skip to content

What does an IEEE 802.1Q tag add to an Ethernet frame, and why does its 12-bit VLAN ID allow only 4,094 VLANs?

level: middleimportance: should knowfreq 40%

answer

  1. four bytes after the source MAC
  2. a type value, then control information
  3. priority, drop eligibility, identifier
  4. two of 4,096 values set aside

basics

~20 s

An 802.1Q tag inserts 4 bytes after the source MAC: TPID 0x8100, then a 3-bit priority (PCP), a 1-bit drop-eligible flag (DEI) and a 12-bit VLAN ID. Twelve bits give 4,096 values; 0 and 4095 are reserved, leaving 1-4094.

solid answer

~50 s

The tag is **4 bytes** inserted between the source MAC address and the frame's original EtherType. Its first 2 bytes are the **TPID**, `0x8100`, the EtherType value IEEE assigns to the 802.1Q customer VLAN tag (C-tag), sitting exactly where an untagged frame keeps its EtherType. The next 2 bytes are the **Tag Control Information**: a 3-bit **PCP** (priority 0-7), a 1-bit **DEI** (drop eligible indicator, formerly CFI) and a 12-bit **VID**. Twelve bits give 4,096 values, but VID `0` means no VLAN at all, just a priority (a priority-tagged frame), and VID `4095` (`0xFFF`) is reserved, so usable VLANs are **1 to 4094**. The frame grows by 4 bytes, which is why IEEE 802.3 allows a 1,522-byte tagged frame against 1,518 untagged, and a switch must recompute the FCS whenever it adds or strips a tag.

code

pseudocode · 4 lines
pseudocode
tci = 0xA014                  // 1010 0000 0001 0100
pcp = (tci >> 13) & 0x7       // 101 -> 5
dei = (tci >> 12) & 0x1       // 0   -> not drop-eligible
vid = tci & 0x0FFF            // 0x014 -> VLAN 20

go deeper

for a junior

Remember the tag is 4 bytes, starts with 0x8100 and carries a 12-bit VLAN ID, so usable VLANs run from 1 to 4094.

for a middle

Walk the TCI bit by bit, PCP, DEI and VID, explain why 0 and 4095 are reserved, and say where the tag sits and why the FCS must be recomputed.

for a senior

Connect the 4-byte growth to real failures, such as gear that drops 1,522-byte frames or stacked tags overflowing a link's frame size, and explain the PCP ordering where 0 outranks 1.

for a principal

Weigh the 4,094-ID ceiling against tenant growth, and decide when stacking tags or moving to an overlay with a wider segment ID is the better design.

## Where the tag sits An untagged Ethernet II frame starts with the destination MAC (6 bytes), the source MAC (6 bytes) and a 2-byte **EtherType** that names the payload (`0x0800` for IPv4, for example). IEEE 802.1Q inserts its 4-byte tag between the source MAC and that EtherType: | Bytes (from the destination MAC) | Untagged frame | 802.1Q-tagged frame | |---|---|---| | 0-5 | destination MAC | destination MAC | | 6-11 | source MAC | source MAC | | 12-13 | EtherType, e.g. `0x0800` | **TPID `0x8100`** | | 14-15 | payload starts | **Tag Control Information (TCI)** | | 16-17 | payload continues | original EtherType, e.g. `0x0800` | Putting the **Tag Protocol Identifier** (TPID) where the EtherType normally sits is the trick that makes tagging safe. Any receiver reads bytes 12-13 to decide what follows. A VLAN-aware switch sees `0x8100`, the EtherType value IEEE assigns to the 802.1Q customer VLAN tag (the **C-tag**, formerly called the Q-tag), and knows a TCI comes next. A station that does not understand VLANs sees an unknown EtherType and discards the frame instead of misreading the tag as payload. ## The Tag Control Information, bit by bit | Field | Width | Meaning | |---|---|---| | **PCP** (priority code point) | 3 bits | Priority 0-7 for queueing | | **DEI** (drop eligible indicator) | 1 bit | Frame may be dropped first under congestion; this bit was called CFI in earlier editions of 802.1Q | | **VID** (VLAN identifier) | 12 bits | Which VLAN the frame belongs to | A worked example: a TCI of `0xA014` is `1010 0000 0001 0100` in binary. - The top three bits, `101`, give **PCP 5**. - The next bit, `0`, means **DEI clear**. - The low twelve bits, `0000 0001 0100`, are `0x014`, which is **VID 20**. ## Why 4,094 and not 4,096 1. Twelve bits encode 2^12 = 4,096 values, 0 through 4095. 2. VID **0** is the null VLAN ID: the frame carries a priority but names no VLAN. Such a frame is called **priority-tagged**, and the receiving switch assigns it to the port's own VLAN (its PVID) exactly as it would an untagged frame. 3. VID **4095** (`0xFFF`) is reserved and never identifies a VLAN. 4. That leaves 4,096 - 2 = **4,094** usable VLANs, IDs 1 to 4094 (RFC 4363 and RFC 5517 both restate this range from 802.1Q). The ceiling matters in large multi-tenant data centres: RFC 7348 names the 4,094-VLAN limit as one motivation for VXLAN, whose segment ID is 24 bits wide. ## The priority code point The three PCP bits let switches queue frames by class even where nobody looks at IP headers. 802.1Q's ordering is not simply numeric, as RFC 6325 restates it: **1 is the lowest priority, 7 the highest, and the default 0 ranks above 1 but below 2**. That keeps untagged, unclassified traffic (priority 0 by default) ahead of traffic deliberately marked as background. Which application gets which PCP value, and how queues are scheduled, is a QoS policy decision made per network, not something the tag defines. ## What the extra four bytes cost - **Frame size.** Untagged Ethernet frames run from 64 to 1,518 bytes. IEEE 802.3 raised the maximum to **1,522 bytes** for a frame carrying one 802.1Q tag, so the 1,500-byte payload, and with it the IPv4 or IPv6 MTU, does not shrink when a link is tagged. - **FCS recomputation.** The frame check sequence covers every byte from the destination MAC to the end of the payload, so a switch that adds a tag on a trunk or strips it towards an access port must compute a new FCS. - **Old hardware.** A device that only accepts 1,518-byte frames drops full-size tagged frames; small packets work and large ones vanish, a classic symptom on a newly tagged link. ## Beyond one tag 802.1Q also defines a **service tag** (S-tag, EtherType `0x88A8`) that a provider can push in front of the customer's C-tag, so a frame carries two tags, a scheme often called Q-in-Q. Each tag adds another 4 bytes, and each has its own 12-bit VID. ```pseudocode // classify a received frame; offsets count from the destination MAC type = read16(frame, 12) if type == 0x8100: // an 802.1Q C-tag follows tci = read16(frame, 14) pcp = (tci >> 13) & 0x7 // top 3 bits dei = (tci >> 12) & 0x1 // next bit vid = tci & 0x0FFF // low 12 bits if vid == 0xFFF: discard(frame) // reserved, never a VLAN if vid == 0: vid = port.pvid // priority-tagged ethertype = read16(frame, 16) // the original EtherType else: vid = port.pvid // untagged: the port decides ethertype = type ```

  • Does tagging a link with 802.1Q force the IP MTU down to 1,496 bytes?
    Not under the standard. IEEE 802.3 allows a 1,522-byte frame when one 802.1Q tag is present, so the payload stays 1,500 bytes. Trouble comes from equipment that only accepts 1,518-byte frames, and from stacked tags, where each extra 4-byte tag must also fit the devices' maximum frame size.
  • What is a priority-tagged frame, and which VLAN does it end up in?
    A frame whose 802.1Q tag carries VID 0: it names a priority in the PCP bits but no VLAN. The receiving switch treats it like an untagged frame for VLAN purposes and assigns it to the port's PVID, while still honouring the priority it carries.
  • Why did the tag's designers place the TPID where the EtherType normally sits?
    Because every receiver already reads that position to learn what follows. A VLAN-aware device sees 0x8100 and parses the tag; a device that does not understand VLANs sees an unknown EtherType and drops the frame rather than misinterpreting the tag as the start of an IP packet. The original EtherType simply moves 4 bytes later.

saying these in an interview costs you the question

  • The 802.1Q tag is placed in front of the destination MAC address.
  • A 12-bit VLAN ID gives 4,096 usable VLANs.
  • PCP 0 is the lowest priority an 802.1Q frame can carry.
  • The DEI bit marks a frame as belonging to the native VLAN.
  • The TPID field holds the VLAN number.