Chapter 18: VLANs and 802.1Q
This chapter follows the topics shown in the Networking chapter menu. Work through each section in order, then use the review questions to check recall and troubleshooting reasoning.
18.1 VLAN Introduction
A VLAN creates a logical Layer 2 broadcast domain on switching infrastructure. Traffic between VLANs requires a Layer 3 forwarding function.
Example: users in VLAN 20 can communicate with one another through switches, but reaching VLAN 30 requires a Layer 3 gateway. If one trunk omits VLAN 20, only paths crossing that trunk fail.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
18.2 Broadcast Domains
Broadcast Domains concerns traffic delivered to every member of a Layer 2 or IP broadcast scope. Broadcast behavior matters because excessive or unintended broadcasts can consume shared capacity and reveal segmentation problems.
Example: place Broadcast Domains in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
18.3 VLAN IDs
A VLAN creates a logical Layer 2 broadcast domain on switching infrastructure. Traffic between VLANs requires a Layer 3 forwarding function.
Example: users in VLAN 20 can communicate with one another through switches, but reaching VLAN 30 requires a Layer 3 gateway. If one trunk omits VLAN 20, only paths crossing that trunk fail.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
18.4 Access VLAN
A VLAN creates a logical Layer 2 broadcast domain on switching infrastructure. Traffic between VLANs requires a Layer 3 forwarding function.
Example: users in VLAN 20 can communicate with one another through switches, but reaching VLAN 30 requires a Layer 3 gateway. If one trunk omits VLAN 20, only paths crossing that trunk fail.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
18.5 Voice VLAN
A VLAN creates a logical Layer 2 broadcast domain on switching infrastructure. Traffic between VLANs requires a Layer 3 forwarding function.
Example: users in VLAN 20 can communicate with one another through switches, but reaching VLAN 30 requires a Layer 3 gateway. If one trunk omits VLAN 20, only paths crossing that trunk fail.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
18.6 Management VLAN
A VLAN creates a logical Layer 2 broadcast domain on switching infrastructure. Traffic between VLANs requires a Layer 3 forwarding function.
Example: users in VLAN 20 can communicate with one another through switches, but reaching VLAN 30 requires a Layer 3 gateway. If one trunk omits VLAN 20, only paths crossing that trunk fail.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
18.7 Native VLAN
NAT changes IP address information as traffic crosses a translation boundary. PAT is a many-to-one form that also distinguishes conversations by transport-layer port numbers.
Example: users in VLAN 20 can communicate with one another through switches, but reaching VLAN 30 requires a Layer 3 gateway. If one trunk omits VLAN 20, only paths crossing that trunk fail.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
18.8 802.1Q Tagging
IEEE 802.1Q tagging inserts VLAN information into Ethernet frames on links that carry multiple VLANs. A native VLAN may be sent untagged depending on the design.
Example: place 802.1Q Tagging in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
18.9 Trunk Ports
Trunk Ports is one of the core topics in VLANs and 802.1Q. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.
Example: place Trunk Ports in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
18.10 Allowed VLAN List
A VLAN creates a logical Layer 2 broadcast domain on switching infrastructure. Traffic between VLANs requires a Layer 3 forwarding function.
Example: users in VLAN 20 can communicate with one another through switches, but reaching VLAN 30 requires a Layer 3 gateway. If one trunk omits VLAN 20, only paths crossing that trunk fail.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
18.11 Native VLAN Mismatch
NAT changes IP address information as traffic crosses a translation boundary. PAT is a many-to-one form that also distinguishes conversations by transport-layer port numbers.
Example: users in VLAN 20 can communicate with one another through switches, but reaching VLAN 30 requires a Layer 3 gateway. If one trunk omits VLAN 20, only paths crossing that trunk fail.
What to check
- Confirm the symptom and determine whether the problem affects one host, one segment, one site, or many sites.
- Compare actual configuration and measurements with the intended design, baseline, or documentation.
- Change one variable at a time, verify the result, and document both the cause and the final fix.
18.12 VLAN Pruning Concepts
A VLAN creates a logical Layer 2 broadcast domain on switching infrastructure. Traffic between VLANs requires a Layer 3 forwarding function.
Example: users in VLAN 20 can communicate with one another through switches, but reaching VLAN 30 requires a Layer 3 gateway. If one trunk omits VLAN 20, only paths crossing that trunk fail.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
18.13 VLAN Assignment
A VLAN creates a logical Layer 2 broadcast domain on switching infrastructure. Traffic between VLANs requires a Layer 3 forwarding function.
Example: users in VLAN 20 can communicate with one another through switches, but reaching VLAN 30 requires a Layer 3 gateway. If one trunk omits VLAN 20, only paths crossing that trunk fail.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
18.14 Inter-Switch VLAN Connectivity
A VLAN creates a logical Layer 2 broadcast domain on switching infrastructure. Traffic between VLANs requires a Layer 3 forwarding function.
Example: users in VLAN 20 can communicate with one another through switches, but reaching VLAN 30 requires a Layer 3 gateway. If one trunk omits VLAN 20, only paths crossing that trunk fail.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
18.15 VLAN Troubleshooting
A VLAN creates a logical Layer 2 broadcast domain on switching infrastructure. Traffic between VLANs requires a Layer 3 forwarding function.
Example: users in VLAN 20 can communicate with one another through switches, but reaching VLAN 30 requires a Layer 3 gateway. If one trunk omits VLAN 20, only paths crossing that trunk fail.
What to check
- Confirm the symptom and determine whether the problem affects one host, one segment, one site, or many sites.
- Compare actual configuration and measurements with the intended design, baseline, or documentation.
- Change one variable at a time, verify the result, and document both the cause and the final fix.
18.16 Guest VLAN
A VLAN creates a logical Layer 2 broadcast domain on switching infrastructure. Traffic between VLANs requires a Layer 3 forwarding function.
Example: users in VLAN 20 can communicate with one another through switches, but reaching VLAN 30 requires a Layer 3 gateway. If one trunk omits VLAN 20, only paths crossing that trunk fail.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
18.17 IoT VLAN
A VLAN creates a logical Layer 2 broadcast domain on switching infrastructure. Traffic between VLANs requires a Layer 3 forwarding function.
Example: users in VLAN 20 can communicate with one another through switches, but reaching VLAN 30 requires a Layer 3 gateway. If one trunk omits VLAN 20, only paths crossing that trunk fail.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
18.18 Server VLAN
A VLAN creates a logical Layer 2 broadcast domain on switching infrastructure. Traffic between VLANs requires a Layer 3 forwarding function.
Example: users in VLAN 20 can communicate with one another through switches, but reaching VLAN 30 requires a Layer 3 gateway. If one trunk omits VLAN 20, only paths crossing that trunk fail.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
18.19 VLAN Security
A VLAN creates a logical Layer 2 broadcast domain on switching infrastructure. Traffic between VLANs requires a Layer 3 forwarding function.
Example: users in VLAN 20 can communicate with one another through switches, but reaching VLAN 30 requires a Layer 3 gateway. If one trunk omits VLAN 20, only paths crossing that trunk fail.
What to check
- Identify the trust boundary and the traffic that should be permitted or denied.
- Check authentication, authorization, encryption, policy order, logs, and time synchronization.
- Verify the control with an allowed test and a denied test so policy behavior is observable.
18.20 VLAN Design
A VLAN creates a logical Layer 2 broadcast domain on switching infrastructure. Traffic between VLANs requires a Layer 3 forwarding function.
Example: users in VLAN 20 can communicate with one another through switches, but reaching VLAN 30 requires a Layer 3 gateway. If one trunk omits VLAN 20, only paths crossing that trunk fail.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.