9 min read

What Is a VLAN? A Plain Explanation for Beginners

A clear beginner guide to VLANs: what they are, why networks use them, how 802.1Q tagging and trunk ports work, and how devices on different VLANs talk to each other.

ByAndré Ribeiro· Founder, Obelinf
What Is a VLAN? A Plain Explanation for Beginners
What Is a VLAN? A Plain Explanation for Beginners · October 7, 2026
On this page

If you have ever plugged a computer into an office switch and wondered why everyone seems to share one big network, that is exactly what is happening. A basic switch connects all of its ports into a single broadcast domain, which means a single network. Every device sees every broadcast, and any device can usually reach any other device without asking permission.

A VLAN is the tool that fixes this. It splits one physical switch into several logical networks that stay separate even though they share the same hardware. Once you understand the idea, the jargon around tagging, trunk ports, and native VLANs becomes much easier to follow.

The Problem a VLAN Solves

Switches forward traffic based on hardware addresses, and broadcast traffic is sent to every port. Address resolution requests, DHCP discovery, and many discovery protocols all broadcast by default. On a small network that is harmless. On a larger one it becomes noise that every device has to process, and it means a single misconfigured device can disrupt far more than its own connection.

Physical separation would solve this, but buying a separate switch for each group is expensive and inflexible. People move desks, devices change roles, and new teams appear. A VLAN gives you the separation without the extra hardware, because the boundary is configured rather than physical. A port can belong to a different group tomorrow with a configuration change.

What a VLAN Actually Is

A VLAN, short for virtual local area network, is a logical grouping of switch ports and devices that behave as if they are on their own network. Two devices in the same VLAN communicate as if they were plugged into the same switch. Two devices in different VLANs do not, even if they are plugged into adjacent ports on the same hardware.

Most switches treat each VLAN as its own independent switch inside the device. The switch keeps a separate forwarding table for each one, and broadcasts stay inside the VLAN they started in. This is why people describe a VLAN as a way to divide one switch into several.

One physical switch divided into two isolated VLANs for staff devices and guest devicesOne physical switch, two logical networksVLAN 10staff computers and printerstheir own broadcast domainVLAN 20guest and smart devicesseparate from the staff networkno directtrafficOne physical switchThe groups share hardware, not traffic.

The word virtual is doing real work here. Nothing about the cabling tells you which VLAN a device is in, and the physical location does not have to match the group. A port on the second floor can belong to the same VLAN as a port on the first, as long as the path between them carries that VLAN.

Tagged and Untagged Frames

Once a frame leaves one switch and travels to another, the receiving switch needs to know which VLAN it belongs to. The 802.1Q standard solves this by inserting a small tag into the Ethernet frame. The tag adds four bytes and carries the VLAN identifier plus a small priority value and a drop eligibility bit.

An untagged frame has no such tag, and a port that sends and receives untagged frames belongs to a single VLAN by configuration. A tagged frame carries its VLAN number so a port that handles many VLANs can tell them apart. That is the entire mechanical difference between an access port and a trunk port.

Where the 802.1Q tag sits inside an Ethernet frame and what the tag fields containThe 802.1Q tag adds four bytes to the frameDest MACSrc MAC802.1QTypePayloadFCS0x8100PCPDEIVLAN ID0x8100 marks the tag. The 12 bit VLAN ID is what identifies the segment.

The tag is small, but it is the reason one cable between two switches can carry traffic for many VLANs at once. Without it, the receiving switch would have no way to keep the segments apart.

Access Ports, Trunk Ports, and the Native VLAN

An access port connects to an end device and belongs to exactly one VLAN. It sends and receives untagged frames, and the switch adds or removes the tag at the edge so the device itself never has to understand VLANs. Your laptop plugged into a wall port is almost always on an access port.

A trunk port connects to another switch, a router, or a server that needs several VLANs, and it carries tagged frames for all of them. Trunks are how a VLAN spans more than one switch. The trunk link itself belongs to no single VLAN, because it is a shared path for many.

Trunks also carry one untagged VLAN, called the native VLAN, for historical compatibility. The default is VLAN 1, and both ends of the link must agree on it. A mismatch is a classic cause of confusing behavior, so many teams change the native VLAN to a dedicated unused value and explicitly avoid VLAN 1 for real traffic.

VLAN IDs and the 802.1Q Standard

Each VLAN is identified by a number from 1 to 4094. The identifier field in the tag is 12 bits wide, which allows values from 0 to 4095. Two values are reserved and a small legacy block sits near the top, which is why the usable range stops at 4094 rather than 4095.

Usable and reserved VLAN identifier ranges under the 802.1Q standardThe VLAN identifier space from 0 to 40950reserved1default VLAN2 to 1001normal user VLANs1006 to 4094extended rangeVLANs 1002 to 1005 are reserved for legacy technologies and are best left alone.VLAN 4095 is reserved, so the highest usable identifier is 4094.

In practice, stay inside the normal range unless you have a reason to go higher, and avoid the default VLAN for user traffic. Many networks also reserve a management VLAN so that switches and infrastructure can be reached on a known segment separate from user devices.

Inter VLAN Routing

A VLAN is a Layer 2 construct, so it cannot route traffic to another VLAN on its own. If the devices show up on different networks, something at Layer 3 has to move traffic between them. A router with an interface for each VLAN, or a Layer 3 switch with a virtual interface for each, provides that path.

A common design is the router on a stick, where one physical link carries tagged traffic for several VLANs and the router uses a subinterface for each one. The Layer 3 switch approach is more common in larger networks because it routes between segments at high speed without sending every flow through a separate router.

A Layer 3 device routing traffic between two VLANs over a tagged trunk linkDevice AVLAN 10Switchtrunk, taggedLayer 3 gatewayroutes between VLANsDevice BVLAN 20Without a Layer 3 hop, the two VLANs stay completely separate.

Handling this traffic is also where policy belongs. Routing between VLANs is convenient, but a segment boundary only becomes a security boundary when you add access rules or a firewall that decides what may cross it. A VLAN on its own separates traffic, it does not filter it.

A Simple Example You Can Picture

Imagine a home or small office with one managed switch and one router. You put your computers and printer on the main VLAN, your guest Wi-Fi and smart speakers on a guest VLAN, and the switch and router management interfaces on a management VLAN. All three share the same hardware and the same internet connection.

Now consider what a guest device can do. On the guest VLAN it can reach the internet and the other guest devices, but the router keeps it away from your computers and your printer. The management VLAN stays reachable only from the administrator’s own devices. You have created separation without buying a second switch or running new cable.

The same pattern scales to a large network. Departments, floors, tenants, and device types each get their own segment, and the Layer 3 devices decide what is allowed to cross between them. When a VLAN grows beyond the reach a single broadcast domain can reasonably support, overlays such as VXLAN extend the same idea across far more segments than the 4094 identifier limit allows.

The Key Takeaway

A VLAN takes one physical switch and turns it into several logical networks that stay separate at Layer 2. Access ports belong to a single VLAN and carry untagged frames, trunk ports carry many VLANs using 802.1Q tags, and routing between VLANs happens only at Layer 3. The identifier space is large enough for almost any network, and the practice is mostly about clear naming and consistent configuration on both ends of a link.

The best next step is to look at your own network and pick two groups that should not share traffic, perhaps guests and internal devices. Most home routers and managed switches can create that segment in a few screens. Configure it, test what can and cannot reach what, and you will understand VLANs far better than any diagram can teach you.

Frequently Asked Questions

What is a VLAN in simple terms?
A VLAN is a logical group of devices that behave as if they are on their own separate network, even when they share the same physical switch. It divides one switch into several isolated groups so broadcasts and traffic stay within each group.
What is the difference between an access port and a trunk port?
An access port belongs to a single VLAN and sends untagged frames to whatever device is plugged into it, such as a computer. A trunk port carries traffic for several VLANs at once using 802.1Q tags so the other end knows which VLAN each frame belongs to.
Can devices on different VLANs talk to each other?
Only if a Layer 3 device routes between them. A router or a Layer 3 switch needs an interface or gateway for each VLAN, and then it forwards traffic from one segment to the other just as it would between any two networks.
Does a VLAN make my network secure?
A VLAN separates traffic and reduces the size of a broadcast domain, but it is not a firewall. Devices can still be reached or attacked across VLANs once routing exists unless you add access control lists or a firewall policy between the segments.

Free Tools

Put this into practice with the free calculators, reference tables, and checklists in the Obelinf toolkit.

Stop reaching for a spreadsheet

Obelinf keeps every subnet, device, circuit, and rack in one live source of truth, with audit logs and a topology view. Free for personal use.

Related Articles