VLANs

LANs drawbacks

A traditional switched LAN has three main drawbacks:

Drawback Explanation

1. No traffic isolation

Broadcast traffic (such as ARP requests and DHCP discovery messages) is sent throughout the entire network.

Limiting the scope of broadcast traffic would improve:

  • performance, by reducing unnecessary traffic
  • security and privacy, because one department's traffic does not reach devices in another department

2. Inefficient use of switches

Suppose there are 10 departments:

  • a traditional design would require 10 separate access switches
  • if each department is small (< 10 people): a single 96-port switch could accommodate everyone
  • however, placing everyone on one switch would eliminate traffic isolation

3. Difficult user management

If an employee changes departments: the physical network cable must be moved to another switch.

If an employee belongs to multiple groups, the problem becomes even more complicated.

Each of these difficulties can be handled by a switch that supports virtual local area networks (VLANs).

What is a VLAN?

A Virtual Local Area Network (VLAN) allows multiple logical LANs to share the same physical switch.

In a port-based VLAN, the network administrator assigns switch ports to VLANs.

Each VLAN forms its own broadcast domain, meaning:

For example, on a 16-port switch:

A single switch with two configured VLANs

This VLAN provides several benefits:

Communication between VLANs

Complete isolation introduces a new problem: how can devices in the EE VLAN communicate with devices in the CS VLAN?

The traditional solution is to connect the VLAN switch to a router:

Logically, this is equivalent to having two separate switches connected by a router.

Today, most enterprise switches include both switching and routing functionality, so a separate external router is usually unnecessary.

VLANs across multiple switches

Suppose some EE and CS hosts are located in a different building but should still belong to their department's VLAN.

A second 8-port switch can be used where the switch ports are defined as belonging to the EE or the CS VLAN:

VLANs across multiple switches

How should the two switches be interconnected?

Solution (a): dedicated links for each VLAN

This approach does not scale: N VLANS would require N ports on each switch.

Solution (b): VLAN trunking:

How does a switch know that a frame crossing a VLAN trunk belongs to a particular VLAN?

The IEEE 802.1Q standard extends the Ethernet frame by adding a 4-byte VLAN tag into the header:

Other ways to define VLANs

Although port-based VLANs are the most common, VLANs can also be defined in other ways.

Previous Link-layer switches All ⏎ Next Retrospective: a day in the life of a web page request

A Kemar Joint