Networking · Concept · 14 min read

What Is a VLAN? One Switch, Several Networks

One switch behaving as several, and four bytes that carry the arrangement to the next switch. Here is the mechanism, the configuration, the attack the defaults invite, and a numbering plan worth copying.

Written by Marko Ristic, Editor Updated Sep 17, 2026
4 BThe tag, which pushes a full frame from 1518 to 1522 bytes
4094VLANs available, from a 12 bit field with two values reserved
1The default VLAN, and the one nothing important should be in
0Frames that cross between VLANs without a router
Short answer

A VLAN splits one physical switch into several separate networks. Ports in different VLANs cannot reach each other directly, and ports in the same VLAN can reach each other across a whole building. Everything else, the tags and the trunks, exists to carry that decision between switches.

  • A VLAN is a broadcast domain made in configuration, not in cabling
  • The 802.1Q tag is 4 bytes, and only trunks carry it
  • Access ports carry one VLAN, trunk ports carry many
  • Two VLANs need a router to talk, exactly like two networks
  • VLAN 1 is every default, which is why it is every assumption
On this page

FundamentalsWhat a VLAN actually does

A network switch without VLANs is one broadcast domain. A broadcast sent by any device reaches every other device on the switch, and every device can reach every other device without a router.

Configure two virtual LANs and that switch behaves as two separate networks that happen to share a chassis. A broadcast in VLAN 10 reaches only the devices on ports in VLAN 10.

A device in VLAN 10 cannot send a frame to a device in VLAN 20 no matter what address it uses, because the switch will not forward the frame out of a port in a different VLAN.

The separation is enforced at layer 2 of the network, which is the part worth being precise about. It is not a firewall rule, not an access list and not an address range. The switch simply does not have a path between the two networks.

That has one consequence people find surprising: a VLAN is not a subnet. In practice almost every virtual LAN carries exactly one subnet, because a broadcast domain and an IP network are the same shape, and putting two subnets on one VLAN or one subnet across two VLANs creates problems for no benefit.

The convention is so consistent that the words get used interchangeably, but they describe different layers. The subnet is the address range. The VLAN is the boundary the frames cannot cross.

Why they existWhat VLANs are actually for

Four reasons account for almost every virtual LAN in service, and they are worth separating because the first is the original one and the second is the one people now assume.

Containing broadcast traffic. This is why VLANs exist at all. Every device on a network broadcasts, and in one large broadcast domain every one of those frames reaches every machine, which each has to process. Splitting the network into VLANs means a broadcast in one VLAN is work only for the devices in that VLAN.

Making network segmentation possible. Putting the cameras, the guest wireless and the servers on separate VLANs is what allows a rule to be written between them. This is the security use, and it is the reason most VLANs get created now.

Grouping devices regardless of where they sit. Two people in different parts of a building can be on one VLAN, and two people at adjacent desks can be on different ones. The network follows the role rather than the cabling, and moving somebody is a change to one port in the configuration rather than a change to the wiring.

Giving traffic different treatment. The VLAN tag carries three priority bits, so voice traffic in its own VLAN can be handled ahead of a large file transfer. It is the simplest form of quality of service in a small network and the usual reason phones get a VLAN of their own.

The management benefit runs through all four. A network divided into named VLANs is one where the question "what can reach the data on the servers" has an answer, and one where the answer can be changed by editing a configuration rather than by tracing a cable.

On a flat network the same question has no answer at all, because everything can reach everything.

One VLAN deserves naming on its own: the management VLAN, the network the switches and access points themselves are reachable on. Leaving management addresses in the same VLAN as staff computers means anyone on a desk can reach the login page of every switch in the building.

Putting them in a VLAN reachable only from the machines that administer the network is the single highest value piece of segmentation in most small networks, and it costs one more VLAN.

Ports and taggingAccess ports, trunk ports and the tag

A VLAN that only exists on one switch needs no further configuration. The moment it spans two network switches, the link between them has to carry more than one VLAN, and the receiving switch has to know which VLAN each frame came from. That is what tagging solves.

An access port carries one VLAN and sends frames untagged. This is where devices plug into the network. The computer has no idea which virtual LAN it is in, sends ordinary frames, and the switch associates them with the port's VLAN internally.

A trunk port carries many VLANs and tags the frames. This is the link between two network switches, or between a switch and a router or hypervisor. Each frame leaving a trunk gets four extra bytes naming its VLAN, and the switch at the other end reads that number and puts the frame back into the right VLAN.

Trunk vs access port, side by side:

Access portTrunk port
VLANs carriedExactly oneMany
Frames are taggedNoYes, except the native VLAN
What plugs inA computer, printer, cameraAnother switch, a router, a hypervisor
The device knows its VLANNoYes, it reads the tags
Configured withswitchport mode accessswitchport mode trunk
Which VLANs are allowedThe one assignedA list worth restricting
A second VLAN on the same portOnly a voice VLANEvery VLAN in the allowed list

The tag itself is small and sits immediately after the source MAC address.

untagged frame   [ dst MAC ][ src MAC ][ type ][ payload ]
tagged frame     [ dst MAC ][ src MAC ][ 8100 ][ pri | VLAN ID ][ type ][ payload ]
                                        2 bytes  2 bytes

Four bytes total. Two identify the frame as tagged, and two carry three priority bits and the twelve bit VLAN ID. Twelve bits is where the range comes from: 4096 values, with 0 and 4095 reserved, leaving 1 to 4094 to use.

Those four bytes push the maximum frame from 1518 bytes to 1522, which is why older network equipment sometimes drops full size tagged frames and why the term baby giant exists.

ConfigurationWhat the configuration looks like

Every vendor words this differently, and the shape is the same everywhere: a port is told which mode it is in and then which VLANs apply to it. The example below is Cisco IOS, because that is the syntax most VLAN documentation is written in.

! an access port, for a desk with a phone and a computer behind it
interface GigabitEthernet0/5
 switchport mode access
 switchport access vlan 10
 switchport voice vlan 20
!
! the trunk to the next switch
interface GigabitEthernet0/24
 switchport mode trunk
 switchport trunk native vlan 999
 switchport trunk allowed vlan 10,20,30,40,99

Four lines in that configuration carry the whole idea.

switchport mode access and switchport mode trunk are stated explicitly. Leaving the mode to negotiation is what allows a device on a desk to talk a port into becoming a trunk.

switchport access vlan 10 puts every untagged frame from that port into VLAN 10. That is the data VLAN for the port: the computer sends ordinary frames and never learns which network its data is traveling on.

switchport voice vlan 20 adds a second, tagged VLAN on the same port. The phone tags its own traffic into VLAN 20 and passes the computer through on the data VLAN untagged, which is how one cable serves two devices on two separate networks.

switchport trunk allowed vlan is a list, not a formality. Naming the VLANs a trunk may carry limits what a compromise on one switch can reach, and a trunk left at its default carries every VLAN the switch knows about.

Some older switches also need switchport trunk encapsulation dot1q before the mode can be set, on the hardware that still supports a second tagging format. If the command is rejected as invalid, the switch only speaks 802.1Q and there is nothing to choose.

The native VLANThe native VLAN, and why it is a security question

One VLAN on every trunk is carried untagged, and it is called the native VLAN. It exists for backward compatibility with network devices that do not understand tagging.

By default the native VLAN is VLAN 1, which is also the VLAN every port starts in. Both defaults are worth changing in the configuration, for the same security reason.

If an attacker is on an access port in VLAN 1, and VLAN 1 is also the native VLAN on a trunk, they can craft a frame with two tags. The first switch strips the outer tag, sees an untagged frame on the native VLAN, and forwards it along the trunk.

The second switch reads the inner tag and delivers the frame into whichever VLAN the attacker named. That is VLAN hopping by double tagging, and it works because the native VLAN is the one place in the configuration where a tag is trusted without being checked.

Three settings close it, and they cost nothing.

Move user ports off VLAN 1. No data and no device that matters should live in the default virtual LAN.

Set the native VLAN to an unused number that carries no devices, so a frame arriving untagged on a trunk lands nowhere.

Turn off dynamic trunking. A port that can negotiate itself into a trunk can be talked into it. The configuration should name access ports as access ports explicitly and trunks as trunks explicitly.

Inter-VLAN routingGetting between VLANs

Two VLANs cannot talk without something that routes, because a VLAN is a broadcast domain and a switch does not carry frames across one.

Three things can be that something: a layer 3 switch holding an address in each VLAN and routing internally, a router on one trunked link with a subinterface per VLAN, or a firewall in the same shape as the router.

The choice is a question about what the traffic between two VLANs is for. Routing that should be fast and unfiltered belongs on a layer 3 switch. Routing that should be examined belongs on a firewall, which is usually the answer for a guest, camera or payment segment.

Inter VLAN routing works through all three, what each host needs configured before any of them helps, and the two mistakes that stop the whole thing working.

A planA VLAN plan that works for a small office

Virtual LANs are cheap to create and expensive to redesign, so the plan matters more than the configuration that implements it. A workable network layout for a company of forty or so people.

VLANPurposeWhy it is separate
10Staff computersThe general population, and the largest range
20Voice, for the phonesTraffic that needs priority and predictable behavior
30Printers and shared devicesChatty, rarely patched, and nothing needs to reach them from outside
40ServersThe things every access rule is written about
50Guest wirelessInternet only, with no path to anything else
60Cameras, door controllers, building systemsDevices that are never updated and are a standing security risk
99Management, for switches and access pointsReachable only from the machines that manage the network
999Native VLAN on trunks, unusedNothing lives here, which is the point

Two rules make the plan useful rather than decorative.

Leave gaps in the numbering. VLAN 10, 20, 30 rather than 1, 2, 3, because the next network requirement always lands between two existing ones.

Write down what each VLAN is for. A virtual LAN whose purpose nobody remembers is one nobody dares to change, and a switch configuration accumulates those quickly.

Network segmentation alone does nothing until security rules exist. Putting the cameras in their own VLAN prevents nothing on its own, because the router will happily carry traffic between VLAN 60 and every other network. The VLAN makes a rule possible to write. Writing it is a separate step, and the one that is forgotten most often.

PitfallsWhere people go wrong

Assuming a VLAN is a security control by itself. It creates a network boundary that a router then crosses. Without an access list or a firewall rule on that router, two networks separated by VLANs are as connected as two ports on one switch.

Leaving everything in VLAN 1. The default VLAN is the one every attack assumes, it holds the management addresses of the switches until somebody moves them, and it is also the native VLAN on trunks unless it is changed.

Forgetting the trunk between two switches. A VLAN whose configuration is identical on two switches with an access port between them does not span them. The link has to be a trunk and it has to allow that virtual LAN.

Allowing every VLAN on every trunk. The allowed list on a trunk is a real security control. Restricting it limits what a compromise on one network switch can reach.

Mismatched native VLANs on the two ends of a trunk. Frames leak between the two native VLANs silently, and the symptom is network traffic appearing where it has no business being.

Building virtual LANs with no routing plan. Devices come up, cannot reach anything on the network, and the fix ends up being a hurried allow rule that undoes the separation.

Putting two subnets in one virtual LAN. Legal and almost always a mistake. The devices are in one broadcast domain and cannot reach each other without a router, which is exactly the confusion nobody needs.

ONE SWITCH, THREE NETWORKS, AND ONE LINK CARRYING ALL OF THEMONE PHYSICAL SWITCH1234567891011TRPORTS 1 to 4: VLAN 10, staffPORTS 5 to 8: VLAN 30, printersPORTS 9 to 11: VLAN 50, guestPORT 12: trunk, taggedNEXTSWITCHsame 3 VLANsON AN ACCESS PORT, THE FRAME IS UNTAGGEDdst MAC | src MAC | type | payloadON THE TRUNK, FOUR BYTES NAME THE VLANdst | src | 8100 | VLAN 30 | type | payloadA frame never crosses between the colors inside the switch. Reaching another VLAN takes a router.The devices on ports 1 to 11 have no idea any of this is happening.Change a port from VLAN 10 to VLAN 30 and the machine moves networks without moving desks.
The separation lives inside one box. The trunk on the right is the only place the VLAN numbers are written down on the wire.

ComparisonThree ways to separate a network, and what each one really guarantees

CriterionVLANSubnetSeparate switch
What layer it works atLayer 2Layer 3Physical
Enforced byThe switchNothing, it is an address rangeThe absence of a cable
Configured inSoftwareSoftwareHardware and cabling
Devices in it can talk directlyYesOnly if in the same VLANYes
Crossing it needs a routerYesYesYes
Cost to add anotherFreeFreeA switch
Survives a switch misconfigurationNoNoYes

The last row is the honest limit. VLAN separation is a configuration, and a configuration can be wrong. For the small number of things where a mistake is unacceptable, a physically separate network is still the stronger answer.

FAQFrequently asked questions

How do I configure a VLAN?

On a Cisco switch, create the VLAN and then set each port: an access port with switchport mode access and switchport access vlan <id> for an end device, and a trunk with switchport mode trunk and switchport trunk allowed vlan <list> for the link to the next switch.

Every vendor words a VLAN configuration differently, but the shape, a mode and then which VLANs apply, is the same everywhere. The section above walks through a working example.

What is a VLAN in simple terms?

A virtual LAN is a way to divide one physical network switch into several separate networks. Ports in different VLANs cannot reach each other directly, even though they are on the same box.

What is the difference between a VLAN and a subnet?

A VLAN is a layer 2 network boundary configured on switches. A subnet is a layer 3 range of IP addresses. Almost every VLAN carries exactly one subnet, which is why the words get used interchangeably.

How many VLANs can I have?

4094, from a 12 bit field with two values reserved. Practical network limits arrive long before that, usually in how many VLANs the switch hardware can handle at once.

What is the difference between an access port and a trunk port?

An access port carries one VLAN and sends frames untagged, for devices. A trunk port carries many VLANs and tags each frame, for links between switches.

When do I use a trunk port instead of an access port?

A trunk whenever the link has to carry more than one VLAN, which means links between switches and links to a router or a hypervisor. An access port everywhere a single device plugs in.

Can a port be both trunk and access?

Not in the sense of switching between them. The one exception is a voice VLAN, where an access port carries the computer untagged and the phone tagged on a second VLAN.

What happens if I plug a computer into a trunk port?

It receives tagged frames it does not understand and drops them, so it sees only the native VLAN if there is one. Nothing breaks loudly, which is why the misconfiguration survives.

What is 802.1Q?

The IEEE standard for VLAN tagging. It defines the four byte tag added after the source MAC address, which carries the VLAN ID and three priority bits.

Do network devices know which VLAN they are in?

Normally no. An access port strips and adds tags on the device's behalf, so a computer sends and receives ordinary untagged frames. Phones and hypervisors are the usual exceptions.

What is the native VLAN?

The one VLAN carried untagged on a trunk. Setting it to an unused number closes the double tagging attack that targets it.

Why should I move devices off VLAN 1?

Because it is the default everywhere, it is the native VLAN unless changed, and both facts are assumed by anyone attacking the switch.

How do two VLANs communicate?

Through something that routes between the two networks: a layer 3 switch, a router on a trunk link, or a firewall. No data crosses between them at layer 2.

Does a VLAN improve network security?

It makes security enforceable rather than providing it. The boundary only holds until a router crosses it, and the rule in the router configuration is what does the work.

Do VLANs reduce broadcast traffic?

Yes, and that was the original reason for them. Each VLAN is its own broadcast domain on the network, so a broadcast reaches only the ports in that VLAN.

What is a voice VLAN?

A second VLAN carried on an access port alongside the data VLAN, so an IP phone can tag its own traffic while the computer plugged into the back of it keeps sending data untagged.

Can VLANs span multiple switches?

Yes, and that is most of the point. The link between the network switches has to be a trunk that allows the VLAN, and the virtual LAN has to exist in the configuration on both.

What is the difference between VXLAN vs VLAN?

A VLAN separates traffic at layer 2 with a 12 bit tag, which allows about 4,000 segments on one switched network. VXLAN wraps layer 2 frames inside UDP packets with a 24 bit identifier, which allows about 16 million segments and lets them stretch across a routed network. Offices use VLANs. Data centers use VXLAN.

Read next · Network security What Is a Firewall? A VLAN makes a rule possible to write, and this is the thing that writes it. Open this next14 min
Also worth reading
One packet a weekA short, illustrated explainer every Tuesday. No vendor pitches, unsubscribe in one click.