skip to content

Splitting the Broadcast Domain

How many hosts share a segment decides how far a first-hop or discovery claim reaches, and splitting them turns free local traffic into routed traffic. Interviewers pair it with 'what broke?'.

on this pageshow

questions

4

All 900 hotel guest rooms sit in one VLAN — what does a compromised laptop there reach without ever crossing the firewall?

level: juniorimportance: must knowfreq 70%

answer

  1. same subnet, no router involved
  2. the filter sits one hop too far up
  3. domain width equals blast radius
  4. count devices, not rooms
  5. absent log lines are not absence of traffic

basics

~20 s

Every other host in that VLAN — with three devices a room, roughly 2,700 of them. Traffic between hosts in one broadcast domain is switched, never routed, so the inter-VLAN firewall neither filters nor logs it.

solid answer

~40 s

A VLAN is one broadcast domain and one subnet, and hosts inside it reach each other by layer-2 switching. The default gateway is only involved when the destination is in a different subnet, so a firewall or access list sitting at the routed boundary is simply not in the path for guest-to-guest traffic. One compromised laptop can therefore scan, connect to, and answer address-resolution requests for every other device in that VLAN — around 2,700 hosts if each of 900 rooms has three — and the boundary log will show only that laptop's outbound sessions. The practical consequence is that the width of the broadcast domain *is* the containment number: whatever you paid for at the boundary buys you nothing between rooms, and no amount of policy up there changes it.

code

text · 8 lines
text
# inter-VLAN firewall, guest zone, 02:00-06:00
02:14:07  10.40.0.61   -> 203.0.113.9   443/tcp  allow
02:14:09  10.40.0.61   -> 10.10.10.53    53/udp  allow
03:02:44  10.40.2.117  -> 203.0.113.44  443/tcp  allow
...
# absent, and never logged anywhere:
#          10.40.0.61   -> 10.40.2.117   445/tcp
#          (same /21 - switched, never routed)

go deeper

for a junior

Be ready to say plainly that hosts in one VLAN and subnet talk by switching, so the router and anything beside it never sees that traffic. Give a number for the reachable host count when the scenario gives you rooms and devices.

for a middle

Explain why the frame never reaches the gateway — destination in the local subnet, MAC forwarding table, no routed hop — and name what an adjacent host can do beyond port scanning, such as answering a neighbour's broadcast requests.

for a senior

Show the judgment: state the containment number for the design as built, say honestly that you have no record of intra-domain traffic, and price the split — relayed address assignment, broken discovery, hairpinned traffic — instead of just recommending more VLANs.

for a principal

Own the argument that a broadcast domain's width is a risk number the business already accepted, usually without being told. Be able to put it in front of an owner alongside what narrowing it will break and who pays for that.

## What layer-2 adjacency actually means A VLAN is a broadcast domain. Every host in it shares one IP subnet and reaches every other host by switching: the switch looks the destination MAC address up in its forwarding table and sends the frame out a port. The default gateway is consulted only when the destination address is outside the local subnet. So for two guest devices in the same VLAN, the router is not in the path, and neither is anything sitting at or beyond the routed boundary — the inter-VLAN firewall, the router's access list, or the flow exporter on the routed interface. That one fact converts a design decision into a containment number. **The width of the broadcast domain is the blast radius of one first-hop claim.** A 900-room hotel with a phone, a laptop and a streaming device per room is not "one guest VLAN"; it is 2,700 hosts that a single compromised device can address directly, plus whatever back-of-house kit was quietly cabled into the same closets. ## What adjacency gives an adversary Being on the wire with someone is not just reachability to their open ports. A host in the same broadcast domain receives and can answer broadcast traffic: address-resolution requests and address-assignment requests from its neighbours. Answering those is how a device stops being a peer and starts being the path — the neighbour's traffic is then delivered to it before it goes anywhere else. The mechanics of those forgeries and the first-hop switch features that validate such claims are a separate subject; what matters here is the scoping consequence, and it is blunt: **anything an adversary can do to a neighbour, they can do to every host in the domain, because "neighbour" is defined by the domain, not by distance.** ## What the boundary log does and does not prove When the incident is written up, the inter-VLAN firewall log will contain the compromised laptop's outbound sessions and nothing else. Reading the absence of guest-to-guest records as "there was no lateral movement" inverts the evidence: the records are absent because the traffic never traversed a device that keeps records, not because the traffic did not happen. The only witnesses to intra-VLAN traffic are the endpoints themselves and, partially, the access switch — which is not usually exporting per-flow data. Being able to say that out loud is most of what an interviewer is testing. One partial exception is worth knowing: traffic addressed *to the gateway's own interface* — its resolver, its management service — does terminate on the router and can be logged. That is traffic to the boundary, not through it. ## What narrowing the domain costs The fix is to make the domain smaller: per-floor VLANs, per-wing VLANs, or port isolation within a VLAN so that guest devices can talk only to the gateway. None of it is free, and the price is why flat estates stay flat: - **Addressing and assignment.** Each new segment needs its own address range and its own relayed address assignment, because the assignment request no longer reaches the server by broadcast; a relay on each gateway interface has to forward it and mark which segment it came from so the right pool is used. - **Anything that assumes neighbours can hear each other.** Screen casting to the display in a meeting room, printing by discovery, and device pairing are built on link-local broadcast and multicast. Split the domain and they stop, and the person who booked the room calls the helpdesk, not the security team. - **Traffic that used to be switched now hairpins.** Every packet between two segments goes up to the routed boundary and back down, on a device sized for internet traffic rather than for the site's east-west volume. - **Operational surface.** More subnets, more relay configuration, more exceptions written for the one shared device everyone needs. ## The answer that lands Say the number, not the concept: "one first-hop claim reaches every host in the domain, so with three devices per room across 900 rooms that is roughly 2,700 hosts, none of which appear in the boundary log." Then say what splitting costs, because the interviewer's next question is always why the estate is still flat.

  • The incident report says the firewall shows no lateral movement. What is wrong with that sentence?
    It treats missing records as evidence of nothing happening. Intra-VLAN traffic is switched and never presented to the firewall, so it could not have been logged whether or not it occurred. The honest statement is that there is no visibility of guest-to-guest traffic at all, and the only remaining witnesses are the endpoints.
  • Does putting hosts on different access switches in the same VLAN reduce the blast radius?
    No. A VLAN spans every switch the trunk carries it to, so hosts in different closets are still one hop apart at layer 2 and still exchange frames without routing. Physical separation only helps if it coincides with a separate broadcast domain.
  • Where is the only place you could see guest-to-guest traffic today?
    On the endpoints themselves, and partially on the access switch — port counters, forwarding-table churn, or per-port flow export if the platform does it. None of that is normally collected, which is why the honest answer to "what moved between rooms" is usually that nobody can say.

A hotel corridor with no doors between rooms. The lobby desk records everyone who leaves the building and nobody who walks next door.

saying these in an interview costs you the question

  • Thinks the inter-VLAN firewall inspects traffic inside its own subnet
  • Calls a VLAN a security boundary between the hosts on it
  • Reads an empty boundary log as proof no lateral movement occurred
  • Counts rooms rather than devices when stating the blast radius
  • Assumes hosts on different access switches are separated

context

open as a page

Private VLAN isolation stops guest-to-guest attacks, yet DHCP still works and casting to the room screen fails — why?

level: middleimportance: should knowfreq 45%

basics

~20 s

An isolated port may exchange frames only with promiscuous ports, where the gateway and the address relay sit — so assignment still completes. Two guest devices are both isolated, so the host-to-host discovery casting depends on is dropped.

open as a page

Segmenting a flat 4,000-host site into per-floor VLANs to contain an intruder hairpins east-west traffic through one firewall — what fills first?

level: seniorimportance: should knowfreq 50%

basics

~20 s

Usually the firewall's session table and connection-setup rate, plus an uplink now carrying every flow twice. And you cannot size it from flow records: the traffic you are relocating never crossed a routed hop, so none was ever exported.

open as a page

Port isolation breaks the shared-screen meeting rooms the venue sells — who decides, and what do you write down?

level: principalimportance: should knowfreq 33%

basics

~20 s

The events business owns the decision, because the revenue is theirs to trade; you own stating the cost accurately. Write a per-room exception with a named owner, an expiry tied to the booking, and what one guest reaches.

open as a page