
Trace the VLAN context of one Ethernet frame across three links. Explain the difference between a tag present on the wire and the VLAN membership that a switch assigns to traffic. Read the actual switch documentation before interpreting its port settings.
Ingress means a frame is entering a port; egress means it is leaving. An 802.1Q VLAN tag identifies VLAN context on a tagged link. An untagged frame has no such tag on that link, but can still belong to a VLAN within the network.
On switches using a port VLAN ID, or PVID, accepted untagged ingress traffic is classified using that port's configured VLAN context. Egress membership settings determine whether a VLAN's outgoing traffic is tagged or untagged. These settings are related but are not interchangeable fields in every switch interface. Frame-admission and membership filtering can reject traffic; setting a PVID alone is not proof that a frame will be accepted.
Assume the administrator has approved the following simple topology and all illustrated interfaces are forwarding:
Camera C1 connects to SW1 port 3. SW1 port 24 connects to SW2 port 24. SW2 port 8 connects to recorder R1.
C1 and R1 are configured to send and receive ordinary untagged Ethernet frames. SW1/3 and SW2/8 are access ports for VLAN 110. The inter-switch connection carries VLAN 110 with an 802.1Q tag at both ends. Both endpoints use the administrator's supplied IP plan in the same subnet. The example does not route traffic or translate an IP address.
Follow a camera frame toward the recorder:
The frame's visible tag treatment changes at link boundaries. The intended VLAN stays 110 throughout this example. Do not describe an untagged access link as being outside all VLANs. Do not claim that the switch must store an internally tagged wire-format copy; internal switching implementation is outside this exercise.
For SW1/3, record the endpoint's tagging capability, the access VLAN and accepted frame types. For each trunk end, record allowed VLAN membership, tagged egress membership, native or untagged behavior and ingress classification. For SW2/8, confirm that the recorder expects the outgoing frame format.
A switch display might show a VLAN as untagged on egress while presenting ingress PVID in another panel. Read both, using the vendor's terminology. A PVID should not be treated as a universal command to remove tags from every outgoing frame. Likewise, marking one VLAN tagged does not automatically authorize every other VLAN on that port.
The poster illustrates VLAN 110 as tagged across the uplink. It does not say every frame on every trunk must be tagged. Some configurations carry a native VLAN untagged; other platforms or designs tag it or restrict untagged traffic. Determine the actual approved handling and verify both ends.
A port supporting an IP phone and attached computer, or a general/hybrid port, can have more complex behavior than the basic access-port example. Do not copy a camera port setting to a phone, wireless access point or controller without understanding its requirements. This lesson is not a universal recipe for voice VLANs, priority-tagged frames or stacked VLAN tags.
Scenario A: The recorder is accidentally configured to require tagged VLAN 110, but SW2/8 still sends untagged frames. The worksheet shows an endpoint-to-port expectation mismatch. Present the evidence to the administrator; do not guess whether to modify the endpoint or the switch.
Scenario B: SW1/24 sends VLAN 110 tagged, but SW2/24 excludes VLAN 110. A physical link can remain up while the intended traffic path fails. A link light cannot verify membership.
Scenario C: A changed uplink sends untagged traffic that SW1 classifies into VLAN 110 and SW2 classifies into VLAN 120. This is an inconsistent boundary. Stop treating the link as an approved continuation of VLAN 110 and escalate the configuration discrepancy. Do not solve it by allowing every VLAN.
Scenario D: Both endpoints are untagged and the uplink carries tag 110. A trainee says the camera must be changed to send tag 110 because the recorder is on another switch. That conclusion is wrong for the approved illustrated design: the switches provide the tagged transit between untagged endpoint links.
Build a four-column table: link; expected on-wire format; relevant port settings; observed evidence. Use three rows for camera-to-SW1, SW1-to-SW2 and SW2-to-recorder. Expected formats are untagged, tagged 110 and untagged.
Only record observations actually obtained. Configuration review and packet observation are different evidence. If an administrator supplies a capture, establish where it was collected and whether mirroring or the capture interface preserves VLAN tags before using an absent visible tag as proof about the original link. Do not collect production traffic without authorization.
Trace the reverse journey in the supplied forwarding topology: R1 sends an ordinary untagged frame toward C1. SW2/8 classifies accepted ingress into VLAN110. SW2/24 sends this VLAN's traffic tagged 110 across the approved inter-switch link. SW1 accepts VLAN110 there and sends the camera-bound frame untagged from SW1/3, matching C1's documented expectation.
The three worksheet entries are R1-to-SW2: untagged; SW2-to-SW1: tagged 110; SW1-to-C1: untagged. This is the same VLAN membership with different wire formats, not a routed journey. If the supplied recorder setting changes to require tags, the recorder-facing format expectation no longer matches the approved access-port arrangement; refer the mismatch to the administrator rather than changing both ends by guesswork.
Mistake: Calling the camera's untagged access cable outside VLAN110. Correction: Record no tag on that wire and VLAN110 as the ingress classification; on-wire format and membership are distinct.
Mistake: Using the ingress PVID field as proof of the outgoing frame format. Correction: Inspect the actual port mode and egress tagged/untagged membership separately in the platform documentation.
Mistake: Treating an absent VLAN tag in a supplied capture as conclusive proof of an untagged uplink. Correction: Confirm the capture location and whether mirroring and the capture interface preserve tags before comparing it with the approved link format.
Cisco, Configuring VLAN Settings for Interfaces: https://www.cisco.com/assets/sol/sb/Switches_Emulators_v2_2_015/help/nk_configuring_vlans06.html Read for access/trunk/general distinctions, PVID and frame admission. Product-specific defaults and restrictions are not generalized to every switch.
Cisco, Defining VLAN Membership: https://www.cisco.com/assets/sol/sb/Switches_Emulators_v2_2_015/help/nk_configuring_vlans07.html Read for the difference between egress tagged/untagged membership and ingress PVID. Source wording about interface modes is interpreted within that product's documentation.
This is a national networking fundamental, not a jurisdictional code approval or permission to modify equipment.
Texas journeyman, 15 questions, scored by topic against the 70% mark. No card, and no account needed to start.
Free study material for low-voltage apprentices. This is a national foundation course: requirements differ by state and by local jurisdiction, and a practice that is common in one place is not a rule everywhere. Nothing here is a licence, a certification, or authority to work unsupervised, and completing it does not count as apprenticeship hours or continuing-education credit. Check the codes adopted where you are working, the licensing authority for that work, and your employer's safety programme. VoltMark is not affiliated with, endorsed by, or sponsored by NFPA, OSHA, NICET, BICSI, FOA, or any state or local licensing authority.

Electrician licensing exam prep: practice questions, timed exam simulations, and step-by-step help finding every answer in the NEC.