1Session at a glance
Objectives
- Describe how a switch builds its address table and what it does with a frame it cannot place.
- Say what a VLAN, a virtual local area network, changes, in one sentence, and what it does not change.
- Configure or read a switch port as an access port or a trunk port, naming both settings.
- Say how much power a PoE standard delivers at the port, and why a device can fail on a long run.
- Given a layer 2 symptom, name the setting to check and why.
Before the session
- A real site open in the UniFi console with its networks list, one switch, and the port feeding an access point already located.
- That switch's MAC (media access control) address table and its PoE (Power over Ethernet) figure found in advance, so the demo does not turn into a hunt.
- Everyone with the Learner Guide open, and their own machine's hardware address written down from
ipconfig /all. - A short patch lead on the table. You use it in the open.
| Time | Block | What happens |
|---|---|---|
| 0:00 | Open | One cable, both ends in the same switch, and the whole site goes down. |
| 0:04 | Concept | How a switch learns (4), the broadcast domain (4), what a VLAN changes (5), access and trunk ports (5), PoE (3), loops and spanning tree (2). |
| 0:27 | Show | Live in the UniFi console: the networks list, a switch's ports, the trunk feeding an access point, the MAC address table, the PoE figure. |
| 0:37 | Do | Everyone finds their own hardware address in the table, then reads three ports and says access or trunk and why. |
| 0:49 | Check | Six questions. |
| 0:56 | Close | The work before session 04, and what that session covers. |
The two blocks that carry the session are what a VLAN changes and the two port settings, at five minutes each. If the room is behind, cut loops and spanning tree to the two sentences that matter, a loop makes a broadcast circulate and spanning tree blocks a port to prevent it, and let the open carry the rest of that idea. Do not shorten the broadcast domain block: a VLAN is defined in terms of it, so a room that does not have it cannot follow the next block.
Menu names in the UniFi console move between versions. Confirm the paths in the version the site is running before the session rather than in front of the room.
2Open (0:00, 4 minutes)
Hold up the patch lead. This is a three-dollar cable, and if I put both ends of it into the switch behind me, everything in this building stops in about four seconds. Not the machine it is plugged into. Everything. Phones, printers, the server, all of it. Nothing is broken, nothing is misconfigured, and no setting was changed. By the end of the hour you will know exactly why that happens, why the switch usually saves you from it, and why the one time it does not is when somebody brought a switch in from home.
- Do not explain the loop yet. It is the last concept block, and it lands far better once they have the broadcast domain.
- Say where the hour is going: today is the layer the switch works at, which is the layer that decides who can hear whom before any addressing is involved at all.
3Concept (0:04, 23 minutes)
How a switch learns (4 min)
- Restate the hardware address before using it, since it is the whole basis of the block: 48 bits, set in the interface at manufacture, six pairs of hexadecimal digits, identifies one interface and nothing else. A switch reads these and never looks at IP addresses at all.
- Then the table, built by the switch with nothing configured. Walk the three steps in section 1 of the Learner Guide on the board: a frame arrives on port 4, the switch writes down that the source address lives on port 4, and it looks up the destination.
- Land flooding as a guess rather than a failure. It does not know where the destination is, so it tries every port, the right device answers, and the answer is what teaches the switch. The second frame is never flooded.
- Add the aging, because it explains a real symptom: entries expire after silence, so a machine that has been asleep is flooded to once when it wakes, then not again once the switch relearns its port.
The broadcast domain (4 min)
- Define the broadcast first: a frame addressed to every device at once, and the switch always sends it out every port.
- Then give three real ones, so it is not an abstraction: the "who has this address" question that happens before nearly every conversation, a device with no address asking for one, and printers and phones announcing themselves.
- Then the count. One switch, nothing configured, one broadcast domain. Ten devices is fine. Two hundred is traffic every machine has to process and throw away, and it means the laptop in reception hears the same discovery traffic as the server.
- Set up the next block with the question rather than the answer: so how do you make one switch behave like two.
What a VLAN changes (5 min)
- Give the narrow definition and resist widening it: a VLAN makes one broadcast domain into several. That is the whole mechanism.
- Then derive the consequences out loud rather than listing them. Two devices on different VLANs cannot find each other by broadcast, so they cannot reach each other directly, so anything between them has to go through a router, which means a rule can be applied. That is why cameras, guest Wi-Fi and phones get their own VLANs.
- Then the tag, briefly: four bytes inserted into the frame, twelve bits holding the number, 4,094 usable. It exists only between network equipment and is removed before the frame reaches a workstation, which is why a device never knows what VLAN it is on.
- Finish on the distinction people blur, and put it on the board: a VLAN is who hears whose broadcasts, a subnet is a range of addresses. Separate ideas, always paired one to one, because a device can only reach its neighbors directly and the VLAN decides who those are.
Access ports and trunk ports (5 min)
- One sentence each. An access port carries one VLAN untagged, for an end device. A trunk carries several at once, tagged, between pieces of equipment.
- Say why trunks have to exist: without them a VLAN would stop at the edge of one switch.
- Now the two settings by name, because this is what they will actually touch: Native VLAN / Network and Tagged VLAN Management. Access port is the device's VLAN as the native and Block All on the tagged setting. Trunk is Allow All, or Custom naming the VLANs that may cross.
- Give the reason for Block All on user ports rather than leaving it as a convention: it stops a device tagging its own frames and putting itself on a VLAN nobody gave it.
- And the access point rule from the vendor documentation: the native VLAN on that port should not be the same as a network the access point is broadcasting, because the access point needs it tagged to keep it separate.
Power over Ethernet (3 min)
- Walk the standards table in section 5 of the Learner Guide: 15.4 W, 30 W, 60 W and 100 W at the switch port.
- Say clearly that those are the figures at the port. What reaches the device is less, because some is lost as heat in the cable, and the longer the run the more is lost. That is the whole reason a device works on a patch lead at the rack and fails at its permanent position.
- Then the budget: a switch's total across all ports is smaller than every port at maximum, and a switch at its budget simply stops powering the next device. The symptom is a device that will not come up on a port that tests fine.
Loops and spanning tree (2 min)
- Now pay off the open. A frame crossing a local network carries nothing that counts hops and nothing that expires, so a broadcast on a looped path circulates forever, and each pass floods it again. Seconds, and the switch is saturated.
- Spanning tree finds the loop and blocks one port in it until it is needed. On by default on managed switches, which is why loops are usually survived.
- The two job consequences: a blocking port is usually spanning tree working rather than a fault, and an unmanaged desk switch from somebody's home does not run it, which is how a site actually takes a storm.
4Show (0:27, 10 minutes)
- The networks list. Open Settings then Networks on the real site. Read off each network's VLAN number and subnet as a pair, and say the sentence again: the tag number and the address range are the two halves of one network.
- A user port. Open the switch, open a port with a workstation on it, and point at both settings. Native VLAN is the staff network. Tagged VLAN Management is Block All. Say what each one is doing as you point at it.
- The access point port. Open the port feeding an access point. It is a trunk. Show which VLANs are allowed across it, and tie them to the wireless networks that access point broadcasts. This is the one that makes trunks concrete for people.
- The MAC address table. Find a workstation's hardware address in it and show the port it names. Then find a port with many addresses on it and ask the room what that means. It means another switch or an access point, not a fault.
- The PoE figure. Show what the switch is delivering and what its budget is. Do the subtraction out loud and ask how many more access points at 30 W that would cover.
You will sometimes open a port and find it does not match the documentation. Say so, out loud, and leave it as a real finding rather than skipping past it. It makes the point about the address table better than any prepared example, and it is a ticket.
5Do (0:37, 12 minutes)
- Find yourself in the table. Everyone looks up their own hardware address in the switch's MAC address table and confirms the port matches where they are actually plugged in.
- Read three ports. Give the room three port numbers. For each: access or trunk, which VLAN or VLANs, and what evidence in the two settings says so.
- Trace a wireless network. Pick one wireless network and follow it from the access point back to the switch port, and say whether that port allows the VLAN it needs.
- Power arithmetic. Given the switch's current draw and its budget, work out the headroom and how many more access points it covers.
The answer to watch for is anyone saying a VLAN stops two devices talking. It does not, on its own. It stops them talking directly, and what happens after that is the router's decision and the rules on it. Get that corrected here, because the next session is built on it.
6Check (0:49, 7 minutes)
A switch receives a frame for a hardware address that is not in its table. What does it do, and what happens next that means it will not have to do the same thing again?
AnswerIt floods the frame out every port except the one it arrived on. The right device answers, and the switch reads the source address on that reply and writes it down against the port it came in on. The next frame for that address goes to one port only.
Explain in one sentence each what a VLAN changes and what it does not change.
AnswerIt changes who hears whose broadcasts, splitting one broadcast domain into several. It does not change the physical wiring, and it does not by itself decide whether two VLANs can reach each other, because that is the router's job and the rules on it.
A printer is moved to a port whose native VLAN is 30, the guest network, while the staff machines are on VLAN 10. The printer gets an address and its link light is on. Can staff print to it? Explain.
AnswerNot directly. The printer is now in a different broadcast domain and a different subnet, so a staff machine cannot find it by broadcast. It could only work if the gateway routes between VLAN 10 and VLAN 30 and a rule permits it, and on a guest network that is deliberately blocked, which is the point of the guest network.
The detail worth noticing is that the printer got an address and shows a link light, so everything a user can see says it is fine. The address will be in the guest range rather than the range the documentation gives it, and that is the thing that tells you what happened.
An access point broadcasts a staff network and a guest network. Staff connect fine and guest clients get no address at all. The access point shows as healthy. Where do you look first, and what are you looking for?
AnswerThe switch port feeding that access point. You are looking at Tagged VLAN Management: either it is set to Block All, or it is Custom and the guest VLAN is missing from the list. Staff working and guest not is the tell, because one VLAN crossing the link while another does not is a port setting, not a wireless fault.
A camera works on a short patch lead at the rack and will not power on at its permanent position. The port tests fine and the switch shows plenty of power budget left. What is the likely cause?
AnswerPower lost in the longer cable run. The figure at the switch port is not what arrives at the device, and the loss grows with distance, so a camera close to its power requirement works on a two-foot lead and starves on a long run. Check the run length and whether the port's PoE standard delivers enough for that camera with the loss included.
The obvious answer is the budget, and the question rules it out on purpose. A budget problem would fail the same way on a short lead.
A site goes down completely at 9:15 in the morning. No changes were made, and the switch is still reachable from the console. What do you suspect, what would confirm it, and why is the timing a clue rather than a coincidence?
AnswerA loop. Confirm it from the switch's port statistics, looking for one port carrying far more traffic than any other, from spanning tree events in the log, and by looking for a switch that is not in the documentation. The timing is a clue because 9:15 is when people arrive and plug things in, and the most common loop is created by equipment somebody brought in, which does not run spanning tree and so is not caught.
7Close (0:56, 4 minutes)
Work before the next session
- The practice steps in section 8 of the Learner Guide, on a real site, with the VLAN and subnet list written down and brought along.
- Both port settings, and what each is set to for an access port and for a trunk, said from memory.
- The Network+ companion, chapter 3, networking devices and structured cabling.
Next session
04 - Routing and Gateways. How traffic gets from one of these VLANs to another, what the routing table on a workstation is telling you, and where a packet actually stops.
Open items to settle
- Whether the room gets read-only console access to the demo site for the practice steps, and at which sites.
- Any port found during the session that does not match the documentation, raised as a ticket rather than left in the room.
8Sources
- IEEE, 802.1Q, Bridges and Bridged Networks, for VLAN tagging and the 12-bit VLAN identifier.
- IEEE, 802.1D and 802.1Q, for spanning tree.
- Ubiquiti, Intro to Networking, Power over Ethernet, for the power available at the switch port under each standard.
- Ubiquiti, Switch Port VLAN Assignment (Trunk and Access Ports), for the Native VLAN and Tagged VLAN Management settings and the access point note.
- Ubiquiti, Virtual Network (VLAN) Troubleshooting.
- Kodi A. Cochran, CompTIA Network+ (N10-009) Certification Companion (Apress, 2026), chapter 3, networking devices and structured cabling.
9After the session
| Delivered on | |
| Attendance | |
| What landed | |
| What did not | |
| Changes for next time | |
| Backlog items created |