Virtual LANs
Virtual LANs (VLANs) are isolated broadcast domains within a network.
VLANs tag packets to make traffic appear to be on the network, but they handle the traffic as though it were on a separate network. You can implement VLAN technology between the firewall and 802.1Q–compliant switches and routers.
You can create VLANs on physical interfaces, such as ports (for example Port1, PortA, eth0), RED interfaces, or virtual interfaces, such as bridge or LAG.
For distributed VLANs, you can assign them across multiple switches. Communication within a VLAN happens through the switch, while communication across different VLANs requires a Layer 3 device, such as a router, Layer 3 switch, or firewall.
The firewall recognizes VLAN IDs, allowing you to apply firewall rules specific to each VLAN, including authentication and other relevant policies. You can also apply firewall rules to secure the network between broadcast domains.
Note
Sophos XGS Series hardware appliances don't have a fixed limit on the number of VLAN interfaces you can create on a single physical interface. However, we recommend distributing VLANs across multiple interfaces for better performance and manageability.