Inter VLAN routing is what lets a device in one VLAN reach a device in another. It is needed because a VLAN is a broadcast domain by definition, and a switch will not carry a frame from one broadcast domain into another.
Three ways to be the thing that does: a router with one subinterface per VLAN on a single trunk, called router on a stick; a switch that routes internally through a virtual interface per VLAN, called an SVI; or a physical router port per VLAN, which is the oldest.
On a modern switch the second is the normal answer, and the two mistakes that stop it working are named in the vendor’s own documentation.
- A VLAN is a broadcast domain, so crossing between two is routing
- Router on a stick: one link, one subinterface per VLAN, 802.1Q tags
- SVI: the switch routes internally, one virtual interface per VLAN
- Every host needs its own VLAN’s interface address as its gateway
- A layer 3 switch without ip routing is a layer 2 switch
On this page
Why it is neededWhy two VLANs cannot talk on their own
A VLAN is a broadcast domain. That is not a consequence of VLANs, it is the definition of one, and everything else follows from it.
A switch forwards a frame by looking up its destination MAC address in a table and sending it out the port where that address was last seen. Within a VLAN that works.
Across two VLANs it cannot, because the switch keeps the domains apart on purpose, and a broadcast that would normally find the destination is confined to the sending VLAN.
So a host in VLAN 10 that wants to reach a host in VLAN 20 does what any host does when the destination is not local: it sends the packet to its default gateway and lets something else decide. Inter VLAN routing is the name for whatever answers at that address, whether that is a router or one of the switches.
One packet from VLAN 10 to VLAN 20
The two VLANs are different IP networks, each with its own subnet. The sending host compares the destination with its own mask, sees a different network, and uses ARP to find the MAC address of its gateway instead of the destination.
The switch delivers that frame inside VLAN 10 to the router interface. The router looks up the destination network, finds it directly connected on its VLAN 20 interface, and sends the packet out in a new frame.
With inter VLAN routing on a router, that frame goes back to the switch tagged for VLAN 20. The reply takes the same path in reverse.
This is the same question as any other routing question. The only thing that makes it feel different is that both networks are on the same physical switch, which makes people expect the switch to work it out. It will not, and it should not.
ConfigurationInter VLAN routing configuration, both ways
The examples use Cisco IOS syntax, because that is what most tutorials and most certification labs use. Other vendors name the commands differently and need the same four things. The network is two VLANs: VLAN 10 on 192.168.10.0/24 and VLAN 20 on 192.168.20.0/24, with .1 as the VLAN gateway in each.
Router on a stick
On the switch, create the VLANs, put the host ports in access mode, and configure the port connected to the router as a trunk.
vlan 10
vlan 20
interface GigabitEthernet0/2
switchport mode access
switchport access vlan 10
interface GigabitEthernet0/1
switchport mode trunk
On the router, enable the physical interface and configure one subinterface per VLAN. The subinterface number is only a label. The number after encapsulation dot1Q is what ties it to the VLAN.
interface GigabitEthernet0/0
no shutdown
interface GigabitEthernet0/0.10
encapsulation dot1Q 10
ip address 192.168.10.1 255.255.255.0
interface GigabitEthernet0/0.20
encapsulation dot1Q 20
ip address 192.168.20.1 255.255.255.0
SVIs on a layer 3 switch
The layer 3 switch needs no router and no trunk to route between its own VLANs. Enable routing, create the VLANs, and configure a switched virtual interface for each.
ip routing
vlan 10
vlan 20
interface Vlan10
ip address 192.168.10.1 255.255.255.0
no shutdown
interface Vlan20
ip address 192.168.20.1 255.255.255.0
no shutdown
Access switches below it connect over trunks that carry both VLANs, and the hosts on those switches still use the SVI addresses as their gateways.
Verifying the configuration
show ip route should list both networks as directly connected. show ip interface brief shows whether the subinterfaces or SVIs are up. show interfaces trunk shows the trunk mode, the native VLAN and the VLANs allowed. Then ping from a host in VLAN 10 to a host in VLAN 20.
On every hostWhat has to be true on every host
The routing configuration is only half of it, and the other half is on the machines.
Every device needs a default gateway, and it has to be the address of its own VLAN's interface. Cisco states the requirement plainly: each server and host device must have its default gateway configured to the corresponding VLAN interface IP address on the switch.
That is one gateway address per VLAN, not one for the site. A host in VLAN 20 pointed at VLAN 10's gateway address is pointed at an address it cannot reach, because reaching it would require the routing that is not happening yet.
The symptom is a machine that talks to its own VLAN perfectly and to nothing else, which reads like a firewall problem and is not.
The two mistakesThe two mistakes the vendor names itself
Both of these are in Cisco's own documentation, which is a good sign that they are the common ones.
IP routing left off. A layer 3 switch does not route until told to. Cisco: in order to make the switch function as an L3 device and provide Inter-VLAN routing, make sure that ip routing is enabled globally.
The same document makes the other half explicit: the switch can act as an L2 device with the disablement of IP routing. So a switch with the license, the hardware and every VLAN interface correctly addressed will still forward nothing between VLANs if that one global command is missing, and nothing in the interface configuration hints at why.
A native VLAN that does not match. On an 802.1Q trunk one VLAN is carried untagged, and both ends have to agree which.
Cisco: the native VLAN must be configured the same on each side of the trunk link. It is a common mistake not to match the native VLANs when 802.1Q trunking between the router and the switch is configured.
On the router side the native VLAN's subinterface is written encapsulation dot1Q 1 native rather than as a plain encapsulation, which is easy to leave out and produces a link that comes up and carries most VLANs correctly while one behaves strangely.
How to test itProving it works, in the order that isolates the fault
Four tests, and each one clears a layer. Running them out of order is how an afternoon disappears.
Ping the gateway from the host. If this fails, nothing about routing is involved yet. The host is in the wrong VLAN, has the wrong address, has the wrong mask, or the port is not in the VLAN you think it is. Check the switch port's VLAN membership before touching anything at layer 3.
Ping the other VLAN's gateway address from the host. This is the first test that needs routing. It succeeds and the far host still fails, and the problem is in the far VLAN or on the far host. It fails, and the routing device is the place to look.
Check the routing table on the device doing the work. Every VLAN interface should appear as a connected route. An interface with an address and no route is an interface that is down, and on an SVI that usually means no access port in that VLAN is up, because the virtual interface follows the VLAN's state.
Check the trunk, if there is one. Both ends agree on the native VLAN and both ends carry the VLANs you expect. A trunk that passes most traffic correctly while one VLAN misbehaves is a native VLAN argument nearly every time.
The order matters because each step assumes the one before it passed. Most of the time the answer arrives at step one, and the configuration nobody wanted to look at was never the problem.
What it costsWhat routing gives back, and what it costs
Separating the network was the point of the VLANs. Routing between them puts a path back, and the path is not narrow unless you narrow it.
Two VLANs with routing between them and nothing else are, for practical purposes, one network with two address ranges. The broadcast traffic stays apart, which is worth having, and the access does not. A device compromised in the guest VLAN can reach the server VLAN exactly as any host can.
The control is the access list on the routing interface, not the VLAN. That is where the separation people believe they bought actually lives, and it is the piece most often left at permit any. Write it in the direction that matters, from the less trusted VLAN toward the more trusted one, and check what breaks rather than assuming.
Sending it through a firewall is the other answer. A firewall holding an interface per VLAN routes and inspects in the same hop. It costs more and it sizes differently, because now internal traffic crosses the firewall rather than only traffic leaving the site.
PitfallsWhere people go wrong
Expecting the switch to route because everything is plugged into it. One box, two broadcast domains, and no layer 3 unless something provides it.
Configuring the VLAN interfaces and stopping. Addresses on the SVIs look like a finished job. Without ip routing the switch is still a layer 2 switch with some addresses on it.
One default gateway for the whole site. Each VLAN has its own gateway address, and a host must use its own.
Ignoring the native VLAN on a trunk. It matches or it does not, and when it does not the failure is partial, which is worse than total.
Building router on a stick and then growing. Every inter VLAN packet crosses the same trunk twice. It is fine at small volumes and it is the first thing to saturate.
Treating a routing problem as a firewall problem. A host that reaches its own VLAN and nothing else is almost always a gateway or a routing problem, and the access list is the second thing to check rather than the first.
ComparisonRouter on a stick, the SVI and a port per VLAN
| Criterion | Router on a stick | SVI | One port per VLAN |
|---|---|---|---|
| Where the routing happens | On a router | Inside the switch | On a router |
| Links to the switch | One trunk | None needed | One per VLAN |
| Tagging | 802.1Q, per subinterface | Internal | None, each port is access |
| Scales to many VLANs | Poorly, the trunk is shared | Yes | No, ports run out |
| Typical use today | Small sites, or no layer 3 switch | The normal answer | Legacy |
| Traffic path | Up the trunk and back down | Never leaves the switch | Out and back |
Router on a stick. One physical link between the switch and a router, configured as an 802.1Q trunk. The router carries a subinterface for each VLAN, each with encapsulation dot1Q and that VLAN's number, and each with the IP address that VLAN's hosts use as their gateway.
Every packet crossing between two VLANs travels up the trunk and back down it, so the trunk carries the traffic twice and becomes the ceiling. The SVI. A layer 3 switch holds a virtual interface per VLAN, addressed the same way, and routes between them in hardware without the traffic leaving the box.
This is what almost every network of any size does, and the reason is the previous paragraph: nothing has to go out and come back. One physical port per VLAN. A router port per VLAN, each a plain access port on the switch.
It works, it needs no tagging, and it needs a router port for every VLAN you ever add. This is the arrangement the other two replaced.
FAQFrequently asked questions
What is inter VLAN routing?
Routing traffic between VLANs. A VLAN is a broadcast domain and a switch will not move frames between broadcast domains, so anything crossing from one VLAN to another has to be routed at layer 3, either by a router or by a switch that can route.
Why do I need it at all?
Because separating traffic is the point of a VLAN, and total separation is rarely what anyone wants. VLANs keep broadcast traffic and unwanted access apart; inter VLAN routing puts back exactly the paths you decide to allow, under a routing table and usually an access list.
What is router on a stick?
Inter VLAN routing over a single physical link. The link is an 802.1Q trunk, and the router carries one subinterface per VLAN, each configured with encapsulation dot1Q and the VLAN number, and each holding the gateway address for that VLAN. All inter VLAN traffic goes up the link and back down it.
What is an SVI?
A switched virtual interface: a virtual layer 3 interface on a switch, one per VLAN, holding the gateway address for that VLAN. A layer 3 switch routes between its SVIs internally, so inter VLAN traffic never leaves the switch.
Which method should I use?
The SVI, on any switch that can route, because the traffic stays inside the box and the trunk never becomes the bottleneck. Router on a stick is the answer when the switch cannot route, and a physical port per VLAN is a legacy arrangement rather than a design choice.
Why is my inter VLAN routing not working?
Check three things in this order. Is ip routing enabled globally on the switch. Does every host have its own VLAN's interface address as its default gateway. Does the native VLAN match on both ends of every trunk. Those three account for most of it, and only the third produces a partial failure.
Do I need a layer 3 switch?
Not necessarily. Router on a stick does inter VLAN routing with a layer 2 switch and any router that supports 802.1Q subinterfaces. A layer 3 switch is faster and simpler, and it is what to buy when the network grows.
What is the native VLAN and why does it matter here?
The one VLAN carried untagged on an 802.1Q trunk. Both ends have to agree on which it is. When they disagree, most VLANs pass normally and the traffic on the mismatched one goes to the wrong place, which is why the failure is confusing rather than obvious.
Can a firewall do inter VLAN routing?
Yes, and it is a common design. The firewall holds an interface or a subinterface per VLAN and every crossing is inspected as well as routed. The cost is that all inter VLAN traffic now traverses the firewall, so it has to be sized for internal traffic and not only for the internet link.
Does inter VLAN routing break the isolation VLANs give me?
Only where you allow it. Routing between two VLANs makes them reachable to each other; an access list on the routing interface decides which traffic actually crosses. The separation you keep is whatever the list allows, so the list is the security control rather than the VLAN.
How many VLANs can I route between?
More than the VLAN tag allows on one switch in practice, since the 802.1Q identifier is 12 bits and gives 4,094 usable VLANs. The real limit is the routing capacity and the interface count of the device doing the work, and on a layer 3 switch it is high enough that the tag runs out first.
What does an inter-VLAN routing configuration need?
An inter-VLAN routing configuration needs a layer 3 interface in every VLAN to act as that VLAN's default gateway. On a layer 3 switch, create a switched virtual interface per VLAN and enable IP routing. On a router, create a subinterface per VLAN with 802.1Q tagging on a trunk link, the design known as router on a stick.
Keep readingRelated concepts
Read next · Addressing What Is a Subnet? The addressing that decides whether a destination is local, and therefore whether routing happens at all. Open this next15 min- Addressing · 10 min Default Gateway The address a host sends to when the destination is not local, which is where this begins.
- Switching · 14 min What Is a VLAN? What a VLAN is before anything has to cross between two of them.
- Fundamentals · 9 min Switch vs Router, and Where a Layer 3 Switch Fits Switch, router and layer 3 switch compared, and which one an office actually needs.
- Routing · 11 min HSRP vs VRRP, and What Happens When the Default Gateway Dies HSRP and VRRP, which keep a VLAN gateway answering when the router or switch holding it fails.