Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

Management vlan


I'm confused on the management vlan and how to set this up.

So say I have a flat network with 10 switches with everyone in vlan 5 with a subnet of /23

I see that it's bad practice to you your management vlan and data vlan the same.

If I create vlan 10 as my management /27

This means I will have to gone into each switch and change my gateway to the management vlan gateway. This will be terminated on my ASA. Then the management vlan will be accessed in vlan 10.

I'm confused if I do change my gateway to the management vlan how will user traffic know where to be routed? as the gateway will be in vlan 10?

I'm guessing because all vlan 5 traffic will be in the same broadcast domain so doesn't even need a gateway? so why do we need a DG on the switches if you don't have a management vlan??


Hope someone can clear this up?


Hi,A best practice design


A best practice design tell you that you should have a different vlan for management traffic, for performance and security, so you can accomplish it setting up your ASA to make Inter-VLAN routing, for example VLAN 5 for users and VLAN 10 for management, you will have two broadcast domains and you have to change the ip address for each switch and the default gateway that will be the subinterface on ASA.


Each of your connected hosts

Each of your connected hosts will have a default gateway in Vlan 5 which will be an interface on the ASA.

The default gateway on your switches is simply there to enable you to manage them from a different vlan, it has no bearing on the routing for the connected hosts.

If you created Vlan 10 on all your switches and then changed their management addresses to be in that same vlan, you could still manage them if you plugged into a switchport in vlan 10 because you would be in the same broadcast domain they were in.

I think you are getting confused between the default gateway of the hosts and the default gateway for the switches which are two different things.

The only reason you would be setting a default gateway on each of the switches is so you can get to their management addresses from a host in Vlan 5 as this is a different broadcast domain.

In terms of management, think of the switches as normal hosts.

They have a management address (interface vlan 10) and a default gateway (

Hope this helps

CreatePlease login to create content