One physical switch does not have to mean one network. VLANs let us logically divide a switched LAN into separate Layer 2 broadcast domains — giving us segmentation without needing a separate switch for every network.
A Virtual Local Area Network (VLAN) is a logical segmentation of a Layer 2 network.
Without VLANs, devices connected to the same switched LAN normally belong to the same Layer 2 broadcast domain. A broadcast such as an ARP request can therefore be flooded through that broadcast domain.
VLANs allow us to split the switch into multiple logical Layer 2 networks. Devices in VLAN 10 are in a different broadcast domain from devices in VLAN 20, even if they are connected to the same physical switch.
Separate groups of devices without buying physically separate switches.
A Layer 2 broadcast remains inside its VLAN rather than being flooded into every other VLAN.
Users, phones, servers, management devices and other systems can be placed into logical networks based on their purpose.
Imagine four computers connected to the same physical switch. Two ports belong to VLAN 10 and two belong to VLAN 20.
If PC-A sends a Layer 2 broadcast, SW1 can flood that broadcast to the appropriate ports in VLAN 10. It does not flood that frame into VLAN 20.
Likewise, broadcasts originating in VLAN 20 remain in VLAN 20.
VLANs are identified using a numeric VLAN ID.
| VLAN | Example purpose |
|---|---|
| 10 | Staff |
| 20 | Guest devices |
| 30 | VoIP phones |
| 99 | Network management |
The numbers above are simply examples. The VLAN ID does not inherently mean "staff", "voice" or "management" — that meaning comes from the network design and configuration.
On Cisco switches you will commonly encounter:
VLAN IDs are carried using a 12-bit VLAN identifier in an IEEE 802.1Q tag. The values 0 and 4095 are reserved, leaving usable VLAN IDs 1 through 4094.
A port connected to an ordinary endpoint such as a desktop computer is typically configured as an access port.
An access port belongs to one access VLAN and normally carries ordinary Ethernet frames to and from the endpoint without an 802.1Q VLAN tag. The switch internally associates traffic arriving on that port with the configured VLAN.
Let's create two VLANs and give them useful names.
Switch> enable
Switch# configure terminal
Switch(config)# vlan 10
Switch(config-vlan)# name STAFF
Switch(config-vlan)# exit
Switch(config)# vlan 20
Switch(config-vlan)# name GUEST
Switch(config-vlan)# exit
At this point VLANs 10 and 20 exist on the switch, but we haven't yet assigned our endpoint ports to them.
Suppose a staff PC is connected to interface GigabitEthernet0/1. We want that interface to belong to VLAN 10.
Switch(config)# interface gigabitEthernet 0/1
Switch(config-if)# switchport mode access
Switch(config-if)# switchport access vlan 10
Switch(config-if)# no shutdown
Now configure another interface for a guest device in VLAN 20:
Switch(config)# interface gigabitEthernet 0/2
Switch(config-if)# switchport mode access
Switch(config-if)# switchport access vlan 20
Switch(config-if)# no shutdown
switchport mode access makes the intended port role clear
rather than relying on dynamic behaviour or defaults.
One of the most useful VLAN commands is:
Switch# show vlan brief
VLAN Name Status Ports
---- -------------------------------- --------- -----------------------
1 default active Gi0/3, Gi0/4
10 STAFF active Gi0/1
20 GUEST active Gi0/2
This quickly tells us:
For a specific interface, another useful command is:
Switch# show interfaces gigabitEthernet 0/1 switchport
Name: Gi0/1
Switchport: Enabled
Administrative Mode: static access
Operational Mode: static access
Access Mode VLAN: 10 (STAFF)
A switch learns source MAC addresses as Ethernet frames arrive. VLAN membership is part of the switching context, so the MAC address table associates learned addresses with a VLAN and interface.
Switch# show mac address-table
Mac Address Table
-------------------------------------------
Vlan Mac Address Type Ports
---- ----------- -------- -----
10 0011.2233.4455 DYNAMIC Gi0/1
20 00aa.bbcc.ddee DYNAMIC Gi0/2
When forwarding a frame, the switch considers the destination MAC address within the relevant VLAN.
The interface may have been accidentally assigned to a different VLAN.
Use show vlan brief.
Confirm the required VLAN exists on the switch.
Check that the interface is operational and has not been administratively shut down.
Hosts in different VLANs require Layer 3 routing if they need to communicate with each other.
show vlan brief is one of your most useful verification
commands.
# Create VLAN
vlan 10
name STAFF
# Configure access port
interface gigabitEthernet 0/1
switchport mode access
switchport access vlan 10
# Verify VLANs
show vlan brief
# Verify switchport
show interfaces gigabitEthernet 0/1 switchport
# View learned MAC addresses
show mac address-table
We have multiple VLANs on one switch. Next, we'll learn how to carry those VLANs between switches using trunk links and 802.1Q tagging.