For decades, many corporate networks have been built as a single flat network: servers, user workstations, printers, IP phones and even the hardware management interfaces all share the same segment. It is convenient until it stops being so: a single compromised device has direct visibility over everything else, and broadcast traffic grows until it degrades performance. Network segmentation is the answer to both problems, and VLANs are its fundamental tool.
VLANs let you divide a physical network into multiple isolated logical networks without duplicating switches or cabling. They are a mature, standardised technology supported by any managed switch. But they also have limits: when the infrastructure is virtualised and workloads move between hosts, the classic per-subnet segmentation model falls short. That is where microsegmentation comes in.
In this article we explain how VLANs work (802.1Q tagging, trunk and access ports, native VLAN), how to design a typical enterprise segmentation, where to place the firewall for inter-VLAN traffic, the most common mistakes, and when to make the leap to microsegmentation with per-workload policies and Zero Trust.
What Is a VLAN: 802.1Q, Trunk, Access and Native VLAN
A VLAN (Virtual Local Area Network) is an independent logical network that coexists with others on the same physical infrastructure. Two devices in different VLANs cannot communicate directly at layer 2, even if they are connected to the same switch: for them it is as if they were on physically separate networks. The standard that makes this possible is IEEE 802.1Q, which defines how Ethernet frames are tagged to indicate which VLAN they belong to.
802.1Q tagging inserts a 4-byte tag into the Ethernet frame header. Of those 4 bytes, 12 bits correspond to the VLAN ID, allowing up to 4,094 usable VLANs per domain (IDs 0 and 4095 are reserved). The tag also includes 3 priority bits (802.1p) used for QoS, for example to give preference to VoIP traffic.
On a managed switch there are two port types in relation to VLANs:
- check_circle Access ports: belong to a single VLAN. The switch strips the tag before delivering the frame to the end device (a PC, a printer), which never sees the 802.1Q header. This is the usual mode for end devices.
- check_circle Trunk ports: carry several VLANs simultaneously with their tags. They are used between switches, towards routers and firewalls, and towards hypervisors that need to present several networks to their virtual machines.
On a trunk, frames that arrive untagged are assigned to the native VLAN. By default this is usually VLAN 1, and that is where one of the classic security problems begins: if the native VLAN matches a VLAN in use, an attacker can craft double-tagged frames (a VLAN hopping attack) and jump from one segment to another. Best practice is to assign an empty, unused VLAN as native and tag all legitimate traffic.
Why Segment the Network
Segmenting is not just a matter of tidiness. There are three concrete reasons:
- check_circle Reducing the broadcast domain: on a flat network, every ARP, every DHCP discover and every service announcement reaches all devices. With hundreds of devices, that noise consumes bandwidth and CPU. Each VLAN is an independent broadcast domain.
- check_circle Containing lateral movement: when an attacker compromises a device (a laptop via phishing, a server with an unpatched vulnerability), their next step is to explore the network and jump to other systems. If everything is on the same segment, they have free rein. Segmentation turns every hop into an obstacle that also leaves traces in the firewall. It is the same containment principle applied against DDoS attacks: limiting the blast radius.
- check_circle Separating environments with different requirements: production and development should not share a network; office guests should not see the servers; VoIP traffic needs QoS; backup traffic generates massive peaks that should not compete with applications; and management interfaces should never be reachable from any user workstation.
Typical Enterprise VLAN Design
There is no universal design, but most enterprise infrastructures converge on a similar scheme:
- check_circle Management VLAN: server iLO/iDRAC interfaces, switch management, PDUs and storage arrays. Only reachable from a bastion host or through an administration VPN. It is the most critical VLAN: whoever controls it controls the infrastructure.
- check_circle Server VLAN: internal production workloads (databases, applications, hypervisors). It can be subdivided by criticality or by environment: production, staging and development.
- check_circle User VLAN: workstations. No access to the management network, and access to servers only through the firewall, on the strictly necessary ports.
- check_circle Backup VLAN: copy traffic between servers and repositories. Isolating it prevents backup windows from saturating the production network and adds a barrier against ransomware hunting for the repositories.
- check_circle DMZ: services exposed to the Internet (web, mail, VPN). A compromised server in the DMZ must not be able to initiate connections towards the internal network.
- check_circle VoIP and guest VLANs: telephony with its own QoS, and a guest network that can only reach the Internet.
The design should come with a coherent addressing plan (for example, reflecting the VLAN ID in the third octet of the subnet) and full documentation: segmentation nobody understands ends up disabled at the first incident.
Inter-VLAN Routing: Where to Place the Firewall
Isolating VLANs at layer 2 is half the job; the other half is deciding how they communicate with each other and which device controls that communication. There are three common architectures:
- check_circle Router-on-a-stick: a single trunk link connects the switch to a router or firewall that routes between VLANs through subinterfaces. It is simple and cheap, but all inter-VLAN traffic goes through one link, which becomes a bottleneck.
- check_circle Layer 3 switch: the switch itself routes between VLANs through SVI interfaces at wire speed. It is the highest-performance option, but its ACLs are usually stateless and hard to maintain: they are good for filtering, not for inspecting.
- check_circle Central firewall: each VLAN has its gateway on the firewall, and all traffic between segments goes through stateful inspection, IPS and logging. Maximum control, at the cost of sizing the appliance properly.
Rule of thumb:
Route on the L3 switch only high-volume traffic between segments of the same trust level (for example, servers ↔ backup), and force through the firewall everything that crosses a trust boundary: users → servers, DMZ → internal network, and anything → management.
North-south traffic (towards the Internet) follows its own path through the perimeter firewall and the datacenter's transit providers and peering agreements; we explain that part in detail in our article on peering and BGP.
VLAN Limits and the Leap to Microsegmentation
VLANs segment by subnet: everything inside the same VLAN communicates freely, without passing through any control. In a virtualised datacenter that is a problem, because two neighbouring VMs on the same VLAN can attack each other without the central firewall seeing a single packet. In addition, the 4,094-ID limit falls short in multi-tenant environments, and IP-based ACLs break every time a VM migrates to another host or changes its address.
Microsegmentation inverts the model: instead of defining zones and trusting what is inside them, it defines per-workload policies. Each VM or container carries rules that follow it wherever it runs. The usual technology building blocks are:
- check_circle SDN and VXLAN: software-defined networks encapsulate layer 2 traffic over IP (VXLAN uses a 24-bit identifier: more than 16 million possible segments) and decouple the logical topology from the physical one.
- check_circle Security groups: rules apply to labels or groups ("web-servers", "prod-databases") instead of specific IPs, so policies survive migrations and resizing.
- check_circle Distributed firewall in the hypervisor: platforms such as Proxmox VE (SDN and per-VM firewall), VMware NSX or the security groups of public clouds filter at each machine's virtual interface, also controlling traffic between VMs on the same segment.
The result is Zero Trust applied to east-west traffic: no communication between workloads is allowed by default, not even inside the same segment; everything must be explicitly authorised by a policy.
Common Segmentation Mistakes
These are the flaws we find most often when auditing enterprise networks:
- check_circle Leaving default VLAN 1 everywhere: VLAN 1 is the factory-default native VLAN and carries control protocols on many switches. Using it for users or management makes VLAN hopping easier. Leave it empty and assign a different, unused native VLAN to trunks.
- check_circle Unpruned trunks: a trunk with "all VLANs allowed" propagates every VLAN to every switch, widening the attack surface and the failure domain. Explicitly allow on each trunk only the VLANs it needs to carry.
- check_circle Management on the same VLAN as users: if your servers' iDRAC interface responds from the workstation network, any compromised laptop is one exploit away from full control of the hardware.
- check_circle Believing that VLAN = security: a VLAN without ACLs or a firewall between segments only separates broadcast domains. If inter-VLAN routing is wide open, an attacker crosses from VLAN to VLAN just as on a flat network, only with one extra hop.
Comparison Table: Classic VLAN vs Microsegmentation
The following table summarises the key differences between the two segmentation models:
| Criterion | Classic VLAN (802.1Q) | Microsegmentation |
|---|---|---|
| Segmentation unit | Subnet / switch port | Workload (VM, container) |
| Maximum segments | 4,094 (12-bit ID) | 16+ million (VXLAN, 24 bits) |
| Traffic within the segment | Uncontrolled | Filtered by distributed firewall |
| Policy definition | ACLs by IP and port | Identity-based groups and labels |
| Enforcement point | Switch / central firewall | Each VM's virtual interface |
| Workload mobility | Manual reconfiguration | Policy follows the VM |
| Security model | Trust zones | East-west Zero Trust |
| Complexity and cost | Low: any managed switch | Medium-high: requires SDN/hypervisor |
| Typical use case | Campus networks and physical infrastructure | Virtualised, multi-tenant datacenter |
They are not mutually exclusive technologies: VLANs structure the physical network (management, backup, DMZ) while microsegmentation protects the virtualised workloads running on top of it. Most mature infrastructures combine both.
EasyDataHost: Segmented Networks by Default
At EasyDataHost, segmentation is not an optional extra: we deliver private networks and dedicated VLANs as part of our infrastructure in Spain:
- arrow_right Private VLANs between dedicated servers: your servers communicate over a private network isolated from other customers, without consuming public transit and without exposing internal services.
- arrow_right Segmentation in colocation: if you bring your own hardware to our colocation service, we connect your equipment to the VLANs you define: management, production, backup or interconnection with your cloud.
- arrow_right Cloud with software-defined networking: our cloud platform on Proxmox VE supports SDN, per-tenant VLANs and a per-VM distributed firewall to apply real microsegmentation.
- arrow_right Hybrid interconnection: VLANs extended between your colocation, your dedicated servers and the cloud, so segmentation stays consistent across the whole infrastructure.
Everything runs on our own datacenter in Spain, with ISO 27001 certification and ENS compliance. If you want to review the segmentation design of your infrastructure, contact our team for a technical review with no obligation.
Frequently Asked Questions
How many VLANs does the 802.1Q standard allow?
The 802.1Q VLAN ID is 12 bits long, giving 4,096 possible values; after discounting the reserved ones (0 and 4095), 4,094 usable VLANs remain. When more segments are needed — typical in multi-tenant environments or large datacenters — VXLAN is used instead: its 24-bit identifier allows more than 16 million logical networks.
Is a VLAN a sufficient security measure?
Not on its own. A VLAN isolates at layer 2 and separates broadcast domains, but if inter-VLAN routing is not filtered by ACLs or a firewall, any device can reach the other segments. The VLAN is the foundation of segmentation; security comes from the filtering policies applied between segments and, in its most advanced form, from microsegmentation.
What is the difference between a VLAN and microsegmentation?
A VLAN segments by subnet: it controls traffic between segments, but not within them. Microsegmentation defines per-workload policies (VM or container) enforced by a distributed firewall in the hypervisor, also controls east-west traffic inside the same segment, and the policy follows the VM when it migrates. They are complementary: VLANs structure the physical network and microsegmentation protects virtualised workloads.
Conclusion
Network segmentation is the security measure with the best effort-to-benefit ratio a company can adopt, and VLANs are its natural starting point:
- arrow_right VLANs (802.1Q) divide the physical network into isolated logical networks: less broadcast, less lateral movement and separated environments with a simple managed switch.
- arrow_right The typical design separates management, servers, users, backup and DMZ, with the firewall controlling every trust-boundary crossing.
- arrow_right VLANs are not enough on their own: without inter-VLAN filtering they only separate broadcast, and they never control traffic within the segment itself.
- arrow_right Microsegmentation takes policy down to each workload with SDN, VXLAN and a distributed firewall: Zero Trust for the datacenter's east-west traffic.
If your network is still flat, starting with a few well-chosen VLANs — management, servers, users and backup — is the first step; microsegmentation will come when virtualisation demands it.