What a VLAN actually is
A VLAN (Virtual LAN, standard IEEE 802.1Q) splits one physical network into several separate logical networks. It works by adding a small tag — a number from 1 to 4094 — to each Ethernet frame. Switches keep tagged traffic apart: two machines plugged into the same switch but assigned different VLAN tags simply cannot see each other, as if they were on different cables entirely.
The vocabulary you will meet on a switch:
- Access port — carries exactly one VLAN, untagged. The device plugged in knows nothing about VLANs; the switch adds and strips the tag. This is what an ordinary PC port is.
- Trunk port — carries many VLANs at once, tagged. This is how you connect a switch to another switch, or to a server that needs to be on several networks over one cable.
- Native / untagged VLAN — on a trunk, the one VLAN whose frames travel without a tag.
- VLAN ID / PVID — the number itself. 1 is usually the default; 4095 is reserved.
Datacentres use VLANs to keep, say, storage traffic, management traffic and customer traffic apart while sharing the same physical wiring, and to stop a compromised machine in one segment from seeing another.
LexiVirt does not tag VLANs for you. There is no field where you
type a VLAN id and something happens — an earlier version had exactly that, and it did nothing at all
with the number, which is why it was removed. What LexiVirt can do is attach guests to a host
bridge you have already put on a VLAN. Build br-vlan100 on the node as shown
below, then create a bridged network in the console pointing at it, and every VM on
that network sits on VLAN 100. The tagging is done by the host and the switch; LexiVirt attaches
guests to the result.
If you genuinely need bridged or VLAN-tagged guests
This is a host networking task on the node, configured with your distribution's normal tools. Once a bridge exists on the host, libvirt can attach machines to it directly.
A plain bridge puts VMs straight onto your physical LAN, so they get addresses from your normal DHCP server and are reachable like any other machine — no NAT, no port forwarding:
# Debian/Ubuntu, /etc/netplan/01-bridge.yaml
network:
version: 2
ethernets:
eno1: {dhcp4: no}
bridges:
br0:
interfaces: [eno1]
dhcp4: yes
A VLAN-tagged bridge puts VMs onto one specific VLAN — here, VLAN 100:
network:
version: 2
ethernets:
eno1: {dhcp4: no}
vlans:
eno1.100:
id: 100
link: eno1
bridges:
br-vlan100:
interfaces: [eno1.100]
dhcp4: no
Then, in the console, go to Networks → Create Network, choose Bridged
and give it br-vlan100. Pick that network when you create a VM and the guest
lands on VLAN 100. No hand-editing of XML, and a resize will not undo it — the console preserves a
VM's network when it redefines the domain.
The switch has to agree. The port feeding that server must be
configured as a trunk carrying VLAN 100, or nothing passes. Also build the bridge on
every node: VM placement is random, and the console will grey out a network that does not
exist everywhere rather than let you create a VM that cannot start.