UK’s trusted IT infrastructure partner since 2003
Servnet
ConfiguratorGet in Touch
What is a VLAN, and why it quietly matters for your office network — networkWhat is a VLAN, and why it quietly matters for your office network — reach
Networking

What is a VLAN, and why it quietly matters for your office network

Marcus Whitfield · Infrastructure Consultant8 min read

Most small offices run on one flat network: every laptop, printer, phone, CCTV camera and guest device shares the same digital room and can, in principle, talk to everything else. A VLAN is how you put internal walls in that room without re-cabling the building. It sounds like deep networking trivia - until a guest's infected phone reaches your accounts server, and then it becomes a board-level conversation.

One office network, split into VLANs
4Staff VLANlaptops and PCs - reach servers3Voice VLANVoIP phones - own lane, clear calls2Guest VLANinternet only - no internal access1IoT / camera VLANlocked down - recorder only

One office, many invisible rooms

VLAN stands for Virtual Local Area Network. The key word is virtual: instead of running separate physical cabling for each group of devices, your switches and Wi-Fi create separate logical networks over the same wires and access points.

Think of an open-plan office. Everyone shares the floor, but you put up partitions so the finance team, the warehouse tablets and the visitor sofa each have their own space. People can still be moved between areas, but by default they cannot wander into a space they were not assigned to. A VLAN is that partition, applied to network traffic.

Why one flat network is a quiet risk

On a flat network, every device can attempt to reach every other device. That has three consequences most owners never think about until something goes wrong.

  • Security: a compromised guest phone, smart TV or camera can probe your servers and PCs, because nothing separates them.
  • Noise: chatty devices and broadcast traffic reach everything, which can drag down performance as the network grows.
  • Compliance: card-payment and personal-data rules expect sensitive systems to be separated from general traffic - hard to evidence on one open network.

What businesses actually use VLANs for

The everyday uses are pleasingly mundane, which is exactly why they matter. A typical UK office might split its single physical network into a handful of VLANs, each with its own access rules.

Common groupings are: corporate devices (staff laptops and PCs), a separate guest Wi-Fi that can reach the internet but nothing internal, voice handsets kept on their own lane so calls stay clear, and a locked-down VLAN for cameras, door entry and other 'internet of things' kit that you never want talking to your file server.

Can these two devices talk to each other?
Are they on the same VLAN?
Same VLAN
Yes - they share the lane
Different VLANs
Only if the firewall allows it
Guest to servers
Blocked by default

How traffic moves between VLANs (or does not)

By design, VLANs cannot talk to each other unless something deliberately allows it. That something is usually your firewall or a layer-3 switch acting as a controlled doorway between the rooms.

This is the real prize. Because all inter-VLAN traffic passes through that doorway, you can write simple rules: guests reach the internet but never the office; cameras reach the recorder but nothing else; staff reach the servers they need and no more. You have turned an open floor into a building with locked doors and a security desk.

Do you need them, and what it takes

If you have more than a handful of staff, offer guest Wi-Fi, run VoIP phones, or have any cameras and smart devices on the network, the answer is almost always yes. The good news is you usually do not need new cabling - just business-grade switches and access points that support VLANs (sometimes labelled 'managed' or 'smart'), plus a firewall to police the doorways.

It is also a foundation for other things. Segmented networks are far easier to monitor, and they are a building block for the kind of internal isolation behind modern network security and Zero Trust thinking. Set up the rooms once, and a lot of later security work gets simpler.

Key takeaways
  • A VLAN splits one physical network into separate logical ones, with no new cabling required.
  • Flat networks let every device reach every other device - a security, performance and compliance problem as you grow.
  • Typical business VLANs separate staff devices, guest Wi-Fi, phones, and cameras/IoT kit.
  • VLANs cannot talk to each other unless a firewall or layer-3 switch deliberately allows it - that doorway is where you set the rules.
  • Most offices need only managed switches, capable access points and a firewall to get started.
Frequently asked

FAQs — What is a VLAN, and why it quietly matters for your office network

Understanding VLANs

Is a VLAN a security feature or a performance feature?

Both, and that is why it is so useful. Splitting traffic into separate lanes reduces broadcast noise and contains problems to one segment (performance), while the firewall rules between VLANs control who can reach what (security).

Do VLANs need separate cables for each group?

No - that is the whole point of 'virtual'. A single set of cables and access points carries multiple VLANs at once, tagged so the equipment keeps them apart. You only need switches and access points that support VLAN tagging.

Getting it set up

Can my existing office switches do VLANs?

Basic 'unmanaged' switches cannot. You need managed or smart switches, which most business-grade brands offer at a modest premium. If you are refreshing kit anyway, specifying VLAN support costs little and saves a re-buy later.

Is this overkill for a 10-person office?

Rarely. Even a small office usually wants guest Wi-Fi kept away from internal systems, and cameras or smart devices isolated from staff PCs. Those two VLANs alone close off the most common, and most damaging, routes an attacker takes.

Related

Got a question this article didn't answer?

One conversation with an engineer who's done this before. No sales script.

Talk to Servnet →