In campus network design, how does separating guest traffic with a VLAN differ from separating it with a VRF?
answer
- two different layers
- broadcast domain vs routing table
- the first router is where VLANs meet
- no route in the table, no path
basics
~20 sA VLAN separates guest and corporate hosts only at Layer 2; once both VLANs reach a router with one shared routing table, it routes between them. A VRF gives the guest interfaces their own routing table, so corporate routes are simply absent.
solid answer
~50 sA **VLAN** is a separate Ethernet broadcast domain: guest hosts cannot reach corporate hosts by switching alone. But the moment both VLANs have a routed interface on the same router, that router holds both subnets in **one routing table** and forwards between them unless a filter stops it. A **VRF** (virtual routing and forwarding instance) is a second, independent routing table on the same router; each interface is bound to one VRF and a packet is looked up only in its interface's table. Put the guest interfaces in a guest VRF and the corporate prefixes are not in that table at all, so the guest packet follows whatever the guest VRF offers, typically a default route to an internet firewall. In practice the two work together: VLANs carry each zone to the router, and the VRF keeps it apart from there on.
go deeper
Recall the layer split: a VLAN is a separate broadcast domain, a VRF is a separate routing table. Then say what happens when two VLANs share a router with one table.
Explain that each routed interface belongs to one VRF and lookups use only that table, so absent routes, not filters, keep the zones apart. Mention that overlapping prefixes become possible.
Show that a VRF sends traffic wherever its own routes point, so a default route to the wrong device undoes it. Name misbinding an interface as the quiet failure.
Frame VLAN plus VRF as macro-segmentation: cheap, coarse zones on shared hardware. Weigh it against physical separation and finer policy tools, and say what each zone still shares.
## Two separations at two layers A campus that carries corporate laptops, guest Wi-Fi, IoT sensors and payment terminals on the same switches and routers needs to keep those groups apart. Two tools do that, and they work at different layers. - A **VLAN** (virtual LAN) splits one physical switched network into separate **broadcast domains**. A guest laptop's broadcasts and unknown-destination frames never reach a corporate laptop, and the switch will not forward a frame from one VLAN into another. - A **VRF** (virtual routing and forwarding instance) splits one router into several independent **routing tables**. RFC 7868 defines VRFs as "independent ... routing/forwarding tables that coexist within the same router at the same time", and RFC 4364 (section 3) describes the same idea: a router keeps a default forwarding table plus one table per VRF. ## Where VLAN separation stops VLAN separation is real, but it ends at the first router. Hosts in different VLANs talk by sending to their default gateway, a routed interface in their VLAN (how a router or Layer 3 switch routes between VLANs is an Ethernet subject of its own). Suppose the distribution router has a guest interface for `10.20.0.0/16` and a corporate interface for `10.10.0.0/16`, both in its single global table: 1. A guest laptop at `10.20.4.7` sends a packet to `10.10.8.20`. 2. The packet reaches the guest gateway on the router. 3. The router looks up `10.10.8.20`, finds the directly connected corporate subnet, and forwards it. Nothing about the VLANs stopped this. The only things that could are a filter (an access list or a firewall) on the path, or removing the corporate route from the table the guest packet is looked up in. ## What a VRF changes With VRFs, every routed interface is bound to exactly one VRF, and RFC 4364 section 3.1 states the rule that matters: when a packet arrives on an interface associated with a VRF, its destination is looked up in that VRF. Bind the guest interfaces to a `GUEST` VRF and the corporate interfaces to a `CORP` VRF: | Lookup | Global table only | With VRFs | |---|---|---| | Guest packet for `10.10.8.20` | Corporate subnet found, packet delivered | Not in `GUEST`; follows `GUEST`'s default route or is dropped | | Corporate packet for `10.20.4.7` | Guest subnet found, packet delivered | Not in `CORP`; same outcome | | Two zones reusing one prefix | Impossible: one table, one route | Allowed: each VRF holds its own copy | The separation is now a property of the routing tables, not of a filter someone has to keep correct. Note the precise claim, though: a VRF without a corporate route does not "block" the packet; it sends it wherever the guest VRF's routes say. If the guest VRF's default route leads to a firewall, the firewall decides. If it led to a device that holds corporate routes and forwards freely, the separation would leak there. ## Why designs use both The two tools are complementary, not alternatives: - **VLANs carry a zone to the router.** The guest SSID and the guest switch ports land in a guest VLAN, which keeps guest frames apart until they reach a routed interface. - **The VRF keeps the zone apart from there on.** The routed interface for that VLAN sits in the guest VRF, so the zone's separation continues through every router that carries it. - **VLANs subdivide inside a zone.** Within the corporate VRF there may be a VLAN per floor or per department; those VLANs route to each other freely inside the VRF. This is **macro-segmentation**: coarse zones separated by routing tables and a firewall, with finer-grained policy left to other tools. ## The limits worth stating - A VRF separates routing, not physical capacity: zones still share the same links and routers, so a flood in one zone can congest another. - A single configuration error, such as an interface bound to the wrong VRF, joins two zones without any filter noticing. - Zones in separate VRFs cannot reach each other through the campus routers until something is added on purpose: a controlled route leak for shared services, or a firewall with an interface in each VRF. That deliberate gap is the point. An interviewer asking this wants the layer distinction (broadcast domain vs routing table), the fact that one shared routing table routes between VLANs, and the idea that VRFs make reachability a matter of which routes exist in which table.
- If VLANs alone stop Layer 2 traffic, why not just put an access list on the router instead of using VRFs?You can, and many small sites do. The difference is failure mode: with one shared table, separation depends on every filter being correct on every routed interface, and a missing line opens the path. With VRFs, the other zone's routes are absent, so reachability has to be added deliberately. Filters are still useful inside or between VRFs, but VRFs make the default answer no route.
- Does a guest VRF stop guest hosts from attacking each other?No. Hosts in the same guest VLAN reach each other directly at Layer 2 without touching the router, so neither the VLAN boundary nor the VRF sees that traffic. Isolating guests from one another needs port-level isolation features on the access switches or wireless controller, which is a separate segmentation decision.
VLANs are separate corridors in one building; a shared routing table is a single lobby every corridor opens into. A VRF gives each corridor its own lobby, so walking out of the guest corridor never puts you where the corporate doors are.
saying these in an interview costs you the question
- Separate VLANs alone stop guests reaching corporate hosts, even through a shared router.
- A VRF filters packets the way an access list does.
- VLANs and VRFs are alternatives, so a design picks one.
- A VRF is a Layer 2 feature configured on access switch ports.
- Putting guests in their own VRF also isolates guests from each other.