Switching & VLAN Fabric

This document describes the Layer 2 switching fabric supporting the lab, including physical topology, VLAN propagation, and design boundaries.

Switching is intentionally kept simple. All policy, routing, and enforcement occur at the network edge.

Design principles: see Lab Philosophy.


Design Goals

The switching fabric is designed to:

Switches are treated as transport infrastructure, not decision-makers.


Physical Topology

The switching layout follows a hierarchical model:

Core Switching

The core switch does not perform routing or policy enforcement.


Access Switching

Rack Access

Rack PoE


Remote Access Switching

Office

Living Room


VLAN Propagation Model

All VLANs are defined and terminated on the edge router.

Switches operate strictly at Layer 2 and are responsible only for:

No switch performs inter-VLAN routing.


VLAN Overview

VLANNamePurposeNetwork Policy Summary
99MgmtInfrastructure managementRestricted, no WAN access
110TrustedUsers and serversWAN allowed, inter-VLAN controlled
120IoTEmbedded and consumer gearWAN allowed, no lateral access
130CameraVideo sourcesNo WAN, ZoneMinder-only access

Trunking Strategy

The fabric avoids:

Consistency across switches is prioritized over flexibility.


Layer 3 Boundary

The Layer 3 boundary is intentionally centralized:

This ensures that traffic behavior is:


Failure Characteristics

The switching fabric is designed so that:

Failure domains are clear and intentional.


Design Notes

This document applies to all current and future switching infrastructure unless explicitly stated otherwise.