What Is a VLAN? A Plain Explanation for Beginners
A clear beginner guide to VLANs: what they are, why networks use them, how 802.1Q tagging and trunk ports work, and how devices on different VLANs talk to each other.

On this page
If you have ever plugged a computer into an office switch and wondered why everyone seems to share one big network, that is exactly what is happening. A basic switch connects all of its ports into a single broadcast domain, which means a single network. Every device sees every broadcast, and any device can usually reach any other device without asking permission.
A VLAN is the tool that fixes this. It splits one physical switch into several logical networks that stay separate even though they share the same hardware. Once you understand the idea, the jargon around tagging, trunk ports, and native VLANs becomes much easier to follow.
The Problem a VLAN Solves
Switches forward traffic based on hardware addresses, and broadcast traffic is sent to every port. Address resolution requests, DHCP discovery, and many discovery protocols all broadcast by default. On a small network that is harmless. On a larger one it becomes noise that every device has to process, and it means a single misconfigured device can disrupt far more than its own connection.
Physical separation would solve this, but buying a separate switch for each group is expensive and inflexible. People move desks, devices change roles, and new teams appear. A VLAN gives you the separation without the extra hardware, because the boundary is configured rather than physical. A port can belong to a different group tomorrow with a configuration change.
What a VLAN Actually Is
A VLAN, short for virtual local area network, is a logical grouping of switch ports and devices that behave as if they are on their own network. Two devices in the same VLAN communicate as if they were plugged into the same switch. Two devices in different VLANs do not, even if they are plugged into adjacent ports on the same hardware.
Most switches treat each VLAN as its own independent switch inside the device. The switch keeps a separate forwarding table for each one, and broadcasts stay inside the VLAN they started in. This is why people describe a VLAN as a way to divide one switch into several.
The word virtual is doing real work here. Nothing about the cabling tells you which VLAN a device is in, and the physical location does not have to match the group. A port on the second floor can belong to the same VLAN as a port on the first, as long as the path between them carries that VLAN.
Tagged and Untagged Frames
Once a frame leaves one switch and travels to another, the receiving switch needs to know which VLAN it belongs to. The 802.1Q standard solves this by inserting a small tag into the Ethernet frame. The tag adds four bytes and carries the VLAN identifier plus a small priority value and a drop eligibility bit.
An untagged frame has no such tag, and a port that sends and receives untagged frames belongs to a single VLAN by configuration. A tagged frame carries its VLAN number so a port that handles many VLANs can tell them apart. That is the entire mechanical difference between an access port and a trunk port.
The tag is small, but it is the reason one cable between two switches can carry traffic for many VLANs at once. Without it, the receiving switch would have no way to keep the segments apart.
Access Ports, Trunk Ports, and the Native VLAN
An access port connects to an end device and belongs to exactly one VLAN. It sends and receives untagged frames, and the switch adds or removes the tag at the edge so the device itself never has to understand VLANs. Your laptop plugged into a wall port is almost always on an access port.
A trunk port connects to another switch, a router, or a server that needs several VLANs, and it carries tagged frames for all of them. Trunks are how a VLAN spans more than one switch. The trunk link itself belongs to no single VLAN, because it is a shared path for many.
Trunks also carry one untagged VLAN, called the native VLAN, for historical compatibility. The default is VLAN 1, and both ends of the link must agree on it. A mismatch is a classic cause of confusing behavior, so many teams change the native VLAN to a dedicated unused value and explicitly avoid VLAN 1 for real traffic.
VLAN IDs and the 802.1Q Standard
Each VLAN is identified by a number from 1 to 4094. The identifier field in the tag is 12 bits wide, which allows values from 0 to 4095. Two values are reserved and a small legacy block sits near the top, which is why the usable range stops at 4094 rather than 4095.
In practice, stay inside the normal range unless you have a reason to go higher, and avoid the default VLAN for user traffic. Many networks also reserve a management VLAN so that switches and infrastructure can be reached on a known segment separate from user devices.
Inter VLAN Routing
A VLAN is a Layer 2 construct, so it cannot route traffic to another VLAN on its own. If the devices show up on different networks, something at Layer 3 has to move traffic between them. A router with an interface for each VLAN, or a Layer 3 switch with a virtual interface for each, provides that path.
A common design is the router on a stick, where one physical link carries tagged traffic for several VLANs and the router uses a subinterface for each one. The Layer 3 switch approach is more common in larger networks because it routes between segments at high speed without sending every flow through a separate router.
Handling this traffic is also where policy belongs. Routing between VLANs is convenient, but a segment boundary only becomes a security boundary when you add access rules or a firewall that decides what may cross it. A VLAN on its own separates traffic, it does not filter it.
A Simple Example You Can Picture
Imagine a home or small office with one managed switch and one router. You put your computers and printer on the main VLAN, your guest Wi-Fi and smart speakers on a guest VLAN, and the switch and router management interfaces on a management VLAN. All three share the same hardware and the same internet connection.
Now consider what a guest device can do. On the guest VLAN it can reach the internet and the other guest devices, but the router keeps it away from your computers and your printer. The management VLAN stays reachable only from the administrator’s own devices. You have created separation without buying a second switch or running new cable.
The same pattern scales to a large network. Departments, floors, tenants, and device types each get their own segment, and the Layer 3 devices decide what is allowed to cross between them. When a VLAN grows beyond the reach a single broadcast domain can reasonably support, overlays such as VXLAN extend the same idea across far more segments than the 4094 identifier limit allows.
The Key Takeaway
A VLAN takes one physical switch and turns it into several logical networks that stay separate at Layer 2. Access ports belong to a single VLAN and carry untagged frames, trunk ports carry many VLANs using 802.1Q tags, and routing between VLANs happens only at Layer 3. The identifier space is large enough for almost any network, and the practice is mostly about clear naming and consistent configuration on both ends of a link.
The best next step is to look at your own network and pick two groups that should not share traffic, perhaps guests and internal devices. Most home routers and managed switches can create that segment in a few screens. Configure it, test what can and cannot reach what, and you will understand VLANs far better than any diagram can teach you.
Frequently Asked Questions
What is a VLAN in simple terms?
What is the difference between an access port and a trunk port?
Can devices on different VLANs talk to each other?
Does a VLAN make my network secure?
Free Tools
Put this into practice with the free calculators, reference tables, and checklists in the Obelinf toolkit.
Stop reaching for a spreadsheet
Obelinf keeps every subnet, device, circuit, and rack in one live source of truth, with audit logs and a topology view. Free for personal use.
Related Articles

AWS VPC Design Best Practices: CIDR, Subnets, and Routing
Design an AWS VPC the right way: size the CIDR block, lay out public, private, and isolated subnets across availability zones, and wire route tables without common mistakes.
Read more
Fiber Optic Cable Types Explained: OS1, OS2, OM3, OM4
Understand single mode and multimode fiber grades, what OS1, OS2, OM3, OM4, and OM5 mean, how far each reaches, and how to pick the right cable for a run.
Read more
Kubernetes Network Policies Explained with Examples
Learn how Kubernetes NetworkPolicy objects work, why default deny matters, how ingress and egress selectors combine, and which CNI plugins actually enforce them.
Read more