Edge Port Configuration: PCs, Phones, APs and Servers
CCNA 2.2 edge ports on Catalyst IOS XE: access and voice VLANs, PortFast, BPDU Guard, PoE, AP trunks, LACP to servers, and the show commands that prove it.
- Every edge port gets a template based on what plugs into it: a PC, a phone, an AP, a hypervisor or an appliance. Pick the template first, then type.
- Single hosts get an access port with PortFast and BPDU Guard. Phones add a voice VLAN. Hosts that need several VLANs (FlexConnect APs, hypervisors) get a trunk with PortFast trunk.
- PortFast is only for ports facing end hosts. Never put it on a port that leads to another switch.
Mental model
An edge port is any switch port that faces something that is not a switch. CCNA objective 2.2 asks you to configure these ports for each kind of device, and that comes down to three questions:
- How many VLANs does the device need? One VLAN means an access port. Several VLANs means a trunk (or an access port plus a voice VLAN, for phones).
- Does it need power? Phones, APs and many IoT gadgets draw Power over Ethernet from the switch.
- Could it ever send BPDUs? End hosts should not. That is why edge ports get PortFast (skip the STP wait) and BPDU Guard (shut the port if a BPDU shows up anyway).
Answer those and the config writes itself. Examples are Catalyst 9300 on IOS XE 17.x unless noted.
One port, one job
| Device | Port mode | VLANs | STP settings | PoE | Extras |
|---|---|---|---|---|---|
| Desktop, printer, IoT | Access | One data VLAN | portfast, bpduguard enable | IoT often yes | switchport nonegotiate |
| IP phone (with PC behind it) | Access | Data VLAN plus voice VLAN | portfast, bpduguard enable | Yes | CDP or LLDP-MED tells the phone its VLAN |
| Local mode AP (controller based) | Access | AP management VLAN | portfast, bpduguard enable | Yes | Client traffic rides CAPWAP to the WLC |
| FlexConnect or standalone AP | Trunk | Native VLAN for AP management, tagged client VLANs | portfast trunk | Yes | Allowed VLAN list |
| Hypervisor host | Trunk, often a port channel | Server and VM VLANs | portfast trunk | No | LACP only if the host side runs it too |
| Firewall or load balancer | Access or trunk | Depends on design | Depends on design | No | Match the appliance’s interface config |
Desktops, printers and IoT
This is the default template, and it is the one you will type a thousand times:
SW1(config)# interface GigabitEthernet1/0/5
SW1(config-if)# description PC-ACCT-05
SW1(config-if)# switchport mode access
SW1(config-if)# switchport access vlan 10
SW1(config-if)# switchport nonegotiate
SW1(config-if)# spanning-tree portfast
SW1(config-if)# spanning-tree bpduguard enable
switchport mode access locks the mode and switchport nonegotiate stops DTP, so nobody can talk the port into trunking. PortFast skips the STP wait so DHCP does not time out. BPDU Guard err-disables the port if someone plugs in a switch. See VLANs and BPDU Guard and Root Guard for the background.
Printers and IoT devices (cameras, badge readers) use the same template, usually in their own VLAN so an ACL can fence them in.
IP phones (voice VLAN)
A desk phone usually has a PC plugged into its back. The switch port has to carry the phone’s traffic in one VLAN and the PC’s traffic in another, without becoming a full trunk. That is the voice VLAN:
SW1(config)# interface GigabitEthernet1/0/12
SW1(config-if)# switchport mode access
SW1(config-if)# switchport access vlan 10
SW1(config-if)# switchport voice vlan 110
SW1(config-if)# spanning-tree portfast
SW1(config-if)# spanning-tree bpduguard enable
The PC sends untagged frames in VLAN 10. The phone tags its voice frames with VLAN 110. Cisco supports voice VLAN on access ports only, and configuring it turns PortFast on automatically. Typing spanning-tree portfast anyway keeps the intent obvious.
The switch tells the phone which VLAN to use. A Cisco phone learns the voice VLAN from CDP, which is on by default. Third party phones usually rely on LLDP-MED instead. LLDP is disabled globally by default on Catalyst 9300, so turn it on with lldp run. For explicit control, Catalyst 9000 also supports a network-policy profile that advertises the voice VLAN in the LLDP-MED network policy TLV. More on both protocols in CDP and LLDP.
Phones need power. The default mode is power inline auto: the switch detects a powered device and allocates power if the budget allows. Two other modes matter:
SW1(config-if)# power inline static max 30000
SW1(config-if)# power inline never
static reserves power for the port even before anything is plugged in, so a critical device always gets power. The max value is in milliwatts, and the allowed range depends on the port hardware (4000 to 60000 on UPOE ports). never turns off detection and power. See Power over Ethernet for classes and budgets.
Access points
What the AP port looks like depends on where client traffic leaves the AP.
Local mode AP (controller based). The AP builds a CAPWAP tunnel to the wireless LAN controller and sends client traffic through it. The switch only ever sees the AP’s own management traffic, so a plain access port in the AP management VLAN is enough:
SW1(config)# interface GigabitEthernet1/0/20
SW1(config-if)# description AP-FLOOR2-LOCAL
SW1(config-if)# switchport mode access
SW1(config-if)# switchport access vlan 50
SW1(config-if)# spanning-tree portfast
SW1(config-if)# spanning-tree bpduguard enable
FlexConnect or standalone (autonomous) AP. Client traffic is switched locally, straight out of the AP’s wired port into client VLANs. So the port becomes an 802.1Q trunk. For FlexConnect on a Catalyst 9800, Cisco says the native VLAN in the Flex Profile must match the native VLAN configured on the switch port, and that native VLAN is where the AP’s untagged management traffic lives:
SW1(config)# interface GigabitEthernet1/0/21
SW1(config-if)# description AP-BRANCH-FLEX
SW1(config-if)# switchport mode trunk
SW1(config-if)# switchport nonegotiate
SW1(config-if)# switchport trunk native vlan 50
SW1(config-if)# switchport trunk allowed vlan 50,60,70
SW1(config-if)# spanning-tree portfast trunk
Plain spanning-tree portfast does not apply to a trunk port. On Catalyst 9300 you need the trunk keyword. Trunk details live in Trunks and 802.1Q.
Virtualized hosts and servers
A hypervisor puts VMs in many VLANs behind a virtual switch, so its uplinks are trunks. That virtual switch does not join your spanning tree, so the port is still an edge port:
SW1(config)# interface range TenGigabitEthernet1/0/1 -2
SW1(config-if-range)# switchport mode trunk
SW1(config-if-range)# switchport nonegotiate
SW1(config-if-range)# switchport trunk allowed vlan 200,210,220
SW1(config-if-range)# spanning-tree portfast trunk
SW1(config-if-range)# channel-group 1 mode active
channel-group 1 mode active bundles both links into Port-channel1 with LACP. Active starts LACP negotiation. Passive only answers, so two passive ends never form a channel. Member ports need matching speed, duplex and trunk settings. Details in EtherChannel.
The big catch: the hypervisor side must agree. If its virtual switch runs LACP, use mode active. If it only does static bonding, you need mode on on the switch. If it uses independent NIC teaming (each NIC works alone), skip the port channel completely and configure two separate trunk ports.
Platform note on syntax. The Catalyst 9300 and standard 9500 guides use spanning-tree portfast and spanning-tree portfast trunk. The Catalyst 9500 High Performance guide uses spanning-tree portfast edge and spanning-tree portfast edge trunk instead. Use ? on your switch to see which one it takes.
Network appliances
Firewalls and load balancers do not fit one template. Match how the appliance is built:
- One inside interface per VLAN, or a routed interface into one segment: access port.
- Subinterfaces for several VLANs (router on a stick style): trunk with a tight allowed VLAN list.
- Two links in a bundle: port channel, and match LACP on the appliance.
A firewall in transparent (bridging) mode can pass BPDUs, so check the vendor design guide before adding PortFast or BPDU Guard.
Verification
SW1# show interfaces status
SW1# show interfaces GigabitEthernet1/0/12 switchport
SW1# show power inline
SW1# show etherchannel summary
SW1# show cdp neighbors detail
SW1# show lldp neighbors detail
show interfaces status: connected or err-disabled, VLAN or trunk, speed and duplex.show interfaces ... switchport: operational mode, access, voice and native VLAN.show power inline: admin and oper state, watts allocated, PoE class and device name per port.show etherchannel summary: members should be bundled, not suspended.show cdp neighbors detailandshow lldp neighbors detail: confirm what is really plugged in.
Common mistakes
PortFast on a port that leads to a switch. PortFast (or
portfast trunk) toward a switch like device lets a loop form before STP reacts. Use it only toward single hosts.Phone in the data VLAN. Forgetting
switchport voice vlan, or putting the phone’s VLAN inswitchport access vlan, puts phones and PCs in one VLAN and voice QoS and addressing fall apart.Voice VLAN on a trunk. Cisco supports voice VLAN on access ports only.
LACP on one side only. The switch says
mode active, the hypervisor does plain teaming, and the bundle never comes up. Match both ends.FlexConnect native VLAN mismatch. The AP’s native VLAN in the Flex Profile and the switch port’s native VLAN differ, and the AP cannot reach its controller.
LLDP left off for third party phones. The phone never learns the voice VLAN because LLDP is disabled globally by default on Catalyst 9300.
Lab to try tonight
- In Packet Tracer or CML, build one switch with a PC, an IP phone with a PC behind it, and a server.
- Configure the PC port with the access template. Plug a second switch into it and watch BPDU Guard err-disable the port in
show interfaces status. - Configure the phone port with access VLAN 10 and voice VLAN 110. Check
show interfaces switchportandshow cdp neighbors detail. - Give the server two links, configure
channel-group 1 mode activeon the switch, and tryonversusactiveon the server side to see what bundles. - Run
show power inlinebefore and after settingpower inline static max 15400on the phone port.
Cheat strip
| Device | Template in one line |
|---|---|
| PC, printer, IoT | Access, one VLAN, nonegotiate, PortFast, BPDU Guard |
| IP phone | Access VLAN plus switchport voice vlan, PortFast, BPDU Guard, PoE |
| Local mode AP | Access port in AP management VLAN, PoE |
| FlexConnect AP | Trunk, native VLAN = AP management, portfast trunk, PoE |
| Hypervisor | Trunk, portfast trunk, LACP only if the host runs it |
| Firewall or load balancer | Access or trunk to match the appliance |
| PoE modes | auto (default), static (reserve), never (off) |
Frequently asked questions
Q: Why use PortFast on a trunk to a hypervisor? A: The hypervisor’s virtual switch does not take part in your spanning tree, so the port behaves like any host port. spanning-tree portfast trunk gets it forwarding right away after a reboot or link flap.
Q: Is a voice VLAN port a trunk? A: No. It stays an access port. The phone tags voice frames with the voice VLAN, and the PC behind it sends untagged frames in the access VLAN.
Q: How does the phone find out which voice VLAN to use? A: The switch advertises it. Cisco phones learn it through CDP. Many third party phones use LLDP-MED, which needs LLDP enabled on the switch.
Q: Do I need a trunk for every access point? A: Only when the AP switches client traffic locally, as with FlexConnect or a standalone AP. A local mode AP tunnels client traffic to the controller, so an access port in the AP management VLAN is enough.
Practice: quick check
Every question in the bank, once. No repeats. Missed ones cycle back at the end.
VLANs
CCNA VLAN guide: broadcast domains, access vs trunk ports, 802.1Q tagging, native and voice VLANs, VTP, a 6-step trunk debug, security pitfalls and 7 scenarios.
Trunks & 802.1Q Tagging
How switches carry multiple VLANs over a single link using 802.1Q tags. Includes DTP behavior, native VLAN gotchas, and the allowed-VLAN list.
Want this drilled into reflex?
1:1 weekly sessions, live feedback on your labs, and US interview prep: built around the CCNA® exam blueprint. Free first session. No card on file until you decide.
Related topics
BPDU Guard & Root Guard
Two Spanning Tree security features that protect your STP topology from misconfiguration and rogue switches. BPDU Guard locks user-facing ports; Root Guard pins the root bridge so a misplaced switch can't hijack it.
Network AccessCDP & LLDP: Neighbor Discovery
How devices discover directly connected neighbors. CDP is Cisco-proprietary, LLDP is the vendor-neutral standard, and both share identity, model, IOS and port.
Network AccessEtherChannel (Link Aggregation)
Bundle physical links between two switches into one logical Port-Channel for more bandwidth and instant failover. Covers LACP, PAgP, static and load balancing.
Get the free CCNA 12-week roadmap
You're already reading up on Edge Port Configuration: PCs, Phones, APs and Servers. The roadmap is the order I recommend studying every CCNA topic in: with what to lab each week and where Edge Port Configuration: PCs, Phones, APs and Servers fits. A written personal reply, not an autoresponder. Expect it within one business day.
Personal reply from a senior network engineer. No third-party tracking. Unsubscribe any time.
