CCNA 200-301 LAN Architecture: Access, Distribution, Core, VLANs, and Campus Design
What LAN Architecture Means in CCNA 200-301
In CCNA 200-301, LAN architecture is less about memorizing isolated switch commands and more about understanding how an enterprise campus is structured, why functions are placed in specific layers, and how traffic moves through that design. Cisco expects you to recognize the characteristics of two-tier and three-tier campus architectures, the roles of access, distribution, and core, and how VLANs, trunks, inter-VLAN routing, STP, EtherChannel, and wireless fit into the picture.
At a practical level, a campus LAN includes end hosts, access switches, multilayer switches, routers, wireless APs, and often a wireless LAN controller. Some devices forward frames at Layer 2 based on MAC addresses, while multilayer switches commonly perform both Layer 2 switching and Layer 3 routing. That distinction matters: same-VLAN communication is switched, different-VLAN communication is routed.
A useful memory aid for the exam is: Access attaches, Distribution decides, Core carries. That classic model is still central to CCNA, even though real networks may also use collapsed core or routed access designs.
CCNA Blueprint Alignment: What You Must Know
For this topic, you should be able to describe:
- Characteristics of two-tier and three-tier campus designs
- Functions of the access, distribution, and core layers
- How VLANs create broadcast domains
- Why trunks are used and how 802.1Q tagging works
- How inter-VLAN routing is done with SVIs or router-on-a-stick
- Why STP/RSTP is needed in Layer 2 redundant topologies
- How EtherChannel improves bandwidth and resiliency
- How APs and WLCs integrate into campus LANs
Also remember that CCNA teaches the classic hierarchical campus model conceptually. In production, some networks route closer to the access layer, use centralized policy, or reduce Layer 2 fault domains with routed uplinks.
Hierarchical Campus Design: Why It Exists
Hierarchical design improves scalability, fault isolation, availability, performance, and manageability. Instead of one giant flat switching domain, the network gets split into smaller modules with clear responsibilities. That makes growth easier and limits the blast radius of failures.
Failure domains are especially important.
A loop, trunk mismatch, or VLAN issue at the access layer shouldn’t be able to knock over an entire campus. If a single problem can take down far more of the network than it should, the design probably needs another look.
Good architecture contains problems and gives operators predictable places to troubleshoot.
There are two common models:
| Aspect | Two-Tier / Collapsed Core | Three-Tier |
|---|---|---|
| Layers | Access + distribution/core combined | Access + distribution + core |
| Best fit | Branches, small/medium campuses | Larger campuses |
| Cost/complexity | Lower | Higher |
| Scalability | Moderate | Higher |
Small sites often use a collapsed core because it is simpler and cheaper. Large campuses benefit from a dedicated core for high-speed transport between distribution blocks.
Understanding the Three Layers
Access layer: connects endpoints such as PCs, phones, printers, cameras, and APs. Common access-layer functions include VLAN assignment, PoE, edge security, and awareness of QoS trust boundaries. A Cisco IP phone typically connects to an access port with a data VLAN plus a configured voice VLAN, not a normal trunk from the switch perspective.
Distribution layer: aggregates access switches and commonly provides inter-VLAN routing, policy enforcement, ACLs, route summarization in larger routed designs, and gateway redundancy. In classic campus design, this is often the policy boundary, though modern policy may also be enforced by controllers, firewalls, or fabric-based systems.
Core layer: provides fast, resilient transport between distribution blocks.
The design goal is pretty straightforward: keep latency low, converge quickly when something fails, and don’t stuff the core with unnecessary policy complexity.
In general, the core should not become a services choke point unless the architecture specifically requires it.
For exam recall: access connects, distribution routes and applies policy, core transports quickly.
Broadcast Domains, Collision Domains, and Why VLANs Matter
A VLAN creates a separate broadcast domain.
So broadcasts in VLAN 10 stay in VLAN 10 unless something routes them somewhere else.
This reduces unnecessary traffic and improves segmentation.
Do not confuse a broadcast domain with a collision domain.
In modern switched Ethernet, each switch port is its own collision domain.
VLANs do not create collision domains; they create broadcast boundaries.
VLANs are Layer 2 constructs.
IP subnets, on the other hand, are Layer 3 constructs.
In most enterprise designs, one VLAN maps to one subnet, but they are not the same thing. Stretched VLANs can exist across multiple switches or locations, but they add operational complexity and are generally avoided unless there is a specific requirement.
A simple plan might look like this:
- VLAN 10 - Users - 192.168.10.0/24
- VLAN 20 - Voice - 192.168.20.0/24
- VLAN 30 - Guest - 192.168.30.0/24
- VLAN 99 - Management - example only, not a universal standard
Access Ports, Trunks, and 802.1Q
An access port carries traffic for one data VLAN. A trunk port carries multiple VLANs over one link when multiple VLANs must traverse that connection. Trunks are common on switch-to-switch links and router-on-a-stick links. Between multilayer switches, however, uplinks may instead be configured as Layer 3 routed ports if no VLAN trunking is needed.
CCNA focuses on IEEE 802.1Q, the open standard trunking method used on Cisco equipment. The 802.1Q tag is inserted in the Ethernet frame after the source MAC address and includes fields such as PCP, DEI, and VLAN ID.
The native VLAN is sent untagged on an 802.1Q trunk. Native VLAN mismatches can cause connectivity problems and warnings, and they are also a security concern. A common best practice is to use an unused VLAN as the native VLAN and prune unnecessary VLANs from trunks.
Cisco switches historically supported DTP to negotiate trunking, but best practice is usually to statically configure access or trunk mode rather than rely on negotiation.
interface g0/1 switchport mode trunk switchport trunk native vlan 999 switchport trunk allowed vlan 10,20,30,99
Cisco IOS-style verification commands for CCNA study include:
show interfaces trunk show vlan brief
Inter-VLAN Routing: SVIs and Router-on-a-Stick
If hosts are in different VLANs, they need Layer 3 routing to communicate. Two common CCNA methods are SVIs on a multilayer switch and router-on-a-stick.
SVI-based routing is common in campus LANs. For it to work, the VLAN must exist, the SVI must be configured, the VLAN must be operationally active, and ip routing must be enabled on many Cisco multilayer platforms.
vlan 10 vlan 20 ! interface vlan 10 ip address 192.168.10.1 255.255.255.0 no shutdown ! interface vlan 20 ip address 192.168.20.1 255.255.255.0 no shutdown ! ip routing
How an SVI comes up: if the VLAN does not exist, is shutdown, or has no active member ports on platforms that require active Layer 2 presence, the SVI may stay down/down or administratively down.
Router-on-a-stick uses one physical router interface with multiple 802.1Q subinterfaces. It works well in labs and small environments but is less scalable because inter-VLAN traffic shares one physical link.
interface g0/0.10 encapsulation dot1Q 10 ip address 192.168.10.1 255.255.255.0! interface g0/0.20 encapsulation dot1Q 20 ip address 192.168.20.1 255.255.255.0
| Method | Best fit | Tradeoff |
|---|---|---|
| SVIs on multilayer switch | Campus LANs | Higher performance, simpler local routing |
| Router-on-a-stick | Small sites, labs | Single-link bottleneck |
Packet walk across VLANs: Host A sends to its default gateway, the routing device examines the IP packet, rewrites the Layer 2 header for the destination subnet, and forwards the frame toward Host B after ARP or IPv6 ND resolution.
STP, RSTP, and Loop Prevention
Layer 2 redundancy is useful, but without loop prevention it causes broadcast storms and MAC table instability. STP solves that by creating a loop-free logical topology. For CCNA, know the standards:
- STP - IEEE 802.1D
- RSTP - IEEE 802.1w
- Rapid PVST+ - common Cisco context
Key STP terms:
- Root bridge: the reference switch for the spanning-tree topology
- Root port: a non-root switch’s best path toward the root
- Designated port: the forwarding port for a segment
- Alternate port: a backup path in RSTP
A blocked port is not necessarily broken; it may be the correct loop-prevention result. Root placement matters, so administrators usually try to control which switch becomes root.
On edge ports, PortFast is commonly enabled so end devices do not wait through normal STP transitions. BPDU Guard is often paired with PortFast to shut down the port if a BPDU appears, protecting against accidental switch connections.
interface range g0/2 - 24 spanning-tree portfast spanning-tree bpduguard enable
Useful verification:
show spanning-tree
EtherChannel Modes and Requirements
EtherChannel bundles multiple physical links into one logical Port-Channel for added bandwidth and resiliency. STP sees the bundle as one logical link, not as separate forwarding/blocking decisions for each member under normal operation.
For CCNA, know the modes:
- LACP (standard): active/passive
- PAgP (Cisco proprietary): desirable/auto
- Static: on
Member links must match key settings such as speed, duplex, access/trunk mode, allowed VLANs, and native VLAN. If they do not, ports may fail to bundle or be suspended.
interface range g0/1 - 2 channel-group 1 mode active ! interface port-channel 1 switchport mode trunk switchport trunk allowed vlan 10,20,30,99
Load balancing is typically per flow based on a hash; one single flow does not use all links simultaneously.
show etherchannel summary
First-Hop Redundancy and Gateway Resiliency
Redundant uplinks are only part of high availability.
If the default gateway fails, users can still lose connectivity even when the switch links themselves are perfectly fine.
That is why campus designs often use first-hop redundancy protocols such as HSRP, VRRP, or GLBP at the distribution layer or collapsed core.
At CCNA level, the key idea is simple: hosts use a virtual default gateway address, and multiple devices cooperate so gateway service survives a device failure.
Wireless Traffic Paths in Campus LANs
Wireless is part of LAN architecture, not separate from it. APs usually connect at the access layer and rely on the wired LAN for switching, routing, and upstream access. The exact switchport design depends on the wireless deployment model.
In some local switching or autonomous designs, an AP uplink may be a trunk if multiple SSIDs map directly to multiple VLANs on the switch. In many controller-based CAPWAP deployments, the AP switchport is commonly an access port in an AP management VLAN, while client traffic is tunneled to the WLC instead of bridged locally by the AP.
That is an important exam trap: an AP uplink is not always a trunk.
SSID-to-VLAN mapping is still central. A corporate SSID may map to VLAN 10, while guest traffic maps to VLAN 30 and may be restricted by policy before reaching internal resources.
Campus LAN Security Features
VLANs help with segmentation, but VLAN separation alone is not a complete security boundary. Common access-layer protections include:
- Port security
- DHCP snooping
- Dynamic ARP Inspection
- IP Source Guard
- 802.1X for identity-based access control
- Storm control
- PortFast and BPDU Guard on edge ports
Management-plane basics also matter: use SSH instead of insecure remote access methods, restrict management reachability with ACLs where appropriate, and remember that a management VLAN only works if trunks allow it, the SVI is reachable, and upstream routing/default gateway settings are correct.
Troubleshooting LAN Architecture Step by Step
A good workflow is: physical - Layer 2 - Layer 3 - policy.
- Physical: link up, speed/duplex, PoE for phones/APs
- Layer 2: correct VLAN, trunk carrying the VLAN, STP state, MAC learning
- Layer 3: SVI up, ip routing enabled, correct default gateway, routing table
- Policy: ACLs, wireless policy, DHCP snooping/DAI effects
Common Cisco IOS-style checks:
show vlan brief show interfaces trunk show spanning-tree show mac address-table show ip interface brief show etherchannel summary
Typical failure patterns:
- Users in one VLAN only affected: check VLAN existence, access-port assignment, and trunk allowed VLAN list
- SVI down/down: check whether the VLAN exists and has active member ports
- Redundant link idle: likely STP blocking by design
- Phone has power but no voice: check PoE, voice VLAN, data VLAN, and CDP/LLDP-MED-related provisioning
- Guest Wi-Fi reaches external connectivity but not internal resources: often policy by design, or segmentation enforced by ACLs or a wireless controller
Common Design Pitfalls and Exam Traps
- VLAN is not the same as subnet
- Trunk does not mean faster; it means multi-VLAN
- Blocked by STP does not mean failed
- No ip routing on a multilayer switch can break inter-VLAN routing
- Native VLAN mismatch can cause errors and odd behavior
- EtherChannel members must match key settings
- AP uplinks are design-dependent, not always trunks
- Small campuses do not always need a dedicated core
CCNA Practice Questions: LAN Architecture
1. Two hosts are in different VLANs on the same switch and can’t communicate. What capability is required?
Answer: Layer 3 inter-VLAN routing, such as SVIs with ip routing or router-on-a-stick.
2. A redundant Layer 2 uplink is connected but not forwarding traffic. Is that always a fault?
Answer: No. STP may be blocking the path by design.
3.
3. A switch link must carry VLANs 10, 20, and 30 between switches.
What port type is appropriate?
Answer: Trunk port.
4.
4. A multilayer switch has an SVI with an IP address, but hosts still can’t route between VLANs.
What major setting may be missing?
Answer: ip routing.
5.
5. An AP is connected to a switch in a controller-based WLAN.
Must the AP port always be a trunk?
Answer: No. In many CAPWAP designs it is an access port in an AP management VLAN.
Final Takeaways
For CCNA 200-301, think of LAN architecture as placing the right function in the right layer. Access connects endpoints, distribution commonly handles routing and policy, and core provides fast transport. VLANs segment broadcast domains, trunks carry multiple VLANs, inter-VLAN routing connects those segments, STP prevents loops, EtherChannel improves resiliency, and wireless still depends on the wired campus design.
If you can explain these relationships clearly and trace traffic from host to host, you are in strong shape for both the exam and real troubleshooting.