The term VLAN turns up as soon as you look for a way to separate guest Wi-Fi from the point of sale, or to put security cameras on their own network. The explanations are usually full of jargon and make people back away immediately.
In fact the idea is simple, and the problem it solves is very ordinary.
The idea in one sentence
A VLAN makes a single cable and a single switch behave as though several genuinely separate networks exist inside them.
Picture a building with one corridor. Without VLANs, everyone walks down the same corridor and can meet each other. With VLANs, that corridor is effectively divided into several passages with no connection between them, even though physically it's still one corridor.
Devices in different passages cannot see each other, even when plugged into the same switch.
The problem it solves
Without separation, every device on a network can reach every other. In a business, that means:
- A visitor's laptop shares a space with the point-of-sale computer
- Security cameras are reachable from any guest device
- Rarely-updated smart devices sit next to work files
- One compromised device provides a foothold into the whole network
Why that's risky is covered in the smart device security guide.
When you actually need one
| Situation | VLAN needed? |
|---|---|
| Home, one router | No, the built-in guest network is enough |
| Café, one router and one access point | Usually not yet |
| Two-floor clinic, several access points | Yes, to keep separation consistent |
| Office with switches and cameras | Yes |
| Boarding house with many residents | Useful, but client isolation is often enough |
The first row matters. For homes and businesses with just one router, the built-in guest network solves the same need with far less effort, the steps are in the guide to separating a guest network.
VLANs become necessary once there is more than one network device. A guest network created on the router loses its separation the moment it crosses an ordinary switch on its way to an access point on another floor.
What you need
- A router or gateway that supports VLANs. Some higher-end home routers have it, but generally this is a business-class feature.
- A managed or smart switch. An unmanaged switch cannot separate traffic, the difference is covered in the guide to choosing a network switch.
- Access points supporting multiple SSIDs on different VLANs, if the separation must also apply on the wireless side.
One unsupported device is enough to break the chain. If a switch in the middle of the path doesn't understand VLANs, the separation vanishes as traffic passes through it, with no error message at all. This is why VLAN planning starts by listing every device, not by configuring them one at a time.
A common layout for a small business
| VLAN | Contents | Internet access? |
|---|---|---|
| Operations | Point of sale, work computers, printers | Yes |
| Guest | Visitors | Yes, internet only |
| Devices | Cameras, sensors, smart plugs | Limited |
Three is enough to cover most needs. Adding more rarely delivers a benefit worth the complexity it creates.
The usual inter-VLAN rules: guests may reach nothing but the internet, smart devices may not initiate connections to operations, and operations may reach smart devices when maintenance requires it.
Two terms worth understanding
Untagged is a port for ordinary devices. Laptops, printers, and cameras know nothing about VLANs, so the switch does the tagging on their behalf. One untagged port belongs to one VLAN.
Tagged is a port carrying several VLANs at once over a single cable. It's used to link switch to switch, or a switch to an access point broadcasting several different network names.
The most common beginner mistake is configuring the port heading to another switch as untagged. The result is that only one VLAN gets through, and the rest disappear without a trace.
Easier alternatives
If your needs are simple, there are two much lighter routes:
- The router's built-in guest network. Solves guest separation with no extra hardware at all.
- Client isolation. Stops wireless devices seeing each other, enough for boarding houses and guesthouses, Wi-Fi for boarding houses.
Neither is as strong as a VLAN, but both solve most real problems at zero cost. Moving up to VLANs is best done once those two have proven insufficient, not the other way around.
For offices that genuinely need it, the network layout is covered in the Wi-Fi for small offices guide.
Frequently asked questions
What's the difference between a VLAN and a router's built-in guest network?
A built-in guest network usually only separates wireless users and is often limited to one router. A VLAN separates at the cable level, so the separation holds across every switch and access point in the same building.
Does an ordinary home need VLANs?
Almost never. The guest network feature on a home router already handles separating guests and smart devices. VLANs start to make sense once there are several switches and access points that must stay consistently separated.
What equipment do I need to use VLANs?
A router or gateway that supports VLANs, and a managed or smart switch. An unmanaged switch cannot separate traffic, so the separation disappears the moment traffic passes through it.
What do tagged and untagged mean?
Untagged is a port for ordinary devices that know nothing about VLANs, like a laptop or printer. Tagged is a port carrying several VLANs at once, used to link switches together or to feed an access point broadcasting multiple networks.