VLANs and access ports

VLAN = broadcast domain you choose

A LAN is one broadcast domain: a broadcast (or unknown unicast) floods out every port except the one it came in. See frame switching.

Without VLANs, every port on a switch is one broadcast domain. With them, the switch carves its ports into several, and each carved-out domain is a VLAN. Devices in a VLAN behave like they share a wire even when they sit on different switches, different floors, different buildings.

Each VLAN is a Layer 2 broadcast domain, normally mapped 1:1 to an IP subnet. The convention is to bake the VLAN number into the subnet: VLAN 2 = 10.0.2.0/24, VLAN 3 = 10.0.3.0/24, so the third octet tells you the VLAN.

Why bother

Traffic between VLANs

Traffic never crosses VLANs on its own. Not within a switch, not between switches. Different broadcast domains, full stop.

Crossing requires a Layer 3 device: a router or a multilayer (Layer 3) switch. That’s inter-VLAN routing, either one router interface per VLAN or one trunk carrying all of them (details when we get to trunking).

Carrying multiple VLANs between switches also needs a trunk link on the switch-to-switch connections: 802.1Q trunking.

Access ports

An access port connects an end device (a PC, phone, printer) and belongs to exactly one VLAN. Never point one at another switch.

Traffic on an access port is untagged. A PC’s NIC knows nothing about VLAN tags; the frame arrives plain, and the switch simply files it under the port’s VLAN. The VLAN ID only gets written into the frame as a Layer 2 tag when the traffic crosses a trunk to another switch.

Multiple ports can sit in the same VLAN. Same VLAN, shared broadcast domain; different VLAN, not.

The end device never knows any of this. VLANs exist only in switch config; the host just has an IP and mask, and that subnet happens to map to the port’s VLAN.

Config

console
Switch(config)# vlan 2
Switch(config-vlan)# name SALES
Switch(config)# interface FastEthernet 0/3
Switch(config-if)# switchport mode access
Switch(config-if)# switchport access vlan 2

The number is the VLAN ID, the value carried in the frame tag on trunks. vlan accepts a single ID, a comma list, or a hyphenated range, no leading zeros. no vlan <id> deletes.

Names are optional: ASCII, 1-32 chars, unique in the admin domain. Skip the name and show vlan displays a default like VLAN0002; name it and you see SALES instead.

Defaults: Catalyst switches ship with VLAN 1 holding every port. VLAN 1 is also the default management VLAN, which is where the switch’s own management IP and gateway live if you don’t move them.

Voice VLAN: the access port exception

One VLAN per access port, with a single carve-out: IP phones. A phone daisy-chains the PC through itself into one switch port, and the port carries a data VLAN and a voice VLAN together.

It works because the phone is smart enough to tag: voice frames arrive tagged with the voice VLAN ID, while the PC’s frames pass through untagged and land in the data VLAN.

console
SW1(config)# interface FastEthernet 0/2
SW1(config-if)# switchport mode access
SW1(config-if)# switchport access vlan 2
SW1(config-if)# switchport voice vlan 3

Verify with show interfaces fa0/2 switchport: it shows the admin mode (static access), the access (data) VLAN, and the voice VLAN.

VLAN ID ranges

Auto-created: 1 and 1002-1005. Everything else is manual.

Where VLAN config lives

VLANs 1-1005 are saved in the VLAN database, the vlan.dat file in flash, not in the running config. (The exception: VTP transparent mode also writes them to running config, where they can be saved to startup.)

VTP (VLAN Trunking Protocol) is a Cisco-proprietary Layer 2 protocol that syncs VLAN add, delete, and rename across switches to cut admin overhead. Modes: server, client, transparent.

Extended VLANs (1006-4094): under VTP v1/v2 the switch must be in transparent mode to create them, and they live only in the running config. VTP v3 stores them in vlan.dat and can propagate them, so server and transparent modes both work.