OSNTC.023: Inter-VLAN Routing — Router-on-a-Stick, Layer 3 Switches, SVIs, Default Gateways, and Verification

Realistic color-pencil illustration of Ethernet switch ports and connected network cables for an 802.1Q VLAN trunking lesson.

VLANs separate Layer 2 broadcast domains, which improves organization and control but also prevents devices in different VLANs from communicating directly at Layer 2. When VLAN 10 must communicate with VLAN 20, a Layer 3 device must route packets between the two IP networks. This process is called inter-VLAN routing. This lesson follows OSNTC.022: VLAN Trunking and 802.1Q and builds on OSNTC.004: VLAN Basics, OSNTC.013: Router Basics, and OSNTC.021: Troubleshooting Switch Ports.

ELEMENTARY OVERVIEW

A host in VLAN 10 can communicate directly with another host in VLAN 10 because both devices share the same Layer 2 broadcast domain. A host in VLAN 10 cannot directly deliver an Ethernet frame to a host in VLAN 20 as though both were in the same LAN. Instead, the source host sends the packet to its default gateway. The gateway routes the packet from the VLAN 10 IP network into the VLAN 20 IP network and then forwards it toward the destination.

Inter-VLAN routing can be implemented in several ways. A traditional router can use separate physical interfaces for separate VLANs. A router-on-a-stick design uses one physical router interface divided into logical subinterfaces, with an 802.1Q trunk carrying multiple VLANs to the router. A Layer 3 switch can create switch virtual interfaces (SVIs) and route between VLANs internally at switching hardware speeds.

Close-up realistic photograph of Ethernet switch ports and connected network cables for VLAN trunking and inter-VLAN routing instruction.

LEARNING OBJECTIVES

  • Explain why VLANs require Layer 3 routing to communicate with one another.
  • Describe the role of a default gateway in a VLAN.
  • Explain router-on-a-stick and 802.1Q router subinterfaces.
  • Explain how a Layer 3 switch uses SVIs for inter-VLAN routing.
  • Distinguish an SVI from a physical access or trunk port.
  • Verify routing, trunking, gateway addressing, and VLAN state.
  • Troubleshoot common inter-VLAN routing failures systematically.

WHY A DEFAULT GATEWAY IS REQUIRED

Every IP host determines whether a destination is local or remote by comparing the destination address with its own address and subnet mask or prefix length. If the destination is local, the host resolves the destination’s Layer 2 address and sends directly. If the destination is remote, the host sends the packet to its configured default gateway. The gateway must have a Layer 3 interface in the source VLAN and a route toward the destination network.

For example, VLAN 10 might use network 192.168.10.0/24 with gateway 192.168.10.1, while VLAN 20 uses 192.168.20.0/24 with gateway 192.168.20.1. A host at 192.168.10.50 sends traffic for 192.168.20.50 to 192.168.10.1. The routing device removes the incoming Layer 2 frame, examines the IP packet, selects the connected VLAN 20 route, builds a new Layer 2 frame for VLAN 20, and forwards the packet toward the destination.

ROUTER-ON-A-STICK

Router-on-a-stick uses one physical Ethernet connection between a switch and a router. The switch-facing port is an 802.1Q trunk. On the router, logical subinterfaces divide the physical interface into separate Layer 3 interfaces. Each subinterface is associated with a VLAN tag and receives an IP address that normally becomes the default gateway for that VLAN.

A common Cisco IOS-style example uses a physical interface such as GigabitEthernet0/0 and creates subinterfaces such as GigabitEthernet0/0.10 and GigabitEthernet0/0.20. Each subinterface is configured with 802.1Q encapsulation for its VLAN and with the appropriate gateway IP address. Exact command syntax varies by router platform and software release, so production configuration should be checked against the platform documentation.

Router-on-a-stick is easy to understand and useful in smaller environments, labs, and branch networks. Its main limitation is that all routed VLAN traffic shares one physical router link, so bandwidth and redundancy requirements can eventually favor a Layer 3 switching design.

This router-on-a-stick demonstration explains inter-VLAN routing over an 802.1Q trunk and shows how multiple VLANs reach a router through one physical connection.

LAYER 3 SWITCHING AND SVIS

A multilayer or Layer 3 switch can perform routing in addition to Ethernet switching. Instead of sending every inter-VLAN packet to an external router, the switch can create a switch virtual interface for each VLAN that requires Layer 3 connectivity. Cisco describes an SVI as a VLAN of switch ports represented as one interface to the routing function.

For example, an SVI named interface Vlan10 might use IP address 192.168.10.1/24, and interface Vlan20 might use 192.168.20.1/24. Hosts in VLAN 10 use the VLAN 10 SVI as their gateway; hosts in VLAN 20 use the VLAN 20 SVI. When Layer 3 routing is enabled on the switch, it can route between those connected networks directly.

An SVI is not a physical port. It is a logical Layer 3 interface associated with a VLAN. Physical access ports place endpoints into the VLAN, trunk ports transport the VLAN between devices, and the SVI provides the Layer 3 gateway for that VLAN. All three concepts work together.

ROUTER-ON-A-STICK VS. LAYER 3 SWITCH

  • Router-on-a-stick: one router physical interface, multiple tagged subinterfaces, switch-to-router trunk, simple and common in labs or smaller networks.
  • Layer 3 switch: VLAN gateways live on SVIs inside the switch, routing occurs locally, and inter-VLAN forwarding can scale efficiently.
  • Separate router interfaces: one physical router interface per VLAN, simple conceptually but inefficient when many VLANs are required.

COMMON CISCO IOS-STYLE VERIFICATION

Begin with read-only verification. On the switch, show vlan brief confirms that the expected VLANs exist. show interfaces trunk confirms that the router or upstream switch link is trunking and carrying the required VLANs. show ip interface brief displays routed interfaces and SVI status. show ip route confirms that the routing table contains connected VLAN networks and any required upstream routes.

On a router-on-a-stick design, verify that the physical interface is up, the expected subinterfaces exist, each subinterface has the correct VLAN encapsulation and gateway address, and the connected switch trunk allows those VLANs. On a Layer 3 switch, verify that the SVI is configured, the VLAN exists, at least one required Layer 2 path for the VLAN is active where the platform requires it, and Layer 3 routing is enabled.

COMMON FAILURE PATTERNS

  • Host can reach same-VLAN peers but not another VLAN: verify the host’s default gateway, gateway interface state, and routing table.
  • One VLAN cannot reach the router: verify that the VLAN is allowed on the trunk and that the router subinterface uses the correct 802.1Q VLAN ID.
  • SVI is down: verify the VLAN exists and that the switch has an active Layer 2 port or trunk carrying that VLAN according to platform behavior.
  • Correct gateway but no remote connectivity: verify the routing device has a route toward the destination and that return routing exists.
  • Some VLANs work and one does not: compare that VLAN’s addressing, allowed-trunk list, gateway interface, and spanning-tree state with the working VLANs.
  • Wrong subnet mask or prefix: the host may incorrectly classify a remote destination as local or vice versa.

PACKET WALK: VLAN 10 TO VLAN 20

  1. Host A in VLAN 10 determines that Host B’s VLAN 20 IP address is remote.
  2. Host A sends the packet to the MAC address of its VLAN 10 default gateway.
  3. The switch forwards the frame toward the routing device while preserving VLAN 10 membership.
  4. The router or Layer 3 switch removes the incoming Ethernet header and examines the IP destination.
  5. The routing table selects the connected VLAN 20 network.
  6. The routing device resolves the Layer 2 destination in VLAN 20 if necessary.
  7. A new Ethernet frame is created for VLAN 20.
  8. The switch forwards the frame through VLAN 20 toward Host B.
  9. The return packet follows the same Layer 3 principle in the opposite direction.

PRACTICAL LAB

Build a lab with VLAN 10 and VLAN 20. Assign one host to each VLAN and give each VLAN a different IPv4 subnet. First confirm that the two hosts cannot communicate without Layer 3 routing. Then configure either router-on-a-stick or Layer 3 switch SVIs. Set each host’s default gateway to the corresponding router subinterface or SVI. Verify same-VLAN connectivity, gateway reachability, and finally inter-VLAN reachability.

After successful routing, intentionally remove VLAN 20 from the trunk or change one host’s default gateway to an incorrect address. Record the failure symptoms, then restore the correct configuration and compare the verification output. Perform changes only in a lab or approved maintenance environment.

TECHNICIAN TROUBLESHOOTING WORKFLOW

  1. Confirm the source host’s IP address, subnet mask or prefix, and default gateway.
  2. Confirm the destination host’s IP address, subnet mask or prefix, and default gateway.
  3. Verify that both VLANs exist.
  4. Verify access-port VLAN assignments.
  5. Verify trunk status and allowed VLANs.
  6. Verify router subinterfaces or Layer 3 switch SVIs.
  7. Verify gateway interface state.
  8. Verify connected routes and any required static or dynamic routes.
  9. Use ping in stages: local host to gateway, gateway to destination VLAN, then end to end.
  10. Check ARP or neighbor information where appropriate.
  11. Make the smallest approved correction.
  12. Re-run verification and document the final working state.

KNOWLEDGE CHECK

1. Why can two different VLANs not communicate directly at Layer 2? 2. What role does the default gateway play? 3. What is router-on-a-stick? 4. What is an SVI? 5. Why must the switch trunk carry the VLAN used by a router subinterface? 6. Which command commonly displays the routing table on Cisco IOS-style devices?

ANSWER GUIDE

1. Each VLAN is a separate Layer 2 broadcast domain, so communication between them requires Layer 3 routing. 2. It receives packets destined for remote IP networks and routes them onward. 3. It is a design where one physical router link carries multiple VLANs using 802.1Q-tagged subinterfaces. 4. It is a logical Layer 3 interface representing a VLAN on a multilayer switch. 5. Without that VLAN on the trunk, tagged traffic for the subinterface cannot reach the router. 6. show ip route.

CONCLUSION

VLANs intentionally separate Layer 2 traffic, so communication between VLANs requires a Layer 3 gateway. Router-on-a-stick provides that gateway with tagged subinterfaces over one trunk, while Layer 3 switches provide gateways through SVIs and route internally. The technician’s job is to verify addressing, VLAN membership, trunking, gateway interfaces, and routing in a disciplined order. When those layers are checked one by one, inter-VLAN routing failures become much easier to isolate.

REFERENCES AND PRIOR LESSONS

Primary technical references: Cisco — Configure Inter VLAN Routing with an External Router and Cisco — Configure Inter-VLAN Routing with Catalyst Switches. Continue reviewing VLAN Trunking and 802.1Q, VLAN Basics, Router Basics, and Troubleshooting Switch Ports.

Leave a Reply