Memory hook: Configure the path, then inspect the operational result.
Must remember
Know IOS navigation: user EXEC, privileged EXEC, global configuration and interface configuration. show running-config describes active configuration; show startup-config the saved boot configuration. Save deliberate changes with the appropriate copy operation; a successful command is not proof of the intended forwarding state.
Useful verification commands include show vlan brief, show interfaces trunk, show interfaces switchport, show mac address-table, show etherchannel summary, show spanning-tree and show cdp neighbors detail/show lldp neighbors detail.
An access interface uses the intended VLAN; a trunk must have compatible tagging/native VLAN and allowed VLANs. Voice VLAN behavior supports a phone plus data endpoint. Router subinterfaces or SVIs provide inter-VLAN routing, with forwarding enabled and interfaces operational.
LACP active initiates negotiation; passive responds. Passive/passive does not negotiate a bundle. Member configuration must match. Inspect the logical port-channel and member status; cables being connected is not enough.
STP chooses the lowest bridge ID as root, combining priority and identifying information. Nonroot switches choose root paths based on cost and tie-breakers; designated ports forward for segments and redundant alternatives block/discard as appropriate. Know Rapid PVST+ roles/states, PortFast/edge behavior, BPDU Guard, root guard, loop guard and BPDU filtering conceptually. BPDU Guard protects suitable edge ports from unexpected bridge participation; do not enable edge shortcuts indiscriminately.
Wireless controller designs separate AP and controller roles; control/data paths vary by deployment mode. Trace AP, switch, controller, WLAN, VLAN and authentication settings. GUI success must still be verified through a real client association and correct policy.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Bundle two links with negotiation | Compatible port-channel members and LACP active on at least one side. |
| Unexpected switch on an endpoint port | Appropriate BPDU Guard on a correctly designated edge port. |
| VLAN configured but not reaching gateway | Inspect trunk allowance, SVI/subinterface and operational state. |
Traps
- A configured trunk may not be operationally carrying the intended VLAN.
- PortFast does not replace spanning tree or make loops safe.
Active recall
1. Why does LACP passive/passive fail?
Neither side initiates negotiation.
2. What elects the STP root?
The lowest bridge ID.
3. What verifies an EtherChannel bundle?
show etherchannel summary plus member and port-channel details.
4. Running versus startup configuration?
Current active settings versus saved settings used at boot.
5. What does BPDU Guard protect against on an edge port?
Unexpected bridge protocol participation that could introduce topology risk.