Switching, VLANs, and Layer 2 Segmentation Questions
Layer 2 switching and segmentation: MAC learning, aging and forwarding (including unknown-unicast flooding and cut-through versus store-and-forward), VLAN design and 802.1Q trunking (tag format, native VLAN, DTP trunk negotiation, VTP, voice VLAN, private VLANs, Q-in-Q), spanning tree (STP, RSTP, MST and edge protection such as PortFast, BPDU guard and root guard), EtherChannel/LACP and MLAG, multicast handling with IGMP snooping, and the hand-off between layer 2 and layer 3 (SVIs, router-on-a-stick, routed ports). Covers access and trunk port configuration and verification, switch-level fault diagnosis (trunk and native VLAN mismatches, MAC flapping, broadcast storms, bundles that will not form), campus, small-office and data-centre VLAN plans, and migrating or renumbering VLANs with minimal downtime. Boundary: attack and defense mechanics (MAC flooding, DHCP snooping, ARP inspection, VLAN hopping), routing protocol configuration, VXLAN/EVPN overlays, fabric and whole-campus topology choice, device automation, and the generic layered troubleshooting method are covered elsewhere.
A 50-person company needs its first VLAN plan covering staff, guests, servers, printers, voice phones and management. Propose VLAN IDs, subnet sizes and purpose for each, and say what would be unsafe to leave flat. Which controls between the VLANs are out of scope for your answer?
Sample Answer
Direct answer
For 50 people I would build six VLANs (virtual LANs, separate broadcast domains): staff, voice, servers, printers, guests and management, each in its own subnet, with the routing between them done at the firewall. Leaving everything flat is unsafe for the guest, management and server segments in particular, because a visitor's phone would then share a broadcast domain with the switch login pages and the file server. Writing the filtering rules between the VLANs belongs to the security owner (see the hand-off below).
The plan
Subnet sizes come from usable hosts = 2^(32 - prefix) - 2, with room for growth. The prefix (the number after the slash) is how many of the 32 address bits name the network, and the rest number the hosts. Worked: /25 leaves 32 - 25 = 7 host bits, 2^7 = 128 addresses, minus 2 reserved (network and broadcast) = 126 usable; /26 gives 62, /27 gives 30, /28 gives 14. All subnets are carved from 10.10.0.0/16 with no overlaps.
| VLAN | Name | Subnet | Usable hosts | Purpose and sizing |
|---|---|---|---|---|
| 10 | STAFF | 10.10.10.0/25 | 126 | 50 people at about two devices each is about 100, so /25 keeps headroom |
| 20 | VOICE | 10.10.20.0/26 | 62 | 50 desk phones plus a few spares |
| 30 | SERVERS | 10.10.30.0/27 | 30 | File server, NAS, a few application hosts |
| 40 | PRINTERS | 10.10.40.0/28 | 14 | 6 or so printers and scanners |
| 50 | GUEST | 10.10.50.0/25 | 126 | Visitor phones and laptops; short DHCP leases |
| 99 | MGMT | 10.10.99.0/28 | 14 | Switch, access point and firewall management addresses |
On a trunk every frame normally carries a tag naming its VLAN; the native VLAN is the one VLAN whose frames cross the trunk untagged, and any untagged frame arriving is treated as belonging to it (Cisco: untagged traffic is forwarded in the native VLAN configured for the port). The unused VLAN 999 is the native VLAN on trunks, so untagged traffic lands in a VLAN with no hosts and no gateway, where it can do no harm. VLAN 1 is not used for anything, because Cisco's trunk guide notes that switch housekeeping protocols still run on VLAN 1 even when it carries no user traffic: CDP (neighbour discovery), LACP (link bundling), DTP (automatic trunk negotiation) and VTP (VLAN list sharing between switches). All IDs are below 1006, so they are normal-range VLANs.
Why each is unsafe to leave flat
- Guest: untrusted devices should never see staff broadcasts or reach server ports.
- Management: anyone on the staff network could try to log in to every switch and access point.
- Servers: the most valuable systems should not share a segment with every user laptop and phone.
- Printers: long-lived embedded devices with rarely patched firmware and chatty discovery traffic.
- Voice: phones need predictable quality and should not share a broadcast domain with bulk data.
Trunk basics and port roles (Cisco IOS XE)
The firewall (or router) routes between VLANs on one trunk with a sub-interface per VLAN: a sub-interface is a virtual interface on one physical port, tagged with one VLAN number and holding that VLAN's gateway address (illustratively 10.10.10.1 for VLAN 10, 10.10.20.1 for VLAN 20, and so on), which makes the firewall the default gateway for each subnet. I choose the firewall rather than SVIs (switched virtual interfaces, the switch's own Layer 3 interface per VLAN) because the firewall has to sit between the segments anyway and 50 people produce modest inter-VLAN volume. If the office buys a Layer 3 switch later, SVIs become the better gateway.
vlan 10
name STAFF
interface GigabitEthernet1/0/1
switchport mode access
switchport access vlan 10
switchport voice vlan 20
interface GigabitEthernet1/0/24
switchport mode access
switchport access vlan 40
interface GigabitEthernet1/0/48
switchport mode trunk
switchport trunk allowed vlan 10,20,30,40,50,99
switchport trunk native vlan 999
switchport nonegotiate
The first block shows one VLAN definition; the other five follow the same pattern with the names in the table. The desk port carries the PC in VLAN 10 and the phone in VLAN 20 on one cable (voice VLAN is supported on access ports only). The trunk allows only the six VLANs, so no other VLAN is carried by accident, and switchport nonegotiate stops DTP (Dynamic Trunking Protocol) frames, so the port stays a trunk and cannot be talked into a different mode by whatever is plugged in. Both ends of a trunk must use the same native VLAN, or spanning-tree loops can result, so the firewall side must match 999. Access points get their own trunk, because one access point serves two wireless networks (SSIDs, the network names users see) that must land in different VLANs: staff SSID traffic in VLAN 10, guest SSID traffic in VLAN 50, each tagged, while the access point's own management address lives in VLAN 99. Many access points send that management traffic untagged, so VLAN 99 is set as the native VLAN on that trunk, on both ends, and the trunk allows only VLANs 10, 50 and 99.
Out of scope and hand-off
Not covered here: firewall or ACL (access control list) rules between VLANs, network access control, and DHCP snooping. The hand-off is a one-line intent for the security owner: guests reach the internet only; staff reach servers and printers; management is reachable only from a named admin host or subnet; phones reach the voice platform only.
Pitfalls
Sizing every subnet as /24 is simple but wastes space and hides mistakes. Putting the phone and the PC in the same VLAN defeats QoS (quality of service) and security design. Leaving VLAN 1 as native is the default and is exactly what to change.
Explain how an Ethernet switch learns MAC addresses and decides where to send a frame. Cover what happens when the destination is unknown, and what that flooding means for a large broadcast domain.
Sample Answer
Direct answer
A switch learns by reading the source MAC address of every frame it receives and recording "this address lives behind this port, in this VLAN" in its MAC address table (also called the CAM table, after content-addressable memory, the fast lookup hardware that holds it). It forwards by looking up the destination address. A known unicast destination goes out one port only. An unknown unicast destination, a broadcast, or a multicast (unless the switch filters multicast, for example with IGMP snooping) is flooded out every other port in the same VLAN. A MAC address is the 48-bit hardware address of a network card.
How learning and forwarding work, in order
- A frame arrives on port Gi1/0/5 in VLAN 10 with source MAC
aaaa.aaaa.aaaa. The switch adds or refreshes the entry (VLAN 10,aaaa.aaaa.aaaa, Gi1/0/5) and resets that entry's age timer. - It looks up the destination MAC in the same VLAN's table. The table is effectively per VLAN: the same MAC may appear in two VLANs on two ports.
- Three outcomes:
- Known, on a different port: forward out that one port only.
- Known, on the port the frame arrived on: filter (drop). The destination is behind the same port, for example a hub or a downstream switch, and already saw the frame.
- Unknown: flood out all ports in that VLAN except the one it arrived on (the ingress port, meaning the port a frame enters by).
- Entries age out. The usual Cisco default is 300 seconds, set with
mac address-table aging-time <seconds>(check the platform's command reference for the permitted range and for what a value of 0 does). Static entries (mac address-table static) never age.
Per-entry fields and special destinations
| Item | What the table or switch holds | Why it matters |
|---|---|---|
| VLAN | The VLAN ID the address was learned in | Same MAC can exist in several VLANs |
| MAC address | 48-bit address from the frame source field | The lookup key |
| Port | Ingress port (or port-channel) | Where to send known unicast |
| Type | Dynamic (learned, ages) or static (configured, never ages) | Static pins a server or blocks moves |
| Age | Time since the entry was last refreshed by a frame from that source | Idle entries expire after the aging time |
- Broadcast (destination
ffff.ffff.ffff) is never learned as a source and is always flooded within the VLAN: every host must process it. - Multicast, where the switch does no multicast filtering, is flooded within the VLAN, because no multicast address ever appears as a source. A switch can be given a feature to restrict it to interested receivers (IGMP snooping, where the switch listens to hosts' group-join messages), which is outside the table described here.
What flooding means for a large broadcast domain
A broadcast domain is every port that receives a broadcast sent by any one host, which on a switch is one VLAN. Flooding turns each unknown unicast, broadcast and multicast frame into N-1 copies (if the VLAN has N active ports, one copy leaves every port except the one the frame arrived on, so a 24-port VLAN produces 23 copies of every flooded frame). Every host in the VLAN spends CPU on broadcasts (ARP, DHCP discovery, some discovery protocols), and every switch-to-switch link carries all of it. If the topology has a layer 2 loop that spanning tree has not blocked, flooded frames circulate forever and multiply (a broadcast storm), and the MAC table thrashes because the same source address keeps appearing on different ports.
Worked example: unknown unicast and aging
Host A (aaaa.aaaa.aaaa, port 1) sends to host B (bbbb.bbbb.bbbb, port 2) on a fresh 4-port switch in one VLAN.
- A's first frame is an ARP request to the broadcast address. The switch learns A on port 1, then floods to ports 2, 3 and 4.
- B replies, unicast to A. The switch learns B on port 2 and, because A is known, sends the reply out port 1 only. Ports 3 and 4 never see it.
- A now sends to B: both are known, so each frame goes out exactly one port.
- If B stays silent for 300 seconds (the default aging time) its entry expires. A's next frame to B is an unknown unicast and floods again until B transmits something.
Mitigating excessive flooding
- Shrink the flood scope: keep broadcast domains small. One VLAN per function, with a layer 3 boundary between them, bounds the flood scope. A /24 (254 usable addresses) per VLAN is a common ceiling in campus designs because broadcast load grows with host count.
- Prevent loops: keep spanning tree healthy so flooded frames cannot circulate. On user ports enable PortFast (the port goes straight to forwarding, skipping the listening and learning states) together with BPDU guard (if the port ever receives a spanning-tree BPDU, meaning a switch has been plugged in, the switch shuts the port into the err-disabled state). A stray switch then cannot change the topology.
- Stop table flooding attacks: cap MAC addresses per access port. Port security, the switch feature that limits how many and which MAC addresses a port may learn, has a default limit of one secure MAC address per port, raised with
switchport port-security maximum <value>. The default violation mode is shutdown (error-disabled), and restrict or protect modes drop offending frames instead. This also blunts a MAC flooding attack, where an attacker fills the table with fake sources so legitimate destinations become unknown and are flooded. - Avoid asymmetric paths that leave a destination unlearned. A switch learns only from frames it sees B send. Suppose A sends to B through switch sw-1, but B's replies travel back over a different path that never passes through sw-1. sw-1 never sees B as a source, so it never learns B's port and floods every frame addressed to B, for as long as the asymmetry lasts. Fix the path so replies cross sw-1, or add a static entry for B.
- Size the aging time to the traffic. Lengthening it above 300 seconds reduces re-flooding for quiet hosts but slows stale-entry cleanup after a host moves.
Trade-offs and pitfalls
- Learning is from the source only. A host that never transmits is never learned and always gets flooded traffic.
- A host that moves ports is relearned on its next frame. If the old entry has not aged, traffic misdirects only until that frame arrives.
- A MAC table has finite capacity. When a table is full, behaviour on new sources depends on the platform, so check the datasheet rather than assuming.
A new colleague from the server team asks what a VLAN actually is and why the network team keeps asking to use them. Explain it in plain terms and say what changes for broadcasts, security boundaries and day-to-day operations once a network is split into VLANs.
Sample Answer
Direct answer
A VLAN (virtual local area network) is a way to split one physical switch network into several separate logical networks. Each VLAN is its own broadcast domain: a broadcast sent by one machine (a frame addressed to every device, such as an ARP or DHCP request) is delivered only to ports in the same VLAN. Think of one open-plan office floor that gets partitioned into rooms: same building and same wiring, but a shout stays inside its room, and getting from one room to another requires walking through a door (a router or layer 3 switch).
What changes once the network is split
Broadcasts. On a flat network every ARP (Address Resolution Protocol: "who has this IP address, tell me your MAC address") and every DHCP (Dynamic Host Configuration Protocol: automatic IP address assignment) discover reaches every host. With VLANs those broadcasts stop at the VLAN edge. Each VLAN is normally one IP subnet, so ARP only ever resolves addresses inside the sender's own subnet, and traffic to anything else is sent to the default gateway's MAC address. (A subnet is a block of IP addresses that share a prefix, such as 10.10.10.0/24; the default gateway is the router address a host sends to when the destination is outside its own subnet.)
Security boundaries. A VLAN gives you separation at layer 2: a server in VLAN 10 cannot be reached by a direct frame from a laptop in VLAN 20. Traffic between VLANs has to be routed, and the routing point (a firewall, a router, or the switch's layer 3 interface) is where you apply access control lists (ACLs: permit/deny rules). The boundary is only as strong as that routing point: if the gateway routes everything between VLANs with no ACL, the VLANs separate broadcasts but not risk. A VLAN is a segmentation tool, not a firewall.
Day-to-day operations.
- Moving a person or server to another network is a port configuration change, not a recabling job.
- Every VLAN needs its own subnet, its own default gateway, and its own DHCP scope (the pool of addresses the DHCP server may hand out for that subnet). A DHCP server in another subnet is reached through a DHCP relay agent on the gateway, which forwards the broadcast as unicast to the server.
- Switches are joined by trunk links that carry many VLANs over one cable, each frame labelled with its VLAN number. A VLAN missing from a trunk is the classic "works on this switch, dead on that one" fault.
- Shared environments with several tenants (customers or business units on the same switches) usually start with one VLAN per tenant, paired with separate routing instances (VRFs, virtual routing and forwarding tables: each tenant gets its own private routing table on the same router) or separate firewall policy per tenant. For example, tenants A and B may both use 192.168.1.0/24, which is an overlapping address plan. Each tenant's VLAN lands in its own VRF, so 192.168.1.10 in tenant A and 192.168.1.10 in tenant B never collide, because the router looks up each in a different table, and any traffic between tenants is allowed only where you deliberately permit it.
Worked example
A site has 600 devices: 200 servers, 200 user devices (199 PCs plus the shared printer) and 200 IP phones. Flat, they all share one subnet. A subnet of 2^h addresses has 2^h - 2 usable addresses (minus the network and broadcast addresses), where h is the number of host bits, so it must satisfy 2^h - 2 >= 600. With h = 9, 2^9 - 2 = 510, which is too small; with h = 10, 2^10 - 2 = 1022, which fits. Host bits are 32 minus the prefix length, so h = 10 means a /22. Every broadcast then reaches the other 599 devices. Split into three VLANs of 200 devices each, each subnet needs 2^h - 2 >= 200: h = 7 gives 126 (too small), h = 8 gives 254, so a /24 per VLAN:
| VLAN | Purpose | Subnet | Usable addresses |
|---|---|---|---|
| 10 | Servers | 10.10.10.0/24 | 254 |
| 20 | Users (PCs and the printer) | 10.10.20.0/24 | 254 |
| 30 | Voice | 10.10.30.0/24 | 254 |
A broadcast now reaches 199 other devices instead of 599, and the printer in VLAN 20 no longer sees server chatter. (Addresses and counts here are illustrative.) The users-to-servers path crosses the gateway, where an ACL can permit only the application ports the users need.
Trade-offs and pitfalls
- More VLANs means more gateways, DHCP scopes and trunk allowed-lists to keep consistent. Name and document them.
- Do not treat a VLAN as a security control by itself. Leaving unused ports in a default VLAN, or trunking user VLANs carelessly, weakens the separation.
- Keep VLAN size sensible: a VLAN stretched across the whole campus enlarges the failure domain (a layer 2 loop affects every switch it touches).
You are asked to turn an unused switch port into a user port for the Sales team in a new VLAN. Walk through the configuration you would apply on a Cisco IOS switch, the checks that confirm it works, and what you would do on that port so it comes up fast and cannot accidentally become a trunk.
Sample Answer
Direct answer
Create the VLAN, then configure the port as a static access port in that VLAN, enable PortFast (so it skips the spanning-tree listening and learning delay) and BPDU guard (so a switch plugged in later shuts the port), and turn off trunk negotiation. Verify with show vlan, show interfaces switchport and the MAC table. Platform: Cisco IOS XE (Catalyst 9300 documentation); the vendor-agnostic order is the same everywhere: VLAN exists, port mode access, port assigned, port edge-protected, verify.
Configuration
configure terminal
vlan 40
name SALES
interface GigabitEthernet1/0/12
description Sales user port
switchport mode access
switchport access vlan 40
switchport nonegotiate
spanning-tree portfast
spanning-tree bpduguard enable
no shutdown
end
Command roles:
vlan 40/name SALES: create the VLAN (Cisco's documented creation sequence). Cisco documents that assigning an interface to a VLAN that does not exist creates it, but an implicitly created VLAN has no name and a typo in the number silently creates a wrong one, so create it deliberately first.switchport mode accessandswitchport access vlan 40: the documented access-port sequence. A port in static access mode does not carry tagged frames for other VLANs.switchport nonegotiate: stops the port generating DTP (Dynamic Trunking Protocol) frames. Cisco documents that it must pair with a static access or trunk mode, which is whyswitchport mode accessprecedes it.spanning-tree portfast: the port moves straight to forwarding when the link comes up, so DHCP does not time out waiting for spanning tree. Cisco documents this form for access ports and warns to use it only on ports to end stations. Some other releases and platforms use the formspanning-tree portfast edgeinstead; the Catalyst 9300 guide cited here documents only the plain form, so confirm the exact keyword in the platform's command reference. Rapid PVST (rapid per-VLAN spanning tree) is the faster modern spanning-tree mode.spanning-tree bpduguard enable: if a BPDU (Bridge Protocol Data Unit, the spanning-tree message) arrives, the port goes error-disabled. Cisco documents this as the interface-level form; the global form isspanning-tree portfast bpduguard default, which applies to ports that have PortFast on.
Checks that confirm it works
| Command | Expected result |
|---|---|
show vlan id 40 (or show vlan brief) | VLAN 40 SALES active, Gi1/0/12 listed as a member |
show interfaces GigabitEthernet1/0/12 switchport | Administrative mode static access, access VLAN 40, negotiation of trunking off |
show running-config interface GigabitEthernet1/0/12 | The lines above present |
show mac address-table interface GigabitEthernet1/0/12 | A learned MAC in VLAN 40 once the PC sends a frame |
show spanning-tree interface GigabitEthernet1/0/12 portfast | PortFast shown as enabled for this port (this is the per-port proof) |
show spanning-tree summary | A switch-wide view: spanning-tree mode and how many ports are in each state. It confirms spanning tree is running; it does not prove anything about this one port |
Then test from the end: the PC gets a DHCP lease in the Sales subnet, pings its gateway, and the gateway interface for VLAN 40 exists upstream.
Worked example of what each protection stops
- Someone plugs a small unmanaged switch with a loop cable into the port. Without BPDU guard, the switch treats the new device as part of the spanning-tree topology: the port can start forwarding and the extra switch can send BPDUs that change which switch is root or create a loop that floods the VLAN. With BPDU guard, the port goes error-disabled (the switch shuts the port down and shows it as disabled) on the first BPDU and the problem is contained to that one port. List such ports with
show interfaces status err-disabled. Recover withshutdownthenno shutdownafter removing the device. - A laptop sends DTP trunk-desirable frames. With
switchport mode accessplusnonegotiatethe port never becomes a trunk, so the laptop cannot see tagged traffic for VLANs it was not given.
Trade-offs and pitfalls
- Default switchport mode on Cisco Ethernet interfaces is dynamic auto (Cisco documents it), so a port left at its default can become a trunk if the neighbour asks. Always set the mode explicitly.
- Do not enable PortFast on ports that connect to other switches.
- Create the VLAN deliberately first and make sure it exists on, and is allowed on, the uplink trunk, or the user is isolated on the access switch.
- Describe the port (
description) and document the VLAN assignment so the next engineer does not guess.
You're on a switch and Host A (MAC 00:11:22:33:44:55) in VLAN 10 reports no connectivity to other hosts in same VLAN. List the IOS 'show' commands you would run to verify VLAN membership, physical port state, VLAN learning, and MAC table entries, and explain how you would interpret each command's output to locate the issue.
Sample Answer
Direct answer
Verify in this order: the port is in VLAN 10 and up (show vlan brief, show interfaces status, show interfaces <int> switchport), the switch is forwarding for that VLAN (show spanning-tree vlan 10), and the switch has learned the host's MAC in VLAN 10 on that port (show mac address-table address 0011.2233.4455). A MAC (media access control) address is the hardware address a switch uses to forward frames inside a VLAN; Cisco writes it in dotted form, three groups of four hex digits, so 00:11:22:33:44:55 becomes 0011.2233.4455. Layer 2 means the frame-forwarding level that switches work at, and Layer 3 means IP addressing and routing; the commands here are all Layer 2 checks, so a clean result points you up to Layer 3.
The commands and how to read each
show vlan brief. Columns include VLAN, name, status and ports. Find the port Host A uses. Not listed under VLAN 10: the port is in another VLAN (or is a trunk, or routed), so fixswitchport access vlan 10. VLAN 10 missing from the list: create it (vlan 10). Status not active: the VLAN is shut or suspended.show interfaces status. Is the host's port connected, or notconnect (no link detected: cable, NIC or speed problem), disabled (turned off by an administrator withshutdown; the exact word in the status column can vary by release) or err-disabled (the switch turned it off automatically after a protection rule fired)? Cisco also hasshow interfaces status err-disabled, which lists only ports in the error-disabled state. An err-disabled port is down with a cause (for example BPDU guard, which shuts a port that receives spanning-tree messages where none should arrive) to fix before bringing it back withshutdownthenno shutdown.show interfaces <int> switchport. Confirms the administrative mode (access or trunk), the operational mode, and the access VLAN. A trunk is a port carrying many VLANs tagged; an access port carries exactly one. This catches a port that is an access port in VLAN 1, or one that negotiated into a trunk.show spanning-tree vlan 10. Shows the roles and states of ports for VLAN 10. Host A's port should be forwarding. Spanning tree moves a port through states: a discarding (blocked) port neither learns MAC addresses nor forwards, a learning port records MAC addresses but does not yet forward user frames, and a forwarding port does both. So a port stuck in discarding for VLAN 10 will show no MAC for the host, and a port in learning is only moments from forwarding.show mac address-table address 0011.2233.4455. The output has Vlan, Mac Address, Type and Ports columns: one row reads as 'in this VLAN, this MAC, learned dynamically from traffic rather than typed in by hand, is reachable through this port'. Three outcomes: no entry (the switch has never seen a frame from Host A in that VLAN: port down, host silent or VLAN wrong); entry in VLAN 10 on Host A's port (Layer 2 side is fine, suspect the host's IP settings or the other host); entry on a different port or VLAN (the host is somewhere else, or there is a loop or duplicate MAC). To tell which: run the command twice a few seconds apart. A stable entry on a different port means the host really is plugged in there; an entry that keeps changing port means frames with that source address arrive from two places, a loop or duplicate.show mac address-table(and the same for another host in VLAN 10). Does the destination host's MAC appear in VLAN 10 on its own port? If both appear, the switch can forward between them and the problem is above Layer 2 (addressing, host firewall).
Interpretation summary
| Observation | Meaning | Fix |
|---|---|---|
| Port not under VLAN 10 | Wrong VLAN | Assign the access VLAN |
| Port notconnect | Physical | Cable, NIC, patch |
| Port err-disabled | A protection or violation shut it | Fix cause, then bounce port |
| MAC absent in VLAN 10 | Nothing learned | Check link, host traffic, STP state |
| MAC present on correct port | Layer 2 fine | Check IPs, masks, host firewall |
| MAC on unexpected port | Move or loop | Trace that port with the same commands |
Worked example
Host A is on Gi1/0/5. show vlan brief lists Gi1/0/5 under VLAN 1, not VLAN 10. show mac address-table address 0011.2233.4455 shows the MAC in VLAN 1. Setting switchport access vlan 10 on Gi1/0/5 moves it, and after the host sends a frame the MAC appears in VLAN 10 on that port.
Pitfalls
The MAC table fills only when the host transmits, so ping or ARP from the host before concluding it is silent. Check the command on the right switch: the host's MAC is learned on the switch it attaches to and on ports facing it elsewhere.
Unlock Full Question Bank
Get access to all 9 Switching, VLANs, and Layer 2 Segmentation interview questions and detailed answers.
Sign in to ContinueJoin thousands of developers preparing for their dream job.