Skip to main content
PacketMentor logo
Open menu
← All topics
Network Access Intermediate

Edge Port Configuration: PCs, Phones, APs and Servers

CCNA 2.2 edge ports on Catalyst IOS XE: access and voice VLANs, PortFast, BPDU Guard, PoE, AP trunks, LACP to servers, and the show commands that prove it.

Quick summary
  • Every edge port gets a template based on what plugs into it: a PC, a phone, an AP, a hypervisor or an appliance. Pick the template first, then type.
  • Single hosts get an access port with PortFast and BPDU Guard. Phones add a voice VLAN. Hosts that need several VLANs (FlexConnect APs, hypervisors) get a trunk with PortFast trunk.
  • PortFast is only for ports facing end hosts. Never put it on a port that leads to another switch.

Mental model

An edge port is any switch port that faces something that is not a switch. CCNA objective 2.2 asks you to configure these ports for each kind of device, and that comes down to three questions:

  1. How many VLANs does the device need? One VLAN means an access port. Several VLANs means a trunk (or an access port plus a voice VLAN, for phones).
  2. Does it need power? Phones, APs and many IoT gadgets draw Power over Ethernet from the switch.
  3. Could it ever send BPDUs? End hosts should not. That is why edge ports get PortFast (skip the STP wait) and BPDU Guard (shut the port if a BPDU shows up anyway).

Answer those and the config writes itself. Examples are Catalyst 9300 on IOS XE 17.x unless noted.

One port, one job

DevicePort modeVLANsSTP settingsPoEExtras
Desktop, printer, IoTAccessOne data VLANportfast, bpduguard enableIoT often yesswitchport nonegotiate
IP phone (with PC behind it)AccessData VLAN plus voice VLANportfast, bpduguard enableYesCDP or LLDP-MED tells the phone its VLAN
Local mode AP (controller based)AccessAP management VLANportfast, bpduguard enableYesClient traffic rides CAPWAP to the WLC
FlexConnect or standalone APTrunkNative VLAN for AP management, tagged client VLANsportfast trunkYesAllowed VLAN list
Hypervisor hostTrunk, often a port channelServer and VM VLANsportfast trunkNoLACP only if the host side runs it too
Firewall or load balancerAccess or trunkDepends on designDepends on designNoMatch the appliance’s interface config

Desktops, printers and IoT

This is the default template, and it is the one you will type a thousand times:

SW1(config)# interface GigabitEthernet1/0/5
SW1(config-if)# description PC-ACCT-05
SW1(config-if)# switchport mode access
SW1(config-if)# switchport access vlan 10
SW1(config-if)# switchport nonegotiate
SW1(config-if)# spanning-tree portfast
SW1(config-if)# spanning-tree bpduguard enable

switchport mode access locks the mode and switchport nonegotiate stops DTP, so nobody can talk the port into trunking. PortFast skips the STP wait so DHCP does not time out. BPDU Guard err-disables the port if someone plugs in a switch. See VLANs and BPDU Guard and Root Guard for the background.

Printers and IoT devices (cameras, badge readers) use the same template, usually in their own VLAN so an ACL can fence them in.

IP phones (voice VLAN)

A desk phone usually has a PC plugged into its back. The switch port has to carry the phone’s traffic in one VLAN and the PC’s traffic in another, without becoming a full trunk. That is the voice VLAN:

SW1(config)# interface GigabitEthernet1/0/12
SW1(config-if)# switchport mode access
SW1(config-if)# switchport access vlan 10
SW1(config-if)# switchport voice vlan 110
SW1(config-if)# spanning-tree portfast
SW1(config-if)# spanning-tree bpduguard enable

The PC sends untagged frames in VLAN 10. The phone tags its voice frames with VLAN 110. Cisco supports voice VLAN on access ports only, and configuring it turns PortFast on automatically. Typing spanning-tree portfast anyway keeps the intent obvious.

The switch tells the phone which VLAN to use. A Cisco phone learns the voice VLAN from CDP, which is on by default. Third party phones usually rely on LLDP-MED instead. LLDP is disabled globally by default on Catalyst 9300, so turn it on with lldp run. For explicit control, Catalyst 9000 also supports a network-policy profile that advertises the voice VLAN in the LLDP-MED network policy TLV. More on both protocols in CDP and LLDP.

Phones need power. The default mode is power inline auto: the switch detects a powered device and allocates power if the budget allows. Two other modes matter:

SW1(config-if)# power inline static max 30000
SW1(config-if)# power inline never

static reserves power for the port even before anything is plugged in, so a critical device always gets power. The max value is in milliwatts, and the allowed range depends on the port hardware (4000 to 60000 on UPOE ports). never turns off detection and power. See Power over Ethernet for classes and budgets.

Access points

What the AP port looks like depends on where client traffic leaves the AP.

Local mode AP (controller based). The AP builds a CAPWAP tunnel to the wireless LAN controller and sends client traffic through it. The switch only ever sees the AP’s own management traffic, so a plain access port in the AP management VLAN is enough:

SW1(config)# interface GigabitEthernet1/0/20
SW1(config-if)# description AP-FLOOR2-LOCAL
SW1(config-if)# switchport mode access
SW1(config-if)# switchport access vlan 50
SW1(config-if)# spanning-tree portfast
SW1(config-if)# spanning-tree bpduguard enable

FlexConnect or standalone (autonomous) AP. Client traffic is switched locally, straight out of the AP’s wired port into client VLANs. So the port becomes an 802.1Q trunk. For FlexConnect on a Catalyst 9800, Cisco says the native VLAN in the Flex Profile must match the native VLAN configured on the switch port, and that native VLAN is where the AP’s untagged management traffic lives:

SW1(config)# interface GigabitEthernet1/0/21
SW1(config-if)# description AP-BRANCH-FLEX
SW1(config-if)# switchport mode trunk
SW1(config-if)# switchport nonegotiate
SW1(config-if)# switchport trunk native vlan 50
SW1(config-if)# switchport trunk allowed vlan 50,60,70
SW1(config-if)# spanning-tree portfast trunk

Plain spanning-tree portfast does not apply to a trunk port. On Catalyst 9300 you need the trunk keyword. Trunk details live in Trunks and 802.1Q.

Virtualized hosts and servers

A hypervisor puts VMs in many VLANs behind a virtual switch, so its uplinks are trunks. That virtual switch does not join your spanning tree, so the port is still an edge port:

SW1(config)# interface range TenGigabitEthernet1/0/1 -2
SW1(config-if-range)# switchport mode trunk
SW1(config-if-range)# switchport nonegotiate
SW1(config-if-range)# switchport trunk allowed vlan 200,210,220
SW1(config-if-range)# spanning-tree portfast trunk
SW1(config-if-range)# channel-group 1 mode active

channel-group 1 mode active bundles both links into Port-channel1 with LACP. Active starts LACP negotiation. Passive only answers, so two passive ends never form a channel. Member ports need matching speed, duplex and trunk settings. Details in EtherChannel.

The big catch: the hypervisor side must agree. If its virtual switch runs LACP, use mode active. If it only does static bonding, you need mode on on the switch. If it uses independent NIC teaming (each NIC works alone), skip the port channel completely and configure two separate trunk ports.

Platform note on syntax. The Catalyst 9300 and standard 9500 guides use spanning-tree portfast and spanning-tree portfast trunk. The Catalyst 9500 High Performance guide uses spanning-tree portfast edge and spanning-tree portfast edge trunk instead. Use ? on your switch to see which one it takes.

Network appliances

Firewalls and load balancers do not fit one template. Match how the appliance is built:

  • One inside interface per VLAN, or a routed interface into one segment: access port.
  • Subinterfaces for several VLANs (router on a stick style): trunk with a tight allowed VLAN list.
  • Two links in a bundle: port channel, and match LACP on the appliance.

A firewall in transparent (bridging) mode can pass BPDUs, so check the vendor design guide before adding PortFast or BPDU Guard.

Verification

SW1# show interfaces status
SW1# show interfaces GigabitEthernet1/0/12 switchport
SW1# show power inline
SW1# show etherchannel summary
SW1# show cdp neighbors detail
SW1# show lldp neighbors detail
  • show interfaces status: connected or err-disabled, VLAN or trunk, speed and duplex.
  • show interfaces ... switchport: operational mode, access, voice and native VLAN.
  • show power inline: admin and oper state, watts allocated, PoE class and device name per port.
  • show etherchannel summary: members should be bundled, not suspended.
  • show cdp neighbors detail and show lldp neighbors detail: confirm what is really plugged in.

Common mistakes

  1. PortFast on a port that leads to a switch. PortFast (or portfast trunk) toward a switch like device lets a loop form before STP reacts. Use it only toward single hosts.

  2. Phone in the data VLAN. Forgetting switchport voice vlan, or putting the phone’s VLAN in switchport access vlan, puts phones and PCs in one VLAN and voice QoS and addressing fall apart.

  3. Voice VLAN on a trunk. Cisco supports voice VLAN on access ports only.

  4. LACP on one side only. The switch says mode active, the hypervisor does plain teaming, and the bundle never comes up. Match both ends.

  5. FlexConnect native VLAN mismatch. The AP’s native VLAN in the Flex Profile and the switch port’s native VLAN differ, and the AP cannot reach its controller.

  6. LLDP left off for third party phones. The phone never learns the voice VLAN because LLDP is disabled globally by default on Catalyst 9300.

Lab to try tonight

  1. In Packet Tracer or CML, build one switch with a PC, an IP phone with a PC behind it, and a server.
  2. Configure the PC port with the access template. Plug a second switch into it and watch BPDU Guard err-disable the port in show interfaces status.
  3. Configure the phone port with access VLAN 10 and voice VLAN 110. Check show interfaces switchport and show cdp neighbors detail.
  4. Give the server two links, configure channel-group 1 mode active on the switch, and try on versus active on the server side to see what bundles.
  5. Run show power inline before and after setting power inline static max 15400 on the phone port.

Cheat strip

DeviceTemplate in one line
PC, printer, IoTAccess, one VLAN, nonegotiate, PortFast, BPDU Guard
IP phoneAccess VLAN plus switchport voice vlan, PortFast, BPDU Guard, PoE
Local mode APAccess port in AP management VLAN, PoE
FlexConnect APTrunk, native VLAN = AP management, portfast trunk, PoE
HypervisorTrunk, portfast trunk, LACP only if the host runs it
Firewall or load balancerAccess or trunk to match the appliance
PoE modesauto (default), static (reserve), never (off)

Frequently asked questions

Q: Why use PortFast on a trunk to a hypervisor? A: The hypervisor’s virtual switch does not take part in your spanning tree, so the port behaves like any host port. spanning-tree portfast trunk gets it forwarding right away after a reboot or link flap.

Q: Is a voice VLAN port a trunk? A: No. It stays an access port. The phone tags voice frames with the voice VLAN, and the PC behind it sends untagged frames in the access VLAN.

Q: How does the phone find out which voice VLAN to use? A: The switch advertises it. Cisco phones learn it through CDP. Many third party phones use LLDP-MED, which needs LLDP enabled on the switch.

Q: Do I need a trunk for every access point? A: Only when the AP switches client traffic locally, as with FlexConnect or a standalone AP. A local mode AP tunnels client traffic to the controller, so an access port in the AP management VLAN is enough.

Master this on a real network

Want this drilled into reflex?

1:1 weekly sessions, live feedback on your labs, and US interview prep: built around the CCNA® exam blueprint. Free first session. No card on file until you decide.

Claim my free session →

Get the free CCNA 12-week roadmap

You're already reading up on Edge Port Configuration: PCs, Phones, APs and Servers. The roadmap is the order I recommend studying every CCNA topic in: with what to lab each week and where Edge Port Configuration: PCs, Phones, APs and Servers fits. A written personal reply, not an autoresponder. Expect it within one business day.

Personal reply from a senior network engineer. No third-party tracking. Unsubscribe any time.