Flamingo Raises $4.5M Seed Round

Skip to content

The guest Wi-Fi, the office printers, the door controller and the finance laptops often share one flat network, so one compromised device can reach them all. Splitting them apart used to mean a separate switch per group, with the cabling to match. A VLAN does the same job in software on the switches you already own, and this guide explains how VLANs work, how tagging and trunk ports carry them, and how to set them up without leaving gaps.

TL;DR

  • A VLAN (virtual LAN) splits one physical switch into several separate networks. Devices in different VLANs can't talk to each other unless something routes between them.
  • VLANs travel between switches on trunk ports. Each frame on a trunk carries a small 802.1Q tag with a VLAN ID from 1 to 4094.
  • An access port belongs to one VLAN and sends untagged traffic. That's where laptops, printers and phones plug in.
  • The security value comes from the rules between VLANs, so route them through a firewall or an ACL, not a flat "allow all" router.
  • Harden the switch: turn off dynamic trunking, move everything off VLAN 1, give trunks an unused native VLAN, and shut ports nobody uses.

What Is a VLAN?

A VLAN, or virtual local area network, is a group of switch ports that behaves like its own separate network. Devices inside the group see each other. Devices outside it don't, even when they're plugged into the same switch.

Start with what a normal switch does. When a device sends a broadcast, such as a DHCP request asking "who can give me an address?", the switch floods it to every port. Everything plugged in hears it. That shared space is called a broadcast domain, and on a flat network it covers every device in the building.

A VLAN draws a line through that space. Put ports 1 to 12 in VLAN 10 and ports 13 to 24 in VLAN 20, and a broadcast from port 3 only reaches ports 1 to 12. As far as those devices can tell, they're on two separate switches. No new hardware, no new cables. The switch keeps a table of which port belongs to which VLAN and refuses to forward frames across the line.

That one idea is why VLANs show up in every office network larger than a home setup. Staff laptops, guest phones, printers, cameras and VoIP handsets all want different rules. With VLANs, each group gets its own network on the same switches, and you decide what may cross between them.

This short explainer from Eye on Tech covers the basic idea in a few minutes:

A VLAN is a layer 2 idea. It decides which ports can exchange Ethernet frames. It says nothing about IP addresses, which live at layer 3. In practice, each VLAN gets its own IP subnet, so VLAN 10 might be 10.0.10.0/24 and VLAN 20 might be 10.0.20.0/24. Keeping that one-to-one mapping makes troubleshooting far easier, and we come back to it near the end.

How VLAN Tagging Works: The 802.1Q Tag

Inside one switch, the port table is enough. The switch knows port 3 is in VLAN 10, so it keeps port 3's traffic in VLAN 10. The problem starts when traffic leaves that switch for another one. A single cable between two switches now carries frames from several VLANs, and the receiving switch needs to know which VLAN each frame belongs to.

The answer is a tag. The IEEE 802.1Q standard defines a small field inserted into the Ethernet frame, right after the source MAC address. It adds 4 bytes to the frame and holds four things:

FieldSizeWhat it does
TPID (Tag Protocol Identifier)16 bitsSet to 0x8100, it tells the receiver "this frame is tagged"
PCP (Priority Code Point)3 bitsPriority from 0 to 7, used for quality of service such as voice traffic
DEI (Drop Eligible Indicator)1 bitMarks frames that may be dropped first under congestion
VID (VLAN Identifier)12 bitsThe VLAN number itself

Twelve bits give 4,096 possible values. Two are reserved: 0 and 4095. That leaves 4,094 usable VLAN IDs, from 1 to 4094. Juniper's switch documentation states the same range and notes the reserved IDs can't be assigned. Individual switches may support fewer active VLANs than that, so check the model's data sheet before you design a numbering plan around big numbers.

End devices almost never see the tag. The switch adds it when a frame leaves on a trunk and strips it when the frame exits an access port toward a laptop or printer. The laptop sends and receives plain Ethernet and has no idea it lives in VLAN 10. That's the point. You change the network's shape without touching a single endpoint.

There are exceptions. VoIP phones, wireless access points, hypervisors and firewalls often send and receive tagged frames on purpose, because they carry more than one VLAN themselves. A Hyper-V or ESXi host might tag each virtual machine's traffic with a different VLAN ID so one physical uplink serves the web server, the database and the management network separately.

Access Ports vs Trunk Ports

Every switch port in a VLAN design plays one of two roles. Getting this distinction right solves a large share of VLAN problems before they start.

An access port belongs to exactly one VLAN. Traffic in and out of it is untagged. You plug end devices into access ports: laptops, desktops, printers, cameras. The switch silently assigns everything arriving on that port to its VLAN.

A trunk port carries many VLANs at once. Frames on it are tagged with 802.1Q, so the device on the other end can sort them. Trunks connect switch to switch, switch to firewall, switch to wireless access point, and switch to virtualization host.

Access portTrunk port
VLANs carriedOneMany (an allowed list)
FramesUntaggedTagged, except the native VLAN
Typical deviceLaptop, printer, cameraSwitch, firewall, access point, hypervisor
Main riskSomeone plugs in an unknown deviceCarrying VLANs that shouldn't be there
Hardening stepPort security or 802.1X, shut unused portsExplicit allowed list, unused native VLAN

A common middle case is the desk phone. Many IP phones have a small switch built in, with the PC plugged into the back of the phone. The switch port then carries a data VLAN for the PC (untagged) and a voice VLAN for the phone (tagged). Cisco calls this a voice VLAN. Other vendors call it an auxiliary VLAN or simply configure it as a trunk with one untagged VLAN. The effect is the same: one cable, two networks, and the phone's traffic can get its own priority through the PCP field.

Wireless works the same way. An access point connects to the switch on a trunk. Each SSID maps to a VLAN, so "Office-Staff" drops users into VLAN 10 and "Office-Guest" drops them into VLAN 20. The radio is shared. The networks behind it are not. If your guest Wi-Fi still runs WPA2 with a shared password, our guide to what WPA2 is covers why offices outgrow it.

What Is Trunking?

Trunking is the practice of carrying several VLANs over one link by tagging each frame. The link is the trunk. On modern networks, trunking means 802.1Q. Cisco's older ISL protocol did the same job with a different encapsulation, and you'll only meet it on very old gear.

Three settings decide how a trunk behaves.

The allowed VLAN list says which VLANs the trunk carries. Many switches default to "all VLANs", which is convenient and wide open. A trunk to a guest access point has no reason to carry the server VLAN. Listing only the VLANs each trunk needs keeps a mistake on one device from spreading.

The native VLAN is the one VLAN a trunk sends untagged. It exists for backward compatibility with devices that don't understand tags. Both ends of the trunk must agree on it. If one side says native VLAN 1 and the other says 999, untagged traffic lands in the wrong VLAN on the far side, and some switches log a mismatch warning while others stay quiet.

Dynamic trunking decides whether a port can become a trunk on its own. Cisco's Dynamic Trunking Protocol (DTP) lets two switches negotiate trunk mode automatically. It saves typing and creates a hole: a laptop running the right tool can pretend to be a switch, negotiate a trunk and receive traffic from every VLAN. The fix is simple and belongs in every build. Set each port explicitly to access or trunk, and turn negotiation off.

How VLANs Talk to Each Other

Separate VLANs can't talk to each other on their own. That's the security feature. It's also a problem the moment staff need to print, because the printer lives in another VLAN.

Traffic between VLANs has to be routed, which means a layer 3 device with a leg in each VLAN. There are three common ways to do it.

The first is router on a stick. One router or firewall connects to the switch with a single trunk. It has a virtual interface per VLAN, each with the gateway address for that subnet. Traffic from VLAN 10 to VLAN 20 goes up the trunk, gets routed, and comes back down. It's cheap and easy to reason about. The trunk becomes a bottleneck when a lot of traffic crosses between VLANs.

The second is a layer 3 switch. The switch itself routes between VLANs using switch virtual interfaces (SVIs), one per VLAN. It's fast, because routing happens in the switch's hardware. The catch is that a switch's access lists are usually simpler than a firewall's rules, and it's easy to end up with every VLAN able to reach every other VLAN because nobody wrote the ACLs.

The third is the firewall as the gateway. Every VLAN's default gateway lives on the firewall, so every packet between VLANs passes through firewall rules. This is where segmentation turns into security. You write rules like "guest may reach the internet and nothing else" and "IoT may reach its cloud service and the NVR, nothing more", and the firewall logs what it blocks. If you want the background on how those rules track connections, our guide to a stateful firewall explains it.

Offices often mix the second and third. Busy internal traffic, such as staff to file server, routes on a core layer 3 switch. Anything touching guests, IoT or the internet goes through the firewall. The rule of thumb: the more you distrust a VLAN, the closer its gateway should sit to the firewall.

One more thing breaks when you add VLANs: DHCP. Clients find a DHCP server by broadcasting, and broadcasts stop at the VLAN boundary. If the DHCP server sits in VLAN 10, devices in VLAN 20 get nothing unless the router or layer 3 switch relays their requests. Cisco calls the setting ip helper-address, and other vendors call it DHCP relay. Forget it, and the new VLAN looks dead. The same boundary is why broadcast tools such as Wake-on-LAN stop working across VLANs, which our Wake-on-LAN guide covers.

Why Offices Split Networks Into VLANs

The reason to use VLANs is containment. A flat network lets any device reach any other. When one of them is compromised, the attacker gets the same reach.

That isn't hypothetical guidance. The NSA's network infrastructure security guide (version 1.2, October 2023) describes attackers taking a foothold on easy targets such as printers and moving from there. It recommends putting similar systems into their own subnets or VLANs and keeping workstations, servers, printers and phones apart. CISA's segmentation guidance, published in January 2023, describes segmentation as dividing a network into segments that each act as their own subnetwork, with its own security and control.

For a small or mid-sized office, a VLAN plan rarely needs more than six or seven networks. Here's a starting layout. The IDs are only a convention, so pick any numbers and write them down.

VLANNameWhat lives thereMay reach
10StaffCompany laptops and desktopsInternet, servers, printers
20GuestVisitor phones and laptopsInternet only
30IoTCameras, door access, smart TVs, sensorsTheir own cloud service or NVR only
40VoiceIP desk phonesPhone system and its provider
50ServersFile server, domain controller, NVRStaff, backups, updates
60PrintersPrinters and scannersNothing that starts a connection
99ManagementSwitch, AP and firewall admin interfacesOnly reached from an admin workstation

The guest and IoT networks earn their place first. Guests bring devices you've never seen. IoT gear often ships with old firmware, default passwords and cloud connections nobody documented. The typical way it shows up is that another department buys a system and asks IT for "access to the network" after the contract is signed. Isolating those devices in their own VLAN, with a short allow list at the firewall, limits what a compromised camera can reach.

A 2026 r/sysadmin thread on setting up a firewall for a small office is a good example of the questions that come up at this stage:

Management deserves its own line too. If a switch's admin page answers on the staff VLAN, any staff laptop with malware can try to log into it. A management VLAN that only an admin workstation or a jump host can reach removes that path. The same goes for compliance. The PCI Security Standards Council's scoping and segmentation guidance explains how isolating card systems can shrink an audit's scope, and VLANs plus firewall rules are a common way to build that isolation.

Before you draw the plan, it helps to know what's on the network today. A discovery pass with network mapping software gives you the device list you'll sort into VLANs.

VLAN Security: Where Segmentation Leaks

A VLAN is a boundary drawn by the switch's configuration. If the configuration has a hole, the boundary does too. Two attacks, both grouped under the name VLAN hopping, show where.

Switch spoofing abuses dynamic trunking. An attacker's device answers the switch's DTP messages and negotiates a trunk. Now the port carries every allowed VLAN, and the attacker can send and receive traffic in all of them. It works only when a user-facing port is left in a dynamic mode. The NSA guide puts it plainly: an adversary connected to a dynamic port could turn it into a trunk and reach traffic "without regard to VLAN separation."

Double tagging abuses the native VLAN. The attacker sits in a VLAN that happens to match a trunk's native VLAN, often VLAN 1, and sends a frame with two 802.1Q tags. The first switch strips the outer tag, because native VLAN traffic goes out untagged, and forwards the frame down the trunk. The next switch reads the inner tag and delivers the frame into the target VLAN. It's one-way traffic, but one-way is enough to reach a vulnerable service or send a malicious packet. It only works when the attacker's access VLAN equals the trunk's native VLAN.

Both attacks share a root cause: defaults. Switches ship with every port in VLAN 1, VLAN 1 as the native VLAN on trunks, and on some models dynamic trunking switched on. The NSA's recommendations target each one. Turn off dynamic trunking and set every port to access or trunk explicitly. Move all traffic off VLAN 1 and disallow it on trunks and access ports. Give trunks a native VLAN that's unique, unused by any host and assigned only to trunks.

Here's the NSA's trunk example in Cisco syntax, with two changes: the allowed list names the office VLANs, and switchport nonegotiate stops the port from sending DTP messages at all.

code
vlan 500
 name NATIVE-TRUNK
vlan 997
 name UNUSED-ACCESS
 shutdown
interface <INTERFACE>
 switchport mode trunk
 switchport nonegotiate
 switchport access vlan 997
 switchport trunk native vlan 500
 switchport trunk allowed vlan 10,20,30,40,50,60,99

The guide's own example allows VLANs 2 to 4094 and adds that if you know every VLAN in use, you should list only those. The access VLAN 997 is shut down, so the trunk port has nowhere to drop a device if it ever falls back to access mode.

There's a limit worth stating clearly. A VLAN separates traffic at layer 2. It doesn't inspect anything. If a layer 3 switch routes between all VLANs with no ACLs, you have seven broadcast domains and one flat security zone. The protection comes from the rules at the gateway. That's also why a penetration test often starts by checking which VLANs can reach which, and our guide to network penetration testing explains what testers look for on the inside.

A VLAN Hardening Checklist for Office Switches

The whole list takes about an afternoon per site, and none of it needs new hardware. Work through it on each switch, then save the configuration and back it up. It stays on the switch itself; the wider office build is a separate job.

#CheckWhy
1Every port set to access or trunk explicitly, negotiation offStops switch spoofing
2No device traffic on VLAN 1Removes the default VLAN that spans the whole network
3Trunks use a unique, unused native VLANBlocks double tagging
4Each trunk carries only the VLANs it needsContains mistakes to one path
5Unused ports shut down and placed in a dead VLANNothing works if someone plugs into a spare jack
6Port security or 802.1X on user portsLimits which devices can connect
7Management interfaces on a management VLAN onlyStaff and guest devices can't reach admin pages
8Inter-VLAN traffic passes through firewall rules or ACLsSegmentation becomes enforcement
9DHCP relay set for every VLAN that needs itNew VLANs get addresses on day one
10VLAN plan documented: IDs, names, subnets, allowed flowsThe next technician doesn't guess

On port security, the NSA suggests limiting each access port to one MAC address, or two where a phone and PC share the port, and shutting the port or sending an alert on a violation. It treats port security as a fallback where 802.1X network access control isn't practical.

Common VLAN Mistakes and How They Show Up

VLAN problems tend to look like "the network is down" or "only some things work." A handful of causes cover nearly all of them.

The classic is locking yourself out. You move the switch's management address to a new management VLAN, press enter, and your session drops, because your laptop is still in the old VLAN and nothing routes between them yet. Before changing management, check you have a path in on the new VLAN or console access to the switch. On remote sites, schedule a timed reload that rolls the change back if you don't confirm it.

The second is a new VLAN with no addresses. Devices join VLAN 30, get a 169.254 address and nothing else. The DHCP relay is missing, or the DHCP scope for that subnet doesn't exist. Running ipconfig commands on the affected machine shows the self-assigned address in seconds.

The third is a trunk that doesn't carry the VLAN. You create VLAN 40 for phones on the core switch, but the trunk to the access switch has a fixed allowed list that doesn't include it. Phones on that floor stay dark while phones on the core switch work.

The fourth is a native VLAN mismatch. Untagged traffic on one side lands in a different VLAN on the other. It can look like random devices appearing in the wrong subnet.

This r/HomeNetworking thread asks exactly the question that comes up the first time someone turns on VLAN support and watches the network go quiet:

When a site has dozens of devices, checking each one by hand gets slow. With OpenFrame, you can run a script across a client's devices and collect each one's IP address, subnet and gateway, which shows at a glance which VLAN every machine landed on.

VLAN vs Subnet vs Physical Separation

These three get mixed up, so here's how they relate.

A VLAN is a layer 2 boundary. It decides which switch ports share a broadcast domain.

A subnet is a layer 3 boundary. It decides which IP addresses are local to each other and which need a gateway. In a clean design, each VLAN has exactly one subnet, and the numbering matches: VLAN 20, subnet 10.0.20.0/24. You can put two subnets in one VLAN or stretch one subnet across VLANs, but both make troubleshooting harder and neither buys you security.

Physical separation means different switches, different cables and a firewall between them. It's stronger than VLANs, because an attacker has to compromise the device in the middle to cross over, and a switch misconfiguration can't merge the networks. The NSA guide and CISA both point to physical separation for operational technology, such as building controls or industrial systems, which should stay isolated from the office network and the internet.

For a typical office, VLANs plus firewall rules are the right balance. They cost nothing extra on managed switches and cover guests, IoT, voice and management. Save physical separation for systems where a mistake would be expensive. How those pieces are laid out, star or mesh, is a question of network topology, which we cover separately.

The Short Version

A VLAN turns one physical switch into several separate networks. Frames crossing between switches carry an 802.1Q tag with a VLAN ID, trunk ports carry many VLANs, and access ports put end devices into one. The security value comes from what you allow between VLANs, so route them through firewall rules, not an open layer 3 switch. Then close the defaults: no dynamic trunking, nothing on VLAN 1, an unused native VLAN on trunks, and every spare port shut. If you're reviewing an office network, the next read is our guide to the attack surface, because a flat network is one of its largest parts.

Kristina Shkriabina

Content Marketing Lead

Ohayo! I run content, SEO, social, and community at Flamingo. Before IT, I worked as a correspondent for Ukraine's Public Broadcasting Company and have a Master's in journalism.

Related Content

Blog Posts

Product Releases

Podcasts

Webinars

Case Studies

Events

Onboarding Guides

Frequently Asked Questions

VLAN

A VLAN is a group of switch ports that behaves like its own separate network. Devices in the same VLAN can reach each other directly, while devices in different VLANs need a router or firewall to talk, even when they plug into the same physical switch.
A VLAN is a layer 2 boundary that decides which switch ports share a broadcast domain. A subnet is a layer 3 boundary that decides which IP addresses are local to each other. In a clean design each VLAN carries exactly one subnet, such as VLAN 20 with 10.0.20.0/24.
An access port belongs to one VLAN and sends untagged frames, so it is where laptops, printers and cameras connect. A trunk port carries many VLANs at once using 802.1Q tags and connects switches, firewalls, access points and hypervisors.
The native VLAN is the one VLAN a trunk port sends without a tag. Both ends of the trunk must agree on it. The NSA recommends giving trunks a unique native VLAN that no host uses, which blocks double-tagging VLAN hopping.
VLANs separate traffic but do not inspect it. The security comes from the rules applied where traffic crosses between VLANs, usually on a firewall or in switch ACLs. A layer 3 switch that routes every VLAN to every other VLAN with no rules gives little protection.
The 802.1Q VLAN ID field is 12 bits, which allows 4,094 usable VLAN IDs from 1 to 4094, since 0 and 4095 are reserved. Individual switches may support fewer active VLANs, and a typical small office needs six or seven.

MSP AI Agents

On a five-person desk, reported deployments show $78,000 to $130,000 in annual direct labor savings, roughly 30% fewer escalations, and 15% to 20% better SLA compliance. Broader MSP adoption data adds ticket handling time cut by 45% and five to 12 points of margin, all from reclaimed capacity rather than headcount cuts.
Yes. In production MSP shops today, 10% to 25% of tickets close before a human opens them. Thread alone has processed 173 million tickets across 750-plus MSP partners at 96% triage accuracy, handing back 490,000-plus technician hours. Agents own the low-risk, high-volume work (password resets, MFA enrollment, known installs, onboarding and offboarding) and flag anything that touches production data or needs judgment for a human to take.

About OpenFrame

OpenFrame isn't built to plug into your stack. It replaces it. Instead of duct-taping a dozen tools together (RMM, MDM, SIEM, patching, remote access, each its own login and bill), we bundle it into one unified platform: RMM, MDM, monitoring, automation, remote access, patch management, security monitoring, and ticketing, plus built-in AI copilots. So "does it integrate with X?" usually means: you won't need X anymore.
Most platforms give you one piece and expect you to bolt the rest on. OpenFrame unifies the whole stack in one place, with AI copilots built in. Fewer logins, fewer bills, less duct tape.