A virtual LAN (VLAN) divides one physical switch, or a group of switches, into separate logical Layer 2 networks. Each VLAN is its own broadcast domain and normally its own IP subnet. VLANs let you group users by function rather than location, contain broadcast traffic, and separate traffic for security, for example keeping guest, staff, voice, camera and management traffic apart. Devices in different VLANs cannot talk to each other without a router or Layer 3 switch, which gives you a natural point to apply access control lists between them.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.