Chapter 2 of 620% of exam

Network Access

Network access covers everything that happens inside the LAN: how switches learn and forward, how VLANs segment traffic, how trunks carry many VLANs, how EtherChannel bundles links, how Spanning Tree prevents loops, and how wireless LANs are built and managed. These Layer 2 topics are heavily tested and underpin the routing you will study next. Focus on the exact behaviors — what a switch does with an unknown frame, how 802.1Q tagging works, and how STP elects a root.

Switching Concepts

A switch is a Layer 2 device that forwards Ethernet frames based on MAC addresses. Its core behavior is learn, forward or flood, and filter. When a frame arrives, the switch reads the source MAC and records it against the incoming port in the MAC address table (CAM table), with a default aging timer of 300 seconds. It then looks up the destination MAC. If it finds a match, it forwards the frame out only that one port (a known unicast). If the destination is unknown, a broadcast (FFFF.FFFF.FFFF), or a multicast, it floods the frame out every port in the VLAN except the one it arrived on. Filtering means it will not send a frame back out the port it came in on. Two collision-related terms matter. Each switch port is its own collision domain, which is why full-duplex switched links have no collisions. A VLAN defines a single broadcast domain — a broadcast is flooded to every port in that VLAN but does not cross into other VLANs or past a router. Reducing broadcast-domain size is one reason to use VLANs. Switches support different frame-forwarding methods. Store-and-forward receives the entire frame and checks the frame check sequence (FCS) before forwarding, catching errors but adding latency; this is the method Cisco switches use by default. Cut-through starts forwarding as soon as it reads the destination MAC, lowering latency but passing along corrupt frames. Frames are examined at Layer 2, and the frame check sequence in the trailer lets a receiver detect corruption. Because switches operate in hardware (ASICs), forwarding is extremely fast. Understanding this learn-and-flood behavior explains why a new device is initially reachable via flooding and why the MAC table fills as conversations begin — and it is the basis for attacks and protections you will study in the security domain.

Switch process: learn source MAC, then forward known unicast or flood unknown/broadcast/multicast.
Unknown-unicast, broadcast, and multicast frames are flooded out all ports in the VLAN except the ingress port.
Each port = one collision domain; each VLAN = one broadcast domain.
MAC address table default aging = 300 seconds.
Cisco default forwarding is store-and-forward (checks FCS).

VLANs and Trunking

A VLAN (Virtual LAN) logically divides one physical switch into multiple broadcast domains. Devices in different VLANs cannot talk without a Layer 3 device (a router or Layer 3 switch performing "inter-VLAN routing"), even if they plug into the same switch. VLANs improve security, shrink broadcast domains, and group users by function rather than location. Switch ports operate in one of two modes. An access port belongs to exactly one VLAN and connects to an end device such as a PC or printer; frames on it are untagged. A trunk port carries traffic for many VLANs between switches (or to a router) and tags frames so the far end knows which VLAN each frame belongs to. The tagging standard is IEEE 802.1Q, which inserts a 4-byte tag into the Ethernet header containing the 12-bit VLAN ID (allowing 4,094 usable VLANs). One VLAN on each trunk is the native VLAN, and by default its frames are sent untagged. The native VLAN must match on both ends of a trunk or you get a VLAN mismatch — Cisco's CDP will warn about this. For security many designs change the native VLAN away from the default VLAN 1 and avoid using it for user data. VLAN 1 is the default for all ports and cannot be deleted. The normal VLAN range 1-1005 is stored in vlan.dat, while extended VLANs 1006-4094 require the switch to run in VTP transparent (or off) mode in older designs. DTP (Dynamic Trunking Protocol) can auto-negotiate a trunk, but best practice is to hard-set ports with "switchport mode access" or "switchport mode trunk" and disable DTP with "switchport nonegotiate," because leaving DTP on is a security risk. When a trunk does not come up, the classic checks are: do both ends agree on trunk mode, allowed VLANs, and the native VLAN?

Access port = one VLAN, untagged; trunk port = many VLANs, tagged.
802.1Q inserts a 4-byte tag; the native VLAN is sent untagged and must match on both trunk ends.
Devices in different VLANs need a router / Layer 3 switch to communicate (inter-VLAN routing).
VLAN 1 is the default and cannot be deleted; normal range 1-1005.
Best practice: statically set access/trunk mode and disable DTP with switchport nonegotiate.

Spanning Tree Protocol

Redundant links between switches prevent single points of failure but create Layer 2 loops, and because Ethernet frames have no TTL, a loop causes broadcast storms, MAC table instability, and duplicate frames that can crash a network in seconds. Spanning Tree Protocol (STP, IEEE 802.1D) prevents this by building a loop-free logical topology, blocking redundant links until they are needed. STP elects one root bridge — the switch with the lowest bridge ID. The bridge ID is the 2-byte priority (default 32768) plus the switch MAC address; the extended system ID adds the VLAN number to the priority. When priorities tie (the common case), the lowest MAC address wins. To influence the election, lower a switch's priority in multiples of 4096. Every non-root switch selects one root port — the port with the lowest cumulative path cost toward the root. STP cost is based on link bandwidth: 10 Mbps = 100, 100 Mbps = 19, 1 Gbps = 4, 10 Gbps = 2. Each segment also elects one designated port (the port on the switch with the lowest cost to root that forwards onto that segment); the root bridge's ports are all designated. Any remaining port is put into a blocking (non-designated) state to break the loop. Classic 802.1D port states are blocking, listening, learning, and forwarding, and convergence can take up to 50 seconds. Rapid PVST+ (802.1w) converges in a few seconds and is the modern default on Cisco switches, running a separate instance per VLAN. Two edge-port features are commonly tested: PortFast puts an access port straight into forwarding for hosts (never enable it on a switch-to-switch link), and BPDU Guard err-disables a PortFast port that unexpectedly receives a BPDU, protecting the topology from rogue switches. Root Guard and Loop Guard offer further protection.

Root bridge = lowest bridge ID (priority + MAC); on a tie, lowest MAC wins.
Adjust priority in increments of 4096; each non-root switch has one root port (lowest path cost).
STP costs: 10M=100, 100M=19, 1G=4, 10G=2 (lower is better).
Rapid PVST+ (802.1w) converges in seconds vs up to 50s for classic 802.1D.
PortFast = instant forwarding on host ports; BPDU Guard err-disables a PortFast port that receives a BPDU.

EtherChannel

EtherChannel bundles two or more physical links between the same pair of devices into one logical link (a port-channel). This multiplies bandwidth and adds redundancy, and crucially STP treats the whole bundle as a single link — so none of the member links are blocked. If one member fails, traffic simply continues on the survivors without an STP reconvergence event. A bundle can be negotiated dynamically or set statically. LACP (Link Aggregation Control Protocol, IEEE 802.3ad) is the open-standard negotiation protocol and uses the modes active and passive; at least one side must be active (active-active or active-passive form a channel, but passive-passive does not). PAgP (Port Aggregation Protocol) is Cisco-proprietary and uses the modes desirable and auto, following the same rule that both sides cannot be the passive-style mode (auto-auto fails). The "on" mode forces a channel with no negotiation and must be configured on both ends; mixing "on" with LACP or PAgP will not form a channel. For a bundle to come up, every member port must have identical settings: the same speed, the same duplex, the same allowed VLANs and native VLAN, and the same access/trunk mode. A mismatch on any of these keeps the port out of the channel — a very common troubleshooting item. Verify with "show etherchannel summary," where a healthy bundle shows the flags P (bundled in port-channel) and SU (Layer 2, in use). Traffic is distributed across members by a load-balancing hash of addresses (source/destination MAC or IP, or ports), configurable per device. Because the hash pins each conversation to one member, a single flow cannot exceed one link's speed even though the aggregate is larger. EtherChannel is common between distribution and access switches and on uplinks where both extra bandwidth and resilience are wanted.

EtherChannel bundles links into one logical port-channel; STP does not block the members.
LACP (standard) modes: active/passive — not passive-passive. PAgP (Cisco) modes: desirable/auto — not auto-auto.
'on' mode = static, no negotiation, must match on both ends; do not mix on with LACP/PAgP.
All members must match speed, duplex, allowed VLANs, native VLAN, and mode.
Verify with show etherchannel summary (look for P and SU flags).

Wireless LAN Fundamentals

Wireless LANs (802.11 / Wi-Fi) connect clients over shared radio using access points. Because radio is a shared, half-duplex medium, 802.11 uses CSMA/CA (collision avoidance) rather than the CSMA/CD of legacy Ethernet. Two frequency bands are used: 2.4 GHz offers longer range but only three non-overlapping channels (1, 6, 11) and more interference; 5 GHz offers more channels and higher throughput at shorter range. The SSID is the network name clients see; a BSS is a single AP's coverage cell, and multiple APs sharing an SSID form an ESS to allow roaming. Deployment models differ in where intelligence lives. Autonomous APs are standalone, each configured individually — fine for a few APs but unmanageable at scale. Lightweight APs use a split-MAC architecture: real-time functions stay on the AP while management, RF, and security are centralized on a Wireless LAN Controller (WLC). The AP and WLC communicate over CAPWAP, which builds two tunnels — a control tunnel (UDP 5246) and a data tunnel (UDP 5247) — so client traffic can be tunneled back to the controller. A WLC lets you push configuration, manage channels and power, and roam clients seamlessly across many APs. A lightweight AP boots and discovers its controller (via options such as DHCP option 43, DNS, or broadcast), joins over CAPWAP, and downloads its configuration. On the controller you configure WLANs mapping an SSID to a VLAN interface and a security policy. AP ports on the switch are typically trunk ports (for local switching) or access ports (for central switching), depending on design. For the 200-301 exam you should be comfortable navigating a WLC GUI to create a WLAN, assign an interface/VLAN, and set security (WPA2/WPA3), plus recognize CAPWAP, the difference between autonomous and lightweight APs, and basic RF concepts like non-overlapping channels and the effect of channel overlap on interference.

Wi-Fi uses CSMA/CA on a shared half-duplex medium; 2.4 GHz non-overlapping channels are 1, 6, 11.
Lightweight APs use split-MAC and are managed by a WLC; autonomous APs are standalone.
AP-to-WLC uses CAPWAP: control tunnel UDP 5246, data tunnel UDP 5247.
SSID = network name; a WLAN on the WLC maps an SSID to a VLAN/interface and a security policy.
APs can discover the WLC via DHCP option 43, DNS, or broadcast.

Keep going: the full Cisco CCNA 200-301 guide covers every section of the exam. Cisco CCNA 200-301 — Complete Study Guide (2026) — PDF + EPUB, $14.99 · 14-day refund →

Studying in order?

Practice stays free. The full Cisco CCNA 200-301 study guide is the material itself, taught start to finish — a downloadable PDF + EPUB you keep.

Get the book — $14.99
Report