A switch, by default, treats every connected device as part of the same flat network. That's fine for a handful of PCs — but it breaks down fast in a school, office, or campus where different groups of users shouldn't share the same broadcast domain. This is the problem VLANs solve.
What is a VLAN?
A VLAN (Virtual Local Area Network) is a logical grouping of switch ports that behaves like its own independent network, even though the devices may be plugged into the same physical switch. Traffic in VLAN 10 stays in VLAN 10 unless a router or Layer 3 device explicitly moves it somewhere else.
- Each VLAN is its own broadcast domain
- VLANs are identified by a number from 1 to 4094
- Devices in different VLANs cannot talk directly — they need routing
Why segment a network?
Segmentation isn't just about organization — it directly affects performance and security.
- Smaller broadcast domains — fewer devices see every broadcast, which reduces unnecessary traffic
- Isolation — a compromised device in one VLAN can't freely reach devices in another
- Logical grouping — group by department, device type, or purpose instead of physical location
A VLAN is a Layer 2 concept. Getting traffic between VLANs always requires a Layer 3 device — a router, or a switch capable of routing.
Configuring a VLAN
Creating a VLAN and assigning it to a port takes just a few commands. Here, we create VLAN 10, name it, and assign an access port to it:
What each line does
vlan 10— creates VLAN 10 if it doesn't already existname STUDENTS— gives the VLAN a human-readable nameswitchport mode access— sets the port to carry a single VLANswitchport access vlan 10— assigns the port to VLAN 10
Verifying your configuration
Always verify. show vlan brief lists every VLAN and which ports belong to it:
Creating a VLAN alone does nothing — it must also be assigned to a port with switchport access vlan, or that port stays in VLAN 1.