VLAN Configuration
CCNA 200-301 v2.0 · Live Feb 3, 2027 (v1.1 valid through Feb 2, 2027) Cisco Packet Tracer
مقصدObjectiveObjective
اس لیب میں آپ VLAN بنانا اور پورٹس کو VLANs میں اسائن کرنا سیکھیں گے۔ دو الگ ڈیپارٹمنٹس (Sales اور Accounts) کو ایک ہی سوئچ پر الگ کریں گے۔Is lab mein aap VLAN banana aur ports ko VLANs mein assign karna seekhenge. Do alag departments (Sales aur Accounts) ko ek hi switch par alag karenge.In this lab, you'll learn to create VLANs and assign ports to VLANs. You'll separate two departments (Sales and Accounts) on a single switch.
آسان مثالSimple AnalogySimple Analogy
آپ کے آفس میں ایک ہی سوئچ ہے، لیکن آپ چاہتے ہیں کہ اکاؤنٹس والے اور سیلز والے آپس میں بات نہ کر سکیں — جیسے ایک ہی بلڈنگ میں دو الگ آفسز ہوں جن کے درمیان دیوار ہو۔ VLAN یہی کام کرتا ہے: ایک فزیکل سوئچ کو کاٹ کر الگ الگ ورچوئل سوئچز بنا دیتا ہے۔ ہر VLAN اپنی الگ دنیا ہے۔Aapke office mein ek hi switch hai, lekin aap chahte hain ke accounts wale aur sales wale aapas mein baat na kar saken — jaise ek hi building mein do alag offices hon jinke darmiyan deewar ho. VLAN yahi kaam karta hai: ek physical switch ko kaat kar alag alag virtual switches bana deta hai. Har VLAN apni alag duniya hai.Your office has one switch, but you want the accounts team and the sales team to be unable to talk to each other — like two separate offices in one building with a wall between them. That's what a VLAN does: it slices one physical switch into separate virtual switches. Each VLAN is its own world.
سیٹ اپLab SetupLab Setup
SW1 سوئچ کے Fa0/2 اور Fa0/3 پر PC1-PC2 (VLAN 10)، Fa0/4 اور Fa0/5 پر PC3-PC4 (VLAN 20) کنیکٹڈ ہیں۔ ڈیوائسز: 1x سوئچ 2960 (SW1)، 4x پی سی (PC1-PC4)۔ PC1/PC2: 192.168.10.10 اور .11، ماسک 255.255.255.0۔ PC3/PC4: 192.168.20.10 اور .11، ماسک 255.255.255.0۔ گیٹ وے کی ضرورت نہیں (کوئی روٹنگ نہیں)۔SW1 switch ke Fa0/2 aur Fa0/3 par PC1-PC2 (VLAN 10), Fa0/4 aur Fa0/5 par PC3-PC4 (VLAN 20) connected hain. Devices: 1x Switch 2960 (SW1), 4x PC (PC1-PC4) PC1/PC2: 192.168.10.10 aur .11, mask 255.255.255.0. PC3/PC4: 192.168.20.10 aur .11, mask 255.255.255.0. Gateway ki zaroorat nahi (koi routing nahi).SW1's Fa0/2 and Fa0/3 connect PC1-PC2 (VLAN 10); Fa0/4 and Fa0/5 connect PC3-PC4 (VLAN 20). Devices: 1x Switch 2960 (SW1), 4x PCs (PC1-PC4). PC1/PC2: 192.168.10.10 and .11, mask 255.255.255.0. PC3/PC4: 192.168.20.10 and .11, mask 255.255.255.0. No gateway needed (no routing).
اقداماتStepsSteps
Step 1
سوئچ SW1 پر VLANs بناؤ۔ پہلے دو VLANs بناتے ہیں: 10 (Sales) اور 20 (Accounts)۔Switch SW1 par VLANs banao. Pehle do VLANs banate hain: 10 (Sales) aur 20 (Accounts).Create VLANs on switch SW1. First create two VLANs: 10 (Sales) and 20 (Accounts).
enable configure terminal vlan 10 name SALES vlan 20 name ACCOUNTS exit
Step 2
نام دینا لازمی نہیں لیکن best practice ہے — بعد میں سمجھنا آسان ہوتا ہےNaam dena lazmi nahi lekin best practice hai — baad mein samajhna aasaan hota haiNaming isn't required but is best practice — it makes things easier to understand later.
Step 3
پورٹس کو VLANs میں ڈالو: Fa0/2-3 Sales (VLAN 10) میں۔ Access پورٹ وہ ہے جہاں اینڈ ڈیوائس (PC) لگتا ہےPorts ko VLANs mein daalo: Fa0/2-3 Sales (VLAN 10) mein. Access port woh hai jahan end device (PC) lagta haiAssign the ports to VLANs: Fa0/2-3 into Sales (VLAN 10). An access port is where an end device (PC) connects.
interface range fa0/2 - 3 switchport mode access switchport access vlan 10 exit
Step 4
اب Fa0/4-5 Accounts (VLAN 20) میںAb Fa0/4-5 Accounts (VLAN 20) meinNow Fa0/4-5 into Accounts (VLAN 20).
interface range fa0/4 - 5 switchport mode access switchport access vlan 20 exit
Step 5
ٹیسٹنگ: PC1 سے ping 192.168.10.11 — جواب آنا چاہیے (same VLAN)۔Testing: PC1 se ping 192.168.10.11 — jawab aana chahiye (same VLAN).Testing: from PC1, ping 192.168.10.11 — you should get a reply (same VLAN).
Step 6
PC1 سے ping 192.168.20.10 — جواب نہیں آنا چاہیے (الگ VLAN)۔ یہی VLAN کا کمال ہے۔PC1 se ping 192.168.20.10 — jawab NAHI aana chahiye (alag VLAN). Yehi VLAN ka kamal hai.From PC1, ping 192.168.20.10 — you should NOT get a reply (different VLAN). That's the magic of VLANs.
تصدیقVerifyVerify
show vlan brief سے VLANs اور ان کے پورٹس دیکھو۔ show interfaces status سے پورٹس کا حال کنفرم کرو۔show vlan brief se VLANs aur unke ports dekho. show interfaces status se ports ka haal confirm karo.Check VLANs and their ports with show vlan brief. Confirm port status with show interfaces status.
show vlan brief show interfaces status
خرابی دور کرناTroubleshootingTroubleshooting
⚠️ Same VLAN کے PCs آپس میں پنگ نہیں کر پا رہے۔Same VLAN ke PCs aapas mein ping nahi kar pa rahe.PCs in the same VLAN can't ping each other.
✅ show vlan brief سے دیکھو کہ پورٹ صحیح VLAN میں ہے۔ غلط ہو تو دوبارہ switchport access vlan کمانڈ لگاؤ۔show vlan brief se dekho ke port sahi VLAN mein hai. Ghalat ho to dobara switchport access vlan command lagao.Use show vlan brief to check the port is in the right VLAN. If it's wrong, re-apply the switchport access vlan command.
⚠️ PC1 PC3 کو پنگ کر پا رہا ہے جبکہ نہیں کرنا چاہیے۔PC1 PC3 ko ping kar pa raha hai jabke nahi karna chahiye.PC1 can ping PC3 when it shouldn't be able to.
✅ پورٹس کا موڈ 'access' ہونا چاہیے، 'trunk' نہیں۔ show interfaces fa0/2 switchport سے چیک کرو۔Ports ka mode 'access' hona chahiye, 'trunk' nahi. show interfaces fa0/2 switchport se check karo.The port mode should be 'access', not 'trunk'. Check with show interfaces fa0/2 switchport.
⚠️ VLAN show vlan brief میں نظر نہیں آ رہا۔VLAN show vlan brief mein nazar nahi aa raha.The VLAN doesn't show in show vlan brief.
✅ VLAN create کرنے کے بعد exit ضرور کرو تاکہ VLAN ڈیٹابیس میں save ہو۔ show vlan brief سے تصدیق کرو۔VLAN create karne ke baad exit zaroor karo taake VLAN database mein save ho. show vlan brief se tasdeeq karo.After creating the VLAN, be sure to type exit so it's saved in the VLAN database. Confirm with show vlan brief.
انٹرویو سوالاتInterview Q&AInterview Q&A
❓ VLAN 1 کیا ہے؟VLAN 1 kya hai?What is VLAN 1?
VLAN 1 ڈیفالٹ VLAN ہے — ہر پورٹ شروع میں اسی میں ہوتا ہے۔ سیکیورٹی کے لیے اسے استعمال نہ کرنا بہتر ہے۔VLAN 1 default VLAN hai — har port shuru mein isi mein hota hai. Security ke liye ise istemal na karna behtar hai.VLAN 1 is the default VLAN — every port starts in it. It's better not to use it, for security.
❓ VLAN کے فائدے بتاؤ۔VLAN ke faide batao.What are the benefits of VLANs?
VLAN براڈکاسٹ ڈومین کو چھوٹا کرتا ہے، سیکیورٹی بڑھاتا ہے اور نیٹ ورک کو حصوں میں بانٹ کر مینیج کرنا آسان کرتا ہے۔VLAN broadcast domain ko chhota karta hai, security barhata hai aur network ko hisson mein baant kar manage karna aasaan karta hai.VLANs shrink the broadcast domain, increase security, and make the network easier to manage by dividing it into parts.