skip to content

In Ethernet switching, what is a VLAN, and how does an access port differ from a trunk port?

level: juniorimportance: must knowfreq 68%

answer

  1. one switch, several broadcast domains
  2. membership is a property of the port
  3. the host never sees a tag
  4. one link, many VLANs, an ID each

basics

~20 s

A VLAN is a separate broadcast domain carved out of shared switches. An access port belongs to one VLAN and carries untagged frames for an unaware host; a trunk carries many VLANs between switches, marking each frame with an 802.1Q VLAN ID.

solid answer

~50 s

A **VLAN** (virtual LAN) splits one set of switches into several logical LANs: a broadcast, a flooded unknown-unicast frame or an ARP request sent in one VLAN reaches only ports of that VLAN, so each VLAN is its own broadcast domain and, by convention, its own IP subnet. An **access port** is a member of exactly one VLAN; the host behind it sends and receives ordinary untagged frames and has no idea VLANs exist, because the switch assigns the VLAN on the way in. A **trunk port** carries frames of many VLANs over one link, usually switch to switch or switch to router, and inserts a 4-byte IEEE 802.1Q tag holding a 12-bit VLAN ID so the far end knows which VLAN each frame belongs to; one VLAN per trunk may cross untagged, the so-called native VLAN. Hosts in different VLANs cannot reach each other at layer 2 at all: that traffic must be routed.

go deeper

for a junior

Recall that a VLAN is a broadcast domain, that an access port belongs to one VLAN and talks untagged to its host, and that a trunk carries many VLANs by tagging each frame.

for a middle

Explain the 802.1Q mechanics: the switch classifies untagged frames by the port's VLAN, tags them on a trunk and strips the tag on the way out of an access port, with one native VLAN sent untagged.

for a senior

Show what goes wrong in production: trunks that carry VLANs nobody needs, a native VLAN that doubles as a user VLAN, and the assumption that separate VLANs are isolated once a router joins them.

for a principal

Frame VLANs as a tool with limits, a 4,094-ID space and no policy of its own, and argue when per-department VLANs suffice and when routed segments or overlays should replace them.

## Why VLANs exist An Ethernet switch without VLANs forms a single **broadcast domain**: every broadcast frame (destination `ff:ff:ff:ff:ff:ff`), every frame for an unknown destination MAC and every ARP request is flooded out of every port. That is fine for ten hosts and painful for five hundred, and it means every host can reach every other host directly at layer 2. A **VLAN** (virtual LAN, defined by IEEE 802.1Q) lets one physical switch, or a group of connected switches, behave as several independent LANs. The switch keeps a separate forwarding context per VLAN: a frame that entered in VLAN 10 is only ever forwarded to ports that are members of VLAN 10. Each VLAN is therefore its own broadcast domain, and in practice each is given its own IP subnet. ## The scenario: three departments on one pair of switches A small office runs Finance, Engineering and Guests on two switches, A and B, joined by one cable. | VLAN ID | Department | Example subnet | Where the hosts are | |---|---|---|---| | 10 | Finance | `192.0.2.0/24` | ports on switch A and switch B | | 20 | Engineering | `198.51.100.0/24` | ports on switch A and switch B | | 30 | Guests | `203.0.113.0/24` | ports on switch B only | Without VLANs, a guest laptop would see every Finance broadcast. With them, the three departments share cabling and switch hardware but not broadcast domains. ## Access ports An **access port** connects an end device that knows nothing about VLANs. - It is a member of **exactly one** VLAN. The 802.1Q standard calls the VLAN assigned to untagged frames arriving on a port its **PVID** (port VLAN ID). - The host sends **untagged** frames. The switch classifies each one into the port's VLAN on ingress. - When the switch forwards a frame out of an access port, it sends it **untagged**, so the host receives a plain Ethernet frame. - Moving a desk from Finance to Engineering is a configuration change on the port, not a recabling job. ## Trunk ports A **trunk port** carries traffic for several VLANs over one link, typically between switches or from a switch to a router. - Every frame on the trunk must say which VLAN it belongs to, so the switch inserts a 4-byte **802.1Q tag** after the source MAC address. The tag's 12-bit **VLAN ID** (VID) names the VLAN. - The receiving switch reads the VID and forwards the frame only within that VLAN, removing the tag again if the frame leaves through an access port. - One VLAN per trunk may be sent **untagged**; the industry calls it the **native VLAN**. An untagged frame arriving on a trunk is filed into the receiving port's PVID. - A trunk can be limited to a list of VLANs it is allowed to carry; other VLANs do not cross it. ## A frame's journey from Finance on A to Finance on B 1. A Finance laptop on switch A sends an untagged broadcast. 2. Switch A classifies it into VLAN 10, because that is the access port's VLAN. 3. Switch A floods it only to VLAN 10 ports: local Finance ports and the trunk to B. 4. On the trunk the frame leaves with an 802.1Q tag carrying VID 10. 5. Switch B reads VID 10, strips the tag and floods the frame only to its own VLAN 10 access ports. 6. Engineering and Guest hosts on both switches never see it. ## What a VLAN does not do - **It does not route.** Two hosts in different VLANs have no layer 2 path between them; a router or a layer 3 switch must forward their traffic, using each VLAN's default gateway. - **It does not shrink collision domains.** On a switch every port is already its own collision domain; VLANs divide broadcast domains. - **It is not a complete security control by itself.** Misconfigured trunks allow VLAN-hopping attacks, and any routing between VLANs needs its own access policy. - **It is not unlimited.** The VID is 12 bits wide and the values 0 and 4095 are reserved, so a network has at most 4,094 VLANs, a limit RFC 7348 cites as one reason overlay networks were introduced.

  • Why not run a separate cable between the switches for each department instead of using a trunk?
    That works, and it is exactly what a trunk replaces. Each VLAN would consume a port on both switches and a cable, so ten VLANs need ten links, and adding a department means new cabling. A trunk multiplexes every VLAN over one link by tagging each frame with its VLAN ID, so adding a VLAN becomes a configuration change.
  • Can a server be attached directly to a trunk port?
    Yes, if its network stack understands 802.1Q tags. A virtualisation host or a server that must sit in several VLANs creates one logical interface per VLAN ID on the tagged link. A host that is not VLAN-aware only understands the untagged native VLAN; a tagged frame starts with the tag's type value 0x8100 where it expects an ordinary EtherType, so it discards the frame as an unknown protocol.
  • Does putting Finance and Guests in separate VLANs stop them reaching each other?
    Only at layer 2. Once a router or layer 3 switch gives every VLAN a gateway, packets between the VLANs are routed and arrive unless something on that routed path filters them. VLAN separation is the precondition; the access policy applied where the traffic is routed decides what may actually cross.

Think of an internal mail service between two office buildings. Each department drops plain envelopes into its own mail slot, which is the access port, and never labels them. One van runs between the buildings, which is the trunk, and the mailroom puts every envelope into a bag coloured for its department, which is the VLAN tag. At the other building the bag colour decides which floor receives the envelopes, and the bag is emptied before delivery, so staff only ever see plain envelopes.

saying these in an interview costs you the question

  • A VLAN is just another name for an IP subnet.
  • Hosts on access ports must be configured with their VLAN ID.
  • A trunk link can carry only one VLAN at a time.
  • Two hosts in different VLANs on one switch can talk directly at layer 2.
  • VLANs split collision domains rather than broadcast domains.