Skip to content

Configure Access and Trunk VLAN Ports on Cisco IOS XE

VLANs divide a switched Layer 2 network into separate broadcast domains. An access port carries one untagged VLAN for an endpoint; a trunk carries tagged traffic for multiple VLANs between network devices.

This example uses Cisco Catalyst IOS XE-style commands: VLAN 20 for a workstation, VLAN 30 for voice, and a trunk between switches. Interface names and available syntax vary by model and release. Apply the commands only to the intended ports during an approved change window, with console or out-of-band recovery available.


Step 1: Record the Current Port and VLAN State

01

Inspect the Interfaces Before Changing Them

Pre-Change

Confirm the exact switch model, software version, interface IDs, and connected neighbors. Save the running configuration for the affected interfaces and make sure VLAN 20 and VLAN 30 are not already assigned a different purpose.

show version
show vlan brief
show interfaces status
show running-config interface GigabitEthernet1/0/10
show running-config interface GigabitEthernet1/0/48
❯ View Expected Console Output
Gi1/0/10 connected 1 a-full a-1000 10/100/1000BaseTX
Gi1/0/48 connected trunk a-full a-1000 10/100/1000BaseTX

Step 2: Create the VLANs

02

Add Named VLANs to the Local Switch

VLAN Setup

Create the workload VLANs and an unused native VLAN that has no endpoint access ports. Use the same native VLAN on both ends of the trunk. Creating a VLAN on one switch does not automatically route traffic between VLANs; routing and access policy are separate Layer 3 tasks.

configure terminal
vlan 20
name WORKSTATIONS
exit
vlan 30
name VOICE
exit
vlan 999
name UNUSED_NATIVE
exit
end
show vlan brief
❯ View Expected Console Output
20 WORKSTATIONS active
30 VOICE active
999 UNUSED_NATIVE active

Step 3: Assign an Endpoint Access Port

03

Place the Workstation Port in VLAN 20

Access Port

This example assigns an ordinary workstation to access VLAN 20. VLAN 30 is the voice network used by other phone ports carried on the trunk; this sample workstation port does not use a voice VLAN. Enable PortFast only on endpoint-facing ports, never on a switch-to-switch link.

configure terminal
interface GigabitEthernet1/0/10
description User workstation
switchport mode access
switchport access vlan 20
spanning-tree portfast
end
show interfaces GigabitEthernet1/0/10 switchport
❯ View Expected Console Output
Administrative Mode: static access
Access Mode VLAN: 20 (WORKSTATIONS)
Voice VLAN: none
PuTTY session to Cisco IOS XE showing VLAN 20 and VLAN 30 creation and GigabitEthernet1/0/10 configured as an access port

Figure 1: Cisco IOS XE CLI confirming the workstation VLAN and access-port assignment.


Step 4: Configure a Trunk with an Explicit Allow-List

04
Trunk Port

Configure the inter-switch uplink as a trunk and permit only the VLANs needed on that path. This example explicitly uses VLAN 999 as the unused native VLAN; create it and apply the same native VLAN and allow-list at both ends. Do not apply this example to a link that connects to an endpoint.

configure terminal
interface GigabitEthernet1/0/48
description Uplink to distribution switch
switchport mode trunk
switchport trunk native vlan 999
switchport trunk allowed vlan 20,30,999
end
show interfaces trunk
❯ View Expected Console Output
Port Mode Encapsulation Status Native vlan
Gi1/0/48 on 802.1q trunking 999
Vlans allowed on trunk: 20,30,999
PuTTY session to Cisco IOS XE showing GigabitEthernet1/0/48 trunking with VLANs 20 and 30 allowed and VLAN 999 as the native VLAN

Figure 2: Verify the trunk status and its explicit VLAN allow-list.


Step 5: Verify Connectivity and Save the Change

05

Check VLAN Membership and the Neighboring Switch

Verification

Confirm the access port is in VLAN 20, the trunk is carrying the expected VLANs, and the link is up at both ends. Test DHCP, gateway reachability, and the intended application from an endpoint in each VLAN. Save the running configuration only after validation and according to your change policy.

show vlan brief
show interfaces trunk
show spanning-tree interface GigabitEthernet1/0/10 detail
copy running-config startup-config
❯ View Expected Console Output
The workstation receives an address from its VLAN scope and can reach only the routed services permitted by policy.

See Cisco’s Catalyst 9200 IOS XE VLAN configuration guide and match commands to your hardware and software release.

Comments