What is a VLAN?
A VLAN splits one office network into several separate ones on the same cables. What it is used for, and the equipment it needs.
A VLAN, short for virtual local area network, is a way of splitting one physical network into several separate networks without running new cables. Devices on the same VLAN behave as if they had a network to themselves, even when they are plugged into the same equipment as everything else.
How it works in outline
Each port on a switch is told which VLAN it belongs to. The switch then delivers traffic only between ports on the same VLAN. A computer on the staff VLAN and a camera on the camera VLAN can share a switch and never see each other’s traffic.
When traffic travels from one switch to another, each piece of data carries a small tag that says which VLAN it belongs to, so the next switch knows where it may be delivered. The tag follows a standard called IEEE 802.1Q.
To get from one VLAN to another, traffic has to pass through a router, and the router or firewall can apply rules to it on the way.
Everyday uses in an office
- Guests. Visitors get internet access on a network of their own and cannot reach the file server or the printers. CISA advises keeping guest Wi-Fi separate from the main network.
- Phones. Desk phones sit on a voice VLAN, apart from the computers. The same tag that marks the VLAN can mark voice traffic as higher priority than ordinary data.
- Cameras and smart devices. Many of these give you little control over their built-in security, so NIST describes separation as the main tool for protecting a network that has them on it.
- Sensitive systems. Servers and accounts systems are kept apart from the computers used for web browsing and email.
Why a business should care
The Australian Signals Directorate calls a network where everything can reach everything else a flat network. On a flat network, one infected laptop or one compromised camera gives an attacker a path to every other device. Dividing the network limits how far an intrusion can spread and makes unusual traffic easier to notice.
Creating VLANs is half of the job. The other half is the rules between them. The directorate’s guidance is that if one part of the network has no need to talk to another, it should not be allowed to, and if it only needs one kind of connection, that is all it should get. VLANs with no rules between them make the network tidier and add little protection.
What you need
- Switches that support VLANs. The switch has to be told which VLAN each port is on. Business switches can do this, while the basic plug-in kind has no settings at all.
- Access points that support them, so that each Wi-Fi network name leads to its own VLAN.
- A router or firewall that can route between the VLANs and filter what crosses.
- A plan. Decide which devices belong together and what each group needs to reach before anything is configured.
A very small office may not need VLANs yet. Most small office routers have a guest Wi-Fi setting that keeps visitors away from everything else, which is the same idea in a ready-made form.
To see whether your equipment is up to it, read Is consumer networking equipment good enough for a business?. Our network services team designs and sets up VLANs as part of an office network.
Sources
- Virtual local area network: glossary (NIST) csrc.nist.gov
- Implementing network segmentation and segregation (Australian Signals Directorate) cyber.gov.au
- Information security manual: guidelines for networking (Australian Signals Directorate) cyber.gov.au
- An Introduction to Computer Networks, chapter 3: Advanced Ethernet (Loyola University Chicago) intronetworks.cs.luc.edu
- If you connect it, protect it (NIST) nist.gov
- Securing enterprise wireless networks (CISA) cisa.gov