A local area network (LAN) operates on the principle of broadcasting. Any data transmitted by a device connected to the LAN is received by all other devices within the same broadcast domain.

As the number of devices connected to the LAN increases, the network becomes overloaded. Indeed, the more stations there are, the greater the risk of collisions and the more bandwidth broadcasts consume.

A VLAN (Virtual LAN) is a logical broadcast domain created through software configuration on one or more switches. VLANs therefore enable users or stations to be grouped logically, regardless of their physical location. The broadcast domain comprises all members of a VLAN authorised to communicate.

ℹ Information

On a modern local area network, hosts typically obtain their private IPv4 address automatically via DHCP, along with the gateway address and DNS server addresses. In IPv6, each interface has at least one link-local address (prefix fe80::/10) and can automatically obtain a global address via SLAAC (Stateless Address
(Autoconfiguration) or via DHCPv6. On the same VLAN, devices share the same IP address space, which simplifies routing and the enforcement of security policies.

1. Benefits

· Improved security by protecting certain resources and isolating certain groups (e.g. accounting VLAN, guest VLAN, IoT VLAN)

· Improved performance by limiting broadcast domains — broadcasts remain confined to the VLAN

· Flexibility: if a user moves within the premises, they retain the same access rights to LAN resources without the system administrator having to intervene physically

· Simplifying network management: grouping by function (sales, production, management) rather than by geographical location

⚠ VLAN security

VLAN segmentation improves security, but it is not sufficient on its own to control who is authorised to connect to the network. It is recommended to combine VLANs with access control mechanisms such as port security (limiting the number of approved MAC addresses on a port) and 802.1X authentication based on a RADIUS server. This ensures that only authorised users or devices can access a given VLAN.

2. Types of VLANs

Port-based VLAN: VLANs are defined as groups of ports. All devices connected to the ports in the group then belong to the same VLAN. They are particularly suitable for networks where only one device is connected to each port on the switch. Easy to use.

MAC-based VLANs: VLANs are defined as a list of devices identified by their MAC addresses. As they are more flexible, they allow each device to be assigned to a specific VLAN, regardless of its physical location within the network. These VLANs are complex to manage due to the difficulty involved in managing MAC addresses.

Layer 3 VLANs (Subnet VLANs): group together stations using the same Layer 3 protocol or belonging to the same logical network (IP subnet). They use the same segmentation criteria as routers and integrate well with existing networks. Easier to manage as they operate on Layer 3 addresses that are well known to network operators.

Application-based VLANs: when used in conjunction with Layer 3 VLANs, these enable VLANs to be optimised or customised for specific applications (e.g. VoIP VLANs, CCTV VLANs, multicast VLANs).

3. Standard IEEE 802.1Q — Le trunk VLAN

To carry VLAN information between switches or between a switch and a router, the IEEE 802.1Q standard defines a mechanism for tagging Ethernet frames. A 4-byte tag, inserted into the Ethernet frame, identifies the VLAN to which it belongs.

The structure of the 802.1Q tag is as follows:

TPID (Tag Protocol Identifier): 2 bytes — fixed value 0x8100, identifying the frame as 802.1Q-tagged

PCP (Priority Code Point): 3 bits — frame priority (0 to 7), used for Layer 2 QoS (IEEE 802.1p)

DEI (Drop Eligible Indicator): 1 bit — indicates whether the frame may be dropped in the event of congestion

VID (VLAN Identifier): 12 bits — VLAN number ranging from 0 to 4095 (0 and 4095 are reserved, leaving 4,094 usable VLANs)

Links between switches carrying multiple VLANs are called trunk links. On a trunk, each frame is tagged with the VLAN to which it belongs.

⚠ Attention

The native VLAN (VLAN 1 by default) is not tagged on the trunk — this is an important configuration and security consideration.

As VLANs are separate broadcast domains, communication between two different VLANs requires Layer 3 routing.

There are two common approaches:

Router-on-a-Stick: a router connected to the switch via a single trunk link, with sub-interfaces (sub-interfaces) configured for each VLAN.

Layer 3 switch (L3 Switch): the switch incorporates a hardware routing engine (ASIC). Inter-VLAN routing is performed locally on the switch via SVI interfaces (Switched Virtual Interface), without the need for an external router. This is the recommended solution for performance.

⚡ VXLAN — VLANs for the cloud and data centres

The IEEE 802.1Q standard limits the number of VLANs to 4,094, which is insufficient for public clouds hosting thousands of customers. VXLAN (Virtual Extensible LAN, RFC 7348) solves this problem by encapsulating Layer 2 Ethernet frames within Layer 3 UDP packets, using a 24-bit segment identifier (VNI — VXLAN Network Identifier) supporting over 16 million distinct virtual networks. VXLAN is the standard for data centres and private/public clouds.

E. LAYER 2 PROTOCOLS

In addition to CSMA/CD, several Layer 2 protocols are essential for the operation of modern local area networks. The main ones are the Spanning Tree Protocol, link aggregation and Layer 2 quality of service.

⚠ Native VLANs and security

On an 802.1Q trunk link, the native VLAN is the VLAN whose frames are sent untagged. Misuse of the native VLAN can create security vulnerabilities (such as VLAN hopping attacks or configuration confusion between devices). In practice, it is advisable not to use the native VLAN for user traffic, to reserve it for a dedicated VLAN, and to systematically check the consistency of the VLANs configured on both sides of a trunk.

1. Spanning Tree Protocol (STP — IEEE 802.1D)

In corporate networks, redundant links between switches are necessary to ensure availability in the event of a link failure. However, physical loops at Layer 2 create broadcast storms that can cripple the entire network.

The Spanning Tree Protocol (STP, IEEE 802.1D) resolves this issue by creating a loop-free logical tree from a redundant physical topology. It logically blocks redundant ports and automatically reactivates them should the primary link fail.

His successors improved the convergence rate:

RSTP (Rapid STP, IEEE 802.1w): convergence in a matter of seconds (compared to 30 to 50 seconds for STP). Current standard.

MSTP (Multiple STP, IEEE 802.1s): allows for multiple instances of Spanning Tree for different groups of VLANs, thereby optimising traffic by using different physical links for different VLANs.

2. Link aggregation (LACP — IEEE 802.3ad)

Link aggregation (Link Aggregation, also known as EtherChannel at Cisco, bonding in Linux or Port Channel) allows multiple physical links to be combined into a single logical link. This provides increased bandwidth and automatic redundancy.

LACP (Link Aggregation Control Protocol, IEEE 802.3ad) is the standard protocol that automatically negotiates the formation of an aggregation group between the two ends of the link. For example, four aggregated 10 Gbps links form a logical 40 Gbps link with fault tolerance for a single link.

3. Layer 2 Quality of Service (IEEE 802.1p)

IEEE 802.1p defines eight traffic priority levels (0 to 7) encoded in the PCP field of the 802.1Q tag. Switches use these priorities to ensure that sensitive traffic (voice, video) is processed before ordinary data.

The standard IEEE 802.1p priorities are as follows:

 

Priority

Nom

Typical use

Seven (maximum)

Network Control

Network control traffic (BPDU, OSPF)

6

Internetwork Control

Routing protocols

5

Voice

Voice over IP (VoIP) — latency  150 ms

4

Video

Video conferencing, streaming

3

Excellent Effort

Business-critical applications

2

Spare

Reserved

1

Background

File transfers, backups

0 (default)

Best Effort

Standard, non-prioritised traffic

Modifié le: jeudi 8 octobre 2026, 12:32