Start with purpose
Start by identifying device classes, trust levels, required communications and operational ownership. Create a segment when separation has a clear security, operational or performance purpose.
Common segments
| Segment | Typical contents | Key consideration |
|---|---|---|
| User | Managed clients | Approved internal services and internet. |
| Server | Applications and infrastructure | Restrict access to required services. |
| Management | Switches, APs and controllers | Administrator-only access. |
| Voice | IP phones | QoS and phone/data separation. |
| IoT | Cameras, displays and appliances | Assume weaker device security. |
| Guest | Unmanaged clients | Usually internet-only. |
Layer 3 boundaries
Inter-VLAN traffic requires routing. The gateway may be on a Layer 3 switch, router or firewall. Put the boundary where the required inspection, throughput and operational model make sense.
Security boundaries
VLANs are not a security control by themselves. Enforce the intended separation with firewalls, ACLs, 802.1X and other controls. Define permitted flows explicitly by source, destination, protocol and business purpose.
VLAN and IP planning
Use a consistent numbering scheme and keep VLAN IDs, subnet prefixes, gateways and DHCP scopes documented together. Leave room for growth and avoid overlapping networks.
Design checklist
- Define the purpose and trust level of each segment.
- Document required traffic flows.
- Choose the Layer 3 boundary deliberately.
- Use least-privilege policy where appropriate.
- Plan VLAN IDs and IP ranges together.
- Consider IPv6 from the beginning.
- Document management access separately.
Related tools
Plan VLANs, calculate subnets and review firewall policy together.