A VLAN (virtual local area network) splits one physical network into several separate ones in software. The devices share the same cables and the same switch, but each group behaves as if it had a network of its own, and traffic only crosses between groups where you allow it.
The problem with one flat network
A small office often starts with every device plugged into one switch: laptops, printers, the file server and the Wi-Fi access point for visitors. That is one local area network (LAN), and every device on it is in the same broadcast domain.
A broadcast is a frame sent to everyone at once. Devices broadcast all the time as part of normal work: ARP asks 'who has this IP address?', DHCP asks 'can someone give me an address?', and discovery protocols announce printers and media players. Every device on the LAN receives every one of these frames and has to look at it.
With ten devices that is fine. With a few hundred it becomes noise: bandwidth and processing time spent on frames meant for someone else. The bigger problem is trust. On a flat network a visitor's phone sits next to the payroll server, and a compromised laptop can talk directly to everything else.
The old fix was physical: a separate switch and separate cabling for each group. VLANs do the same job without new hardware.
What a VLAN is
A VLAN is a group of switch ports that the switch treats as its own network. Each VLAN has a number, the VLAN ID, and the switch only forwards a frame between ports in the same VLAN. Broadcasts stay inside the VLAN they started in.
So one 48-port switch can act like three smaller switches: ports 1-20 for office staff, 21-30 for servers, 31-48 for guests. The cables stay as they were. The split is logical, set in the switch's configuration, not physical.
Each VLAN is its own broadcast domain, and in practice each one gets its own IP subnet too. Devices in VLAN 10 might use 10.0.10.0/24 and devices in VLAN 20 10.0.20.0/24. That matters later, when traffic needs to cross between them.
Access ports and trunk ports
A switch port is set up in one of two ways:
- An access port belongs to a single VLAN. It is where an end device plugs in: a laptop, a printer, a server. The device has no idea VLANs exist. It sends ordinary Ethernet frames, and the switch knows which VLAN they belong to from the port they arrived on.
- A trunk port carries many VLANs over one link, usually between two switches or between a switch and a router. Frames on a trunk need a label saying which VLAN each one belongs to.
That label is the 802.1Q tag, a 4-byte field the switch inserts into the Ethernet frame. It holds a 12-bit VLAN ID, which is why VLAN IDs run from 1 to 4094 (0 and 4095 are reserved). The switch adds the tag when a frame goes onto a trunk and removes it before delivering the frame to an access port, so end devices normally never see it.
A trunk also has a native VLAN, whose frames cross the trunk untagged. Both ends of a trunk must agree on it, or traffic leaks from one VLAN into another.
A worked example: office, servers and guests
Take a small company with one switch and three groups:
| VLAN | Who | Subnet |
|---|---|---|
| 10 | Office staff | 10.0.10.0/24 |
| 20 | Servers | 10.0.20.0/24 |
| 30 | Guest Wi-Fi | 10.0.30.0/24 |
On a Cisco switch, creating a VLAN, putting a port in it and setting up a trunk to the router looks like this. Other vendors use different commands for the same ideas.
vlan 10
name OFFICE
!
interface GigabitEthernet1/0/5
switchport mode access
switchport access vlan 10
!
interface GigabitEthernet1/0/48
switchport mode trunk
switchport trunk allowed vlan 10,20,30Port 5 is an access port for an office laptop. Port 48 is a trunk to the router, limited to the three VLANs the company uses. The guest Wi-Fi access point plugs into a port in VLAN 30, or into a trunk if it offers several Wi-Fi networks and maps each one to its own VLAN.
Now a guest's phone can't send a single frame to the file server. The switch won't forward it, because the two ports are in different VLANs.
Getting traffic between VLANs
Complete isolation is rarely what you want. Office staff need the file server, and everyone needs the internet. Because each VLAN is a separate network with its own subnet, crossing between them is routing, a layer 3 job, and a plain layer 2 switch can't do it.
There are two common ways to route between VLANs:
- Router on a stick: a router connects to the switch over one trunk link. It has a logical subinterface per VLAN, each holding that VLAN's default gateway address. Traffic goes up the trunk, gets routed, and comes back down the same link.
- A layer 3 switch: the switch routes by itself, using a virtual interface per VLAN (Cisco calls it an SVI). Traffic never leaves the box and routing happens in hardware, so this is the usual choice once there are more than a handful of VLANs.
The router or firewall in the middle is where the rules live. This is what the video means by 'unless Kitty allows it': the office VLAN can reach the servers on the ports it needs, and guests can reach the internet and nothing else. Here is one office request and one guest request, through a router on a stick:
Routing between VLANs through a router on a stick
Step 1 of 8: The server is on another subnet, so the laptop sends its request to its gateway, the router. It enters the switch on a VLAN 10 port.
DHCP needs extra work once a network is split. A device asks for an address with a broadcast, and broadcasts don't leave their VLAN, so a single DHCP server can't hear requests from the other VLANs. Either each VLAN gets its own DHCP service, or the router relays requests to a central server (Cisco's ip helper-address). The DHCP video covers how that request and reply work.
Why bother
- Less noise: broadcasts reach only one VLAN, so each device handles a fraction of the chatter.
- More security: a compromised guest device or a vulnerable printer can reach only what the routing rules allow, not the whole network. This is network segmentation, and it limits how far an attacker can move.
- Better control: each group gets its own policies. Guest traffic can be rate-limited, phone calls on a voice VLAN can get priority, and servers can be reached only from the places that need them.
Moving someone to another team is also cheaper: it is a configuration change on their port, not a new cable run, which is how VLANs keep a network organised without buying more cables.
A common use is putting public-facing servers in their own VLAN, separated from the internal network by a firewall. That is the idea behind a DMZ.
Common mistakes
- Treating a VLAN as a firewall: VLANs separate traffic at layer 2. Once you add routing between them, everything can reach everything unless you write rules. The security comes from the split plus the rules on the router or firewall.
- Leaving everything in VLAN 1: most switches put every port in VLAN 1 out of the box, and it is the default native VLAN too. Move users and devices off it, and set the native VLAN on trunks to an unused one.
- Letting ports negotiate trunks: some switches turn a port into a trunk if the device at the other end asks. An attacker can use that, or a double-tagged frame on the native VLAN, to reach VLANs they shouldn't. This is called VLAN hopping. Set user-facing ports to access mode explicitly and turn off trunk negotiation.
- Mismatched trunks: if one end allows VLAN 20 and the other doesn't, or the native VLANs differ, traffic disappears or lands in the wrong VLAN.
- Too many VLANs: every VLAN is another subnet, another gateway and another set of rules to maintain. Split by real differences in trust or purpose, not by every team.
Where VLANs fit
VLANs are a LAN tool. The 12-bit ID caps a network at about 4,000 of them, which is plenty for an office but not for a cloud provider hosting millions of customer networks. Data centres use overlays such as VXLAN, whose 24-bit ID allows around 16 million networks. The idea is the same: many logical networks over shared physical hardware.
Key takeaways
- A VLAN splits one physical network into separate logical networks, each its own broadcast domain and usually its own subnet.
- Access ports belong to one VLAN. Trunk ports carry many, using the 802.1Q tag to mark each frame's VLAN.
- Traffic between VLANs has to be routed, by a router or a layer 3 switch, and that is where you decide what is allowed.
- VLANs cut broadcast noise, contain attacks and let you move people between networks without recabling.
- A VLAN is not a firewall: lock down trunks and the native VLAN, and write rules for the routed traffic.