Theme: Traffic separation is not the same as security
Quick definition
A VLAN, or Virtual Local Area Network, divides a bridged Layer 2 network into logical broadcast domains. IEEE 802.1Q covers bridged networks and VLAN bridges. Multiple VLANs can share switch infrastructure while Layer 2 traffic remains in separate logical domains.
In context: how the separation works
Switch ports are assigned to VLANs, while links between network devices can carry identified VLAN traffic. A broadcast normally remains within its VLAN domain. Communication between IP subnets in different VLANs requires routing or another Layer 3 function where policy can be enforced.
For example: an OT network
A site may separate operator stations, building automation and guest access into VLANs over shared switches. A firewall or router permits only defined flows, such as monitoring from a designated server to controls, and records exceptions.
A VLAN alone is not a security boundary
A VLAN organises Layer 2 traffic but does not automatically authenticate devices, encrypt payloads or decide which application requests are permitted. Misconfiguration, compromised network equipment or allowed routing can cross the separation. Security requires multiple enforcing controls.
Opportunities
VLANs can reduce broadcast scope, separate addressing plans and provide a manageable foundation for zones. They may simplify troubleshooting and phased migration where cabling and switches are shared. A documented relationship between system function, VLAN and IP subnet improves support.
Limitations and risks
Numerous VLANs can create configuration debt and a false sense of isolation. Trunks, native VLANs, management interfaces and routing require consistent governance. A VLAN without filtering may still allow broad communication inside its domain.
HubMind’s view
Treat VLANs as a traffic-separation building block, not evidence of protection. Tie each zone to process consequence and an allowed-flow list. Enforce rules in firewalls, routers, access controls or hosts where risk requires them, and test the result.
Next step before commissioning
Which broadcast domains are needed? Where does routing occur? Which control denies unauthorised flows? How are management and trunks protected? How is configuration drift detected? Test both permitted communications and attempts that should be blocked.
Related concepts
Network Segmentation, Ethernet, Cybersecurity (OT), IP-based Automation.
Sources and further reading
Scope and freshness
VLANs in IEEE 802.1Q-2022 and OT segmentation in NIST SP 800-82 Rev. 3. This covers logical Layer 2 separation, not vendor configuration. Reviewed 31 August 2026.
