
What is a VLAN? Here is a simple example. A company has sales, R&D, and finance departments. If you do not split them into VLANs, every computer plugs into the same switch, so any broadcast message (a popup, a device-discovery broadcast, or a fault alarm) reaches every device. With many devices, broadcast packets flood the network and everything lags. Worse, a sales PC can reach the finance server directly — a real data-leak risk.
A VLAN (Virtual Local Area Network) logically cuts one physical switch into several isolated small networks. Physically, all devices still connect to the same switch. Logically, R&D, finance, and sales each run as their own "small network" and, by default, cannot see or talk to each other.
The main benefits of dividing VLANs:
Reduce the broadcast domain and cut network lag.
Broadcasts stay inside their own VLAN instead of flooding the whole LAN.
Security isolation prevents unauthorized access. For example, the finance server is in VLAN 10 and sales is in VLAN 20; normally a sales PC cannot reach finance equipment, removing the leak risk.
Flexible operation, no physical limits. Each isolated network needs no separate switch — you group devices by configuration. All of a company's cameras can sit in one VLAN, for instance.
A VLAN only controls whether devices receive each other's broadcast traffic. It does not handle IP communication — it merely does logical isolation.
An IP subnet assigns network segments to devices (e.g. 192.168.1.0/24, 192.168.2.0/24). Devices in the same subnet talk directly.
A gateway is the bridge between different VLANs and different subnets. Without it, isolated VLANs can never reach each other.
General rule: one VLAN maps to one independent IP subnet, and that subnet's gateway is the exit point for cross-VLAN communication.
Belongs to a single VLAN; data in and out carries no tag. Example: a terminal PC sends data into the switch, the switch adds the VLAN tag, and when data returns it strips the tag — the PC never knows VLAN exists. Used for cameras, office PCs, and wireless APs.
Carries multiple VLANs on one link and tells them apart with 802.1Q tags. Different VLANs' data travel the link with their own tags; the switch forwards to the right access port by tag. Used between switches, and between access switches and a core Layer-3 switch or firewall.
VLAN isolates who can broadcast to whom; QoS (Quality of Service) decides who gets bandwidth first when the link is busy.
On a trunk port, the 802.1Q tag carries a 3-bit Priority Code Point (PCP, or 802.1p). The switch reads it and drops the frame into a high- or low-priority queue. Map a VLAN — voice, camera, or control — to a high PCP and its traffic overtakes bulk downloads. At Layer 3, DSCP does the same job across routers.
CoS (PCP) | Typical traffic |
7 | Network control / management |
6 | Reserved |
5 | Voice (VoIP) |
4 | Video / streaming |
3 | Signaling |
2 | High-priority data |
1 | Background |
0 | Best effort (default) |
In industrial networks, give PLC/SCADA traffic top priority so a control command is never delayed by a big file transfer. See What is QoS? for the full picture.
Devices in the same VLAN communicate directly. Devices in different VLANs need a Layer-3 device. Two common ways:
Layer-3 switch: each VLAN's gateway is a Switch Virtual Interface (SVI) on the switch. Forwarding is fast and done in hardware.
Router-on-a-stick: one physical link to a router, with one sub-interface per VLAN over a tagged trunk.
Without that gateway, VLANs stay isolated — exactly as section 2 says. Full walkthrough: Inter-VLAN Routing Explained.
Management VLAN: put the switch's Web/CLI/SSH management in a separate VLAN, not the user VLAN, so admin access is isolated.
Voice / Video VLAN: IP phones and cameras are auto-assigned to their own VLAN via LLDP or MAC OUI — isolated and prioritized at once.
Native VLAN: change it from the default (VLAN 1) and match both ends of a trunk, or you invite VLAN-hopping attacks.
Forgot the gateway → no cross-VLAN traffic. Add the SVI / sub-interface.
Trunk allowed-VLAN list mismatch → some VLANs "disappear" on one side. Align the allow lists.
Native VLAN mismatch → security gap and odd behavior. Set it the same on both ends.
Subnet not aligned with VLAN → routing confusion. Keep one subnet per VLAN.
On a factory floor, mix office PCs, IP cameras, and real-time PLC/SCADA/HMI on one switch and the control traffic competes with everything else. Put PLC/SCADA on a dedicated control VLAN, add QoS so commands are never delayed, and keep management separate. This IT/OT segmentation is where industrial switches earn their keep. Details and a sample topology: VLAN in Industrial Networks.
Plan VLANs by need — e.g. finance = VLAN 10, office = VLAN 20, monitoring = VLAN 30, each with its own subnet.
Set terminal-facing ports to Access and assign the VLAN.
Set inter-switch ports to Trunk, allowing the needed VLANs.
Configure each VLAN's gateway on a Layer-3 switch or firewall.
A VLAN segments a network logically. Access ports face terminals; trunk ports face switches. Same-VLAN devices talk directly; different-VLAN devices need a Layer-3 gateway. Add QoS and the right VLAN plan and you solve broadcast storms, isolate critical data, and keep control traffic deterministic — basic but essential configuration for office, monitoring, and all-optical industrial networking.
As an independent R&D manufacturer of industrial communication equipment, Rayin provides free technical evaluation to help you match functions to your project. For a complete product plan and technical white paper, visit www.szrayin.com or see our industrial switch solutions and