LAN & VLAN Infrastructure • 1954 words • 8 min read

Enterprise LAN Infrastructure: VLAN Segmentation (802.1Q), Dynamic DHCP, and NAT Port Forwarding

Why can a single physical network switch be carved into dozens of isolated virtual local networks? Deconstruct three core pillars of enterprise LAN engineering: from broadcast storm hazards to IEEE 802.1Q frame tagging (4-byte tag, 12-bit VID, PCP QoS priority); the operational differences between Access ports, Trunk ports, and PVID tag stripping/insertion; comparing router-on-a-stick sub-interfaces with Layer 3 Switch Virtual Interfaces (SVI); dissecting DHCP's 4-step DORA handshake and cross-subnet relay agents; and demystifying NAPT (Port Address Translation), SNAT, DNAT, and Linux kernel conntrack state tables.

Networking Series Part 3 / 12

Computer Networking Masterclass: From Ethernet Principles to Hyperscale InfiniBand Architecture

A ground-zero masterclass to 10,000-GPU AI networking: from physical voltages, twisted pairs, and optical fibers to hubs, collision domains, switches, and MAC/ARP; step-by-step binary derivations of IP addressing, subnet masks, default gateways, VLANs, DHCP, and NAT; in-depth DNS, Socket 5-tuples, TCP 11-state machines, and BBR congestion control; Linux kernel NAPI, sk_buff, and eBPF XDP; datacenter traditional 3-tier vs 2-tier Spine-Leaf fabrics and EVPN-VXLAN; leading up to AI supercomputing: lossless RoCEv2, native InfiniBand NDR/XDR link speeds, credit flow control, Rail-Optimized Fat-Trees, Adaptive Routing, SHARP, and bare-metal OFED/NCCL performance tuning.

Browse all 12 chapters in this series ▾
  1. 01 Computer Networking from Scratch: Bits, Physical Media, Hub Collision Domains, and Switch MAC Addressing First Principles
  2. 02 IP Addressing and Subnetting First Principles: Binary Arithmetic, Subnet Masks, CIDR, and Default Gateway Routing
  3. 03 Enterprise LAN Infrastructure: VLAN Segmentation (802.1Q), Dynamic DHCP, and NAT Port Forwarding Reading
  4. 04 Application & Transport Layer Bridges: DNS Resolution, Sockets, Ports, and UDP vs TCP Foundations
  5. 05 Network & Transport Layers in Depth: IP Routing, CIDR, TCP 11-State Machine, and Sliding Window First Principles
  6. 06 TCP Congestion Control Evolution & High-Performance Transport: From Reno and Cubic to BBR Mathematical Models, and HTTP/2 to HTTP/3 (QUIC)
  7. 07 Linux Kernel Networking Subsystem in Depth: From NIC Drivers, NAPI, and Ring Buffers to eBPF XDP Wire-Speed Forwarding
  8. 08 Modern Data Center Network Architecture First Principles: Clos Topologies, Leaf-Spine Fabrics, BGP Underlay, and EVPN-VXLAN Large Layer-2 Virtualization
  9. 09 RDMA High-Performance Networking Foundations: Kernel Bypass, Zero-Copy, Queue Pairs, and Lossless RoCEv2 (PFC/ECN) Architecture
  10. 10 InfiniBand Architecture First Principles: Physical Link Rates, Credit-Based Link Flow Control, and Subnet Manager Fabric Orchestration
  11. 11 InfiniBand AI Cluster Networking in Practice: Fat-Tree Topologies, Rail-Optimized Architecture, Adaptive Routing (AR), and In-Network Reduction (SHARP)
  12. 12 Production InfiniBand Deployment, Cluster Operations, and NCCL Tuning: OFED Drivers, OpenSM HA, ibdiagnet Fabric Auditing, and GPUDirect RDMA

Introduction: When a Facility Houses Hundreds of Employees Across Multiple Departments

In the previous chapters, we derived Layer 2 MAC switching and Layer 3 IP subnetting from physical principles.

However, as an organization scales to 500 employees across Finance, Engineering, and Human Resources, enterprise network management encounters practical challenges:

  • Security isolation breaks down: If finance servers and workstations share an unsegmented switch with general office devices, packet sniffers can inspect sensitive payroll data;
  • Broadcast storms disrupt the fabric: If a compromised machine floods the network with ARP requests, broadcast processing consumes CPU cycles on all 500 connected hosts;
  • Manual IP configuration becomes unmanageable: Manually assigning static IPs, subnet masks, gateways, and DNS resolvers to every visiting laptop is error-prone and unsustainable;
  • Public IPv4 addresses are scarce: An Internet Service Provider typically assigns a single public IPv4 address to an enterprise. How can 500 hosts share this address simultaneously?

To resolve these challenges, modern enterprise networks rely on three core protocols: VLANs (Virtual Local Area Networks), DHCP (Dynamic Host Configuration Protocol), and NAT (Network Address Translation).


1. VLAN First Principles: Segmenting the Broadcast Domain

A VLAN (Virtual Local Area Network) partitions a physical switch into multiple isolated virtual switches at the hardware ASIC level, avoiding the need to purchase separate physical hardware:

flowchart TD
    subgraph PhysicalSwitch["Single 24-Port Physical Layer 2 Switch"]
        subgraph VLAN10["VLAN 10: Finance Department (192.168.10.0/24)"]
            Port1["Port 1 (Finance PC A)"]
            Port2["Port 2 (Payroll Server)"]
        end
        subgraph VLAN20["VLAN 20: Engineering Department (192.168.20.0/24)"]
            Port3["Port 3 (Engineer PC B)"]
            Port4["Port 4 (Git Server)"]
        end
    end
    Port1 -. "Broadcast frames blocked at the hardware port level" .-x Port3
  • Broadcast Isolation: Broadcast frames (such as ARP requests) originating within VLAN 10 are physically filtered by switch silicon from egressing onto VLAN 20 ports, containing broadcast storms;
  • Security Boundaries: Separate VLANs remain isolated at Layer 2, preventing unauthorized cross-department packet capture.

2. 802.1Q Tagging Mechanics and Access vs Trunk Ports

Endpoint network cards typically process standard, untagged Ethernet frames. How do switches identify which VLAN a frame belongs to?

They use the standard IEEE 802.1Q frame tagging specification.

2.1 The 802.1Q Tag Structure

The 802.1Q standard inserts a 4-byte (32-bit) VLAN Tag between the Source MAC and EtherType fields of a standard Ethernet frame:

Standard Ethernet Frame with 802.1Q Tag Inserted:
+-----------+-----------+-------------------------+-----------+---------------+---------+
| Dest MAC  | Source MAC| 802.1Q Tag Header       | EtherType | Payload Data  | FCS     |
| (6 Bytes) | (6 Bytes) | 4 Bytes (32 Bits)       | (2 Bytes) | (46 - 1500B)  | (CRC,4B)|
+-----------+-----------+-------------------------+-----------+---------------+---------+
                        |                         |
                        v                         v
       +------------------+-------+-----+------------------+
       | TPID             | PCP   | DEI | VID (VLAN ID)    |
       | 16 Bits (0x8100) | 3Bits | 1Bit| 12 Bits (1-4094) |
       +------------------+-------+-----+------------------+
  1. TPID (Tag Protocol Identifier, 16 bits): Set to 0x8100, indicating an 802.1Q-tagged frame follows;
  2. PCP (Priority Code Point, 3 bits): Provides 8 priority levels (0–7) for Class of Service (QoS) traffic prioritization (e.g., prioritizing VoIP or video over bulk downloads);
  3. VID (VLAN Identifier, 12 bits): 212=40962^{12} = 4096. Values 0 and 4095 are reserved, leaving valid VLAN IDs from 11 to 40944094.

2.2 Switch Port Types: Access vs Trunk

Switches connect to both end-user devices and upstream network equipment, relying on two distinct port modes:

+-------------------------------------------------------------------------------+
| Access Port (Endpoint Links): Connects to PCs, printers, and standard servers |
|   - Characteristics: Assigned to a single VLAN (e.g., PVID=10)                |
|   - Ingress: Adds a VLAN tag matching the port's PVID to incoming frames      |
|   - Egress: Strips the 802.1Q tag, delivering standard frames to end hosts    |
+-------------------------------------------------------------------------------+
| Trunk Port (Backbone Links): Connects switches to switches or routers         |
|   - Characteristics: Transports multiplexed traffic from multiple VLANs       |
|   - Ingress/Egress: Preserves 802.1Q tags to retain VLAN identity across hops |
+-------------------------------------------------------------------------------+
sequenceDiagram
    autonumber
    actor PC_A as Host A (Untagged NIC)
    actor SW1 as Switch 1
    actor SW2 as Switch 2
    actor PC_B as Host B (Untagged NIC)

    Note over PC_A: Transmits standard untagged Ethernet frame
    PC_A->>SW1: Ingresses Access Port (PVID=10)
    Note over SW1: Inserts 802.1Q Tag: VID=10
    
    SW1->>SW2: Crosses Trunk link preserving Tag=10
    
    Note over SW2: Identifies egress Access Port (PVID=10)
    Note over SW2: Strips 802.1Q Tag, restoring standard untagged frame
    SW2->>PC_B: Delivered to Host B interface

2.3 Inter-VLAN Routing: Router-on-a-Stick vs Layer 3 Switches (SVI)

When hosts in Engineering (VLAN 10) need to reach an internal API in Finance (VLAN 20), traffic must be routed:

  • Router-on-a-Stick: Connects the switch's trunk port to a physical router interface configured with virtual sub-interfaces (e.g., eth0.10, eth0.20), using the router to perform inter-subnet routing;
  • Layer 3 Switch (Switch Virtual Interface, SVI): The standard enterprise design. The switch uses onboard routing ASICs to terminate VLANs on internal Switch Virtual Interfaces (SVIs, e.g., interface Vlan 10), routing between VLANs at wire speed across the internal backplane without sending packets through an external router.

3. DHCP: The 4-Step DORA Protocol

When an employee plugs a laptop into a wall jack, the operating system obtains an IP address, subnet mask, gateway, and DNS servers within seconds using DHCP (Dynamic Host Configuration Protocol) (running over UDP: server port 67, client port 68):

sequenceDiagram
    autonumber
    actor Client as Booting Laptop (Client)
    actor Switch as Switch
    actor Server as DHCP Server (192.168.1.1)

    Note over Client: Has no IP (Src: 0.0.0.0)
Target unknown (Dest: 255.255.255.255) Client->>Switch: 1. DHCP Discover (Broadcast): "Is there a DHCP server on this link? I need an IP!" Switch-->>Server: Floods broadcast to DHCP server Note over Server: Reserves IP from pool: 192.168.1.105 Server->>Switch: 2. DHCP Offer (Unicast/Broadcast): "Offer: 192.168.1.105, Mask /24, Gateway 192.168.1.1, Lease 24h" Switch->>Client: Delivered to client Client->>Switch: 3. DHCP Request (Broadcast): "Accepting 192.168.1.105 from server 192.168.1.1!" Note over Client,Server: (Broadcast informs other responding DHCP servers to release their reserved offers) Switch-->>Server: Delivered to server Server->>Switch: 4. DHCP ACK (Unicast/Broadcast): "Lease committed! Configuration active." Switch->>Client: Laptop configures interface and comes online
  • Lease Renewal Timers:
    • T1 Timer (50% of lease): The client attempts a unicast DHCP Request directly to the issuing server to extend the lease;
    • T2 Timer (87.5% of lease): If the issuing server fails to respond, the client broadcasts a DHCP Request to any reachable DHCP server; if the lease reaches 100% without renewal, the interface releases the IP and falls back to an APIPA address (169.254.x.x).

4. Network Address Translation (NAT): Multiplexing a Public IP

4.1 The Core Challenge: Private IPs Are Non-Routable

As covered in Chapter 2, RFC 1918 private IPv4 addresses (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) are filtered by public Internet routers.

If an enterprise has a single public IP (e.g., 203.0.113.88), how can 500 private hosts access external web services concurrently?

The Solution: NAPT (Network Address Port Translation / PAT)!

sequenceDiagram
    autonumber
    actor Host as Internal PC (192.168.1.50:50001)
    actor Router as NAT Gateway (Public IP: 203.0.113.88)
    actor Web as External Web Server (93.184.216.34:80)

    Note over Host: Initiates outbound HTTP request
    Host->>Router: Packet: [Src=192.168.1.50:50001, Dst=93.184.216.34:80]
    
    Note over Router: SNAT and Port Rewriting:
Allocates state in conntrack table:
(192.168.1.50:50001) <-> (203.0.113.88:62000)
Rewrites source IP and source port Router->>Web: Masqueraded: [Src=203.0.113.88:62000, Dst=93.184.216.34:80] Note over Web: Web server returns payload to 203.0.113.88:62000 Web->>Router: Reply: [Src=93.184.216.34:80, Dst=203.0.113.88:62000] Note over Router: Reverse conntrack lookup:
Maps port 62000 to internal 192.168.1.50:50001
Restores original destination IP and port Router->>Host: Delivered: [Src=93.184.216.34:80, Dst=192.168.1.50:50001]

4.2 SNAT vs DNAT (Port Forwarding)

  • SNAT (Source NAT):
    • Direction: Internal hosts initiating outbound traffic to the Internet;
    • Operation: Rewrites the source IP and source port on egress, masking internal addresses behind the gateway's public IP;
  • DNAT (Destination NAT / Port Forwarding):
    • Direction: External clients accessing internal servers (e.g., exposing an internal web server);
    • Operation: Rewrites the destination IP and destination port on ingress. For example, incoming requests to 203.0.113.88:8080 are rewritten and forwarded to internal host 192.168.1.200:80.

5. Linux Networking and Inspection Commands

Managing VLANs, connection tracking, and NAT rules on Linux:

# 1. Create an 802.1Q tagged interface on physical adapter eth0 (VLAN ID 10)
ip link add link eth0 name eth0.10 type vlan id 10
ip addr add 192.168.10.1/24 dev eth0.10
ip link set eth0.10 up

# 2. Inspect active Netfilter NAT tables
iptables -t nat -L -n -v

# 3. Standard masquerade rule for outbound traffic
# iptables -t nat -A POSTROUTING -s 192.168.0.0/16 -o eth0 -j MASQUERADE

# 4. Inspect active connection states in the kernel conntrack table
conntrack -L -p tcp
# Sample output:
# tcp 6 431999 ESTABLISHED src=192.168.1.50 dst=93.184.216.34 sport=50001 dport=80 \
#                          src=93.184.216.34 dst=203.0.113.88 sport=80 dport=62000 [ASSURED]

6. Summary and Next Steps

VLANs, DHCP, and NAT provide the operational backbone for enterprise networks:

  • VLANs and 802.1Q Tagging isolate broadcast domains and segment departments using 4-byte headers across Access and Trunk ports;
  • DHCP automates host addressing through the 4-step DORA handshake;
  • NAT / PAT tracks session state in kernel conntrack tables, allowing thousands of internal hosts to multiplex through a shared public IP.

With Layer 2 and Layer 3 configured, how do applications resolve services and exchange data?

  • When you type www.google.com into a browser, how does the global DNS hierarchy resolve human-readable domains into routable IP addresses?
  • Once a packet reaches a server hosting multiple applications, how do Ports and Operating System Sockets direct the payload to the correct process?
  • Why do real-time voice and video streams choose UDP, while web browsers and databases rely on TCP?

In Chapter 4 of our masterclass, we explore the boundary between transport and applications: Application & Transport Layer Bridges: DNS Resolution, Sockets, Ports, and UDP vs TCP Foundations!


Frequently Asked Questions (FAQ)

Q1: If two PCs on the same switch share the same subnet (e.g., `192.168.1.10/24` and `192.168.1.20/24`) but are assigned to different VLANs (VLAN 10 and VLAN 20), can they communicate?

No. Traffic is dropped at Layer 2 inside the switch ASIC. Because both PCs reside on 192.168.1.0/24, PC A issues an ARP broadcast looking for PC B's MAC address. When the broadcast enters PC A's switch port (an Access port assigned to VLAN 10), the switch tags the frame with VID=10. The switch's forwarding logic strictly prevents frames tagged with VID=10 from exiting ports that do not belong to VLAN 10. PC B's port (assigned to VLAN 20) never receives the frame. Because the ARP request is never delivered, PC A never resolves PC B's MAC address, preventing communication.

Q2: Why does Router-on-a-Stick introduce bandwidth bottlenecks, and how do Layer 3 switches resolve this?

  • Router-on-a-Stick Bottleneck: All inter-VLAN traffic must traverse a single physical trunk link to the router, be processed by the router's CPU, and return across the same link to the switch. This halves usable bandwidth on the link and risks CPU saturation under heavy traffic;
  • Layer 3 Switch Resolution: Layer 3 switches incorporate routing logic directly into internal switching ASICs. Inter-VLAN traffic is routed via on-chip Switch Virtual Interfaces (SVIs) across the internal backplane at full hardware wire speed, removing the external router bottleneck entirely.

Q3: Why can't two private hosts behind different home NAT routers establish direct P2P connections by default, and how does "NAT Traversal (Hole Punching)" solve this?

Root Cause: Stateful NAT drop policies on unsolicited inbound traffic. Unless an internal host initiates an outbound session, the router's conntrack table contains no matching entry for external IP addresses. When a remote peer sends unsolicited packets to your public IP, your router drops them as potential attacks. Hole Punching Mechanics: Both peers communicate with a public STUN server to discover their respective <Public IP: Mapped Port> bindings. Both peers then simultaneously transmit UDP probe packets toward each other's mapped public endpoints. These outgoing packets create outbound session entries in their respective local NAT conntrack tables. Subsequent incoming packets from the peer match these established session entries and are forwarded through, establishing direct P2P communication.

Related Articles

Start with the same topic, then continue with the latest deep dives.

Production InfiniBand Deployment, Cluster Operations, and NCCL Tuning: OFED Drivers, OpenSM HA, ibdiagnet Fabric Auditing, and GPUDirect RDMA

What bare-metal operational challenges arise when translating network architecture into physical 10,000-GPU AI data centers? A comprehensive guide to production InfiniBand operations: installing and managing Mellanox OFED / DOCA driver stacks and firmware tools (flint/mlxlink); configuring high-availability Master/Standby Subnet Manager topologies with OpenSM; auditing fabric health and diagnosing dirty optical links (Symbol Errors) and speed renegotiation drops using ibdiagnet; and diving into the GPU communication layer to configure GPUDirect RDMA (nvidia-peermem) and tune mission-critical NCCL parameters (NCCL_IB_HCA, NCCL_NET_GDR_LEVEL=5) for wire-speed All-Reduce performance.

InfiniBand AI Cluster Networking in Practice: Fat-Tree Topologies, Rail-Optimized Architecture, Adaptive Routing (AR), and In-Network Reduction (SHARP)

How can thousands of 8-GPU servers be interconnected with tens of thousands of optical links into a non-blocking, deadlock-free high-performance fabric? Deconstruct modern AI supercluster topologies: from Charles Leiserson's 1985 Fat-Tree mathematical model and port count k derivations for 2-Tier and 3-Tier non-blocking ceilings to the 8-plane Rail-Optimized architecture tailored for DGX H100/H200/B200 clusters; analyze how FTree and Up/Down routing engines forbid 'Down-then-Up' turns to eliminate credit loop deadlocks; and discover how hardware Adaptive Routing (AR) and SHARP in-network aggregation achieve a 2x throughput boost during GPU All-Reduce operations.

InfiniBand Architecture First Principles: Physical Link Rates, Credit-Based Link Flow Control, and Subnet Manager Fabric Orchestration

Why does native InfiniBand remain the dominant fabric for 10,000-GPU AI compute clusters and top-tier supercomputers in 2026? Deconstruct the layered InfiniBand protocol stack and physical link evolution: from EDR 100G, HDR 200G, and NDR 400G (Quantum-2) to the 2026 mass production of XDR 800G (Quantum-X800/ConnectX-8); analyze link-layer first principles: Flit-level Credit-Based hardware flow control and sub-100ns Cut-Through switching mechanics; and explore the control engine: Subnet Manager (OpenSM) fabric discovery, dynamic GUID/LID/LMC allocation, and Linear Forwarding Table (LFT) hardware orchestration.

← Prev TCP Congestion Control Evolution & High-Performance Transport: From Reno and Cubic to BBR Mathematical Models, and HTTP/2 to HTTP/3 (QUIC) Next → Application & Transport Layer Bridges: DNS Resolution, Sockets, Ports, and UDP vs TCP Foundations
← Back to Articles