Why can't two hosts in different VLANs talk at layer 2, and how do router-on-a-stick and a switch virtual interface route between them?
answer
- each VLAN is its own broadcast domain
- ARP never crosses a VLAN
- one tagged link, a gateway per VLAN
- the switch itself holds the gateways
basics
~20 sDifferent VLANs are separate broadcast domains and subnets, so ARP never crosses between them and a layer 2 path does not exist; traffic must be routed. Router-on-a-stick puts every VLAN's gateway on one tagged link; a switch virtual interface puts them inside a layer 3 switch.
solid answer
~50 sTwo hosts in different VLANs sit in **separate broadcast domains**, hence separate IP subnets. A host finding a destination outside its subnet sends to its **default gateway**, and ARP, a broadcast, is confined to the VLAN, so there is no layer 2 path between VLANs at all; a **router** must forward between them. **Router-on-a-stick** connects a router to the switch by a single 802.1Q trunk and gives the router one **subinterface per VLAN**, each tagged with that VLAN's ID and holding that VLAN's gateway address; a packet from VLAN 10 to VLAN 20 arrives tagged 10, is routed, and leaves tagged 20 over the same link. A **switch virtual interface (SVI)** does the same inside a layer 3 switch: a logical IP interface per VLAN acts as each VLAN's gateway, and the switch routes between SVIs in hardware, with no external router or trunk.
go deeper
Know that different VLANs are different subnets, that reaching another VLAN needs a router, and that a trunk on its own does not route.
Explain why ARP cannot cross a VLAN, and describe router-on-a-stick's per-VLAN tagged subinterfaces and an SVI as each VLAN's gateway inside a layer 3 switch.
Compare the two: the one-trunk bottleneck of router-on-a-stick against line-rate SVI routing, and state exactly what the router rewrites, the MACs and TTL, not the IPs.
Choose the inter-VLAN design for the scale: router-on-a-stick for a small site, distributed SVIs or a routed core where inter-VLAN volume and availability demand it.
## Why layer 2 stops at the VLAN boundary A VLAN is one **broadcast domain**, and each VLAN is conventionally one **IP subnet**. Two consequences follow directly: 1. **ARP cannot cross.** To send an Ethernet frame to another host in its own subnet, a host broadcasts an ARP request for that host's MAC address. A switch floods that broadcast only within the sender's VLAN, so a host in VLAN 10 can never learn the MAC address of a host in VLAN 20. No MAC, no frame. 2. **Off-subnet traffic goes to the gateway.** When the destination IP is outside the host's own subnet, the host does not ARP for the destination at all. It sends the frame to its configured **default gateway**'s MAC address, and the gateway, a router, forwards the packet towards the destination subnet. So reaching another VLAN is **routing**, not switching. Something with an interface in both subnets must receive the packet, decrement the IP time-to-live, and forward it into the other VLAN. The two standard ways to provide that are router-on-a-stick and the switch virtual interface. ## Router-on-a-stick An external router connects to the switch over a **single 802.1Q trunk** (the "stick"). The router's physical interface is divided into one **subinterface per VLAN**: - Each subinterface is configured with a VLAN ID so it sends and receives frames **tagged** for that VLAN. - Each subinterface holds the **gateway IP address** of its VLAN's subnet, so every host uses its own VLAN's subinterface as its default gateway. A packet from a Finance host (VLAN 10) to an Engineering host (VLAN 20): 1. The Finance host sends the frame to its gateway's MAC; the switch forwards it up the trunk **tagged VID 10**. 2. The router receives it on the VLAN 10 subinterface, looks up the destination, and finds the VLAN 20 subinterface. 3. The router rewrites the Ethernet header (new source and destination MACs), decrements the IP TTL, and sends the packet back down the trunk **tagged VID 20**. 4. The switch delivers it into VLAN 20 to the Engineering host. Every inter-VLAN packet therefore traverses the one trunk **twice**, once in, once out, which makes that link the bottleneck. Router-on-a-stick is cheap and simple, and it is how a small site with a plain router and a plain switch routes between VLANs. ## The switch virtual interface A **layer 3 switch** combines switching and routing in one box. For each VLAN it can own a **switch virtual interface (SVI)**: a logical IP interface, not tied to any physical port, that holds that VLAN's gateway address. - Hosts in each VLAN use their VLAN's SVI address as the default gateway. - When a packet must move between VLANs, the switch routes between the two SVIs **internally**, usually in hardware, at line rate. - No external router and no dedicated trunk are needed; the routing happens where the frames already are. | | Router-on-a-stick | Switch virtual interface | |---|---|---| | Where routing happens | External router | Inside the layer 3 switch | | VLAN-to-VLAN path | Up and down one trunk, twice per packet | Internal, between SVIs | | Typical performance | Limited by the one trunk link | Line-rate, hardware-forwarded | | Each VLAN's gateway lives on | A tagged subinterface on the router | An SVI on the switch | | Suits | Small sites, few VLANs, low volume | Campus and data-centre cores with heavy inter-VLAN traffic | Both are **implementation features**, not protocol mechanisms: the protocol fact is that inter-VLAN traffic is ordinary IP routing between subnets, and both designs simply decide where the router lives and how the VLANs reach it. What crosses the wire between switch and router in the router-on-a-stick case is standard 802.1Q-tagged Ethernet. ## Common misconceptions - **A trunk does not route.** A trunk carries many VLANs but keeps them separate; it never forwards a frame from one VLAN into another. Only a router or an SVI does that. - **The gateway is not optional.** Give two VLANs addresses but no router between them and the hosts simply cannot reach each other, however the switch is cabled. - **Same switch, different VLAN, still routed.** Two hosts on one physical switch but in different VLANs still need a router or SVI; sharing a switch does not give them a layer 2 path. - **The router rewrites the Ethernet header, not the IP addresses.** Routing between VLANs changes source and destination MACs and decrements the TTL; the source and destination IP addresses stay the same (barring NAT, which is a different function).
- In router-on-a-stick, why is the single trunk link the performance limit?Every packet that moves between VLANs travels the trunk twice: up to the router tagged with the source VLAN, and back down tagged with the destination VLAN. All inter-VLAN traffic for every VLAN shares that one link's bandwidth in both directions, so it saturates well before a design that routes internally at switch speed.
- What does the router change in the packet when it routes between two VLANs?It rewrites the Ethernet frame: the source MAC becomes the router's interface for the destination VLAN and the destination MAC becomes the next hop's. It also decrements the IP time-to-live and recomputes the IPv4 header checksum. The source and destination IP addresses are unchanged; only a separate NAT function would alter those.
- Do hosts know whether their gateway is a router subinterface or an SVI?No. A host only knows its default gateway's IP and MAC address and sends off-subnet traffic there. Whether that gateway is a subinterface on an external router reached over a trunk, or an SVI inside a layer 3 switch, is invisible to the host; both answer ARP for the gateway and forward its packets identically.
saying these in an interview costs you the question
- A trunk link routes traffic between the VLANs it carries.
- Two hosts in different VLANs on one switch can reach each other without a router.
- Router-on-a-stick needs a separate cable for every VLAN.
- Routing between VLANs rewrites the source and destination IP addresses.
- An ARP request can cross from one VLAN into another.