ENGINEERING GUIDE · DESIGN

Network Segmentation & VLAN Design

Design practical VLAN and network segmentation schemes for users, servers, management, voice, IoT and guest networks.

Network designVLANs · Segmentation
The important bit: Good segmentation starts with trust boundaries and traffic requirements, not arbitrary VLAN numbers.

Start with purpose

Start by identifying device classes, trust levels, required communications and operational ownership. Create a segment when separation has a clear security, operational or performance purpose.

Common segments

SegmentTypical contentsKey consideration
UserManaged clientsApproved internal services and internet.
ServerApplications and infrastructureRestrict access to required services.
ManagementSwitches, APs and controllersAdministrator-only access.
VoiceIP phonesQoS and phone/data separation.
IoTCameras, displays and appliancesAssume weaker device security.
GuestUnmanaged clientsUsually internet-only.

Layer 3 boundaries

Inter-VLAN traffic requires routing. The gateway may be on a Layer 3 switch, router or firewall. Put the boundary where the required inspection, throughput and operational model make sense.

Security boundaries

VLANs are not a security control by themselves. Enforce the intended separation with firewalls, ACLs, 802.1X and other controls. Define permitted flows explicitly by source, destination, protocol and business purpose.

VLAN and IP planning

Use a consistent numbering scheme and keep VLAN IDs, subnet prefixes, gateways and DHCP scopes documented together. Leave room for growth and avoid overlapping networks.

Design checklist

  1. Define the purpose and trust level of each segment.
  2. Document required traffic flows.
  3. Choose the Layer 3 boundary deliberately.
  4. Use least-privilege policy where appropriate.
  5. Plan VLAN IDs and IP ranges together.
  6. Consider IPv6 from the beginning.
  7. Document management access separately.

Related tools

Plan VLANs, calculate subnets and review firewall policy together.

VLAN Planner →   Subnet Calculator →   Firewall Policy Analyzer →