Draw the affected VLAN path
The reporting service enters VLAN 70, but the VLAN 30 batch stops communicating after the same change. Draw the hosts, access ports, switches, and trunks actually crossed. Record the management VLAN: a switch ping might follow 20 and establish nothing about 30. Keep state and configuration from both ends with time and interface. Look for the first failed condition on the actual path, rather than changing gateways or firewalls simply because the symptom appears as an application timeout.
Bilateral permission is not enough
With A permitting 20, 30, 70 and B permitting 20, 70, the intersection is 20, 70. Missing 30 is a concrete incident hypothesis. After correction, check that the VLAN exists and is active, the trunk is operational, and per-VLAN STP state is appropriate at each hop. A configured list describes intent; forwarding state describes another necessary condition. Preserve already approved VLANs when adding 70. If the window ends without acceptance, use the defined rollback and tell the batch owner the actual state.
Native VLAN: make assumptions explicit
In the exercise, A sends its native VLAN 20 traffic untagged, and B accepts it with native VLAN 30. B classifies it into 30. This assumes default native behavior, no native tagging, and no earlier discard; it does not promise normal forwarding in a real mismatched topology. Protections and spanning-tree inconsistencies may exist. Document both values and correct disagreement within approved scope. Do not use link-up state to declare service separation correct.
Root and cost are different decisions
Compare bridge IDs within the same instance. With base priorities 24576, 28672, and 32768 for VLAN 70, the first value wins before a MAC tie-break; do not choose the smallest MAC while ignoring priority. Then calculate each switch’s path to the root. If P1 receives cost 4 with local cost 19, it totals 23. P2 receives 19 with local cost 2, totaling 21. P2 offers lower cost despite the larger received advertisement. This fixture avoids ties; other tie-breaks need additional BPDU information.
An alternate can be healthy and discarding
Let A be root, B-A cost 4, C-A cost 8, and B-C cost 19 in both directions. B and C prefer their direct paths. On segment B-C, B advertises lower cost and is designated; C remains alternate/discarding. This avoids a data loop and does not prove cable failure. If only C-A fails, C’s remaining path via B costs 23 and can become its root path after convergence. Measure interruption and request outcomes: the design does not prove lossless failover. Role and instantaneous state can also differ during transitions.
The logical aggregate can hide a lost member
An up port-channel may have only one useful member when the design expects two. Compare each member’s state, LACP neighbor, speed, and effective trunk, native, and allowed-VLAN configuration. If a port is suspended after a list change, investigate that difference before forcing mode on. Static mode does not negotiate LACP or remove compatibility requirements. Retain recovery access and apply correction consistently at both ends. Recheck members and traffic instead of accepting port-channel state alone.
Per-flow capacity and minimum policy
Two 1 Gb/s members do not guarantee 2 Gb/s of payload for one flow. In our fixture, the hash keeps a flow on one member; multiple flows use both only if distribution maps them to different ports. Nominal sum also does not establish payload throughput. With min-links=2 and two active members, losing one makes the aggregate inactive if no replacement exists. That may protect a capacity requirement. Lowering the threshold changes the behavior and needs explicit acceptance of degraded operation.
Guided practice and handover criteria
Calculate the permitted intersection, the best P1/P2 cost, and aggregate state after one member fails in the fixture below. Results:20 and 70, P2 with 21, and inactive aggregate with minimum 2. In an authorized lab, handover should include per-VLAN and member state, new and existing transactions, and a controlled failure/recovery test. Record observed loss, remaining capacity, cut-off, owner, and rollback. This path’s models only check sets and arithmetic over fictional inputs; they do not execute Cisco IOS or simulate real convergence or hashing.
Synthetic teaching fixture, not device output
VLANs allowed A: 20,30,70
VLANs allowed B: 20,70
P1: advertised_root_cost=4 local_cost=19
P2: advertised_root_cost=19 local_cost=2
Po10: bundled_up_members=2 min_links=2
Failure: one bundled member lost; no standbyReporting in 70 works, the batch in 30 fails, and management in 20 responds. The second end’s list omits 30; management ping does not validate the service.
Common pitfalls
Using link-up or management as proof for all VLANs; forcing PortFast between switches; summing bandwidth per flow; ignoring min-links.
Related topics: IP connectivity · Change management
Validate each path condition and measure recovery; configured redundancy does not prove service continuity.
Reference: VLAN trunks · 200-301 CCNA v1.1