← CCNA: networking and production troubleshooting
08 / 8 · 70 MIN

L2 paths and uplink failures

Interpret VLANs, STP costs, and aggregation before approving a network change.

Draw the affected VLAN path

The reporting service enters VLAN 70, but the VLAN 30 batch stops communicating after the same change. Draw the hosts, access ports, switches, and trunks actually crossed. Record the management VLAN: a switch ping might follow 20 and establish nothing about 30. Keep state and configuration from both ends with time and interface. Look for the first failed condition on the actual path, rather than changing gateways or firewalls simply because the symptom appears as an application timeout.

Bilateral permission is not enough

With A permitting 20, 30, 70 and B permitting 20, 70, the intersection is 20, 70. Missing 30 is a concrete incident hypothesis. After correction, check that the VLAN exists and is active, the trunk is operational, and per-VLAN STP state is appropriate at each hop. A configured list describes intent; forwarding state describes another necessary condition. Preserve already approved VLANs when adding 70. If the window ends without acceptance, use the defined rollback and tell the batch owner the actual state.

Native VLAN: make assumptions explicit

In the exercise, A sends its native VLAN 20 traffic untagged, and B accepts it with native VLAN 30. B classifies it into 30. This assumes default native behavior, no native tagging, and no earlier discard; it does not promise normal forwarding in a real mismatched topology. Protections and spanning-tree inconsistencies may exist. Document both values and correct disagreement within approved scope. Do not use link-up state to declare service separation correct.

Root and cost are different decisions

Compare bridge IDs within the same instance. With base priorities 24576, 28672, and 32768 for VLAN 70, the first value wins before a MAC tie-break; do not choose the smallest MAC while ignoring priority. Then calculate each switch’s path to the root. If P1 receives cost 4 with local cost 19, it totals 23. P2 receives 19 with local cost 2, totaling 21. P2 offers lower cost despite the larger received advertisement. This fixture avoids ties; other tie-breaks need additional BPDU information.

An alternate can be healthy and discarding

Let A be root, B-A cost 4, C-A cost 8, and B-C cost 19 in both directions. B and C prefer their direct paths. On segment B-C, B advertises lower cost and is designated; C remains alternate/discarding. This avoids a data loop and does not prove cable failure. If only C-A fails, C’s remaining path via B costs 23 and can become its root path after convergence. Measure interruption and request outcomes: the design does not prove lossless failover. Role and instantaneous state can also differ during transitions.

The logical aggregate can hide a lost member

An up port-channel may have only one useful member when the design expects two. Compare each member’s state, LACP neighbor, speed, and effective trunk, native, and allowed-VLAN configuration. If a port is suspended after a list change, investigate that difference before forcing mode on. Static mode does not negotiate LACP or remove compatibility requirements. Retain recovery access and apply correction consistently at both ends. Recheck members and traffic instead of accepting port-channel state alone.

Per-flow capacity and minimum policy

Two 1 Gb/s members do not guarantee 2 Gb/s of payload for one flow. In our fixture, the hash keeps a flow on one member; multiple flows use both only if distribution maps them to different ports. Nominal sum also does not establish payload throughput. With min-links=2 and two active members, losing one makes the aggregate inactive if no replacement exists. That may protect a capacity requirement. Lowering the threshold changes the behavior and needs explicit acceptance of degraded operation.

Guided practice and handover criteria

Calculate the permitted intersection, the best P1/P2 cost, and aggregate state after one member fails in the fixture below. Results:20 and 70, P2 with 21, and inactive aggregate with minimum 2. In an authorized lab, handover should include per-VLAN and member state, new and existing transactions, and a controlled failure/recovery test. Record observed loss, remaining capacity, cut-off, owner, and rollback. This path’s models only check sets and arithmetic over fictional inputs; they do not execute Cisco IOS or simulate real convergence or hashing.

Synthetic teaching fixture, not device output
VLANs allowed A: 20,30,70
VLANs allowed B: 20,70
P1: advertised_root_cost=4 local_cost=19
P2: advertised_root_cost=19 local_cost=2
Po10: bundled_up_members=2 min_links=2
Failure: one bundled member lost; no standby
IN PRACTICE

Reporting in 70 works, the batch in 30 fails, and management in 20 responds. The second end’s list omits 30; management ping does not validate the service.

Common pitfalls

Using link-up or management as proof for all VLANs; forcing PortFast between switches; summing bandwidth per flow; ignoring min-links.

Related topics: IP connectivity · Change management

Take this idea with you

Validate each path condition and measure recovery; configured redundancy does not prove service continuity.

Create account

Reference: VLAN trunks · 200-301 CCNA v1.1

CCNA® and Cisco® are registered trademarks of Cisco Systems, Inc. and/or its affiliates. bigsavant.com is an independent preparation platform and is not affiliated with, associated with, sponsored, authorised or endorsed by Cisco. Content and questions are original, are not official exam questions, and completing our tests does not award or guarantee any certification. Names are used only to identify the subject. All other trademarks belong to their respective owners.