Creating a VLAN on a Cisco Catalyst 1300 switch does not automatically make that VLAN active on a port. The VLAN must be created, assigned to the correct interface, and configured with the right tagged or untagged behavior.
This guide explains how to configure VLANs and trunk ports through the C1300 Web UI and CLI. It also covers Access, Trunk, and General mode, PVID, Native VLAN, Voice VLAN, and the most common reasons a tagged VLAN does not pass between a C1300 switch and another switch or firewall.
- How C1300 handles tagged and untagged traffic
- Create VLAN IDs before assigning port membership
- Configure endpoint ports, switch uplinks, and firewall links
- C1300 CLI examples for Access, Trunk, and General mode
- Find the mismatch when VLAN traffic does not pass
- Common Cisco C1300 VLAN and trunk questions
- A practical sequence for configuring and checking VLANs
Start With the Traffic Path
Before changing settings, write down where the traffic is supposed to go. A PC, access point, IP phone, camera, switch uplink, and firewall may all use VLANs differently.
| Link | Typical Port Mode | VLAN Treatment |
|---|---|---|
| PC to C1300 | Access | One untagged VLAN |
| Camera to C1300 | Access | One untagged VLAN |
| C1300 to another switch | Trunk | Multiple tagged VLANs, optionally one Native VLAN |
| C1300 to firewall | Trunk or firewall-specific design | Must match the firewall VLAN interfaces |
| C1300 to wireless AP | Trunk or General | Management and client VLANs according to the AP design |
| IP phone to C1300 | Access with Voice VLAN | Data VLAN and voice VLAN handled separately |
Also decide where Layer 3 routing takes place. VLAN membership separates Layer 2 traffic, but it does not automatically route traffic between different VLANs. Inter-VLAN communication requires routing on the C1300, an upstream router, or a firewall.
This guide can be used when configuring C1300 models such as C1300-24P-4G, C1300-24P-4X, C1300-16P-2G, and C1300-8P-E-2G. The exact port numbering and available features should be checked on the installed model.
Send the model, port, VLAN IDs, and connected device for review.
Access, Trunk, and General Mode Explained
The C1300 Web UI provides several interface VLAN modes. Selecting the wrong mode is one of the fastest ways to create a configuration that looks correct but does not pass the expected traffic.
Access Mode
An Access port is an untagged member of one VLAN. It is normally used for devices that send and receive ordinary Ethernet frames without VLAN tags.
Typical examples include desktop computers, printers, cameras, basic IoT devices, and other endpoints that do not understand 802.1Q tagging.
Trunk Mode
A Trunk port can be an untagged member of one VLAN and a tagged member of additional VLANs. It is commonly used between switches, between a switch and a firewall, or between a switch and a VLAN-aware wireless access point.
A trunk does not necessarily carry every VLAN that exists on the switch. The allowed VLAN list controls which VLANs can use the trunk.
General Mode
General mode allows a port to have one or more tagged and untagged VLAN memberships. It is useful for flexible 802.1Q configurations, but it also creates more opportunities for inconsistent settings.
For a conventional switch-to-switch uplink, Trunk mode is usually easier to document and troubleshoot. Use General mode when the design specifically requires separate tagged and untagged membership behavior.
Cisco’s C1300 documentation defines Access, Trunk, and General mode separately. These definitions should be used instead of assuming that every Cisco switch series uses exactly the same interface behavior.
Create a VLAN in the C1300 Web UI
The C1300 Web UI provides a dedicated VLAN management area. Start by creating the VLAN IDs that will be used by the network.
VLAN Settings
Open VLAN Management > VLAN Settings.
- Click Add.
- Select the option to create a VLAN.
- Enter the VLAN ID.
- Add an optional VLAN name.
- Enable VLAN Interface State if required.
- Click Apply.
| Example VLAN | Example Purpose |
|---|---|
| 10 | User data |
| 20 | Voice |
| 30 | Guest wireless |
| 99 | Network management |
These VLAN IDs are examples only. Use the IDs defined by the network plan.
Creating VLAN 10, VLAN 20, and VLAN 30 does not automatically assign them to ports. The next step is to configure the interface mode and VLAN membership.
If the C1300 will perform inter-VLAN routing, the required VLAN interfaces and IPv4 routing settings must also be configured. If routing is performed by a firewall, the firewall interfaces and policies must match the VLAN design.
Configure Access and Trunk Ports in the Web UI
Configure an Access Port
Use an Access port for a device that should belong to one untagged VLAN.
Open VLAN Management > Interface Settings, select Port, choose the required interface, and click Edit.
- Set Switchport Mode to Layer 2.
- Set Interface VLAN Mode to Access.
- Apply the configuration.
- Open VLAN Management > Port to VLAN or Port VLAN Membership.
- Assign the required VLAN as the Access VLAN.
- Confirm that the port is an Untagged member.
For a PC connected to port `gi1/0/10` in VLAN 10, the intended result is an Access port, VLAN 10 as the Access VLAN, and untagged membership for VLAN 10.
Configure a Trunk Port
Use a Trunk port when one link must carry multiple VLANs.
In VLAN Management > Interface Settings, select the uplink port or LAG, set Switchport Mode to Layer 2, and set Interface VLAN Mode to Trunk.
Then open the port membership page and configure:
- Native VLAN
- Tagged VLANs
- Allowed VLAN list
- Any required untagged membership
For a trunk carrying VLANs 10, 20, and 30, the design might use VLAN 99 as the Native VLAN and transmit VLANs 10, 20, and 30 as tagged traffic. The exact Native VLAN depends on the device at the other end of the link.
Do not choose a Native VLAN independently on one side of the link. If the switch and firewall or the two switches use different Native VLANs, untagged traffic may be classified incorrectly.
Use the VLAN Configuration Wizard
The C1300 also includes a VLAN Configuration Wizard under Configuration Wizards > VLAN Configuration Wizard.
The wizard can help configure trunk ports, a new or existing VLAN, untagged trunk membership, tagged trunk membership, and Access-port membership.
Review the resulting port membership after completing the wizard. A configuration can be valid on the C1300 and still fail to match the VLAN behavior required by a firewall, AP, or second switch.
Configure VLANs and Trunks With the CLI
The Cisco Catalyst 1300 has its own CLI guide. The commands resemble Cisco switching commands, but they should not be copied blindly from Catalyst 9200 or Catalyst 9300 IOS XE documentation.
Create VLANs
vlan database
vlan 10
vlan 20
vlan 30
exit
You can also assign a name while creating a VLAN:
vlan database
vlan 10 name Users
vlan 20 name Voice
vlan 30 name Guest
exit
Configure an Access Port
The following example assigns port `gi1/0/10` to VLAN 10:
interface gi1/0/10
switchport mode access
switchport access vlan 10
exit
The intended result is a Layer 2 Access port with VLAN 10 as its untagged access VLAN.
Configure a Trunk Port
The following example configures port `gi1/0/24` as a trunk carrying VLANs 10, 20, and 30:
interface gi1/0/24
switchport mode trunk
switchport trunk allowed vlan add 10,20,30
switchport trunk native vlan 99
exit
Use the Native VLAN only when it is part of the link design. The connected switch, firewall, or AP must use matching VLAN behavior.
Configure a General Port
General mode is useful when the design needs explicit tagged and untagged memberships:
interface gi1/0/4
switchport mode general
switchport general allowed vlan add 10-20 tagged
switchport general allowed vlan add 99 untagged
switchport general pvid 99
exit
In this example, VLANs 10 through 20 leave the port tagged, VLAN 99 leaves the port untagged, and untagged ingress traffic is associated with PVID 99.
Use the current Cisco Catalyst 1300 CLI VLAN command reference when checking syntax for the installed software release.
PVID, Tagged VLANs, and Troubleshooting
PVID and Native VLAN
PVID is a per-port setting used to classify untagged incoming traffic. If an untagged frame arrives on a port with PVID 99, the switch associates that frame with VLAN 99.
PVID does not automatically make the VLAN tagged on egress. On a Trunk port, the Native VLAN identifies the VLAN used for untagged traffic. The Native VLAN and PVID should match the intended design on the connected device.
Tagged and Untagged Membership
A Tagged VLAN leaves the port with an 802.1Q VLAN tag. This is normally used for traffic crossing a trunk between VLAN-aware devices.
An Untagged VLAN leaves the port without a VLAN tag. This is normally used toward an endpoint that does not understand VLAN tagging or for the Native VLAN of a trunk.
When a VLAN Exists but Does Not Work
When a VLAN has been created but devices cannot communicate, check the configuration in this order:
- Confirm that the VLAN exists on the relevant device.
- Confirm that the port is a member of the VLAN.
- Check whether the port is Access, Trunk, or General mode.
- Verify Tagged and Untagged membership.
- Check the allowed VLAN list on the trunk.
- Compare the Native VLAN and PVID on both ends.
- Check DHCP, gateways, routing, and firewall policies separately.
In the CLI, use the following commands to review VLAN and switchport information:
show vlan
show interfaces switchport
show interfaces switchport gi1/0/24
The `show interfaces switchport` command can display the administrative and operational status of the interface, including Access VLAN, Native VLAN, General PVID, VLAN membership, and ingress-filtering information.
Switch-to-Switch VLAN Problems
Check whether both ports are configured as trunks, whether the VLAN exists on both switches, and whether the VLAN is included in the allowed list.
A trunk can be physically up while a specific VLAN is still excluded, forbidden, or assigned with the wrong tagging behavior.
Firewall VLAN Problems
For a firewall connection, compare the C1300 trunk with the firewall VLAN subinterfaces. Verify the VLAN IDs, tagging, Native VLAN, gateways, and firewall policies.
If the firewall expects VLAN 10, VLAN 20, and VLAN 30 as tagged subinterfaces, configuring the physical C1300 port as a single untagged Access VLAN will not produce the intended result.
AP and Voice VLAN Problems
An AP may have link connectivity but still fail to provide client access if its management VLAN, client VLANs, Native VLAN, or allowed VLAN list is wrong.
For an IP phone with a PC connected behind it, check the Data VLAN, Voice VLAN, phone discovery method, LLDP-MED settings, and the untagged treatment of the PC traffic.
The C1300 Administration Guide includes Voice VLAN, Auto Voice VLAN, Telephony OUI, and LLDP-MED-related settings. Start with the basic data and voice VLAN design before enabling automatic discovery features.
For the official Web UI paths, review the Cisco Catalyst 1300 VLAN Management Guide.
Frequently Asked Questions
Final Takeaway
Most C1300 VLAN problems are not caused by the VLAN ID itself. They come from a mismatch between the two ends of the link: one side tags the traffic while the other expects it untagged, the VLAN is missing from the allowed list, or the PVID and Native VLAN do not match.
Start with the traffic path, define the intended behavior for every link, and then verify the configuration in this order: VLAN exists, port membership is correct, port mode matches the connected device, tagged and untagged treatment is consistent, allowed VLANs are present, and routing or firewall policy is configured separately.
If the issue remains, send the C1300 model, affected port, VLAN IDs, current port mode, and connected device model for a configuration review.













































































































































