What is a VLAN?
A VLAN (Virtual LAN) is a separate network that runs over the same cables and switches. It is used to separate the phones from the rest of the computers — to give them priority, to protect them and to diagnose problems easily.
One physical network, several logical networks
Without VLANs, everything connected to the switches in the office is on one big network: computers, phones, printers, cameras, and the guests' mobile phones on the Wi-Fi. Everyone "sees" everyone. When one computer transmits a lot, everyone feels it. When one computer catches a virus, it has a direct path to all the other devices.
A VLAN divides this physical network into several separate networks, without pulling a single new cable. Think of an office building with a shared hallway, where each company gets a floor with its own locked door. The cables and switches are the same cables and switches — but traffic of one VLAN doesn't pass to another VLAN, unless the router or firewall explicitly allows it.
In the context of telephony, people usually talk about a Voice VLAN: a dedicated network for phones only. Next to it there is a network for computers, and sometimes another one for guests and one for cameras.
How it works: tags on the packets
The magic behind VLANs is a standard called 802.1Q. It adds a small "tag" with a number to every network packet — the VLAN number, between 1 and 4094. The switch reads the tag and knows where the packet belongs. A packet with tag 20 reaches only the ports of network 20.
On each port of the switch, you define how it treats tags:
- Untagged — the port belongs to one VLAN, and the connected device doesn't even know it is in a VLAN. Suitable for a computer or a printer.
- Tagged — the port carries several VLANs together, and each packet carries its own tag. This is how you connect switch to switch, switch to router, and… an IP phone.
And here is the trick that makes VLANs so common in telephony: most IP phones have two network ports — one for the wall and one for a computer. The phone tags its own traffic into the voice VLAN, and passes the traffic of the computer connected behind it through as is, into the computers' VLAN. One network jack in the wall, two devices, two separate networks. In an office with one jack per desk, this saves wiring.
How the phone knows which VLAN to join
A phone straight out of the box doesn't know the voice VLAN number in your office. There are several ways to tell it:
- LLDP-MED — a protocol in which the switch "informs" the phone, the moment it connects, which VLAN it should be in and which priority to mark. This is the most convenient way, and most managed switches and phones support it.
- DHCP — the server that hands out addresses can also give the phone the VLAN number, using a special option.
- Manual setup — you enter the number in the phone's menu or in the configuration file it receives through auto-provisioning.
What's important to know: a phone configured for a VLAN that doesn't exist on the network simply won't connect. If you move such a phone to a home or another branch, it will look "dead" until you restore the setting. This is a common problem, and easy to solve — if you know where to look.
Why separate at all: three reasons
- Priority. When all the voice is on one network, it's easy to give it QoS — one rule: "everything in this VLAN goes first."
- Security. An infected computer on the office network can't scan the phones and try to break into them. And a guest who connected to the Wi-Fi won't see them at all. This matters, because a hacked phone is an opening for toll fraud.
- Diagnosis. When there is an audio problem, you know exactly which traffic belongs to the phones, and you can look at it alone.
There is also a quiet advantage: broadcasts. On one big network, every device receives "broadcast" messages from all the other devices. On a network of hundreds of devices this is noise that burdens everything. Separation reduces the noise on each network.
Examples from the field
A yeshiva with a dormitory. There is Wi-Fi for the staff, computers in the office, cameras in the yard, and phone stations in the hallways. Separating into different networks ensures that a load on one network doesn't hurt the phones, and that the cameras aren't reachable from every computer.
A service center. Twenty agents, each with a phone and a computer on a single jack at the desk. The computer is connected through the phone, each in its own VLAN.
A nonprofit on a fundraising night. Volunteers bring laptops and connect to the Wi-Fi. When the guest network is separate from the phone network, a laptop with a heavy update or with malware won't hurt the agents' calls in the middle of the evening.
An office of five employees. Here you usually don't need it. A simple switch and a good router are enough, and the complexity isn't worth the gain.
What you need and what to check
- A managed switch that supports 802.1Q. A simple switch doesn't understand tags. It's best if it also supports LLDP-MED and PoE.
- A router or firewall that can route between the networks and reach the Internet from each one.
- A DHCP server for each network, so each device gets an address in the right range.
- Documentation. A simple table: which VLAN number is for which purpose, and which ports on the switch belong to which network. Without it, whoever comes after you will have a very hard time.
And the classic mistake: someone plugs a computer straight into the phones' port, or connects a small home switch under the desk, and suddenly nothing works. A home switch sometimes passes tags and sometimes doesn't. If the network is separated, ask employees not to connect their own equipment.
A full example: a network plan for an office of 20 workstations
Take a fictional real estate office in Bnei Brak: 20 desks, each with a phone and a computer on one network jack, two printers, four cameras, and Wi-Fi for waiting customers. This is what the network plan looks like that the installer writes on a page before touching the switch:
| VLAN number | Name | Address range | Who is in it | Where it may go |
|---|---|---|---|---|
| 10 | Computers | 192.168.10.x | 20 computers, 2 printers | Internet, printers |
| 20 | Voice | 192.168.20.x | 20 phones | Internet (the PBX servers) only |
| 30 | Guests | 192.168.30.x | Wi-Fi for customers | Internet only, with a speed cap |
| 40 | Cameras | 192.168.40.x | 4 cameras, recorder | Only to the recorder; not to the Internet |
And now the ports on the switch. Ports 1–20 (the desks): VLAN 10 untagged (for the computer) and VLAN 20 tagged (for the phone). The phone gets the number 20 from the switch through LLDP-MED, tags its voice, and passes the computer behind it through untagged. Ports 21–22: the printers, VLAN 10 untagged. Ports 23–24: the wireless access points, with tags 10 and 30 (staff and guests on two separate wireless networks). Port 25: the cameras through their own small switch, VLAN 40. Port 26: the link to the router, with the tags of all four networks.
The router receives the four networks, hands out addresses on each separately, and enforces the last column of the table. That column is the heart of it: it's what prevents a customer on the Wi-Fi from seeing the phones, and an infected computer from touching the cameras. This whole plan is one page. Without the page, every future change is a guess.
VLAN versus the alternatives: a comparison table
Separating into VLANs is not the only way to give the phones peace and quiet. There are three alternatives, and each has its place:
| One network for everyone | VLAN | A separate physical network | |
|---|---|---|---|
| Cables and switches | Existing | Existing, managed switch | An extra switch and cable for every phone |
| Wall jacks per desk | One (computer through the phone) | One | Two |
| Voice priority | By server addresses only | One simple rule | Built in — nothing to compete with |
| Isolation from guests and viruses | None | Full, as long as the router enforces it | Full |
| Complexity | Zero | Medium, requires documentation | Low, but expensive |
| Best for | Up to about 10 workstations | A mid-size office, call center, institution | Places without a managed switch, or where the cabling already exists |
A common confusion: VLAN versus a subnet. A subnet is a range of addresses — 192.168.20.x — whereas a VLAN is the actual separation on the switch. You can give the phones their own address range without a VLAN, but then they are still in the same "room" as all the computers, and anyone who wants to can talk to them. Usually you do both together: each VLAN gets its own address range, and that is what lets the router route between them and enforce rules.
When it goes wrong: VLAN problems by symptom
- The phone doesn't get an address, and the screen is stuck on "Connecting." It tags for a VLAN that the port doesn't pass — for example after it was moved to a printer's port, or after a switch was replaced. Check that the port is configured with the tag of the voice network.
- The phone got an address from the computers' range. It didn't tag at all: LLDP-MED is off on the switch, or the phone doesn't support it and was set manually to a different network. It will work, but without priority and without isolation. Turn on LLDP-MED or enter the number in the configuration file.
- The computer behind the phone has no network. The computer port on the phone is disabled, or the port on the switch lacks an "untagged" setting for the computers' network. Two places to check.
- Everything works except one floor. The link between the switches (a trunk) doesn't pass all the networks. After a switch is replaced, this is the first problem to suspect.
- The phones get an address but don't register. There is a network, but no way out of it: the router doesn't route VLAN 20 to the Internet, or the firewall blocks it. On the PBX's extensions screen, all the extensions of that network will appear unregistered at once — a strong hint.
- A home switch under the desk. An employee connected a cheap five-port switch to connect a laptop too. Some cheap switches strip tags. The phone on that switch will lose the voice network.
A working rule: when something doesn't work after a network change, ask "what moved?" before "what's broken?" A phone that changed rooms, a switch that was replaced, a port that was cleaned up — with VLANs, almost every problem is a move.
How it works with us at Kesher
The communications cabinet we set up has a PoE switch, a router, a patch panel, and a label for every jack by room. When everything is labeled, it's easy to know which port serves a phone and which a computer — and that's the basis for any future separation.
Should you separate the phones into a VLAN? It depends on the size of the office, the existing equipment, and what else runs on the network. We check this together with you and will recommend what fits — sometimes separation, and sometimes a good router and a network cable for each phone are entirely enough.
The phones we supply arrive preconfigured, and in the control panel, on the extensions screen, you can see whether each extension is registered and from which device. If a phone moved networks and stops registering, you see it there immediately.
FAQ
Is a VLAN required for IP phones?
No. In small offices, phones work very well without separation. A VLAN helps mainly in large, busy networks, or ones that have guest Wi-Fi.
Can I connect a computer through the phone?
Yes. Most IP phones have a second port for a computer. With a VLAN, the phone and the computer are each on their own network, on the same wall jack.
What is the difference between Tagged and Untagged?
On an Untagged port the device belongs to one VLAN and doesn't know about it. On a Tagged port several networks pass together, and each packet is marked with the number of its network.
Why doesn't the phone connect after I took it home?
It may have been set to the office's VLAN, and at home there is no such network. Return the VLAN setting to the default and it will connect.
Which VLAN number should I give the phones?
There is no "right" number. It's common to choose round, memorable numbers — for example 10 for computers, 20 for voice, 30 for guests — and write them on one page. What matters is consistency across all the switches.
What is LLDP-MED and why is it important?
A protocol in which the switch tells the phone, the moment it connects, which VLAN to join and which priority to mark. Without it you have to configure each phone manually, and a phone that moves between ports stops working.
Are a VLAN and a subnet the same thing?
No. A subnet is a range of addresses; a VLAN is the actual separation on the switch. Usually each VLAN is given its own address range, but an address range alone doesn't isolate anything.