What is a VLAN, and why would a home network need one?
A virtual LAN splits one physical network into several logically separate ones, so devices on different VLANs cannot see each other even though they share the same switch and cabling.
How it works. Switches add a small tag to each Ethernet frame identifying which VLAN it belongs to, and only forward frames to ports in the same VLAN. A single cable can therefore carry several isolated networks — a trunk — while individual access ports belong to one VLAN each.
Each VLAN is normally its own IP subnet, so traffic between them must pass through a router or firewall, where rules can be applied. That is the point: separation with a controlled crossing.
Why businesses use them. To keep departments, phone systems, payment terminals and guest access separate without running separate cabling — which was the original motivation and remains the main one.
Why a home might genuinely want them:
IoT isolation. Smart bulbs, plugs, cameras, televisions and doorbells are frequently poorly secured, rarely updated, and reach the internet continuously. Putting them on their own VLAN means a compromised device cannot reach your computers, network storage or backups. This is the strongest argument, and it is a real risk rather than a theoretical one.
Guest network separation, which many routers already provide as a simplified VLAN.
Cameras, which generate constant traffic and frequently should not have internet access at all — easy to enforce with a VLAN and a firewall rule.
Work devices kept apart from household ones.
Children's devices, where different filtering rules apply.
What it requires. A managed switch, an access point supporting multiple SSIDs mapped to VLANs, and a router or firewall capable of routing between them. Consumer all-in-one routers generally cannot; prosumer ecosystems and open-source firewall platforms can.
The practical difficulties, which are worth knowing before starting: device discovery breaks across VLANs. Casting, printer discovery, smart speakers and media servers rely on mDNS and broadcast traffic that does not cross VLAN boundaries by default. Making them work needs mDNS reflection or repeater configuration, and this is where most home VLAN projects stall.