This simulator models two access switches joined by a single 802.1Q trunk. A source workstation on the left switch sends an untagged Ethernet frame toward a destination workstation on the right switch, and you control each switch's VLAN assignment, the trunk's allowed-VLAN list, and each side's native VLAN to see exactly when the frame is delivered, blocked, or misdelivered.
• A real-time 3D cutaway of the left and right access switches, the source and destination workstations, the 802.1Q trunk patch link and a tag-inspection overlay station, with home view, focus-selected-part, toggleable full enclosure, exploded view, auto-rotate, expand and label toggle controls, and numbered parts matching the companion diagram. • A left access-VLAN selector and a right access-VLAN selector (VLAN 10 or 20 each). • A trunk-available toggle, plus independent allow-VLAN-10-on-trunk and allow-VLAN-20-on-trunk toggles that model trunk pruning. • A left native-VLAN selector and a right native-VLAN selector (VLAN 1, 10 or 20 each), used to demonstrate a native VLAN mismatch. • Auto-traffic with an adjustable interval (0.5–5 s) and a manual "Send test traffic" action, alongside start/stop trial controls. • Play/pause, single 0.1 s step and 1 s step time controls, plus a playback-speed selector (10x slow motion, real time, 10x, 60x/1 minute-per-second). • Six live metrics: ingress VLAN, destination VLAN, last receiving VLAN, frames offered, frames delivered and frames blocked. • A Curves & measurements tab with two charts (ingress VLAN vs. last receiving VLAN; delivered vs. blocked frames), the full model equations, and snapshot readouts. • An Experiments tab with four guided scenarios (same VLAN, separated endpoints, pruned trunk, native mismatch), a model-verification bench of independent automated checks, and a timestamped event log with a copyable trial report. • A Learn & assess tab with four guided lessons (assign access membership, encode on the trunk, interpret at the far end, protect the boundary), a two-question knowledge-check quiz, and a written scope/reference statement citing Cisco's VLAN trunking documentation.
An untagged frame entering an access port is assigned to that port's configured VLAN — the source workstation itself never sets a VLAN tag. When that frame crosses the trunk, the left switch tags it with an 802.1Q header unless its VLAN happens to match the trunk's native VLAN, in which case it crosses untagged instead. The receiving switch then either reads the tag directly, if one is present, or falls back to its own configured native VLAN for anything arriving untagged.
Even a correctly tagged frame can still be blocked: the trunk's allowed-VLAN list independently prunes traffic, so disabling "Allow VLAN 10 on trunk" drops VLAN 10 frames even when the source and destination access ports both belong to VLAN 10 — exactly what the pruned-trunk experiment demonstrates.
The equations panel states it plainly: a frame is tagged when the source VLAN differs from the left switch's native VLAN; the received VLAN equals the tag's ID when tagged, or the right switch's native VLAN when untagged; and delivery requires the trunk to be up, the VLAN to be allowed, and the received VLAN to match the destination's configured VLAN. The native-mismatch experiment sets the left native VLAN to 10 and the right native VLAN to 20 with both endpoints otherwise matching VLAN 10 and 20 respectively — because the frame leaves untagged (since it matches the left's native VLAN) and the right switch assigns untagged frames to its own native VLAN of 20, the frame is incorrectly delivered into VLAN 20 instead of being blocked, showing why native VLANs must match on both ends of a trunk.
This is a focused single-frame classification model: it does not model MAC learning or routing, uses an untagged native VLAN in this fixture, and inter-VLAN communication in a real network requires an explicitly configured Layer 3 path that this simulator does not include.
An access port always assigns its own configured VLAN to any untagged frame it receives — the sending workstation does not tag its own traffic. On the trunk side, a frame carries an explicit 802.1Q tag if its VLAN differs from that switch's native VLAN; if it matches the native VLAN, it crosses untagged, and the receiving switch then falls back to its own native VLAN setting for any untagged arrival.
The trunk's allowed-VLAN list is checked independently of the access-port VLAN assignments. The pruned-trunk experiment sets both endpoints to VLAN 10 but disables "Allow VLAN 10 on trunk," and the frame is blocked at the trunk even though source and destination otherwise match — delivery requires the trunk to be up, the VLAN to be allowed, and the received VLAN to match the destination.
The native-mismatch experiment configures the left switch's native VLAN as 10 and the right switch's native VLAN as 20. The frame leaves the left switch untagged because it matches the left native VLAN, but the right switch interprets any untagged arrival using its own native VLAN of 20 — so the frame is misdelivered into VLAN 20 instead of reaching the intended VLAN 10 destination or being blocked, which is exactly the isolation failure a native mismatch causes.
This is a focused single-frame classification exercise. It does not model MAC address learning, spanning tree, or Layer 3 inter-VLAN routing, uses an untagged native VLAN as its fixture convention, and every frame, tag and pruning decision is simulated entirely offline rather than on real switching hardware.