Capstone Project 2 — Configure VLANs¶
In this capstone project, you'll build a production-style segmented network using Virtual Local Area Networks (VLANs). You'll divide a single physical network into multiple logical networks, configure trunk and access ports, enable inter-VLAN routing, and implement basic security controls. VLANs are widely used in enterprises to improve security, performance, scalability, and network management. Every Network Engineer, DevOps Engineer, Platform Engineer, Cloud Engineer, and System Administrator should know how to design and configure VLANs.
Learning Path¶
Course Progress
Project Objectives¶
By completing this project, you'll be able to:
- Design a VLAN-based enterprise network
- Configure VLANs on managed switches
- Configure access and trunk ports
- Enable inter-VLAN routing
- Verify VLAN communication
- Implement VLAN security
- Troubleshoot VLAN issues
Skills Covered¶
This project integrates concepts from:
- Ethernet Switching
- VLANs
- IEEE 802.1Q
- Trunking
- Access Ports
- Routing
- DHCP
- DNS
- Linux Networking
- Network Troubleshooting
Project Scenario¶
Your company has one large flat network.
Problems:
- Too much broadcast traffic
- Poor security
- Difficult management
- No department isolation
Your task is to divide the network into multiple VLANs.
Enterprise Network Design¶
Router
│
Trunk Connection
│
Managed Layer-2 Switch
┌──────────┬──────────┬──────────┬──────────┐
│ │ │ │
VLAN10 VLAN20 VLAN30 VLAN40
Users Servers DevOps Guest
Each department receives its own isolated network.
Lab Requirements¶
Hardware:
- Managed Switch (or Virtual Switch)
- Linux Router (Optional)
- Multiple Virtual Machines
Software:
- Ubuntu Server
- VirtualBox / VMware / Proxmox
- Docker (Optional)
VLAN Design¶
| VLAN ID | Name | Network |
|---|---|---|
| 10 | Users | 192.168.10.0/24 |
| 20 | Servers | 192.168.20.0/24 |
| 30 | DevOps | 192.168.30.0/24 |
| 40 | Guest | 192.168.40.0/24 |
| 99 | Management | 192.168.99.0/24 |
Network Diagram¶
Step 1 — Create VLANs¶
Create:
Verify VLAN creation.
Step 2 — Configure Access Ports¶
Example:
| Port | VLAN |
|---|---|
| 1 | VLAN10 |
| 2 | VLAN10 |
| 3 | VLAN20 |
| 4 | VLAN20 |
| 5 | VLAN30 |
| 6 | VLAN40 |
Devices connected to an access port belong to a single VLAN.
Step 3 — Configure Trunk Port¶
Configure the uplink as:
Allow:
- VLAN10
- VLAN20
- VLAN30
- VLAN40
- VLAN99
The trunk carries traffic for multiple VLANs.
Step 4 — Configure Router-on-a-Stick¶
One physical interface:
Subinterfaces:
Each subinterface acts as the gateway for its VLAN.
Step 5 — Configure IP Addresses¶
Example:
| VLAN | Gateway |
|---|---|
| 10 | 192.168.10.1 |
| 20 | 192.168.20.1 |
| 30 | 192.168.30.1 |
| 40 | 192.168.40.1 |
| 99 | 192.168.99.1 |
Step 6 — Configure Client Systems¶
Example:
Verify each device belongs to the correct VLAN.
Step 7 — Enable Inter-VLAN Routing¶
Verify:
Communication occurs only through the router or Layer-3 switch.
Step 8 — Configure DHCP (Optional)¶
Provide separate DHCP scopes.
Example:
Repeat for every VLAN.
Step 9 — Configure DNS¶
All VLANs should resolve:
Verify DNS from every VLAN.
Step 10 — Configure Firewall Rules¶
Example:
Allow:
Block:
Restrict traffic according to business requirements.
Step 11 — Verify Connectivity¶
Within VLAN:
Across VLANs:
DNS:
Step 12 — Verify VLAN Tags¶
Capture packets.
Verify:
Tagged frames should appear on trunk links.
Enterprise VLAN Architecture¶
Security Improvements¶
Implement:
- Separate Guest VLAN
- Management VLAN
- Restrict Inter-VLAN Access
- Disable Unused Ports
- Enable Port Security
- Limit Management Access
Validation Checklist¶
| Item | Status |
|---|---|
| VLANs Created | ☐ |
| Access Ports Configured | ☐ |
| Trunk Port Working | ☐ |
| Router Configured | ☐ |
| Inter-VLAN Routing Working | ☐ |
| DNS Working | ☐ |
| Firewall Rules Applied | ☐ |
| Guest Isolation Verified | ☐ |
| Documentation Updated | ☐ |
Common Problems¶
| Problem | Solution |
|---|---|
| Devices Cannot Communicate | Check VLAN Assignment |
| Trunk Failure | Verify Allowed VLANs |
| No Inter-VLAN Routing | Verify Router Configuration |
| DHCP Not Working | Check VLAN Scope |
| DNS Failure | Verify Gateway & DNS Server |
Troubleshooting Commands¶
View interfaces.
View routes.
Verify connectivity.
Resolve DNS.
Capture packets.
Bonus Challenges¶
Extend the project by:
- Configuring a Layer-3 Switch
- Implementing Dynamic Routing
- Deploying Kubernetes across VLANs
- Configuring HA Firewalls
- Creating a Dedicated Storage VLAN
- Configuring QoS between VLANs
- Automating VLAN creation with Ansible
Learning Outcomes¶
After completing this project, you'll be able to:
- Design VLAN architectures
- Configure access and trunk ports
- Implement inter-VLAN routing
- Secure enterprise networks
- Troubleshoot VLAN communication
- Build segmented production networks
Project Deliverables¶
By the end of this project, you should have:
- Multiple VLANs
- Trunk Configuration
- Access Port Configuration
- Router-on-a-Stick
- Inter-VLAN Routing
- DHCP (Optional)
- DNS Connectivity
- Firewall Rules
- Updated Network Documentation
Self-Assessment¶
Before moving to the next project, confirm:
- Can you create VLANs on a managed switch?
- Can you configure access and trunk ports?
- Can you implement Router-on-a-Stick?
- Can you configure inter-VLAN routing?
- Can you isolate guest traffic?
- Can you troubleshoot VLAN issues?
- Can you document the VLAN design?
Summary¶
In this capstone project, you designed and deployed a production-style VLAN architecture. You segmented the network into logical departments, configured trunk and access ports, enabled inter-VLAN routing, applied security controls, and validated communication across the enterprise network.
This project reflects common enterprise networking practices used in corporate offices, data centers, educational institutions, and cloud-connected environments.
Key Takeaways¶
- VLANs logically separate networks without requiring additional physical infrastructure.
- Use access ports for end devices and trunk ports between network devices.
- Inter-VLAN communication requires a router or Layer-3 switch.
- Apply firewall rules to control communication between VLANs.
- Always document VLAN IDs, IP ranges, gateways, and port assignments.
- Network segmentation improves security, performance, and manageability.
What's Next?¶
In the next capstone project, you'll learn how to Build a DNS Server.
You'll install and configure a production-style DNS server, create forward and reverse lookup zones, manage DNS records, configure client name resolution, and troubleshoot DNS issues in an enterprise environment.