VLAN Security – Are There Security Advantages to Activating VLAN Tagging?

private-vlanSecuritytrunkvlan

I understand the concepts of generating a VLAN. However, on a small, closed, sophisticated network, are there any security advantages to activating VLAN tagging?

Best Answer

The security part comes from using VLANs. Users and devices on one VLAN cannot communicate with users and devices on another VLAN, except through a router. This gives you the opportunity to place restrictions (firewall, ACLs, etc.) on the VLAN-to-VLAN communication.

VLAN tags are used on a trunk, where traffic from multiple VLANs travels, in order to tag the frames so that switches know which frames belongs to which VLAN. Most end-devices don't understand VLAN tags on frames, and tagging frames to an end-device will usually result in the frames being dropped. This part isn't really about security, except where it helps keep the traffic separate on trunks where there is traffic from multiple VLANs.