Enterprise LAN Infrastructure: VLAN Segmentation (802.1Q), Dynamic DHCP, and NAT Port Forwarding
Why can a single physical network switch be carved into dozens of isolated virtual local networks? Deconstruct three core pillars of enterprise LAN engineering: from broadcast storm hazards to IEEE 802.1Q frame tagging (4-byte tag, 12-bit VID, PCP QoS priority); the operational differences between Access ports, Trunk ports, and PVID tag stripping/insertion; comparing router-on-a-stick sub-interfaces with Layer 3 Switch Virtual Interfaces (SVI); dissecting DHCP's 4-step DORA handshake and cross-subnet relay agents; and demystifying NAPT (Port Address Translation), SNAT, DNAT, and Linux kernel conntrack state tables.
Computer Networking Masterclass: From Ethernet Principles to Hyperscale InfiniBand Architecture
A ground-zero masterclass to 10,000-GPU AI networking: from physical voltages, twisted pairs, and optical fibers to hubs, collision domains, switches, and MAC/ARP; step-by-step binary derivations of IP addressing, subnet masks, default gateways, VLANs, DHCP, and NAT; in-depth DNS, Socket 5-tuples, TCP 11-state machines, and BBR congestion control; Linux kernel NAPI, sk_buff, and eBPF XDP; datacenter traditional 3-tier vs 2-tier Spine-Leaf fabrics and EVPN-VXLAN; leading up to AI supercomputing: lossless RoCEv2, native InfiniBand NDR/XDR link speeds, credit flow control, Rail-Optimized Fat-Trees, Adaptive Routing, SHARP, and bare-metal OFED/NCCL performance tuning.
Browse all 12 chapters in this series ▾
- 01 Computer Networking from Scratch: Bits, Physical Media, Hub Collision Domains, and Switch MAC Addressing First Principles
- 02 IP Addressing and Subnetting First Principles: Binary Arithmetic, Subnet Masks, CIDR, and Default Gateway Routing
- 03 Enterprise LAN Infrastructure: VLAN Segmentation (802.1Q), Dynamic DHCP, and NAT Port Forwarding Reading
- 04 Application & Transport Layer Bridges: DNS Resolution, Sockets, Ports, and UDP vs TCP Foundations
- 05 Network & Transport Layers in Depth: IP Routing, CIDR, TCP 11-State Machine, and Sliding Window First Principles
- 06 TCP Congestion Control Evolution & High-Performance Transport: From Reno and Cubic to BBR Mathematical Models, and HTTP/2 to HTTP/3 (QUIC)
- 07 Linux Kernel Networking Subsystem in Depth: From NIC Drivers, NAPI, and Ring Buffers to eBPF XDP Wire-Speed Forwarding
- 08 Modern Data Center Network Architecture First Principles: Clos Topologies, Leaf-Spine Fabrics, BGP Underlay, and EVPN-VXLAN Large Layer-2 Virtualization
- 09 RDMA High-Performance Networking Foundations: Kernel Bypass, Zero-Copy, Queue Pairs, and Lossless RoCEv2 (PFC/ECN) Architecture
- 10 InfiniBand Architecture First Principles: Physical Link Rates, Credit-Based Link Flow Control, and Subnet Manager Fabric Orchestration
- 11 InfiniBand AI Cluster Networking in Practice: Fat-Tree Topologies, Rail-Optimized Architecture, Adaptive Routing (AR), and In-Network Reduction (SHARP)
- 12 Production InfiniBand Deployment, Cluster Operations, and NCCL Tuning: OFED Drivers, OpenSM HA, ibdiagnet Fabric Auditing, and GPUDirect RDMA
Introduction: When a Facility Houses Hundreds of Employees Across Multiple Departments
In the previous chapters, we derived Layer 2 MAC switching and Layer 3 IP subnetting from physical principles.
However, as an organization scales to 500 employees across Finance, Engineering, and Human Resources, enterprise network management encounters practical challenges:
- Security isolation breaks down: If finance servers and workstations share an unsegmented switch with general office devices, packet sniffers can inspect sensitive payroll data;
- Broadcast storms disrupt the fabric: If a compromised machine floods the network with ARP requests, broadcast processing consumes CPU cycles on all 500 connected hosts;
- Manual IP configuration becomes unmanageable: Manually assigning static IPs, subnet masks, gateways, and DNS resolvers to every visiting laptop is error-prone and unsustainable;
- Public IPv4 addresses are scarce: An Internet Service Provider typically assigns a single public IPv4 address to an enterprise. How can 500 hosts share this address simultaneously?
To resolve these challenges, modern enterprise networks rely on three core protocols: VLANs (Virtual Local Area Networks), DHCP (Dynamic Host Configuration Protocol), and NAT (Network Address Translation).
1. VLAN First Principles: Segmenting the Broadcast Domain
A VLAN (Virtual Local Area Network) partitions a physical switch into multiple isolated virtual switches at the hardware ASIC level, avoiding the need to purchase separate physical hardware:
flowchart TD
subgraph PhysicalSwitch["Single 24-Port Physical Layer 2 Switch"]
subgraph VLAN10["VLAN 10: Finance Department (192.168.10.0/24)"]
Port1["Port 1 (Finance PC A)"]
Port2["Port 2 (Payroll Server)"]
end
subgraph VLAN20["VLAN 20: Engineering Department (192.168.20.0/24)"]
Port3["Port 3 (Engineer PC B)"]
Port4["Port 4 (Git Server)"]
end
end
Port1 -. "Broadcast frames blocked at the hardware port level" .-x Port3
- Broadcast Isolation: Broadcast frames (such as ARP requests) originating within VLAN 10 are physically filtered by switch silicon from egressing onto VLAN 20 ports, containing broadcast storms;
- Security Boundaries: Separate VLANs remain isolated at Layer 2, preventing unauthorized cross-department packet capture.
2. 802.1Q Tagging Mechanics and Access vs Trunk Ports
Endpoint network cards typically process standard, untagged Ethernet frames. How do switches identify which VLAN a frame belongs to?
They use the standard IEEE 802.1Q frame tagging specification.
2.1 The 802.1Q Tag Structure
The 802.1Q standard inserts a 4-byte (32-bit) VLAN Tag between the Source MAC and EtherType fields of a standard Ethernet frame:
Standard Ethernet Frame with 802.1Q Tag Inserted:
+-----------+-----------+-------------------------+-----------+---------------+---------+
| Dest MAC | Source MAC| 802.1Q Tag Header | EtherType | Payload Data | FCS |
| (6 Bytes) | (6 Bytes) | 4 Bytes (32 Bits) | (2 Bytes) | (46 - 1500B) | (CRC,4B)|
+-----------+-----------+-------------------------+-----------+---------------+---------+
| |
v v
+------------------+-------+-----+------------------+
| TPID | PCP | DEI | VID (VLAN ID) |
| 16 Bits (0x8100) | 3Bits | 1Bit| 12 Bits (1-4094) |
+------------------+-------+-----+------------------+ - TPID (Tag Protocol Identifier, 16 bits): Set to
0x8100, indicating an 802.1Q-tagged frame follows; - PCP (Priority Code Point, 3 bits): Provides 8 priority levels (0–7) for Class of Service (QoS) traffic prioritization (e.g., prioritizing VoIP or video over bulk downloads);
- VID (VLAN Identifier, 12 bits): . Values
0and4095are reserved, leaving valid VLAN IDs from to .
2.2 Switch Port Types: Access vs Trunk
Switches connect to both end-user devices and upstream network equipment, relying on two distinct port modes:
+-------------------------------------------------------------------------------+
| Access Port (Endpoint Links): Connects to PCs, printers, and standard servers |
| - Characteristics: Assigned to a single VLAN (e.g., PVID=10) |
| - Ingress: Adds a VLAN tag matching the port's PVID to incoming frames |
| - Egress: Strips the 802.1Q tag, delivering standard frames to end hosts |
+-------------------------------------------------------------------------------+
| Trunk Port (Backbone Links): Connects switches to switches or routers |
| - Characteristics: Transports multiplexed traffic from multiple VLANs |
| - Ingress/Egress: Preserves 802.1Q tags to retain VLAN identity across hops |
+-------------------------------------------------------------------------------+
sequenceDiagram
autonumber
actor PC_A as Host A (Untagged NIC)
actor SW1 as Switch 1
actor SW2 as Switch 2
actor PC_B as Host B (Untagged NIC)
Note over PC_A: Transmits standard untagged Ethernet frame
PC_A->>SW1: Ingresses Access Port (PVID=10)
Note over SW1: Inserts 802.1Q Tag: VID=10
SW1->>SW2: Crosses Trunk link preserving Tag=10
Note over SW2: Identifies egress Access Port (PVID=10)
Note over SW2: Strips 802.1Q Tag, restoring standard untagged frame
SW2->>PC_B: Delivered to Host B interface
2.3 Inter-VLAN Routing: Router-on-a-Stick vs Layer 3 Switches (SVI)
When hosts in Engineering (VLAN 10) need to reach an internal API in Finance (VLAN 20), traffic must be routed:
- Router-on-a-Stick: Connects the switch's trunk port to a physical router interface configured with virtual sub-interfaces (e.g.,
eth0.10,eth0.20), using the router to perform inter-subnet routing; - Layer 3 Switch (Switch Virtual Interface, SVI): The standard enterprise design. The switch uses onboard routing ASICs to terminate VLANs on internal Switch Virtual Interfaces (SVIs, e.g.,
interface Vlan 10), routing between VLANs at wire speed across the internal backplane without sending packets through an external router.
3. DHCP: The 4-Step DORA Protocol
When an employee plugs a laptop into a wall jack, the operating system obtains an IP address, subnet mask, gateway, and DNS servers within seconds using DHCP (Dynamic Host Configuration Protocol) (running over UDP: server port 67, client port 68):
sequenceDiagram
autonumber
actor Client as Booting Laptop (Client)
actor Switch as Switch
actor Server as DHCP Server (192.168.1.1)
Note over Client: Has no IP (Src: 0.0.0.0)
Target unknown (Dest: 255.255.255.255)
Client->>Switch: 1. DHCP Discover (Broadcast): "Is there a DHCP server on this link? I need an IP!"
Switch-->>Server: Floods broadcast to DHCP server
Note over Server: Reserves IP from pool: 192.168.1.105
Server->>Switch: 2. DHCP Offer (Unicast/Broadcast): "Offer: 192.168.1.105, Mask /24, Gateway 192.168.1.1, Lease 24h"
Switch->>Client: Delivered to client
Client->>Switch: 3. DHCP Request (Broadcast): "Accepting 192.168.1.105 from server 192.168.1.1!"
Note over Client,Server: (Broadcast informs other responding DHCP servers to release their reserved offers)
Switch-->>Server: Delivered to server
Server->>Switch: 4. DHCP ACK (Unicast/Broadcast): "Lease committed! Configuration active."
Switch->>Client: Laptop configures interface and comes online
- Lease Renewal Timers:
- T1 Timer (50% of lease): The client attempts a unicast DHCP Request directly to the issuing server to extend the lease;
- T2 Timer (87.5% of lease): If the issuing server fails to respond, the client broadcasts a DHCP Request to any reachable DHCP server; if the lease reaches 100% without renewal, the interface releases the IP and falls back to an APIPA address (
169.254.x.x).
4. Network Address Translation (NAT): Multiplexing a Public IP
4.1 The Core Challenge: Private IPs Are Non-Routable
As covered in Chapter 2, RFC 1918 private IPv4 addresses (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) are filtered by public Internet routers.
If an enterprise has a single public IP (e.g., 203.0.113.88), how can 500 private hosts access external web services concurrently?
The Solution: NAPT (Network Address Port Translation / PAT)!
sequenceDiagram
autonumber
actor Host as Internal PC (192.168.1.50:50001)
actor Router as NAT Gateway (Public IP: 203.0.113.88)
actor Web as External Web Server (93.184.216.34:80)
Note over Host: Initiates outbound HTTP request
Host->>Router: Packet: [Src=192.168.1.50:50001, Dst=93.184.216.34:80]
Note over Router: SNAT and Port Rewriting:
Allocates state in conntrack table:
(192.168.1.50:50001) <-> (203.0.113.88:62000)
Rewrites source IP and source port
Router->>Web: Masqueraded: [Src=203.0.113.88:62000, Dst=93.184.216.34:80]
Note over Web: Web server returns payload to 203.0.113.88:62000
Web->>Router: Reply: [Src=93.184.216.34:80, Dst=203.0.113.88:62000]
Note over Router: Reverse conntrack lookup:
Maps port 62000 to internal 192.168.1.50:50001
Restores original destination IP and port
Router->>Host: Delivered: [Src=93.184.216.34:80, Dst=192.168.1.50:50001]
4.2 SNAT vs DNAT (Port Forwarding)
- SNAT (Source NAT):
- Direction: Internal hosts initiating outbound traffic to the Internet;
- Operation: Rewrites the source IP and source port on egress, masking internal addresses behind the gateway's public IP;
- DNAT (Destination NAT / Port Forwarding):
- Direction: External clients accessing internal servers (e.g., exposing an internal web server);
- Operation: Rewrites the destination IP and destination port on ingress. For example, incoming requests to
203.0.113.88:8080are rewritten and forwarded to internal host192.168.1.200:80.
5. Linux Networking and Inspection Commands
Managing VLANs, connection tracking, and NAT rules on Linux:
# 1. Create an 802.1Q tagged interface on physical adapter eth0 (VLAN ID 10)
ip link add link eth0 name eth0.10 type vlan id 10
ip addr add 192.168.10.1/24 dev eth0.10
ip link set eth0.10 up
# 2. Inspect active Netfilter NAT tables
iptables -t nat -L -n -v
# 3. Standard masquerade rule for outbound traffic
# iptables -t nat -A POSTROUTING -s 192.168.0.0/16 -o eth0 -j MASQUERADE
# 4. Inspect active connection states in the kernel conntrack table
conntrack -L -p tcp
# Sample output:
# tcp 6 431999 ESTABLISHED src=192.168.1.50 dst=93.184.216.34 sport=50001 dport=80 \
# src=93.184.216.34 dst=203.0.113.88 sport=80 dport=62000 [ASSURED] 6. Summary and Next Steps
VLANs, DHCP, and NAT provide the operational backbone for enterprise networks:
- VLANs and 802.1Q Tagging isolate broadcast domains and segment departments using 4-byte headers across Access and Trunk ports;
- DHCP automates host addressing through the 4-step DORA handshake;
- NAT / PAT tracks session state in kernel
conntracktables, allowing thousands of internal hosts to multiplex through a shared public IP.
With Layer 2 and Layer 3 configured, how do applications resolve services and exchange data?
- When you type
www.google.cominto a browser, how does the global DNS hierarchy resolve human-readable domains into routable IP addresses? - Once a packet reaches a server hosting multiple applications, how do Ports and Operating System Sockets direct the payload to the correct process?
- Why do real-time voice and video streams choose UDP, while web browsers and databases rely on TCP?
In Chapter 4 of our masterclass, we explore the boundary between transport and applications: Application & Transport Layer Bridges: DNS Resolution, Sockets, Ports, and UDP vs TCP Foundations!
Frequently Asked Questions (FAQ)
Q1: If two PCs on the same switch share the same subnet (e.g., `192.168.1.10/24` and `192.168.1.20/24`) but are assigned to different VLANs (VLAN 10 and VLAN 20), can they communicate?
No. Traffic is dropped at Layer 2 inside the switch ASIC. Because both PCs reside on 192.168.1.0/24, PC A issues an ARP broadcast looking for PC B's MAC address. When the broadcast enters PC A's switch port (an Access port assigned to VLAN 10), the switch tags the frame with VID=10. The switch's forwarding logic strictly prevents frames tagged with VID=10 from exiting ports that do not belong to VLAN 10. PC B's port (assigned to VLAN 20) never receives the frame. Because the ARP request is never delivered, PC A never resolves PC B's MAC address, preventing communication.
Q2: Why does Router-on-a-Stick introduce bandwidth bottlenecks, and how do Layer 3 switches resolve this?
- Router-on-a-Stick Bottleneck: All inter-VLAN traffic must traverse a single physical trunk link to the router, be processed by the router's CPU, and return across the same link to the switch. This halves usable bandwidth on the link and risks CPU saturation under heavy traffic;
- Layer 3 Switch Resolution: Layer 3 switches incorporate routing logic directly into internal switching ASICs. Inter-VLAN traffic is routed via on-chip Switch Virtual Interfaces (SVIs) across the internal backplane at full hardware wire speed, removing the external router bottleneck entirely.
Q3: Why can't two private hosts behind different home NAT routers establish direct P2P connections by default, and how does "NAT Traversal (Hole Punching)" solve this?
Root Cause: Stateful NAT drop policies on unsolicited inbound traffic. Unless an internal host initiates an outbound session, the router's conntrack table contains no matching entry for external IP addresses. When a remote peer sends unsolicited packets to your public IP, your router drops them as potential attacks. Hole Punching Mechanics: Both peers communicate with a public STUN server to discover their respective <Public IP: Mapped Port> bindings. Both peers then simultaneously transmit UDP probe packets toward each other's mapped public endpoints. These outgoing packets create outbound session entries in their respective local NAT conntrack tables. Subsequent incoming packets from the peer match these established session entries and are forwarded through, establishing direct P2P communication.