Mesab / Engineering portfolioGNS3 network lab
VLAN segmentation · 802.1Q trunking · Packet analysis

A segmented network, tested in GNS3

Two switches, six virtual PCs and three VLANs. Verify cross-switch connectivity, prove Layer 2 isolation and trace a configuration fault from failure to recovery.

Executed in native GNS3 · Recorded VPCS results · Actual trunk packet capture
7 / 7Verification checks passed
3 VLANsStaff · Servers · Guest
69 framesCaptured on the 802.1Q trunk
5 / 5Replies in each reachability test
Download native GNS3 projectDownload packet captureDownload lab & evidence

Native GNS3 topology

Actual GNS3 Web UI screenshot showing Mesab's running two-switch topology, six VPCS endpoints and 802.1Q trunk
Captured from the running GNS3 Web UI. Switch ports 1, 2 and 3 are access ports in VLANs 10, 20 and 30; port 0 carries the trunk with native VLAN 1.

Measured connectivity & recovery

All results below were recorded from the virtual devices. Isolation tests deliberately put a host in another VLAN into the same IP subnet, so a missing route cannot explain the failure.

TestSourceMeasured resultCheck
VLAN 10: cross-switch connectivityVLAN10-A5/5 replies · reachablePASS
VLAN 20: cross-switch connectivityVLAN20-A5/5 replies · reachablePASS
VLAN 30: cross-switch connectivityVLAN30-A5/5 replies · reachablePASS
VLAN 10 to VLAN 20: same-subnet isolationVLAN10-A0/5 replies · isolatedPASS
VLAN 10 to VLAN 30: same-subnet isolationVLAN10-A0/5 replies · isolatedPASS
Injected access-port mismatch: connectivity failsVLAN10-A0/5 replies · isolatedPASS
Access-port repair: connectivity restoredVLAN10-A5/5 replies · reachablePASS

The two VLAN-isolation cases and the injected port mismatch failed ARP resolution as expected. After restoring the access port to VLAN 10, all five ICMP requests succeeded. No router or inter-VLAN routing is part of this Layer 2 lab.

Device console evidence

Expand a test to inspect its recorded VPCS command and output.

VLAN 10: cross-switch connectivity
VLAN10-A> ping 192.168.10.12 -c 5
ping 192.168.10.12 -c 5

84 bytes from 192.168.10.12 icmp_seq=1 ttl=64 time=0.269 ms
84 bytes from 192.168.10.12 icmp_seq=2 ttl=64 time=0.489 ms
84 bytes from 192.168.10.12 icmp_seq=3 ttl=64 time=0.571 ms
84 bytes from 192.168.10.12 icmp_seq=4 ttl=64 time=0.406 ms
84 bytes from 192.168.10.12 icmp_seq=5 ttl=64 time=0.352 ms

VLAN10-A> 
VLAN 20: cross-switch connectivity
VLAN20-A> ping 192.168.20.12 -c 5
ping 192.168.20.12 -c 5

84 bytes from 192.168.20.12 icmp_seq=1 ttl=64 time=0.348 ms
84 bytes from 192.168.20.12 icmp_seq=2 ttl=64 time=0.637 ms
84 bytes from 192.168.20.12 icmp_seq=3 ttl=64 time=0.437 ms
84 bytes from 192.168.20.12 icmp_seq=4 ttl=64 time=0.422 ms
84 bytes from 192.168.20.12 icmp_seq=5 ttl=64 time=0.370 ms

VLAN20-A> 
VLAN 30: cross-switch connectivity
VLAN30-A> ping 192.168.30.12 -c 5
ping 192.168.30.12 -c 5

84 bytes from 192.168.30.12 icmp_seq=1 ttl=64 time=0.325 ms
84 bytes from 192.168.30.12 icmp_seq=2 ttl=64 time=0.551 ms
84 bytes from 192.168.30.12 icmp_seq=3 ttl=64 time=0.508 ms
84 bytes from 192.168.30.12 icmp_seq=4 ttl=64 time=0.330 ms
84 bytes from 192.168.30.12 icmp_seq=5 ttl=64 time=0.406 ms

VLAN30-A> 
VLAN 10 to VLAN 20: same-subnet isolation
VLAN10-A> ping 192.168.10.99 -c 5
ping 192.168.10.99 -c 5

host (192.168.10.99) not reachable

VLAN10-A> 
VLAN 10 to VLAN 30: same-subnet isolation
VLAN10-A> ping 192.168.10.98 -c 5
ping 192.168.10.98 -c 5

host (192.168.10.98) not reachable

VLAN10-A> 
Injected access-port mismatch: connectivity fails
VLAN10-A> ping 192.168.10.12 -c 5
ping 192.168.10.12 -c 5

host (192.168.10.12) not reachable

VLAN10-A> 
Access-port repair: connectivity restored
VLAN10-A> ping 192.168.10.12 -c 5
ping 192.168.10.12 -c 5

84 bytes from 192.168.10.12 icmp_seq=1 ttl=64 time=0.290 ms
84 bytes from 192.168.10.12 icmp_seq=2 ttl=64 time=0.328 ms
84 bytes from 192.168.10.12 icmp_seq=3 ttl=64 time=0.424 ms
84 bytes from 192.168.10.12 icmp_seq=4 ttl=64 time=0.355 ms
84 bytes from 192.168.10.12 icmp_seq=5 ttl=64 time=0.379 ms

VLAN10-A> 
Download full console transcriptDownload measured results

Inside the trunk capture

69 measured Ethernet frames, all tagged with 802.1Q. The capture includes ARP resolution, ICMP echo requests and replies, and unanswered ARP during isolation and fault tests.

69 captured frames

FrameVLANProtocolSource IPDestination IPBytes
110ARP request192.168.10.11192.168.10.1268
210ARP reply192.168.10.12192.168.10.1168
310ICMP echo request192.168.10.11192.168.10.12102
410ICMP echo reply192.168.10.12192.168.10.11102
510ICMP echo request192.168.10.11192.168.10.12102
610ICMP echo reply192.168.10.12192.168.10.11102
710ICMP echo request192.168.10.11192.168.10.12102
810ICMP echo reply192.168.10.12192.168.10.11102
910ICMP echo request192.168.10.11192.168.10.12102
1010ICMP echo reply192.168.10.12192.168.10.11102
1110ICMP echo request192.168.10.11192.168.10.12102
1210ICMP echo reply192.168.10.12192.168.10.11102
1320ARP request192.168.20.11192.168.20.1268
1420ARP reply192.168.20.12192.168.20.1168
1520ICMP echo request192.168.20.11192.168.20.12102
1620ICMP echo reply192.168.20.12192.168.20.11102
1720ICMP echo request192.168.20.11192.168.20.12102
1820ICMP echo reply192.168.20.12192.168.20.11102
1920ICMP echo request192.168.20.11192.168.20.12102
2020ICMP echo reply192.168.20.12192.168.20.11102
2120ICMP echo request192.168.20.11192.168.20.12102
2220ICMP echo reply192.168.20.12192.168.20.11102
2320ICMP echo request192.168.20.11192.168.20.12102
2420ICMP echo reply192.168.20.12192.168.20.11102
2530ARP request192.168.30.11192.168.30.1268
2630ARP reply192.168.30.12192.168.30.1168
2730ICMP echo request192.168.30.11192.168.30.12102
2830ICMP echo reply192.168.30.12192.168.30.11102
2930ICMP echo request192.168.30.11192.168.30.12102
3030ICMP echo reply192.168.30.12192.168.30.11102
3130ICMP echo request192.168.30.11192.168.30.12102
3230ICMP echo reply192.168.30.12192.168.30.11102
3330ICMP echo request192.168.30.11192.168.30.12102
3430ICMP echo reply192.168.30.12192.168.30.11102
3530ICMP echo request192.168.30.11192.168.30.12102
3630ICMP echo reply192.168.30.12192.168.30.11102
3720ARP request192.168.10.99192.168.10.9968
3820ARP request192.168.10.99192.168.10.9968
3920ARP request192.168.10.99192.168.10.9968
4010ARP request192.168.10.11192.168.10.9968
4110ARP request192.168.10.11192.168.10.9968
4210ARP request192.168.10.11192.168.10.9968
4320ARP request192.168.20.12192.168.20.1268
4420ARP request192.168.20.12192.168.20.1268
4520ARP request192.168.20.12192.168.20.1268
4630ARP request192.168.10.98192.168.10.9868
4730ARP request192.168.10.98192.168.10.9868
4830ARP request192.168.10.98192.168.10.9868
4910ARP request192.168.10.11192.168.10.9868
5010ARP request192.168.10.11192.168.10.9868
5110ARP request192.168.10.11192.168.10.9868
5230ARP request192.168.30.12192.168.30.1268
5330ARP request192.168.30.12192.168.30.1268
5430ARP request192.168.30.12192.168.30.1268
5510ARP request192.168.10.11192.168.10.1268
5610ARP request192.168.10.11192.168.10.1268
5710ARP request192.168.10.11192.168.10.1268
5810ARP request192.168.10.11192.168.10.1268
5910ARP reply192.168.10.12192.168.10.1168
6010ICMP echo request192.168.10.11192.168.10.12102
6110ICMP echo reply192.168.10.12192.168.10.11102
6210ICMP echo request192.168.10.11192.168.10.12102
6310ICMP echo reply192.168.10.12192.168.10.11102
6410ICMP echo request192.168.10.11192.168.10.12102
6510ICMP echo reply192.168.10.12192.168.10.11102
6610ICMP echo request192.168.10.11192.168.10.12102
6710ICMP echo reply192.168.10.12192.168.10.11102
6810ICMP echo request192.168.10.11192.168.10.12102
6910ICMP echo reply192.168.10.12192.168.10.11102

Decoded from the downloadable PCAP. This table presents recorded packets; it is not a live network connection or a Wireshark screenshot.

Download decoded packets

Addressing & implementation

VLANPurposePC-APC-BSubnet
10Staff192.168.10.11192.168.10.12/24
20Servers192.168.20.11192.168.20.12/24
30Guest192.168.30.11192.168.30.12/24

GNS3 Server 2.2.54 · Dynamips 0.2.25 built-in Ethernet switches · VPCS 0.8.4 · uBridge 1.0.1. The native project uses built-in nodes and needs no Cisco IOS image. The source package includes automation and a reproducible test procedure.

Packet Tracer companion

The package also includes an equivalent two-switch Cisco configuration kit and rebuild guide for Packet Tracer. The measured evidence on this page comes from GNS3; the companion kit is supplied as a build guide.

Download Packet Tracer configuration kit

Learning references: GNS3 built-in switches and Cisco networking lab concepts. Topology and recorded results were produced for this original lab.