Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium


How VLAN's Work

Posted on 2010-01-11
Medium Priority
Last Modified: 2012-05-08

I am thinking about employing vlan technology in my workplace but am trying to get a greater understanding of the benefits / limitations before I call someone in. From what I have read All servers / printers / switches / networking devices could be in one subnet or vlan and the users / workstations could be on another subnet / vlan. Ideally I am interested in doing the following. For example users need access to the wireless access point but do not need access to the configuration page for the wireless device, same for printers and switches, and servers for that point. I know all these pages are password protected, and some devices you can limit by ip what devices can manage the device. I was not sure if vlan does a similar thing for example give file access and login capabilities to the server, but if they attempt to go to the server webpage the request fails? Just trying to understand how vlan's work in greater detail. If I was to seperate workstations and servers into seperate vlan's they still need to be able to talk to each other so people can access their work?

Any advice would be greatly appreciated.

Question by:elschott
  • 2

Expert Comment

ID: 26288315
That is not what vlans do; here is a link about how vlans work in greater detail, it will be easier to read than me writing it all down here. It also has pictures to help illustrate.
LVL 14

Assisted Solution

amichaell earned 600 total points
ID: 26288328
VLANs are used to create virtual networks to limit broadcast domains and/or for security purposes.  To my knowledge, I don't believe a VLAN can accomplish your goal as they work off of IP addresses.  

Accepted Solution

dgware earned 800 total points
ID: 26288349
LVL 21

Assisted Solution

Rick_O_Shay earned 600 total points
ID: 26289181
VLANs let you separate what devices are local to each other and restrict where broadcasts will go.
Communications between VLANs requires a router or L3 switching interface in each VLAN.
Since you need to have users get to resources on servers you wouldn't want to completely isolate them with VLANs but at the router's interface you can apply ACLs or filters to control what access is permitted from the user VLAN to the server, and management VLANs. If the general population of users are not allowed to manage devices then you could control that easily with an ACL for example.

Featured Post

What does it mean to be "Always On"?

Is your cloud always on? With an Always On cloud you won't have to worry about downtime for maintenance or software application code updates, ensuring that your bottom line isn't affected.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I eventually solved a perplexing problem setting up telnet for a new switch.  I installed a new Cisco WS-03560X-24P switch connected to an existing Cisco 4506 running a WS-X4013-10GE Sup II-Plus. After configuring vlans and trunking,  I could no…
Hello to you all, I hear of many people congratulate AWS (Amazon Web Services) on how easy it is to spin up and create new EC2 (Elastic Compute Cloud) instances, but then fail and struggle to connect to them using simple tools such as SSH (Secure…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Suggested Courses

564 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question