Skip to content
Technology infrastructure that keeps your business connected.Consultation

VLAN design that survives the next office move

Most VLAN schemes are drawn around a floor plan. Then the floor plan changes, and the scheme becomes a list of exceptions nobody can read.

28 August 20263 min readadmin

VLAN design that survives the next office move
Share

Almost every VLAN scheme starts the same way: somebody opens the floor plan and draws one VLAN per area. Sales on the second floor, accounts on the third, a separate one for the meeting rooms. It is easy to explain, easy to document, and it survives exactly until the first desk move.

Why the floor plan is the wrong axis

A VLAN is a broadcast domain and, in practice, a security boundary. Neither of those things has anything to do with where somebody sits. When accounts takes six desks on the second floor because the third is being repainted, a location-based scheme leaves you with three bad options: trunk the accounts VLAN to a switch that should not carry it, move those users into the sales VLAN and lose the boundary, or re-address six machines.

All three happen. The third is the only correct one and it is the one nobody has time for, so the exceptions accumulate. Two years later the documentation says one thing and the switch configuration says another, and the person who knows the difference has left.

Segment by what the traffic is, not where it sits

The scheme that ages well is drawn around function:

  • Staff devices — laptops and desktops that people log into.
  • Servers — anything that other things connect to.
  • Voice — handsets, which want their own QoS treatment anyway.
  • Surveillance — cameras and the recorder, which talk to each other constantly and to nothing else.
  • Building services — access control, HVAC, anything with a web interface from 2014 that will never be patched.
  • Guest — internet only, no route to anything internal.

A desk move now changes nothing. The port gets the staff VLAN because a staff laptop is plugged into it, and that is true on every floor.

The one that is always forgotten

Building services. It is the VLAN nobody asks for and the one that matters most, because it contains the devices with the worst security stories and the longest lives. An access control panel commissioned in 2016 with a default password and no firmware since is a real thing in real buildings. It needs to reach one server and nothing else, and the only reliable way to enforce that is to put it somewhere it cannot reach anything else by default.

Leave room

Number them with gaps. VLAN 10, 20, 30, 40 rather than 1, 2, 3, 4. When a new category appears — and it will, the first time somebody installs a digital signage system — there is somewhere obvious to put it that does not mean renumbering.

The same applies to addressing. A /24 per VLAN is more than most segments will ever use, and the alternative is re-subnetting a live network at the exact moment you are busiest.

Write down why, not just what

The documentation that survives is not the list of VLAN IDs. It is the one sentence per VLAN explaining what belongs in it. "VLAN 50 is for devices that must reach the recorder and nothing else" answers next year's question. "VLAN 50 — CCTV" does not.

Related

Ran into this on your own network?

If something here matches a problem you are seeing, describe it and we will tell you what we would check first.