Cisco · Cisco IOS XE

Cisco VLAN and Trunk Show Commands: Find the Missing VLAN

Quick answer #

Use show vlan brief to inspect local VLAN membership and show interfaces trunk to inspect operational trunks. Then examine the affected interface with show interfaces ... switchport. A VLAN being allowed on a trunk does not establish that it is active locally or forwarding through spanning tree.

Scope: Catalyst switching on IOS XE 17.x; command and behavior baseline: Catalyst 9200 17.15.x. Applies to 802.1Q switchports, not arbitrary routed router interfaces or NX-OS.

Read-only commands #

Read-only commands
Cisco IOS XE · Authorized EXEC mode; context specified below

Read-only
show vlan brief
Read-only

Replace these example values: 120.

show vlan id 120
Read-only
show interfaces trunk
Read-only

Replace these example values: GigabitEthernet1/0/24.

show interfaces GigabitEthernet1/0/24 switchport
Read-only

Replace these example values: GigabitEthernet1/0/24.

show interfaces GigabitEthernet1/0/24 trunk
Read-only

Replace these example values: GigabitEthernet1/0/24.

show running-config interface GigabitEthernet1/0/24
Output may contain sensitive operational data.
Read-only

Replace these example values: 120.

show spanning-tree vlan 120

Read the trunk view in stages #

Start with the operational trunk state and native VLAN. Then read the separate VLAN lists: permitted on the trunk, permitted and active locally, and forwarding through spanning tree without pruning. These answer different questions. Do not stop at the first list because it contains the desired VLAN number.

Workflow #

  1. Start at the endpoint. Record its expected VLAN and whether the device sends tagged or untagged frames. This avoids comparing an access-port design with a trunk-port expectation.
  2. Inspect the local access port's switchport state. The configured administrative mode and the current operational mode are separate evidence.
  3. Check whether the target VLAN exists on this switch. Then identify the actual uplink, including whether it is a port-channel.
  4. Run the trunk checks at both ends of every relevant link. Compare the VLAN number and native-VLAN handling; a correct local allowed list cannot correct a remote omission.
  5. If the VLAN is present and allowed but does not forward, follow the spanning-tree reference. If Layer 2 checks succeed, move to the gateway, ARP and route lookup.

Common mistakes #

The access-port list in show vlan brief is not a complete list of VLANs crossing trunks. The trunk view supplies that separate evidence. An up/up SVI also does not demonstrate that every access path in its VLAN is working.

For an EtherChannel uplink, inspect the port-channel and its members together. A member that has not joined the bundle can make a cabling diagram misleading. Do not fix a suspected VLAN omission by replacing an entire allowed-VLAN list during diagnosis: unrelated services may share the trunk.

Evidence to save #

Capture both ends of the link, the target VLAN and the exact stage where it disappears. "VLAN 120 is allowed locally but absent from the peer's active list" gives the next engineer a concrete discrepancy to verify.

Useful tools and references #

Sources

Documentation reviewed: 8 October 2026