Hermetic Networks Hermetic Networks

CompTIA Network+ (N10-009) - Session 03 - Learner Guide

Switching and VLANs

How a switch decides where to send a frame, what a VLAN actually changes, and how access ports and trunk ports carry them.

1What a switch actually does

This is your copy to keep. The gold Going deeper boxes go past what the session covers, for anyone sitting the CompTIA Network+ exam or who wants the fuller picture.

A switch connects the devices inside one office and moves traffic between them. It does that using the MAC address, short for media access control address. A MAC address is the 48-bit hardware address set in every network interface at manufacture, written as six pairs of hexadecimal digits, such as 00:1A:2B:3C:4D:5E. A switch never looks at IP addresses. It only reads the hardware addresses on each frame, the name for a unit of data as it crosses one local network.

It keeps a table pairing each hardware address with the port it was last heard on, called the MAC address table, and it builds that table by itself.

  1. A frame arrives on port 4. The switch reads the source address on it and writes down that this address lives on port 4. That is the only way a switch ever learns anything.
  2. The switch reads the destination address. If it is already in the table, the frame goes out that one port and no other port sees it.
  3. If the destination is not in the table, the switch sends the frame out every port except the one it arrived on. This is called flooding, and it is a guess that works: the right device answers, and the answer teaches the switch where that device is, so the next frame is not flooded.

Nothing configures this and nothing maintains it. Entries age out after a period of silence and are relearned when the device speaks again. That is why a machine that has been asleep is briefly flooded to when it wakes, and stops being flooded to as soon as the switch relearns its port.

2The broadcast domain

Some frames are addressed to every device at once. A broadcast is a frame sent to the special destination FF:FF:FF:FF:FF:FF, and a switch always floods it out every port. The set of devices that receive each other's broadcasts is called the broadcast domain.

Broadcasts are not an edge case. They are how normal work gets done.

  • A device that knows an IP address on its own network but not the matching hardware address broadcasts "who has 192.168.10.10" and the owner answers. That is ARP (Address Resolution Protocol), and it happens before nearly every conversation.
  • A device with no address at all broadcasts to ask for one, because it has no address to send from and nowhere specific to send to.
  • Printers, phones and media devices announce themselves by broadcast so other devices can find them without being told an address.

One switch with nothing configured is one broadcast domain, and every device on it hears every one of those. That is fine at ten devices. At two hundred it becomes traffic every machine has to process and discard, and it means the guest laptop in reception hears the same discovery traffic as the server. Splitting the broadcast domain is what the rest of this session is about.

3What a VLAN changes

A VLAN (virtual local area network) divides one physical switch into separate networks by configuration. Ports 1 to 12 can be the staff network and ports 13 to 24 the guest network, on the same switch, with no traffic crossing between them and nothing physical marking the difference.

What a VLAN actually does is narrow: it makes one broadcast domain into several. A broadcast sent by a device on the staff VLAN reaches only the ports on the staff VLAN. The switch treats the two groups as if they were two separate switches that happen to share a chassis.

Everything else follows from that one change. Two devices on different VLANs cannot find each other by ARP, so they cannot reach each other directly, so anything between them has to be carried by a router, which means a rule can be applied to it. That is the reason cameras, guest Wi-Fi and phones go on their own VLANs: separation is the point, and the router is the only door between them.

The way the switch keeps track is a tag, defined by the standard IEEE 802.1Q. The switch inserts four extra bytes into the frame, and twelve of those bits hold the VLAN number, which gives 4,094 usable VLAN numbers. A tagged frame is only tagged while it is travelling between network equipment. The tag is removed before the frame is handed to a workstation, which is why a device never knows or cares what VLAN it is on.

A VLAN and a subnet are two different things

A VLAN is a layer 2 boundary: who hears whose broadcasts. A subnet is a layer 3 range of addresses. They are separate ideas and they always travel together, one subnet per VLAN, because a device can only reach its neighbors directly and the VLAN is what decides who its neighbors are. When documentation says "VLAN 20 is 192.168.20.0/24", it is naming both halves of the same network: the tag number and the address range.

4Access ports and trunk ports

Every switch port is configured one of two ways, and the difference is only about tags.

An access port

Carries one VLAN, untagged. A workstation, a printer or a camera plugs in, sends ordinary untagged frames, and the switch adds the port's VLAN internally. The device never sees a tag and needs no configuration.

Most ports in a building are access ports.

A trunk port

Carries several VLANs at once, tagged, so the equipment at the other end can tell them apart. It is used between a switch and another switch, between a switch and the gateway, and between a switch and an access point that broadcasts more than one wireless network.

Without trunk ports, a VLAN would stop at the edge of one switch.

In the UniFi console both are set on the same two fields on the port.

The two port settings, and what each produces
SettingAccess portTrunk port
Native VLAN / NetworkThe one VLAN the device is on. Frames leave untagged.The VLAN used for untagged frames on that link, usually the management network.
Tagged VLAN ManagementBlock All. Only the native VLAN passes, so a device cannot reach any other VLAN by sending its own tags.Allow All, or Custom to name the specific VLANs that may cross.

Two practical points come out of those settings. Setting Block All on user ports is what stops a device from tagging its own frames and placing itself on a VLAN it was not given. And on a port feeding an access point, the native VLAN should not be the same as a network the access point is broadcasting, because the access point needs that network tagged in order to keep it separate.

5Power over Ethernet

PoE (Power over Ethernet) sends electrical power down the same cable as the data, so a phone, a camera or an access point needs no separate power supply. The switch is the power source, and how much it can deliver depends on which standard the port supports.

The PoE standards, as the power available at the switch port
StandardCommon nameMaximum at the switch portTypically powers
IEEE 802.3afPoE15.4 WDesk phones, older access points
IEEE 802.3atPoE+30 WMost access points, pan-tilt-zoom cameras
IEEE 802.3bt type 3PoE++60 WLarger access points, some displays
IEEE 802.3bt type 4PoE++100 WPowered devices at the top of the range

What reaches the device is less than the figure at the port, because some is lost as heat in the cable. The longer the run, the more is lost, which is why a device can work on a short cable and fail on a long one with no fault anywhere.

A switch also has a total power budget across all its ports, and that budget is usually smaller than the sum of every port at its maximum. A switch at its budget stops powering further devices. The symptom is a device that will not come up on a port that tests fine, and the place to look is the switch's own power figure rather than the cable.

6Loops, and what stops them

Plug a cable from one switch port into another port on the same switch, or wire two switches to each other twice, and you have made a loop. A broadcast now goes round it forever, because a frame crossing a local network carries nothing that counts hops and nothing that expires. Each pass floods it again, the traffic doubles each time round, and within seconds the switch is saturated. This is a broadcast storm, and the symptom is the entire site failing at once with no configuration change to explain it.

What prevents it is spanning tree, a protocol the switches run between themselves that finds loops in the wiring and deliberately blocks one port in each loop until it is needed. The blocked port carries nothing while the main path is healthy and takes over if it fails. Spanning tree is on by default on managed switches, which is why loops are far more often survived than fatal.

Two things follow for the job. A port that shows as blocking is usually spanning tree doing its job rather than a fault. And an unmanaged desk switch a user brought from home does not run spanning tree, so a loop created through one is not caught, which is the most common way a site takes a storm.

7Diagnosing at layer 2

Layer 2 faults share a shape: the cable is fine, the device has power and a link light, and it still reaches nothing or reaches the wrong things. Four causes cover nearly all of them.

The four layer 2 faults you will meet
SymptomLikely causeWhat to check
Link light on, no address, reaches nothingPort on the wrong VLAN, or on a VLAN with no addressing serviceThe port's native VLAN in the console against the site's addressing scheme
Device reaches its own network but not the others it shouldTagged VLAN management blocking a VLAN the device needsWhether the port is Allow All or Custom, and which VLANs the Custom list names
One access point broadcasts some networks and not othersThe port feeding it is an access port, or its custom list is missing a VLANThat the port is a trunk and that every broadcast network's VLAN is allowed on it
Whole site slow or down at once, nothing changedA loop, often through equipment somebody plugged inSwitch port statistics for a port passing far more traffic than the rest, and any switch not in the documentation

Reading the MAC address table

The table is the switch telling you where it believes each device is, and it settles questions nothing else can.

  • A device that appears on the port you expect proves the cabling and the port are working, whatever the user is reporting.
  • A device that appears on a different port than the documentation says means the documentation is wrong or somebody moved the cable.
  • A device that does not appear at all has sent nothing the switch has heard, which puts the fault at the cable, the port, or the device itself rather than anywhere above.
  • Many addresses on one port is normal and means another switch or an access point is there, not a fault.
Going deeper

One more fault belongs here because it looks like a wiring problem and is not. Two ends of a link have to agree on speed and on duplex, meaning whether they can send and receive at the same time. If one end is fixed and the other is negotiating, they can settle on different answers. The link comes up, small transfers work, and anything sustained collapses with errors counting up on the port. The fix is to have both ends negotiate, and the tell is the error counter on the port rather than anything the user can describe.

8Practice

  1. Open a site in the UniFi console and find its list of networks. Write down each VLAN number and the subnet that goes with it.
  2. Open a switch at that site and look at its ports. Find one access port and one trunk port, and say how you can tell which is which from the two settings named in section 4.
  3. Find the port feeding an access point. Confirm it is a trunk and that every VLAN the access point broadcasts is allowed on it.
  4. Find the switch's MAC address table and look up your own machine's hardware address in it. Confirm the port it names is the port you are actually plugged into.
  5. Find the switch's PoE figure: how much power it is delivering and what its budget is. Say how much headroom is left and how many more access points that would cover at 30 W each.

9Check for understanding

  1. A switch receives a frame for a hardware address that is not in its table. What does it do, and what happens next that means it will not have to do the same thing again?

  2. Explain in one sentence each what a VLAN changes and what it does not change.

  3. A printer is moved to a port whose native VLAN is 30, the guest network, while the staff machines are on VLAN 10. The printer gets an address and its link light is on. Can staff print to it? Explain.

  4. An access point broadcasts a staff network and a guest network. Staff connect fine and guest clients get no address at all. The access point shows as healthy. Where do you look first, and what are you looking for?

  5. A camera works on a short patch lead at the rack and will not power on at its permanent position. The port tests fine and the switch shows plenty of power budget left. What is the likely cause?

  6. A site goes down completely at 9:15 in the morning. No changes were made, and the switch is still reachable from the console. What do you suspect, what would confirm it, and why is the timing a clue rather than a coincidence?

10Before the next session

  • Do the practice steps in section 8 on a real site, and bring the VLAN and subnet list you wrote down.
  • Be able to state the two port settings and what each is set to for an access port and for a trunk port.
  • Read the Network+ companion, chapter 3, the sections on networking devices and structured cabling.

Next session. 04 - Routing and Gateways. How traffic gets from one of these VLANs to another, and what the routing table is telling you.

11Glossary

Switch
The device connecting machines inside one local network, forwarding by hardware address.
MAC address
Media access control address. The 48-bit hardware address set in a network interface at manufacture, written as six pairs of hexadecimal digits.
Frame
A unit of data as it crosses one local network, carrying hardware addresses.
MAC address table
The switch's record of which hardware address was last heard on which port.
Flooding
Sending a frame out every port except the one it arrived on, because the destination is not yet in the table.
Broadcast
A frame addressed to every device on the local network at once.
Broadcast domain
The set of devices that receive each other's broadcasts.
ARP
Address Resolution Protocol. Finds the hardware address matching a known IP address on the local network, by broadcast.
VLAN
Virtual local area network. One physical switch divided into separate broadcast domains by configuration.
Tag
Four bytes added to a frame under IEEE 802.1Q, twelve bits of which hold the VLAN number.
Access port
A switch port carrying one VLAN, untagged, for an end device.
Trunk port
A switch port carrying several VLANs at once, tagged, between pieces of network equipment.
Native VLAN
The VLAN a port uses for untagged frames.
PoE
Power over Ethernet. Electrical power carried on the same cable as the data.
Power budget
The total power a switch can deliver across all its ports at once.
Loop
A wiring path that lets a frame return to where it started, so a broadcast circulates without end.
Broadcast storm
The saturation that follows a loop, as circulating broadcasts multiply.
Spanning tree
The protocol switches run between themselves to find loops and block a port in each one until it is needed.
Duplex
Whether a link can send and receive at the same time. Both ends must agree, or the link works for small transfers and fails for sustained ones.

12Sources