← Network reference library

Wolex engineer reference · Switching

VLANs, trunks & MAC learning

Follow one endpoint VLAN across access ports, trunks and the gateway without confusing link state with forwarding.

Download branded PDF

Revision 2.0 · Documentation reviewed 2026-10-10 · Original Wolex reference

Client VLAN 30Access port802.1Q uplinkVLAN 30 gateway
Verify the same VLAN at every hop. A physical uplink can be up while VLAN 30 is absent or blocked.

Quick reference

CheckAccess portTrunk / uplink
VLAN identityAssigned access VLANAllowed, active and forwarding VLAN
TaggingUsually untagged endpoint802.1Q; native handling must match
MAC learningClient on expected portClient follows expected uplink
GatewayClient resolves its gatewayGateway interface and return path

What to understand first

01

A VLAN is a Layer 2 broadcast domain. Access and trunk describe interface behavior; routing between VLANs requires an L3 gateway and the relevant policy.

02

A trunk has several distinct tests: negotiated/configured mode, VLAN permission, VLAN existence and spanning-tree forwarding. Passing the first does not prove the others.

03

Native VLAN and untagged handling must match the design on both ends. Junos native-vlan-id and interface-mode placement depend on model and configuration style.

04

MAC tables learn source addresses from traffic and age entries out. An absent MAC can mean an idle endpoint, wrong VLAN or missing frames, rather than a broken switch.

Commands and interpretation

Inspection commands are read-only unless explicitly labeled otherwise. Capture commands start collection; configuration-mode commits change device state.

Cisco IOS XE

Read-only EXEC

show interfaces GigabitEthernet1/0/1 switchport
show interfaces trunk
show mac address-table vlan 30
show spanning-tree vlan 30

Inspect: Follow VLAN 30 through allowed, active and forwarding lists; trace the client MAC.

Junos EX/QFX

Read-only operational

show ethernet-switching interfaces
show vlans
show ethernet-switching table
show spanning-tree interface

Inspect: Compare VLAN membership, learned MAC location and STP state. Output details vary by release.

Worked example · Illustrative, not a device capture

Illustrative trunk evidence

Uplink state: up
Configured allowed VLANs: 10,20,30
Active VLANs:             10,20
Client VLAN:             30

VLAN 30 is permitted but not active in this simplified example. Check VLAN existence and the intended configuration on both switches.

Do not overwrite the whole allowed-VLAN list to repair one entry; review the approved change and existing traffic first.

Troubleshooting sequence

  1. Record endpoint MAC, VLAN, port and gateway; generate one controlled application attempt.
  2. Verify access VLAN and physical errors at the endpoint port.
  3. Follow the MAC and VLAN hop by hop, checking trunk permission and STP forwarding at both ends.
  4. Once the gateway is reached, move to ARP, routing and firewall/session checks.
  5. Retest another VLAN sharing the uplink to detect unintended impact.

Common mistakes

  • Equating trunk status with carriage of every VLAN.
  • Copying ELS stanzas directly into a non-ELS switch or vice versa.
  • Changing native VLANs on one end or replacing an allowed list blindly.

Acceptance checks

  • Expected VLANs traverse the uplink and unintended VLANs do not.
  • MACs learn on the expected paths without unexplained movement.
  • Gateway and real client applications pass on each affected VLAN.

Primary references

Vendor documentation and protocol specifications support this guide. The diagrams, scenarios and troubleshooting sequences are Wolex-authored.