Put lin-srv on two VLANs through one tagged adapter

applied · 50 min · Objective 2.2

Task

Give lin-srv presence on two VLANs, 10 and 20, through a single virtual adapter carrying tagged traffic, each VLAN with its own address. Prove each works by reaching a partner on the same VLAN, then misconfigure the tag deliberately and record the symptom: a link that is up and a server that reaches nothing.

Steps

  1. On lin-srv, create VLAN interfaces 10 and 20 on the lab adapter with ip link add link <if> name <if>.10 type vlan id 10 (and 20), give them 10.10.10.10/24 and 10.20.20.10/24, and bring them up. Save ip -d link show to lab/vlan/links.txt.
  2. Do the same on the partner VM with .11 addresses in each subnet.
  3. Ping the partner on both VLANs and save the results to lab/vlan/ping-ok.txt.
  4. Change the partner's VLAN 20 interface to VLAN 21 while keeping its address, ping 10.20.20.11 again, and save the result to lab/vlan/ping-mismatch.txt. Save ip -br link from the partner to lab/vlan/link-state.txt.
  5. Restore VLAN 20 and record in lab/vlan/diagnosis.txt the symptom of the mismatch and the two places you would check first on a real switch and server.

Verify

These checks run in a POSIX shell: Terminal on macOS or Linux, and on Windows Git Bash (it comes with Git for Windows) or WSL. A stock Windows PowerShell or Command Prompt has no awk or grep, so there the first line fails.

grep -Ec 'vlan (protocol 802.1Q )?id (10|20)' lab/vlan/links.txt
grep -Ec ' 0% packet loss' lab/vlan/ping-ok.txt
grep -Ec '100% packet loss|Unreachable' lab/vlan/ping-mismatch.txt
grep -c 'UP' lab/vlan/link-state.txt
grep -Eic 'tagged|tagging|vlan id|trunk|allowed' lab/vlan/diagnosis.txt

Both VLAN interfaces carry their IDs, both pings succeed, and the mismatched ping fails completely while the link state still shows UP. That combination -- link up, address right, nothing reachable -- is the signature of a VLAN mismatch, and the reason the troubleshooting domain says to check tagging before anything else.

Notes

A real switch would also need the VLANs in the trunk's allowed list. The hypervisor's virtual switch plays the switch's part here, so a VLAN missing from its trunk configuration produces exactly the same symptom.

This is an independent study companion for CompTIA Server+ SK0-005 and is not produced by or endorsed by CompTIA.