VLAN (Virtual Local Area Network)

A Virtual LAN is a logical Layer-2 network segment overlaid on a physical switched network, defined by IEEE 802.1Q. VLANs let operators isolate traffic, management, voice, guest, IoT, over shared infrastructure. VLAN-hopping attacks (double tagging, switch spoofing) are mitigated by disabling DTP, pruning trunks, and not using VLAN 1 for production traffic.

Categories: Threats and AttacksEncryption and CryptographyIoT

VLAN in context

Telecom threats range from opportunistic SMS phishing and SIM swap to nation-state grade location tracking. The common thread is that most attacks exploit the inherited trust model of legacy signaling protocols.

Cryptography in telecom spans air-interface ciphers (A5/1, A5/3, ZUC, SNOW, NEA/NIA), transport (IPsec, TLS) and identity (AKA, 5G-AKA, EAP-AKA'). Weak or downgradeable ciphers remain a live risk on 2G/3G fallback.

To place VLAN in the wider telecom-security picture, review A5/2, Botnet, IVR, Network Slicing, Operational Security (OPSEC) and SSID — each entry cross-references back to this page so you can walk the topic in either direction.

Related terms

More from the TelcoSec Glossary

Browse the full TelcoSec Glossary, the Ultimate Guide to Mobile Network Security, or the P1 Arsenal of telecom-security tools.