VLANs logically divide the LAN into separate broadcast domains without using routers. Switches with VLAN capability allow ports to be configured as access, trunk, or general ports. Access ports belong to one VLAN and use untagged frames. Trunk ports can belong to multiple VLANs and use tagged frames, with a native VLAN using untagged frames. Ingress filtering ensures frames are tagged with an associated VLAN.