VLANs logically segment networks into broadcast domains based on organizational functions rather than physical connections. Switches maintain separate bridging tables for each VLAN to restrict communication between ports in different VLANs. Routers provide security and traffic management between VLANs. Common ways to assign devices to VLANs include by port, MAC address, or protocol.