Troubleshooting VLANs & Trunks

This topic is to discuss the following lesson:

Thanks alot Rene, these lessons are very helpful.
Keep up the good work.

Hi Renee,
With switchport trunk allowed vlan xx, do you have to specify this on both sides of the trunk link or is one side enough?

Hans de Roode.

Hi Hans,

Best to do it on both sides. Your switch(es) will complain when you receive traffic for VLANs that are not allowed on the trunk. It’s best practice to ensure that both ends of the trunk have the same configuration.


Hello Rene.
Could you explain me what’s the difference between show ip interface brief and show interface fa0/x switchport? I’m asking this because you use first the show ip interface to check the status of a swichport (up/down) and the other to check operational mode. My question is why you don’t use only interface fa0/x switchport to get both information ( status and operatinal mode?

Hello Rodrigo

There are various ways to show the status of interfaces and each command provides different information and in different formats. The command initially chosen by Rene is the show ip interface brief will show the status and protocol of all the interfaces in a list, so you get a general picture of all interfaces with one command. If any of those interfaces are configured with IP addresses, those are also displayed.

The show interface fa0/x switchport command will show the switchport configuration of a single port in detail. This can be used when the only information you’re looking for is about that port in particular.

There is also the show interface status command which will provide a list of all the interfaces and include a column that shows the VLAN on which they are assigned if they are access ports, or if they are trunk ports, the word trunk will appear in that column. This command shows all the interfaces including the operational mode in which the ports are functioning.

I hope this has been helpful!



Are you familiar with the switch error - %sw_matm-4-macflap_notif. What causes them? What is flapping?

Hi Jason,

This message shows up when your switch receives a frame with the same source MAC address on two different interfaces.

Do you see this for one MAC address or multiple? If you see multiple MAC address, you might have a L2 loop. If you only see one source MAC address, it’s probably a misconfiguration. Track it down like this:

SW1#show mac address-table dynamic address 0017.94a5.a618 
          Mac Address Table

Vlan    Mac Address       Type        Ports
----    -----------       --------    -----
 200    0017.94a5.a618    DYNAMIC     Gi0/34
Total Mac Addresses for this criterion: 1

If you have multiple switches, do this on all switches until you get to the source. One example where this can happen is when you configure link aggregation / load balancing on a server but not on your switch.


A post was merged into an existing topic: VLAN Access-List (VACL)