VLANs: Virtual Networks Explained
What is a VLAN
A VLAN (Virtual Local Area Network) splits one physical switch into several independent logical networks. Devices in a VLAN can only talk to each other directly — as if they were plugged into separate switches — even though they share the same hardware.
Physical switch (24 ports)
┌─────────────────────────────────────────┐
│ VLAN 10 (Mgmt) VLAN 20 (Data) │
│ ┌─────────────┐ ┌──────────────┐ │
│ │ P1 P2 P3 │ │ P4 P5 P6 │ │
│ └─────────────┘ └──────────────┘ │
│ VLAN 30 (VoIP) VLAN 99 (Native) │
│ ┌─────────────┐ ┌──────────────┐ │
│ │ P7 P8 P9 │ │ P10 ... P24 │ │
│ └─────────────┘ └──────────────┘ │
└─────────────────────────────────────────┘
Why use VLANs
- Security — isolate sensitive traffic (management interfaces, cameras, storage) from the rest of the network.
- Performance — smaller broadcast domains mean less background noise per segment.
- Organization — group devices by function, not by where they happen to be plugged in.
- Compliance — separate networks where regulation demands it (PCI-DSS, HIPAA).
Access vs trunk ports
Access port
Belongs to one VLAN. The connected device never sees any VLAN tagging — the switch handles it transparently. This is where you plug in servers, PCs and phones.
Trunk port
Carries traffic for multiple VLANs at once. Each frame carries a tag identifying its VLAN. Trunks are used between switches, or between a switch and a router/firewall.
Server ──[access VLAN 20]── Switch A ══[trunk]══ Switch B ──[access VLAN 20]── Server
──[access VLAN 10]── Admin PC
802.1Q tagging
IEEE 802.1Q is the standard that defines how Ethernet frames are tagged with VLAN information. It inserts 4 bytes into the frame header:
| Field | Bits | Description |
|---|---|---|
| TPID | 16 | Protocol identifier (0x8100) |
| PCP | 3 | Priority (QoS) |
| DEI | 1 | Drop eligible indicator |
| VLAN ID | 12 | The VLAN identifier |
The 12-bit field gives 4094 usable VLANs (IDs 1–4094; 0 and 4095 are reserved). On a trunk, one VLAN — the native VLAN — travels untagged.
Common VLANs in a datacenter
| VLAN ID | Name | Purpose |
|---|---|---|
| 1 | Default | Factory default — avoid using it |
| 10 | Management | Management interfaces (iLO, iDRAC, switch management) |
| 20 | Servers | Production server traffic |
| 30 | Storage | Storage network (iSCSI, NFS) |
| 40 | VoIP | IP telephony |
| 50 | DMZ | Internet-facing servers |
| 99 | Native | Custom native VLAN (good practice) |
| 100 | Monitoring | SNMP, syslog, metrics traffic |
| 999 | Blackhole | Unused ports (security) |
Good practice: never use VLAN 1 as a working VLAN. Move the native VLAN to a dedicated ID (e.g. 99) and assign unused ports to a VLAN with no connectivity (e.g. 999).
Inter-VLAN routing
By design, VLANs are isolated from each other. For devices in different VLANs to communicate, traffic must be routed:
- Router-on-a-stick — a router connected by one trunk, with a subinterface per VLAN. Simple, but the single link can become a bottleneck.
- Layer 3 switch — a switch with routing capability creates a virtual interface (SVI) per VLAN and routes between them in hardware. The standard approach in datacenters.
VLANs in CreaRack
When documenting your network in CreaRack, you can record which VLANs ride on each switch port as part of the port configuration — see [[crearack—racks—port-mapping]]. That makes it easy to see which network segments pass through each device. Observatory monitors the state of switch interfaces via SNMP, including those carrying your VLANs.
Related
- [[crearack—redes-infra—switches-routers]] — the switches that implement VLANs
- [[crearack—redes-infra—direccionamiento-ip]] — the IP subnets behind each VLAN
- [[crearack—redes-infra—cableado]] — the physical trunks carrying VLANs
- [[crearack—redes-infra—conceptos-snmp]] — reading interface state via SNMP
- [[crearack—racks—port-mapping]] — documenting VLANs per port in CreaRack
- [[crearack—monitoring—que-es-observatory]] — monitoring switch interfaces
Véase también
- [[crearack—redes-infra—switches-routers]]
- [[crearack—redes-infra—direccionamiento-ip]]
- [[crearack—redes-infra—cableado]]
- [[crearack—redes-infra—conceptos-snmp]]
- [[crearack—racks—port-mapping]]
- [[crearack—monitoring—que-es-observatory]]