Volver a la wiki

VLANs: Virtual Networks Explained

What is a VLAN

A VLAN (Virtual Local Area Network) splits one physical switch into several independent logical networks. Devices in a VLAN can only talk to each other directly — as if they were plugged into separate switches — even though they share the same hardware.

Physical switch (24 ports)
┌─────────────────────────────────────────┐
│  VLAN 10 (Mgmt)       VLAN 20 (Data)    │
│  ┌─────────────┐      ┌──────────────┐  │
│  │ P1  P2  P3  │      │ P4  P5  P6   │  │
│  └─────────────┘      └──────────────┘  │
│  VLAN 30 (VoIP)       VLAN 99 (Native)  │
│  ┌─────────────┐      ┌──────────────┐  │
│  │ P7  P8  P9  │      │ P10 ... P24  │  │
│  └─────────────┘      └──────────────┘  │
└─────────────────────────────────────────┘

Why use VLANs

Access vs trunk ports

Access port

Belongs to one VLAN. The connected device never sees any VLAN tagging — the switch handles it transparently. This is where you plug in servers, PCs and phones.

Trunk port

Carries traffic for multiple VLANs at once. Each frame carries a tag identifying its VLAN. Trunks are used between switches, or between a switch and a router/firewall.

Server ──[access VLAN 20]── Switch A ══[trunk]══ Switch B ──[access VLAN 20]── Server
                                                          ──[access VLAN 10]── Admin PC

802.1Q tagging

IEEE 802.1Q is the standard that defines how Ethernet frames are tagged with VLAN information. It inserts 4 bytes into the frame header:

FieldBitsDescription
TPID16Protocol identifier (0x8100)
PCP3Priority (QoS)
DEI1Drop eligible indicator
VLAN ID12The VLAN identifier

The 12-bit field gives 4094 usable VLANs (IDs 1–4094; 0 and 4095 are reserved). On a trunk, one VLAN — the native VLAN — travels untagged.

Common VLANs in a datacenter

VLAN IDNamePurpose
1DefaultFactory default — avoid using it
10ManagementManagement interfaces (iLO, iDRAC, switch management)
20ServersProduction server traffic
30StorageStorage network (iSCSI, NFS)
40VoIPIP telephony
50DMZInternet-facing servers
99NativeCustom native VLAN (good practice)
100MonitoringSNMP, syslog, metrics traffic
999BlackholeUnused ports (security)

Good practice: never use VLAN 1 as a working VLAN. Move the native VLAN to a dedicated ID (e.g. 99) and assign unused ports to a VLAN with no connectivity (e.g. 999).

Inter-VLAN routing

By design, VLANs are isolated from each other. For devices in different VLANs to communicate, traffic must be routed:

  1. Router-on-a-stick — a router connected by one trunk, with a subinterface per VLAN. Simple, but the single link can become a bottleneck.
  2. Layer 3 switch — a switch with routing capability creates a virtual interface (SVI) per VLAN and routes between them in hardware. The standard approach in datacenters.

VLANs in CreaRack

When documenting your network in CreaRack, you can record which VLANs ride on each switch port as part of the port configuration — see [[crearack—racks—port-mapping]]. That makes it easy to see which network segments pass through each device. Observatory monitors the state of switch interfaces via SNMP, including those carrying your VLANs.

Véase también

Subir