Vlans are designed to help segregate network traffic which can be based simply on the administrative function of the user. To explain how vlans are useful imagine one large conference hall with a large audience of people (hosts) located throughout the hall with multiple speakers and they are all speaking at once. The audience will hear not only from the speaker they are trying to listen and talk too but they will unnecessarily hear from the other the speakers and people in that conference hall they don’t really need to hear from. Although this one large room (vlan) is able to accommodate everyone it’s not really adequate for the conference given the amount of people trying to listen and talk with each other related to their own specific subject So now the administrator of this conference has decided to partition/segregate the conference hall into smaller rooms (vlans) and each room having its own speaker and specific audience. These rooms has now become single vlans , Independent domains allowing the speaker and audience members to converse (broadcast) to each other only in that room(vlan) without other people outside that room(vlan) from hearing. Outside the door of each room (gateway) with have a sign showing a subject of the room and number (vlan number& name) If people wish to speak/listen to others in different rooms (vlans) they can do so by going through their own room door (gateway) then they will be directed towards the other rooms. Providing these rooms (vlans) allow entrance a user(s) from each room will be able to speak freely with each other. Access between these rooms (vlans) can be controlled or even prohibited on a room by room or even down to an individual hosts to host basis if desired. So given that analogy, Vlans on a network can help greatly in controlling access between users(hosts) in different departments and to reduce unwarranted traffic on the office network at the same time provide great flexibility when/if the need arises to implement differing security/management polices to each vlan, And as these vlans can span a single/multiple network switches it will allow users to be connected to the network wherever they are located physically in office building but actually they are sharing the same virtual room (vlan) as their department colleagues located elsewhere.
... View more