The formal definition of a local area network is geographic, and it has not been useful for a long time.
RFC 1983, the Internet Users' Glossary, defines a LAN as a data network intended to serve an area of only a few square kilometers or less, and adds that because the area is small, optimizations permit data rates up to 100Mb/s. Both halves have aged: nobody sizes a network in square kilometers, and 100 megabits is now the slow end of a desk.
The definition that still works is not about distance at all. A LAN is a broadcast domain, the set of devices that receive each other's broadcasts, which is why they find each other with ARP and why a router is the boundary.
- The formal definition is geographic, and dates from 1996
- The working definition is one broadcast domain
- Devices find each other by broadcasting, which is what ARP does
- A router does not forward broadcasts, so it is the boundary
- A VLAN makes several broadcast domains out of one switch
On this page
The old definitionWhat the glossary actually says, and when
Worth reading the official definitions in full, because their datedness is the argument rather than a curiosity.
RFC 1983 defines a local area network as a data network intended to serve an area of only a few square kilometers or less, and explains that because the network covers only a small area, optimizations can be made in the signal protocols that permit data rates up to 100Mb/s.
The same glossary defines a wide area network as a network, usually constructed with serial lines, which covers a large geographic area. And it defines a metropolitan area network as one intended to serve an area approximating that of a large city, noting that such networks are implemented by innovative techniques such as running fiber cables through subway tunnels.
Read those three together and the shared assumption is obvious. All of them are distances, and the technology attached to each distance is fixed. That was a reasonable way to describe networks when the distance genuinely decided what you could run over the wire.
It stopped being reasonable for two reasons. Speed detached from distance, so a link across a country can now be faster than a building's Ethernet cabling was in 1996.
And virtualization detached the local area network from geography entirely, so a single office switch can hold networks that behave as if they were in separate buildings, while two data centers on different continents can be stitched into what behaves as one.
The definitions were not wrong. They described the thing that used to determine the answer.
The working oneThe definition that still works
Take away distance and one property remains that genuinely separates one local area network from another: whether the devices connected to it can hear each other shout.
A broadcast is a frame addressed to everything on the Ethernet segment rather than to one recipient. The set of devices that receive it is the broadcast domain, and that set is the LAN in the only sense that affects how anything behaves.
The mechanism is easiest to see in address resolution. RFC 826 describes what happens when a host knows an IP address and needs the hardware address to go with it: it builds a request and causes that packet to be broadcast to all stations on the cable.
Every device in the domain receives it, the one that owns the address answers, and the conversation proceeds directly from there.
That single mechanism produces most of what people mean by same network:
Devices on one LAN find each other without help. No router, no configuration, no name service required. ARP resolves the address because the question reaches every device in the domain.
Devices on different LANs cannot. The broadcast does not arrive, so the question is never asked. Reaching them requires a default gateway, which is a router, and routers do not forward broadcasts.
The boundary is therefore a router, always. Not a wall, not a building, not a distance. Wherever a router sits, one local area network stops and another begins.
The mechanismWhat each device does to the domain
The reason a broadcast domain is the useful definition becomes clear from what the equipment does to it. This is also the history of Ethernet in one table.
| Device | Collision domains | Broadcast domains |
|---|---|---|
| Hub | One, shared by everything connected to it | One |
| Switch | One per port, which is why collisions stopped mattering | Still one, across every port |
| Switch with VLANs | One per port | Several, decided by configuration |
| Router | Not applicable | Terminated, one per interface |
Read the right hand column downward, because it is the whole argument. Replacing hubs with switches solved the collision problem completely and did nothing at all to the broadcast domain: every device connected to a switch still hears every broadcast on it. Ethernet got faster and the domain stayed exactly as large.
That is why VLANs exist. Once the switch had stopped being the limit on traffic, the remaining reason to split a network was the broadcast domain itself, and splitting it physically meant buying more switches.
Doing it in configuration was the obvious answer, and it is why one piece of hardware can hold several local area networks that cannot reach each other.
The bottom row is the boundary. A router has an interface in each domain and forwards between them by address rather than by flooding, so broadcasts stop there by construction rather than by policy. Nothing has to be configured to make that happen, which is why the router is the boundary in every network regardless of how it was designed.
The partsWhat a local area network is made of
The broadcast domain is the definition. The equipment is what builds one, and a small office local area network is four kinds of thing: a network interface in every computer, cabling, one or more switches, and a router at the edge. An access point adds the wireless side.
The wired side is Ethernet over twisted pair. Each computer has a network interface, a patch cable carries that connection to a switch port, and switches connect to each other or to the router. The UTP cable category decides the speed a link can negotiate, not the shape of the LAN.
The wireless side is the same LAN with a radio for the first hop. An access point takes a wired uplink into a switch port and bridges its clients onto the broadcast domain behind it. A laptop on Wi-Fi and a desktop on a cable sit on one LAN and one subnet.
The router is where the local area network stops and the internet begins. Its inside interface holds the default gateway address every device on the domain is handed, and its outside interface holds the connection to the provider.
Nothing on the LAN reaches the internet without passing through that router, which is also why filtering, address translation and any measurement of internet usage happen there rather than on the switches.
A home network is all of that in one box. A consumer router is a router, a switch, an access point and a DHCP server in one case, with the provider connection in its own port. That is why a home LAN is one broadcast domain, and why splitting a home network into two LANs takes a deliberate act.
One broadcast domain is also one security boundary. Every device on it can reach every other device directly, so a compromised computer on a flat LAN has an unfiltered path to the servers.
Splitting the network into VLANs is the usual first control, and a separate wireless guest network is the usual first split. Neither changes what a local area network is. Both change how many LANs the office has.
ArrangementHow a LAN is arranged, and who serves whom
Two other questions get folded into the word LAN: how the devices are physically arranged, and what the connected machines do for each other. The cabling used to decide both. Today one of them is settled and the other is still a choice every office makes.
Every modern wired LAN is a star topology. Each device has its own cable to a switch and the switch is the center. Older LANs used a bus, with every computer sharing one coaxial run, or a ring topology, where each station passed a token to the next one.
The arrangement decided the failure behavior, which is why it changed. One bad cable in a star takes down one device. One bad cable on a bus, or a break in a ring, took down the whole network, and that is a large part of why the wiring in every building went to a star.
The second question is who serves whom. A peer to peer LAN has no server: each computer shares its own files and its own printer, which is what a two person office and almost every home network run.
A client server LAN puts the shared resources on a machine that does nothing else, which is where directory services, central authentication and scheduled backup become possible. The networking underneath is identical: the same switches, the same cables, the same broadcast domain.
Neither model changes the count of LANs. A peer to peer office and a client server office with the same switch and the same router have one local area network each, and both connect to the internet over one shared connection.
Four wordsFour words for overlapping things
These get used interchangeably and they are not synonyms. Being precise about them settles most arguments about whether two machines are on the same network.
| Term | What it actually is | Layer |
|---|---|---|
| Broadcast domain | The set of devices that receive each other's broadcasts | Two |
| LAN | In practice, one broadcast domain | Two |
| VLAN | A broadcast domain defined by configuration rather than by cabling | Two |
| Subnet | A range of IP addresses treated as directly reachable | Three |
The pairing that causes trouble is the last two. A VLAN and a subnet are different things at different layers, and they are almost always configured one to one because anything else is painful to reason about. That habit makes them look like the same object until somebody builds an exception, at which point the distinction becomes urgent.
The useful test is what each one breaks. Put a device in the wrong VLAN and it cannot hear the broadcast traffic it needs, so it will not even get an address. Give a device the wrong subnet mask in the right VLAN and it hears everything, has an address, and simply misjudges which destinations are local.
PitfallsWhere people go wrong
Thinking a local area network is a building. It is a broadcast domain. One building routinely holds many, and one broadcast domain can span buildings.
Assuming one switch is one LAN. Switches with VLANs configured hold several, and devices connected to different ones cannot reach each other without a router even though they share the hardware.
Treating VLAN and subnet as the same thing. They are different layers. Configuring them one to one is sensible practice, not an identity.
Diagnosing a routing problem when the device has no address. No address usually means the broadcast never reached a DHCP server, which is a broadcast domain question rather than a routing one.
Quoting the geographic definition in an argument. It is the formal one and it will not settle anything, because nothing anybody is arguing about turns on square kilometers.
Forgetting that the wireless side is the same LAN. A WLAN is a local area network with a radio for its first hop. The access point bridges onto the same broadcast domain, which is why the rest of the network cannot tell the difference.
ComparisonLAN, MAN and WAN as RFC 1983 defined them, and what survived
| Criterion | LAN | MAN | WAN |
|---|---|---|---|
| Defined by | A few square kilometers or less | An area like a large city | A large geographic area |
| Glossary example given | Ethernet, FDDI, token ring | Fiber through subway tunnels, SMDS | Serial lines |
| Speed assumed in 1996 | Up to 100Mb/s | Higher than a WAN | Whatever a serial line gave |
| Still a useful distinction | Only if restated as a broadcast domain | Rarely used at all now | Yes, as somebody else's infrastructure |
| What decides it today | Where the router is | Nothing much | Whether you own the link |
The third row is the one that dates the whole scheme. Every speed in it has been overtaken, and the row underneath is what survived: LAN still means something once restated, WAN still means something because ownership of the link is a real distinction, and MAN has quietly stopped being a category anybody needs.
FAQFrequently asked questions
What is a local area network?
Formally, RFC 1983 defines it as a data network serving an area of a few square kilometers or less. In practice a local area network is one broadcast domain: the set of devices that receive each other's broadcasts.
What is the difference between a LAN and a WAN?
The glossary distinguishes them by distance. The distinction that survives is ownership and boundary: a LAN is one broadcast domain you control, and a WAN links sites across infrastructure you usually do not own.
Is a LAN the same as a broadcast domain?
In every way that affects behavior, yes. That is the definition worth using, because it predicts what devices can and cannot do.
Where does a LAN end?
At a router. Routers do not forward broadcasts, so the domain stops wherever routing begins, regardless of walls or distance.
Can one switch hold more than one LAN?
Yes, with VLANs. Each VLAN is a separate broadcast domain, and devices connected to different ones need a router to reach each other even though they share the switch.
Is a VLAN the same as a subnet?
No. A VLAN is a broadcast domain at layer two; a subnet is a range of IP addresses at layer three. They are usually configured one to one, which makes them look identical until they are not.
Is Wi-Fi a LAN?
Yes. A wireless LAN is the same local area network with a radio as the first hop, and the access point bridges onto the same broadcast domain as the wired Ethernet devices.
What is a MAN?
A metropolitan area network, defined in the same glossary as serving an area like a large city, with fiber through subway tunnels given as the example. It is rarely a useful category today.
Why does the old definition mention 100Mb/s?
Because RFC 1983 dates from a time when the short distance was what made higher speeds possible. Speed and distance have since separated, which is exactly why the geographic definition stopped being useful.
How do devices on a LAN find each other?
By broadcasting. RFC 826 describes ARP asking the whole segment which device owns an address, and only the owner replies.
Why did my device get a 169.254 address?
Because no DHCP server answered, and DHCP requests are broadcasts. That points at the broadcast domain, usually the wrong VLAN or a missing relay, rather than at routing.
Can a LAN span two sites?
It can, if layer two is extended between them, and doing so means the two sites share one broadcast domain and one failure domain. That is a deliberate design choice with real costs rather than an accident.
What is a MAN network?
A MAN, or metropolitan area network, covers a city or a large campus. It sits between a LAN, which covers a building, and a WAN, which covers regions or countries. A MAN network is usually built from carrier fiber or metro Ethernet services linking several sites of one organization.
Keep readingRelated concepts
Read next · Wireless A WLAN Is a LAN With a Radio in Front of It The same local network with a radio for its first hop, bridged onto the same broadcast domain as the wired side. Open this next9 min- Switching · 14 min What Is a VLAN? How one switch comes to hold several broadcast domains, and the configuration that decides which port is in which.
- Fundamentals · 13 min ARP Explained, and the One Thing Everyone Gets Wrong About It The broadcast that makes the domain visible, and the reason devices on one LAN need nothing to find each other.