What is a VLAN?
Definition
A VLAN, or virtual LAN, is a logical network segment created on shared physical switches and access points. Defined in IEEE 802.1Q, it keeps traffic on one segment separate from every other. Guest, staff, payment and IoT traffic typically run on separate VLANs so they cannot reach each other.
VLAN explained
Each Ethernet frame on a VLAN-aware network carries a 12-bit VLAN identifier in its header. Switches use that tag to keep each VLAN in its own broadcast domain, so devices on one VLAN behave as if they were on a separate physical network. Traffic can only cross between VLANs through a router or firewall that explicitly allows it.
On WiFi, SSIDs are mapped to VLANs. The access point tags traffic from the guest SSID with the guest VLAN ID and traffic from the staff SSID with the staff VLAN ID, and the switches carry each to the right place. Without VLANs, every device shares one broadcast domain, which creates both security and performance risks.
VLANs can also be assigned per user. With dynamic VLAN assignment, the RADIUS server tells the network which VLAN to place each user or device on at sign-in, based on their role. That lets one SSID serve several groups, and it is the basis of tenant isolation in multi-tenant buildings, where each tenant or resident gets a VLAN of their own.
Need more than a definition?
Talk to our team about how Purple combines guest WiFi, captive portals, RADIUS, and analytics into a single platform that runs on the access points you already own.