunk Changes
Native VLAN Warnings
STP Changes
MAC FlappingConfirm no unexpected new events appear.
69. Verify Stability
Section titled “69. Verify Stability”Do not close the incident immediately after one successful ping.
Monitor:
Connectivity
Interface State
Errors
Packet Loss
MAC Stabilityfor an appropriate validation period.
70. Escalation Criteria
Section titled “70. Escalation Criteria”Escalate when:
-
multiple switches exhibit unexplained VLAN loss
-
STP instability exists
-
Layer 2 loops are suspected
-
MAC flapping continues
-
production core configuration requires senior approval
-
hardware failure is suspected
-
switch software defects are suspected
-
change authority is required
-
root cause cannot be isolated safely
71. Escalation Package
Section titled “71. Escalation Package”Provide:
Incident ID
Affected VLANs
Affected Switches
Affected Interfaces
Business Impact
Expected Topology
Actual Behavior
VLAN Output
Trunk Output
MAC Table
STP Output
Relevant Syslog
Tests Completed
Changes Made72. Example Escalation
Section titled “72. Example Escalation”INC-VLAN-2041
VLAN 10 connectivity is unstable between SW02 and SW01.
Access ports and VLAN membership have been verified.
The inter-switch trunk remains operational.
VLAN 10 is allowed and active.
Syslog shows repeated spanning-tree topology changes.
MAC addresses are intermittently moving between Gi0/1and Gi0/2.
No configuration changes have been made.
Suspected Layer 2 loop.
Requesting Network Engineering investigation.73. VLAN Troubleshooting Decision Tree
Section titled “73. VLAN Troubleshooting Decision Tree”VLAN Connectivity Failure ↓Physical Port Up? ┌───┴───┐ NO YES ↓ ↓ Layer 1 Correct Access VLAN? ┌───┴───┐ NO YES ↓ ↓ Correct VLAN Exists? ┌───┴───┐ NO YES ↓ ↓ VLAN DB MAC Learned? ┌───┴───┐ NO YES ↓ ↓ Endpoint/L2 Cross-Switch? ┌───┴───┐ NO YES ↓ ↓ Local L2 Trunk Up? ┌───┴───┐ NO YES ↓ ↓ Trunk VLAN Allowed? ┌───┴───┐ NO YES ↓ ↓ Allow STP/Gateway74. Selective VLAN Failure Decision Tree
Section titled “74. Selective VLAN Failure Decision Tree”Trunk Is UP ↓Some VLANs Work? ↓ YES ↓Check Affected VLAN ↓VLAN Exists? ↓VLAN Allowed? ↓VLAN Active? ↓STP Forwarding? ↓Gateway Available?75. Quick Command Reference
Section titled “75. Quick Command Reference”show vlan briefInterface State
Section titled “Interface State”show interfaces statusAccess Port
Section titled “Access Port”show interfaces <interface> switchportTrunks
Section titled “Trunks”show interfaces trunkMAC Table
Section titled “MAC Table”show mac address-tableInterface Counters
Section titled “Interface Counters”show interfaces <interface>Spanning Tree
Section titled “Spanning Tree”show spanning-treeshow spanning-tree vlan <VLAN-ID>Configuration
Section titled “Configuration”show running-configLayer 3 Interfaces
Section titled “Layer 3 Interfaces”show ip interface brief76. Wireshark Quick Reference
Section titled “76. Wireshark Quick Reference”| Investigation | Filter |
|---|---|
| ARP | arp |
| VLAN tagged traffic | vlan |
| Specific VLAN | vlan.id == 10 |
| ICMP | icmp |
| DHCP | dhcp |
77. Common VLAN Problems
Section titled “77. Common VLAN Problems”| Problem | Typical Symptom |
|---|---|
| Wrong access VLAN | Device placed in wrong network |
| VLAN missing | Ports cannot use expected VLAN |
| Trunk down | Multiple VLANs fail across switches |
| VLAN not allowed | One or selected VLANs fail |
| Native VLAN mismatch | Unexpected connectivity / warnings |
| STP blocking | Path unavailable by design or topology issue |
| MAC-learning failure | Endpoint unreachable |
| Wrong AP VLAN mapping | Wireless connectivity failure |
| Wrong gateway VLAN mapping | VLAN cannot reach routed networks |
78. Operational Checklist
Section titled “78. Operational Checklist”Incident Intake
Section titled “Incident Intake”-
Incident recorded
-
Exact symptom documented
-
Business impact determined
-
Scope identified
-
Recent changes reviewed
Endpoint
Section titled “Endpoint”-
Physical connectivity verified
-
IP configuration reviewed
-
MAC address recorded
-
Expected VLAN identified
-
Gateway tested
Access Port
Section titled “Access Port”-
Interface identified
-
Interface up
-
Speed/duplex checked
-
Access mode verified
-
Correct VLAN assigned
-
Errors reviewed
-
VLAN exists
-
VLAN active
-
VLAN present on required switches
-
Correct ports assigned
MAC Learning
Section titled “MAC Learning”-
Endpoint MAC learned
-
Correct VLAN associated
-
Correct interface associated
-
MAC flapping checked
-
Required trunk identified
-
Trunk operational
-
Both ends compared
-
Required VLAN allowed
-
VLAN active on trunk
-
Native VLAN compared
Spanning Tree
Section titled “Spanning Tree”-
STP state reviewed
-
Unexpected blocking investigated
-
Topology changes reviewed
-
Layer 2 loops considered
-
MAC flapping investigated
Gateway
Section titled “Gateway”-
Gateway interface operational
-
Correct VLAN mapping verified
-
Router/SVI configuration checked
-
Gateway reachable
Wireless
Section titled “Wireless”-
SSID VLAN mapping checked
-
AP uplink configuration checked
-
Wireless VLAN allowed across trunks
-
Gateway reachable
Monitoring
Section titled “Monitoring”-
SNMP checked
-
Syslog reviewed
-
Interface alerts reviewed
-
STP events reviewed
Remediation
Section titled “Remediation”-
Root cause identified
-
Current configuration documented
-
Proposed change documented
-
Risk considered
-
Rollback considered
-
Minimum required change implemented
Verification
Section titled “Verification”-
VLAN configuration verified
-
Trunk configuration verified
-
MAC learning verified
-
Gateway connectivity verified
-
Same-VLAN connectivity verified
-
Cross-switch connectivity verified
-
Other VLANs tested
-
Monitoring healthy
Closure
Section titled “Closure”-
Root cause documented
-
Corrective action documented
-
Preventive action documented
-
Users confirmed recovery
-
Incident closed
79. Incident Documentation Template
Section titled “79. Incident Documentation Template”# VLAN and Trunk Incident
## Incident Information
Incident ID:
Date:
Start Time:
Resolution Time:
Severity:
## Business Impact
## Affected Users
## Affected VLANs
## Affected Switches
## Reported Symptoms
## Incident Scope
## Expected Network Path
## Recent Changes
## Initial Evidence
## Access Port Investigation
## VLAN Investigation
## MAC Address Investigation
## Trunk Investigation
## Allowed VLAN Investigation
## Native VLAN Investigation
## Spanning Tree Investigation
## Gateway Investigation
## Root Cause
## Corrective Action
## Verification
## Monitoring Status
## Preventive Recommendation
## Escalation
## Final Status
RESOLVED / ESCALATED80. Preventive Recommendations
Section titled “80. Preventive Recommendations”Depending on the root cause, consider:
Configuration Backups
Automated Configuration Comparison
Change Approval
Post-Change Testing
VLAN Standards
Trunk Standards
Allowed-VLAN Documentation
Native-VLAN Standards
STP Monitoring
MAC-Flapping Alerts
Configuration Templates81. Example Preventive Action
Section titled “81. Example Preventive Action”Instead of:
Improve monitoring.write:
Configure monitoring to alert when VLAN 10 disappearsfrom the allowed VLAN list on the SW01-to-SW02production trunk.Specific recommendations are operationally useful.
82. Runbook Success Criteria
Section titled “82. Runbook Success Criteria”The runbook is successfully completed when:
Affected VLAN=OperationalAccess Ports=CorrectRequired Trunks=OperationalAllowed VLANs=CorrectMAC Learning=NormalGateway Connectivity=Operationaland:
Root Cause=DocumentedRunbook Review
Section titled “Runbook Review”VLAN troubleshooting should never begin with:
"The trunk is probably broken."Instead determine:
Is the endpoint connected? ↓Is the port correct? ↓Is the VLAN correct? ↓Does the VLAN exist? ↓Is the MAC learned? ↓Does traffic need a trunk? ↓Is the trunk operational? ↓Is the VLAN allowed? ↓Is STP forwarding? ↓Is the gateway available?This transforms a vague Layer 2 problem into a sequence of testable questions.
A trunk can be:
UPwhile one VLAN remains:
DOWNfrom the user’s perspective.
Similarly:
VLAN Existsdoes not automatically mean:
VLAN Can Traverse the NetworkThe professional troubleshooting approach is therefore:
Expected State ↓Actual State ↓Difference ↓Evidence ↓Root Cause ↓Controlled Remediation ↓ValidationThe purpose of VLAN and trunk troubleshooting is not merely to restore connectivity. It is to identify exactly where Layer 2 forwarding differs from the intended network design, correct the minimum required configuration, and prove that segmentation and connectivity remain correct after remediation.
What’s Next?
Section titled “What’s Next?”Runbook 03 — DHCP and IP Addressing Troubleshooting
Section titled “Runbook 03 — DHCP and IP Addressing Troubleshooting”The next runbook moves from Layer 2 connectivity into endpoint network configuration and address-assignment failures.
You will troubleshoot:
-
missing IPv4 configuration
-
APIPA addresses
-
incorrect static addressing
-
incorrect subnet masks
-
incorrect default gateways
-
DHCP scope exhaustion
-
DHCP server failures
-
DHCP relay failures
-
incorrect DHCP options
-
duplicate IP addresses
-
lease problems
-
VLAN-to-DHCP relationships
-
DHCP packet analysis
-
DORA failures
-
remediation and verification
The operational progression becomes:
Layer 2 Connectivity ↓VLAN / Trunk Validation ↓IP Addressing ↓DHCP ↓Gateway Configuration ↓Root Cause ↓Remediation ↓Validation➡️ Next: Runbook 03 — DHCP and IP Addressing Troubleshooting