Read-only commands #
Read-only commands
Cisco IOS XE · Authorized EXEC mode; context specified below
show vlan briefReplace these example values: 120.
show vlan id 120show interfaces trunkReplace these example values: GigabitEthernet1/0/24.
show interfaces GigabitEthernet1/0/24 switchportReplace these example values: GigabitEthernet1/0/24.
show interfaces GigabitEthernet1/0/24 trunkReplace these example values: GigabitEthernet1/0/24.
show running-config interface GigabitEthernet1/0/24Output may contain sensitive operational data.Replace these example values: 120.
show spanning-tree vlan 120Read the trunk view in stages #
Start with the operational trunk state and native VLAN. Then read the separate VLAN lists: permitted on the trunk, permitted and active locally, and forwarding through spanning tree without pruning. These answer different questions. Do not stop at the first list because it contains the desired VLAN number.
Workflow #
- Start at the endpoint. Record its expected VLAN and whether the device sends tagged or untagged frames. This avoids comparing an access-port design with a trunk-port expectation.
- Inspect the local access port's switchport state. The configured administrative mode and the current operational mode are separate evidence.
- Check whether the target VLAN exists on this switch. Then identify the actual uplink, including whether it is a port-channel.
- Run the trunk checks at both ends of every relevant link. Compare the VLAN number and native-VLAN handling; a correct local allowed list cannot correct a remote omission.
- If the VLAN is present and allowed but does not forward, follow the spanning-tree reference. If Layer 2 checks succeed, move to the gateway, ARP and route lookup.
Common mistakes #
The access-port list in show vlan brief is not a complete list of VLANs crossing trunks. The trunk view supplies that separate evidence. An up/up SVI also does not demonstrate that every access path in its VLAN is working.
For an EtherChannel uplink, inspect the port-channel and its members together. A member that has not joined the bundle can make a cabling diagram misleading. Do not fix a suspected VLAN omission by replacing an entire allowed-VLAN list during diagnosis: unrelated services may share the trunk.
Evidence to save #
Capture both ends of the link, the target VLAN and the exact stage where it disappears. "VLAN 120 is allowed locally but absent from the peer's active list" gives the next engineer a concrete discrepancy to verify.
Useful tools and references #
- VLAN and Ethernet overhead calculator: Check frame-size overhead when the VLAN path works but a tagged service has a size-related problem.
Sources
Documentation reviewed: 8 October 2026