The design places management on a tagged VLAN, and the engineer configures that VLAN tag on the appliance's management interface. The cable, however, lands on a switch port configured as an untagged access port, and the appliance turns out to be completely isolated. Why?
Select an answer to reveal the explanation.
Short Explanation
A VLAN tag is a conversation between two ends — an appliance configured alone to speak tagged isn't joining a VLAN, it's talking to a switch that doesn't understand the language. The frames die at that port in silence, because layer-2 silence doesn't raise any alarm on your console. Match the tag on both ends, then prove reachability from inside the VLAN; the far end's configuration is part of your configuration.
Full Explanation
A VLAN is an agreement spanning both sides of the link. When the appliance stamps frames with a tag and the switch port is configured as untagged access, the switch discards or mishandles the tagged frames because that port expects untagged traffic and owns a single native membership; return traffic then arrives untagged toward an interface expecting tags, and the system is isolated in both directions. Nothing on the appliance's console reports an error, because layer-2 discard is silent — which is precisely why the configuration task is not complete until reachability is tested from a host inside the target VLAN. The gateway explanation fails by layer: with the layer-2 membership mismatched, frames never reach any gateway to be missing, so a routing diagnosis cannot explain total isolation at the access port. The native-VLAN retag claim misreads switch behavior — native-VLAN handling is a trunk-side concept, and an access port configured for one untagged VLAN does not adopt and forward an unexpected tagged frame; the frames simply do not cross. The high-VLAN-ID story is a wrong rule for this scenario: the failure pattern of complete silence with both ends 'configured' is a mismatch between them, not a numeric boundary on the appliance's transmit path. Exam caveat: verify the far-end port mode and allowed VLANs as part of the appliance network task, not as somebody else's ticket. Operational check: have the network side confirm the port mode and tag, then test reachability from a host in the management VLAN before sign-off.