Router-on-a-Stick: Route VLAN 10 and VLAN 20

intermediate EVE-NG / Cisco IOS router + L2 switch roasvlantrunking
LAB TOPOLOGY

Router-on-a-Stick Lab

One 802.1Q trunk · router subinterfaces as gateways

ACCESS VLAN 10NICE0/1ACCESS VLAN 20NICE0/3802.1Q TRUNKE0/0E0/0PC1VLAN 10192.168.10.10/24PC2VLAN 20192.168.20.10/24SW1Layer-2 SwitchR1802.1Q SubinterfacesE0/0.10 .254 · E0/0.20 .254

Scenario

Sales users are in VLAN 10 and Marketing users are in VLAN 20. SW1 is Layer 2 only, so R1 will provide the gateways through a single physical link using 802.1Q subinterfaces.

Addressing

DeviceInterfaceAddress / role
PC1NIC192.168.10.10/24, GW 192.168.10.254
PC2NIC192.168.20.10/24, GW 192.168.20.254
SW1E0/0trunk to R1
R1E0/0.10192.168.10.254/24, dot1q 10
R1E0/0.20192.168.20.254/24, dot1q 20

Configure SW1

SW1# configure terminal
SW1(config)# vlan 10
SW1(config-vlan)# name SALES
SW1(config-vlan)# vlan 20
SW1(config-vlan)# name MRKT
SW1(config-vlan)# exit
SW1(config)# interface ethernet 0/1
SW1(config-if)# switchport mode access
SW1(config-if)# switchport access vlan 10
SW1(config-if)# exit
SW1(config)# interface ethernet 0/2
SW1(config-if)# switchport mode access
SW1(config-if)# switchport access vlan 20
SW1(config-if)# exit
SW1(config)# interface ethernet 0/0
SW1(config-if)# switchport trunk encapsulation dot1q
SW1(config-if)# switchport mode trunk
SW1(config-if)# end

Configure R1

R1# configure terminal
R1(config)# interface ethernet 0/0
R1(config-if)# no shutdown
R1(config-if)# exit
R1(config)# interface ethernet 0/0.10
R1(config-subif)# encapsulation dot1q 10
R1(config-subif)# ip address 192.168.10.254 255.255.255.0
R1(config-subif)# exit
R1(config)# interface ethernet 0/0.20
R1(config-subif)# encapsulation dot1q 20
R1(config-subif)# ip address 192.168.20.254 255.255.255.0
R1(config-subif)# end

Verify before pinging

SW1# show interfaces trunk
SW1# show vlan brief
R1# show ip interface brief
R1# show running-config interface ethernet 0/0.10
R1# show running-config interface ethernet 0/0.20

Now ping PC2 from PC1. If it fails, verify PC gateway first, then VLAN membership, trunk state, subinterface encapsulation and R1 interface state—in that order.

Break it

Change R1 E0/0.20 encapsulation to VLAN 30 while SW1 still sends VLAN 20. Predict which VLAN fails and prove it with trunk/subinterface output before fixing it.

Reference

VLAN IDs, trunk interface concept, subinterface pattern and gateway addresses follow the Router-on-a-Stick section of the supplied CCNA All LABS PDF.