Exploring the Default Behaviour of Interconnected IOS Switches
In this lab, we will examine the default behavior of interconnected Cisco IOS switches. Two switches, Switch A and Switch B, will be connected to two test hosts, H1 and H2.
The goal is to determine whether H1 and H2 can communicate without any manual configuration on the switches. We will use ping tests, packet captures, and protocol analysis to understand how the switches handle traffic by default.
This lab also demonstrates the role of VLANs, trunking, ARP, DTP, Spanning Tree Protocol (STP), and Cisco Discovery Protocol (CDP) in switch-to-switch communication.
Lab Task
Step 1: Connect the SwitchesConnect Switch A and Switch B using an Ethernet link. This link will provide connectivity between the two switches.
Step 2: Connect the PCs: Connect hosts H1 and H2 to the appropriate switch interfaces. These hosts will be used to test communication across the interconnected switches.
Step 3: Configure the Hosts: Configure the interfaces on H1 and H2 with IP addresses from the same subnet. This allows the hosts to communicate at Layer 3.
Step 4: Leave the Switches Unconfigured: Do not apply any manual configuration to the switches. The objective is to observe their default behavior when they are connected.
Step 5: Test Connectivity: From H1, ping H2 and check whether the two hosts can communicate successfully.
Step 6: Analyze the Results: If the ping succeeds, examine the packet captures to determine how the switches forwarded the traffic. Analyze the relevant protocols, VLAN information, MAC addresses, and encapsulation.
By following these steps, we can explore the default behavior of interconnected IOS switches and understand the communication between the switches and PCs. Whether it’s for upskilling your knowledge or troubleshooting network issues, this task is a great starting point for anyone looking to learn more about IOS switches.

Analysis of the Cisco IOS Switch Lab
1. Successful Communication: H1 and H2 were able to ping each other successfully. This indicates that traffic was forwarded between the two switches and that both hosts were able to exchange packets.
2. Trunking and ISL Encapsulation:The packet capture on the source-side exit interface showed that the link was operating as a trunk and that ISL encapsulation was being used.
Technical wording note: Avoid saying that DTP “chose ISL” unless your specific platform/documentation establishes that behavior. DTP negotiates trunking; encapsulation is a separate configuration/negotiation aspect.
3. Destination-Side Trunk Mode: The destination-side interface showed similar behavior. The interface was operating in trunk mode and the packet capture showed ISL encapsulation.
4. ARP Broadcast: Because the switches were forwarding the relevant VLAN traffic, the ARP broadcast was able to travel from the source host through the switches to the destination host. The destination host then responded with its MAC address.
5. Native VLAN and 802.1Q: The packet capture showed VLAN ID 1, which corresponds to the default/native VLAN in this scenario.
6. Spanning Tree Protocol: Spanning Tree Protocol (STP) messages were observed at approximately two-second intervals. STP helps prevent Layer 2 switching loops.
7. Cisco Discovery Protocol: Cisco Discovery Protocol (CDP) messages were observed at approximately 60-second intervals. CDP allows Cisco devices to discover information about directly connected Cisco neighbors.
8. STP Multicast MAC Address: The Spanning Tree multicast MAC address observed in the capture was: 01:80:C2:00:00:00
9. CDP Multicast MAC Address: The CDP multicast MAC address observed in the capture was: 01:00:0C:CC:CC:CC
10. DTP Multicast MAC Address: The DTP multicast MAC address observed in the capture was also: 01:00:0C:CC:CC:CC
Packet Capture and CLI Outputs
Testing Connectivity Between H1 and H2
The first step is to test communication between H1 and H2 using ping. A successful ping indicates that the hosts can communicate through the interconnected switches.

ARP Broadcast Request Between Hosts
Before sending traffic to the destination, H1 uses ARP to determine the MAC address associated with H2’s IP address. The ARP request is broadcast within the local Layer 2 network.

ARP Response Containing the Destination MAC Address
H2 responds to the ARP request with its MAC address. The response allows H1 to build its ARP table and send subsequent packets to the correct destination MAC address.

The system acts as a single broadcast domain, the ARP broadcast message has reached the destination target and the target responded with its MAC address.
Identifying the Destination MAC Address

Default Switchport Configuration on the Source-Side Host Port

Default Switchport Configuration on the Source Switch Exit Interface

Packet Capture from the Source Switch Exit Interface

Conclusion
This lab demonstrated the default behavior of interconnected Cisco IOS switches and showed how two hosts can communicate through the switches without manual switch configuration.
The successful ping between H1 and H2 confirmed that Layer 2 connectivity was established. Packet captures also provided useful evidence of ARP broadcasts, MAC address learning, VLAN information, trunking, and control protocols such as STP, CDP, and DTP.
The lab provides a practical understanding of how Cisco switches handle traffic by default. Analyzing packet captures alongside switch behavior is especially useful for learning network troubleshooting and identifying the protocols responsible for successful communication.
Overall, this exercise provides a strong foundation for understanding Cisco switch configuration, VLANs, trunking, ARP, and Layer 2 network connectivity.
Related Topic: Learn how network ping works and how ICMP is used to test connectivity.