Configure Access and Trunk VLAN Ports on Cisco IOS XE
VLANs divide a switched Layer 2 network into separate broadcast domains. An access port carries one untagged VLAN for an endpoint; a trunk carries tagged traffic for multiple VLANs between network devices.
This example uses Cisco Catalyst IOS XE-style commands: VLAN 20 for a workstation, VLAN 30 for voice, and a trunk between switches. Interface names and available syntax vary by model and release. Apply the commands only to the intended ports during an approved change window, with console or out-of-band recovery available.
Step 1: Record the Current Port and VLAN State
Inspect the Interfaces Before Changing Them
Pre-ChangeConfirm the exact switch model, software version, interface IDs, and connected neighbors. Save the running configuration for the affected interfaces and make sure VLAN 20 and VLAN 30 are not already assigned a different purpose.
show versionshow vlan briefshow interfaces statusshow running-config interface GigabitEthernet1/0/10show running-config interface GigabitEthernet1/0/48β― View Expected Console Output
Gi1/0/10 connected 1 a-full a-1000 10/100/1000BaseTXGi1/0/48 connected trunk a-full a-1000 10/100/1000BaseTXStep 2: Create the VLANs
Add Named VLANs to the Local Switch
VLAN SetupCreate the workload VLANs and an unused native VLAN that has no endpoint access ports. Use the same native VLAN on both ends of the trunk. Creating a VLAN on one switch does not automatically route traffic between VLANs; routing and access policy are separate Layer 3 tasks.
configure terminalvlan 20 name WORKSTATIONSexitvlan 30 name VOICEexitvlan 999 name UNUSED_NATIVEexitendshow vlan briefβ― View Expected Console Output
20 WORKSTATIONS active30 VOICE active999 UNUSED_NATIVE activeStep 3: Assign an Endpoint Access Port
Place the Workstation Port in VLAN 20
Access PortThis example assigns an ordinary workstation to access VLAN 20. VLAN 30 is the voice network used by other phone ports carried on the trunk; this sample workstation port does not use a voice VLAN. Enable PortFast only on endpoint-facing ports, never on a switch-to-switch link.
configure terminalinterface GigabitEthernet1/0/10 description User workstation switchport mode access switchport access vlan 20 spanning-tree portfastendshow interfaces GigabitEthernet1/0/10 switchportβ― View Expected Console Output
Administrative Mode: static accessAccess Mode VLAN: 20 (WORKSTATIONS)Voice VLAN: none
Figure 1: Cisco IOS XE CLI confirming the workstation VLAN and access-port assignment.
Step 4: Configure a Trunk with an Explicit Allow-List
Carry Only the VLANs Needed on the Uplink
Trunk PortConfigure the inter-switch uplink as a trunk and permit only the VLANs needed on that path. This example explicitly uses VLAN 999 as the unused native VLAN; create it and apply the same native VLAN and allow-list at both ends. Do not apply this example to a link that connects to an endpoint.
configure terminalinterface GigabitEthernet1/0/48 description Uplink to distribution switch switchport mode trunk switchport trunk native vlan 999 switchport trunk allowed vlan 20,30,999endshow interfaces trunkβ― View Expected Console Output
Port Mode Encapsulation Status Native vlanGi1/0/48 on 802.1q trunking 999Vlans allowed on trunk: 20,30,999
Figure 2: Verify the trunk status and its explicit VLAN allow-list.
Step 5: Verify Connectivity and Save the Change
Check VLAN Membership and the Neighboring Switch
VerificationConfirm the access port is in VLAN 20, the trunk is carrying the expected VLANs, and the link is up at both ends. Test DHCP, gateway reachability, and the intended application from an endpoint in each VLAN. Save the running configuration only after validation and according to your change policy.
show vlan briefshow interfaces trunkshow spanning-tree interface GigabitEthernet1/0/10 detailcopy running-config startup-configβ― View Expected Console Output
The workstation receives an address from its VLAN scope and can reach only the routed services permitted by policy.See Ciscoβs Catalyst 9200 IOS XE VLAN configuration guide and match commands to your hardware and software release.