EMZETT.
Login

VLAN

In short: Virtual LAN — a logically separate network that runs on the same physical switch infrastructure as if it were a network of its own.

In more detail: Instead of cabling separate switches for each department, VLAN-capable switches mark data packets with a VLAN ID (802.1Q tagging) and separate the traffic logically. Devices in different VLANs can’t see each other directly by default, even if they’re connected to the same switch — communication between VLANs requires routing.

In Depth

Technically, VLAN separation works via 802.1Q tagging: an additional field with a VLAN ID (1–4094) is inserted into each Ethernet frame as soon as it runs over a “trunk port” (a connection that carries traffic of several VLANs at the same time, e.g. between two switches). VLAN-capable switches read this tag and only forward frames to ports belonging to the same VLAN ID — an “access port” (to which a normal end device is connected) usually belongs permanently to exactly one VLAN and doesn’t see the tagging itself at all.

The big practical advantage: a single physical cabling and switch infrastructure can serve several logically completely separate networks at the same time, without separate switches and cables having to be laid for each department/purpose. For communication BETWEEN two VLANs (e.g. when accounting needs to access a central print server in another VLAN), a router or layer 3 switch that explicitly switches between the VLANs is always needed — this deliberate hurdle is a central security feature, because it allows exact control over which traffic is allowed between which network segments at all.

See also: Subnet, Switch