Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 
New Member

VLAN types and Router on a Stick

Two quick questions here.

1. Do User/Data VLANs prevent voice and management traffic from accessing the other VLANs, or does it not work or what? I've read a few conflicting things about it.

2. Does putting a router on a stick to allow for cross VLAN communications defeat the purpose of a VLAN? I thought VLANs were meant to block traffic from getting to other VLANs. Router on a stick sounds like buying a firewall and not plugging it in.

I'm still a baby at Cisco, so try to keep it in simple terms please.   


Cisco Employee

VLAN types and Router on a Stick

1. Access Vlan is used for data on  the network and the Voice Vlan is used for Voice on the same network but  with a different subnet.This allows for 1 cat 6 cable to be connected to  the network and supply a user with Cisco IP Phone access and data.

Access vlan  140

Voice Vlan 141

A Voice VLAN is no different than any other VLAN. The command "Voice"  VLAN only tells the router, that it should pass this VLAN information  onto a Cisco IP Phone --using the CDP protocol-- to inform the phone  which VLAN to use for its internal phone switchport traffic to be sent  on, accross the Dot1Q trunk. It also informs the switch that it is OK to  receive Dot1Q headers on Ethernet frames, so long as the VLAN ID is  equal to that of the configured Voice VLAN.

2. Yep you are correct when you say one vlan traffic cant access other vlan's traffic. But with the deployment of intervlan routing you can have cross vlan communication. This you need to deploy on your need, entirely on your choice.

It is generally used to route traffic between two networks that have a  partial overlap. So, you want to block complete traffic between vlans, dont use it.


Please rate useful posts.

VLAN types and Router on a Stick

A VLAN is simply a logical way to separate ports on a switch.  In a way, if you had a 24-port switch and was able to break it in half so that 12-ports were on each half, that's somewhat how a VLAN functions.  It is simply a way to group ports for traffic.  It does "block" traffic in a way that each VLAN is a separate Ethernet LAN...requiring a router to route traffic between VLANs.

Functions such as "voice", "data", etc. are simply labels that we put on VLANs, and do not affect the functionaly.  VLANs function the same way.  The labels are simply and administrative way of helping us understand what traffic should be on the VLAN.

Routing between VLANs (whether by router-on-a-stick or other methods) does not defeat the purpose of a VLAN.  It is necessary in the even one needs cross-VLAN communications.

Loosely think of each VLAN as a separate switch.

Cisco Employee

VLAN types and Router on a Stick

Hi Randall,

VLANs are used to create multiple network over a single switched physical topology. Imagine you wanted to have separate networks for, say, two or three different units in your company: developers, graphics, marketing, for security and management purposes. You would either buy a separate switch (or switches) for each of these units and keep the networks physically separate, or you will use a single switched topology and instead, create the (now logically) separate networks using VLANs.

So VLANs are about virtualizing switches, much in a similar way to using VirtualBox or VMWare to virtualize PCs. Instead of having multiple pieces of the same hardware, you are using the same hardware and use additional mechanisms to virtualize it and create multiple instances. VLANs are just that - virtual broadcast domains spanning over a switched topology, separate and isolated on Layer2 between each other.

However, having VLANs does not mean you want to prevent them from ever communicating. You want to contain the broadcasts, have VLANs to use separate IP ranges, exert tighter control over the inter-VLAN traffic. There may be legal reasons, however, why the VLAN networks for developers, graphics and marketing may be allowed to communicate for some purpose (say, the shared printer is in the marketing VLAN and everybody wants to print on it). That is why it is completely legal to request for inter-VLAN communication. This is accomplished by using a router-on-stick or using multilayer switches that perform inter-VLAN routing inside their hardware directly. In other words, just as you would interconnect multiple physically distinct switched networks with a router, you are doing the same with router-on-stick.

1. Do  User/Data VLANs prevent voice and management traffic from accessing the  other VLANs, or does it not work or what? I've read a few conflicting  things about it.

Any VLAN will keep the data within it closed and will not leak it to any other VLAN, unless the traffic is routed to another VLAN. So unless the VLAN carries IP traffic that is purposefully addressed to recipients located in another VLAN (or another network), this traffic will not leave its original VLAN. In addition, it must be a router that takes packets from one VLAN and puts them into another, so the inter-VLAN communication is not provided by switches but only by routers or devices capable of routing.

2. Does putting a router on a stick to allow for cross VLAN communications defeat the purpose of a VLAN?

Not at all - think about the reasons described before.

You are certainly welcome to ask further!

Best regards,


CreatePlease to create content