VLANs, Trunk y Voice VLAN - Verificación

Cómo comprobar que las VLANs, los troncales y la VLAN de voz quedaron bien. La configuración está en VLANs, Trunk y Voice VLAN - Configuración y el diagnóstico en VLANs, Trunk y Voice VLAN - Troubleshooting.

Quiero comprobar…Comando
Qué VLANs existen y qué puertos de acceso tienenshow vlan brief
Modo, VLAN de acceso, VLAN de voz y nativa de un puertoshow interfaces <if> switchport
Qué troncales hay, su nativa y sus VLANs permitidasshow interfaces trunk
Qué negoció DTP en un puertoshow dtp interface <if>
Si un equipo se aprende en la VLAN correctashow mac address-table vlan <n>
Si el teléfono IP está conectadoshow cdp neighbors

VLANs

Lista de VLANs y sus puertos

Switch# show vlan brief

Salida típica:

VLAN Name                 Status    Ports
---- -------------------- --------- -------------------------------
1    default              active    Fa0/2, Fa0/3, Fa0/4, Fa0/5
                                    Fa0/6, Fa0/7, Fa0/8, Fa0/9
                                    ... (resto de puertos no asignados)
                                    Gi0/1, Gi0/2, Gi0/3, Gi0/4
10   VLAN_INGENIEROS      active    Fa0/1
20   VLAN0020             active
1002 fddi-default         act/unsup
1003 token-ring-default   act/unsup
1004 fddinet-default      act/unsup
1005 trnet-default        act/unsup

Cómo leerla:

  • Cada VLAN aparece con su número, nombre y Status.
  • Debajo de Ports se listan los puertos de acceso de esa VLAN. Los puertos no asignados siguen en la VLAN 1 (default).
  • Los troncales no aparecen aquí, porque transportan varias VLANs. Para ellos se usa show interfaces trunk.
  • Status:
    • active: VLAN operativa.
    • act/unsup: activa pero no soportada; es lo normal en las reservadas 1002-1005 (Token Ring y FDDI).
    • suspended: la VLAN está suspendida y no reenvía.
  • Una VLAN creada sin nombre (por ejemplo la 20) aparece con el nombre por defecto VLAN0020.

Para la tabla completa, con más detalle: Switch# show vlan

Puerto de acceso y su VLAN

Switch# show interfaces fastEthernet 0/1 switchport

Salida típica (recortada):

Name: Fa0/1
Switchport: Enabled
Administrative Mode: static access
Operational Mode: static access
Administrative Trunking Encapsulation: negotiate
Operational Trunking Encapsulation: native
Negotiation of Trunking: Off
Access Mode VLAN: 10 (VLAN_INGENIEROS)
Trunking Native Mode VLAN: 1 (default)
Voice VLAN: none
Qué mirarValor esperadoSignificado
Operational Modestatic accessEl puerto funciona como de acceso
Access Mode VLAN10 (VLAN_INGENIEROS)La VLAN de acceso y su nombre. Aquí se detecta un puerto en la VLAN equivocada
Negotiation of TrunkingOffNo intenta negociar troncal (correcto en un puerto de usuario)

Configuración aplicada al puerto

Switch# show running-config interface fastEthernet 0/1

Debe mostrar switchport mode access y switchport access vlan 10.

MAC aprendidas por VLAN

Switch# show mac address-table vlan 10

Confirma que la MAC del equipo aparece en el puerto correcto y bajo la VLAN 10.


Trunk y DTP

Ver los enlaces troncales

Switch# show interfaces trunk

Salida típica:

Port      Mode      Encapsulation  Status        Native vlan
Fa0/10    on        802.1q         trunking      99

Port      Vlans allowed on trunk
Fa0/10    10,20,30,99

Port      Vlans allowed and active in management domain
Fa0/10    10,20,30,99

Port      Vlans in spanning tree forwarding state and not pruned
Fa0/10    10,20,30,99

Cómo leerla:

CampoSignificado
Modeon (troncal fijo), auto o desirable (negociación DTP)
Encapsulation802.1q (dot1q)
Statustrunking = troncal operativo. not-trunking = el enlace quedó de acceso
Native vlanLa VLAN nativa. Debe coincidir con el otro extremo
Vlans allowed on trunkLo que configuraste como permitido
Vlans allowed and activeDe las permitidas, cuáles existen y están activas en este switch
Vlans in spanning tree forwardingCuáles están realmente reenviando (no bloqueadas por STP ni podadas)

Si una VLAN está en “allowed” pero no en “allowed and active”, es que no existe en ese switch.

Detalle del puerto troncal

Switch# show interfaces fastEthernet 0/10 switchport
Qué mirarSignificado
Administrative ModeLo que configuraste (trunk, dynamic auto, etc.)
Operational ModeCómo quedó realmente (trunk o static access)
Operational Trunking Encapsulationdot1q
Negotiation of TrunkingOff si pusiste nonegotiate; On si DTP está activo
Trunking Native Mode VLANLa VLAN nativa operativa
Trunking VLANs EnabledLas VLANs permitidas en el troncal

Aquí confirmas si el enlace realmente quedó troncal (Operational Mode: trunk) o si por negociación terminó en acceso.

Estado de DTP en el puerto

Switch# show dtp interface fastEthernet 0/10

Salida típica:

DTP information for FastEthernet0/10:
  TOS/TAS/TNS:                    ACCESS/AUTO/ACCESS
  TOT/TAT/TNT:                    NATIVE/NEGOTIATE/NATIVE
  Neighbor address 1:             3037A6797F0C
  Neighbor address 2:             000000000000
  Hello timer expiration (sec/state):     19/RUNNING
  ...
  FSM state:                      S2:ACCESS
  Enabled:                        yes
  In STP:                         no
  • TOS/TAS/TNS = Trunk Operational / Administrative / Negotiated Status. En el ejemplo, ACCESS/AUTO/ACCESS: administrativamente está en auto, pero quedó en access (no formó troncal).
  • TOT/TAT/TNT = lo mismo para el tipo de encapsulación.
  • Enabled: yes: DTP está activo en el puerto. Con nonegotiate deja de enviar tramas.
  • FSM state: estado final de la negociación (ACCESS o TRUNK).

Voice VLAN

Detalle del puerto (datos + voz)

Switch# show interfaces fastethernet 0/10 switchport
Qué mirarValor esperadoSignificado
Operational Modestatic accessSigue siendo un puerto de acceso, con la voz como VLAN auxiliar
Access Mode VLAN20La VLAN de datos (la PC)
Voice VLAN30La confirmación de que la voz quedó bien

El puerto no aparece como troncal

Switch# show interfaces fastethernet 0/10 trunk

Un puerto de acceso con VLAN de voz normalmente no aparece como troncal en este comando, porque no es un trunk real. La confirmación definitiva es el campo Voice VLAN de show interfaces ... switchport.

VLANs de datos y voz

Switch# show vlan brief

Las dos VLANs (datos y voz) deben existir y estar active.

Teléfono y alimentación

! El teléfono IP debe verse como vecino CDP (capability Phone)
Switch# show cdp neighbors

! Si el teléfono se alimenta por PoE
Switch# show power inline
Switch# show power inline fastethernet 0/10

En show power inline el puerto debe estar entregando energía (on) con la potencia asignada. PoE se amplía en PoE - Verificación.

Confianza de QoS (si se configuró)

Switch# show mls qos interface fastethernet 0/10

Confirma que el puerto confía en el marcado del teléfono (trust). Ver QoS - Verificación.


Checklist de verificación

VLANs

  • show vlan brief: la VLAN existe, está active y con el nombre correcto.
  • show vlan brief: el puerto aparece bajo la VLAN esperada (no bajo la 1).
  • show interfaces <if> switchport: Operational Mode: static access y Access Mode VLAN correcta.
  • show mac address-table vlan <n>: la MAC del equipo se aprende en la VLAN correcta.

Trunk y DTP

  • show interfaces trunk: el puerto aparece como trunking, con 802.1q y la nativa correcta.
  • La nativa coincide en ambos extremos.
  • Las VLANs permitidas son exactamente las que deben cruzar, y aparecen en “allowed and active”.
  • show interfaces <if> switchport: Operational Mode: trunk y Negotiation of Trunking: Off si usaste nonegotiate.
  • show dtp interface <if>: el estado negociado (TOS) es el que buscabas.

Voice VLAN

  • show interfaces <if> switchport: Access Mode VLAN (datos) y Voice VLAN (voz) correctas.
  • show cdp neighbors: el teléfono aparece con capability Phone.
  • La VLAN de voz está permitida en los troncales hacia el servidor de telefonía.