- Cisco Switch User's Manual
VLAN Management
VLANs
Cisco Small Business 300 Series Managed Switch Administration Guide  186
12
VLAN Roles
VLANs function at Layer 2. All VLAN traffic (Unicast/Broadcast/Multicast) remains 
within its VLAN. Devices attached to different VLANs do not have direct 
connectivity to each other over the Ethernet MAC layer. Devices from different 
VLANs can communicate with each other only through Layer 3 routers. An IP 
router, for example, is required to route IP traffic between VLANs if each VLAN 
represents an IP subnet. 
The IP router might be a traditional router, where each of its interfaces connects to 
only one VLAN. Traffic to and from a traditional IP router must be VLAN untagged. 
The IP router can be a VLAN-aware router, where each of its interfaces can 
connect to one or more VLANs. Traffic to and from a VLAN-aware IP router can be 
VLAN tagged or untagged. 
Adjacent VLAN-aware devices exchange VLAN information with each other by 
using Generic VLAN Registration Protocol (GVRP). As a result, VLAN information is 
propagated through a bridged network.
VLANs on a device can be created statically or dynamically, based on the GVRP 
information exchanged by devices. A VLAN can be static or dynamic (from GVRP), 
but not both. For more information about GVRP, refer to the GVRP Settings section.
Some VLANs can have additional roles, including: 
• Voice VLAN: For more information refer to the Voice VLAN section.
• Guest VLAN: Set in the Edit VLAN Authentication page.
• Default VLAN: For more information refer to the Configuring Default VLAN 
Settings section.
• Management VLAN (in Layer 2-system-mode systems): For more 
information refer to the Layer 2 IP Addressing section.
QinQ
QinQ provides isolation between service provider networks and customers' 
networks. The device is a provider bridge that supports port-based c-tagged 
service interface. 
With QinQ, the device adds an ID tag known as Service Tag (S-tag) to forward 
traffic over the network. The S-tag is used to segregate traffic between various 
customers, while preserving the customer VLAN tags. 










