VLANs explained: what they are, and how to plan them
KINNEX Team5 min read
A VLAN lets one switch behave like several. Devices in different VLANs cannot talk to each other except through a router or firewall, which is where rules are applied.
Why use them
Containing broadcast traffic, separating staff, guests, cameras and servers, and giving each group its own policy.
Planning
- Give each VLAN one purpose and one subnet.
- Use a numbering convention people can remember, such as 10 for servers, 20 for staff, 50 for CCTV, 99 for management.
- Keep a table: VLAN ID, name, subnet, gateway, who owns it.
- Leave gaps in the numbering for future use.
Access and trunk ports
Access ports carry one VLAN to an end device. Trunk ports carry several between switches and to the firewall. Allow only the VLANs needed on each trunk.
Common mistakes
- Leaving unused ports in the default VLAN.
- Allowing every VLAN on every trunk.
- Mismatched native VLANs.
- Forgetting the management VLAN, then losing access to switches.
- No documentation.
Between VLANs
Routing between VLANs should pass a firewall wherever the traffic matters. Write rules from the principle of least access.
Test
After changes, check that each device lands in the right VLAN and that blocked paths really are blocked.