A VLAN lets one network cable carry several separate networks, each tagged with a number from 1 to 4094. On Linux every VLAN becomes its own interface on top of a physical port or a bond. How you declare it depends on the network stack your distribution uses, and getting the address of the uplink wrong is a quick way to lose the server.
The same VLAN 10 on eth0 looks different in each tool, but the idea is constant: a device named eth0.10 that carries tag 10 and has its own address.
# netplan
vlans:
eth0.10:
id: 10
link: eth0
addresses: ["192.168.10.1/24"]
# iproute2 (until reboot)
ip link add link eth0 name eth0.10 type vlan id 10
ip addr add 192.168.10.1/24 dev eth0.10
ip link set eth0.10 upIf the port that carries your SSH session gets its address by DHCP today, a new file that declares that port with no DHCP removes the address. Add the VLANs on top and leave the uplink alone, or test with netplan try, which rolls back by itself after 120 seconds unless you confirm.
sudo netplan trynetworkd applies only the first .network file that matches an interface and ignores the rest. To add VLANs to an interface that is already configured, use a drop-in directory next to its file instead of a second file with the same match.
# /etc/systemd/network/10-eth0.network.d/vlans.conf
[Network]
VLAN=eth0.10A bond joins several ports for failover or more bandwidth: active-backup needs nothing from the switch, while 802.3ad (LACP) needs a matching switch configuration. A hypervisor usually puts each VLAN on a bridge so virtual machines can attach to it, and the address moves from the VLAN device to the bridge.
Open the VLAN & interfaces generator
ifupdown needs the vlan package (and ifenslave for bonds, bridge-utils for bridges). netplan and systemd-networkd handle VLANs themselves.
A VLAN tag adds four bytes, and the interface MTU stays at 1500 by default. If you use jumbo frames, set the same MTU on the uplink and every VLAN, and make sure the whole path supports it.
The switch port must be configured as a trunk that allows the VLAN. The host side can be perfect and still see nothing.