What is a VLAN? How one switch is split into separate broadcast domains
A VLAN (virtual LAN) groups switch ports under a number, and each group is its own broadcast domain: ports in one VLAN talk at Layer 2 as usual, while different VLANs cannot see each other. That number is the VLAN ID, 1 to 4094; on links shared by several VLANs, an 802.1Q tag carries it.
What is a VLAN? VLAN stands for virtual local area network: a logical LAN carved out of a physical switch. The switch gives each port a number, the VLAN ID, forwards frames only between ports with the same number, and sends broadcasts only to ports in the same VLAN. One 48-port switch can therefore carry a production network, a management network and an IPMI network at the same time with no Layer 2 path between them, exactly as if you had built each one on its own switch. VLANs are defined by the IEEE 802.1Q standard, and the VLAN ID is a 12-bit number with a usable range of 1 to 4094.
Without VLANs, one switch is one broadcast domain
A switch forwards frames using its MAC address table. For every frame it receives, it records which port the source MAC address came from, then looks up the destination MAC address; if it finds it, the frame goes out of that one port. Frames for a destination the switch has not learned yet (unknown unicast), and broadcasts addressed to FF:FF:FF:FF:FF:FF, are flooded out of every port except the one they arrived on.
ARP requests and DHCP discover messages are both broadcasts. On a switch with factory settings every port is in VLAN 1, so a 24-port switch is one broadcast domain: every ARP request from any server reaches the other 23 ports, and every server is fully visible to every other at Layer 2. Before VLANs, separating database servers from public-facing web servers, or putting BMC management ports on a network of their own, meant buying more switches and running separate cabling.
How a switch uses VLANs to split broadcast domains
Once VLANs are configured, the switch does three extra things:
- Assigns each port to a VLAN: for example, ports 1–4 to VLAN 10 and ports 5–8 to VLAN 20.
- Classifies every incoming frame: a frame arriving on port 3 belongs to VLAN 10 inside the switch.
- Looks up and floods per VLAN: the MAC address table is keyed on VLAN plus MAC address, and broadcasts and unknown unicasts go only to other ports in the same VLAN.
Take an 8-port switch configured that way, and assume the server on port 1 already knows the other servers’ MAC addresses:
| Source | Frame | What the switch does | Sent to |
|---|---|---|---|
| Port 1 (VLAN 10) | ARP broadcast | Floods it within VLAN 10 | Ports 2, 3, 4 |
| Port 5 (VLAN 20) | ARP broadcast | Floods it within VLAN 20 | Ports 6, 7, 8 |
| Port 1 (VLAN 10) | Unicast to the server on port 2 | Finds port 2 among VLAN 10’s entries | Port 2 only |
| Port 1 (VLAN 10) | Unicast to the server on port 6 | That MAC was learned only in VLAN 20, so VLAN 10 has no entry for it; the frame is flooded as unknown unicast within VLAN 10 | Ports 2, 3, 4; port 6 never receives it |
The last row shows where the isolation comes from: the switch simply never delivers a VLAN 10 frame to a VLAN 20 port. On a Cisco switch, the first column of the MAC address table is the VLAN:
Switch# show mac address-table dynamic
Mac Address Table
-------------------------------------------
Vlan Mac Address Type Ports
---- ----------- -------- -----
10 0050.56a1.0001 DYNAMIC Gi1/0/1
10 0050.56a1.0002 DYNAMIC Gi1/0/2
20 0050.56a1.0005 DYNAMIC Gi1/0/5
Huawei and H3C switches show the same table with display mac-address, which also has a VLAN column. If the same MAC address shows up in two VLANs, those are two unrelated entries.
For servers in VLAN 10 to talk to servers in VLAN 20, traffic has to leave Layer 2 and be routed by a Layer 3 device: a virtual interface for each VLAN on a Layer 3 switch acting as the gateway, or a router or firewall. That is why every VLAN gets its own subnet.
VLAN ID vs VLAN tag: what is the difference?
The two terms are often used interchangeably, but they are different things. The VLAN ID is the VLAN’s number: the membership the switch assigns to each port and each frame. The tag is how that number is written into an Ethernet frame, and it is only needed when a frame crosses a link that carries more than one VLAN.
Picture two switches joined by a single cable that has to carry both VLAN 10 and VLAN 20. When the far switch receives a frame, how does it know which VLAN the frame belongs to? The sender inserts a 4-byte 802.1Q tag right after the source MAC address. The tag begins with the type value 0x8100, followed by a 3-bit priority field, a 1-bit DEI flag and the 12-bit VLAN ID. The receiver reads the ID and puts the frame into that VLAN. Here is what a frame looks like at each point along the way:
| Where the frame is | Tagged? | Where its VLAN membership comes from |
|---|---|---|
| Server NIC to a switch access port | No | The switch assigns the port’s VLAN |
| Inside the switch | Every frame carries an internal VLAN membership | From the port or from the tag |
| Switch to switch (trunk) | Yes, carrying the VLAN ID | Read from the tag |
| Switch to a virtualization host (trunk) | Yes | The host uses the tag to deliver frames to the right VM network |
| Switch access port to a server | No, the tag is removed before sending | — |
So an ordinary server has no idea which VLAN it is in. It sends and receives plain Ethernet frames, and its VLAN is decided entirely by the switch port it is plugged into. Only links between switches, and between switches and hypervisors, speak 802.1Q. Exactly how each port type handles tagged and untagged frames is the topic of access, trunk and hybrid port modes, which this article does not cover.
VLAN IDs also come with rules about which values you can use:
| VLAN ID | Use |
|---|---|
| 0 | Not a VLAN; the tag carries only a priority value |
| 1 | The default VLAN: every port starts in it and it cannot be deleted. Keep production traffic out of it |
| 2–1001 | Normal range, free to use |
| 1002–1005 | Reserved by Cisco for legacy FDDI and Token Ring and cannot be used; Huawei and H3C have no such restriction |
| 1006–4094 | Called the extended range by Cisco; older IOS releases could only create these VLANs in VTP transparent mode or with VTP version 3, depending on the release |
| 4095 | Reserved, cannot be used |
Some platforms also set aside a block of VLANs for internal use. Cisco Nexus switches reserve a range starting at VLAN 3968 by default, and some Catalyst platforms allocate internal VLANs from 1006 upward for routed ports, which you can list with show vlan internal usage. The exact ranges vary by model and software version, so check every platform you run for reserved blocks before you draw up a network-wide VLAN numbering plan.
VLAN vs physical network segment
A physical segment means one network gets its own switch or set of switches, so who can reach whom is decided by cabling. With VLANs it is decided by configuration. Data centers use both approaches:
| Aspect | Physical segment (one network, one set of switches) | VLAN (one switch, several networks) |
|---|---|---|
| How isolation works | Networks are not physically connected | The switch separates traffic by VLAN ID, as configured |
| Hardware and cabling | One set of switches and cables per network | Switches are shared; one trunk carries many VLANs between switches |
| Moving a server to another network | Re-cable on site or swap switches | Change the port’s VLAN in the configuration |
| Extending a network across racks or floors | Run dedicated cabling for that network | Allow the VLAN on the trunk |
| Bandwidth | Each network has its own switches and uplinks | VLANs share ports, uplinks and switching capacity |
| Impact of a failure | A failed switch affects one network | A failed switch takes down every VLAN on it |
| Impact of a configuration mistake | Hard to connect the wrong things | A port in the wrong VLAN, or a wrong trunk allowed list, joins networks that should be separate |
| Suited to | Networks that must be physically isolated | Most production networks |
A common compromise in data centers: production networks are split with VLANs, while the out-of-band management network (server IPMI/BMC ports and switch management ports) gets at least its own VLAN and, where possible, its own switches, so you can still get in remotely when something goes wrong on the production network.
A VLAN is not a subnet either
A VLAN is a Layer 2 concept: it decides which ports a frame can reach. A subnet is a Layer 3 concept: it decides which hosts a machine considers local and when it has to go through a gateway. The two normally map one to one, but the switch does not check that for you. Two mismatches come up again and again:
- Two subnets in one VLAN: servers in 10.0.10.0/24 and 10.0.20.0/24 are all in VLAN 10. They need a gateway to reach each other, so they look isolated, but they share one broadcast domain and receive each other’s ARP and DHCP broadcasts. A single rogue DHCP server can hand machines in the other subnet the wrong addresses.
- One subnet split across two VLANs: half the servers in 10.0.10.0/24 are in VLAN 10 and the other half in VLAN 20. Each host believes the others are on its local network and sends ARP requests for them directly, but ARP broadcasts cannot cross the VLAN boundary. The servers cannot reach each other, and they never fall back to the gateway.
What is a VLAN switch?
A VLAN switch is not a separate kind of device; the term simply means a switch that supports 802.1Q. By capability, switches fall into four groups:
| Switch type | 802.1Q VLANs | Routing between VLANs | Where it fits in a data center |
|---|---|---|---|
| Unmanaged switch | No, there is nothing to configure | No | Only as a temporary port extender; keep it out of production |
| Smart or web-managed switch | Most support them; some offer only local port-based VLANs that add no 802.1Q tags and cannot span switches | No | Small offices, CCTV networks |
| Layer 2 managed switch | Yes, with access, trunk and other port modes | No; traffic between VLANs needs an uplink to a Layer 3 device | Access layer in the rack |
| Layer 3 switch | Yes | Yes, with an SVI (VLANIF) as each VLAN’s gateway | Aggregation and core layers |
Beyond basic support, look at the numbers: how many VLANs can be active at once, how many SVIs the switch can hold and how large its MAC table is all vary by model, so check the datasheet. And watch for unmanaged switches in the path. They cannot read VLANs, so every device plugged into one ends up in the same broadcast domain, whichever VLAN it was meant to be in. A small switch quietly added to a rack is a common hazard for exactly this reason.
Keeping VLANs and subnets in sync in a management system
Once the relationship between VLANs and subnets is clear, it becomes obvious that day-to-day problems are rarely about the concept itself. They are about the mapping: which VLAN a port is in, which subnet that VLAN uses, and whether your records match what is actually configured on the switch. In Toplink DCIM, switch management shows the switch port, port speed and VLAN for every machine in the server list. When a customer goes live or moves, you change the port’s VLAN in the web interface and the system translates the change into vendor commands. IP address management records, for every IP block, the VLAN it lives in and the switch that holds its gateway. Compare the VLAN on the port with the VLAN on the block, and mismatches such as two subnets in one VLAN, or one subnet split across two VLANs, are easy to spot.
FAQ
Why should production traffic stay out of VLAN 1?
VLAN 1 is the catch-all: any device plugged into an unconfigured port lands in it, and Cisco Layer 2 protocols such as CDP, VTP and DTP use VLAN 1 by default. If production traffic shares it, a device plugged into the wrong port can see production broadcasts. Put both production and management in VLANs you create, and leave VLAN 1 empty.
What if 4094 VLANs are not enough?
The 802.1Q VLAN ID has only 12 bits, giving 4094 usable values. Carriers and data centers often use QinQ (IEEE 802.1ad), which adds an outer tag around the original one; the two layers together can tell apart about 16.76 million (4094 × 4094) networks. Cloud platforms mostly use VXLAN, which identifies segments with a 24-bit VNI.
What is the difference between a VLAN and an SVI?
A VLAN is a Layer 2 broadcast domain. An SVI (switched virtual interface, called VLANIF on Huawei and Vlan-interface on H3C) is a virtual Layer 3 interface that a Layer 3 switch creates for one VLAN; give it an IP address and it becomes that VLAN's gateway. A VLAN with no SVI and no gateway on a router or firewall works internally, but its traffic cannot leave it.