Anasayfa / Software / How to Set Up VLANs for Network Segmentation in a Small Business

How to Set Up VLANs for Network Segmentation in a Small Business

network segmentation

Network segmentation is one of the most effective ways to improve security, performance, and manageability in a small‑business environment. By grouping devices into Virtual LANs (VLANs) you can keep sensitive data traffic separate from guest Wi‑Fi, isolate IoT devices, and reduce broadcast storms without buying extra physical switches. This guide walks you through the entire process—from planning your VLAN topology to configuring a Cisco switch, a Linux server, and a typical consumer router. You’ll get real commands, screenshots, and a list of common mistakes to avoid, so you can implement a reliable VLAN architecture in just a few hours.

What You’ll Need

  • A managed switch that supports 802.1Q tagging (e.g., Cisco Catalyst 2960, Netgear ProSAFE, or TP‑Link JetStream).
  • A router or firewall capable of inter‑VLAN routing (Cisco ISR, pfSense, Ubiquiti EdgeRouter, or a Layer‑3 capable switch).
  • At least one Linux server or workstation for testing (Ubuntu 22.04 LTS recommended).
  • Access to the switch’s console (USB‑to‑serial cable or SSH).
  • Basic network diagram showing which devices belong to which VLAN.
  • Optional: A spare Ethernet cable for a direct console connection.

Step 1: Plan Your VLAN Architecture

Before you touch any hardware, sketch a simple diagram. Identify logical groups such as Management (switch admin, servers), Staff (workstations, printers), Guest Wi‑Fi, and IoT (cameras, smart lights). Assign each group a unique VLAN ID (1‑4094). A common convention is:

  • VLAN 10 – Management
  • VLAN 20 – Staff
  • VLAN 30 – Guest
  • VLAN 40 – IoT

Write down the subnet you’ll use for each VLAN (e.g., 192.168.10.0/24 for Management). Keeping subnets separate simplifies firewall rules and DHCP scopes later on.

Step 2: Configure the Managed Switch

Log into the switch via SSH or console. The example below uses Cisco IOS syntax; adjust for other vendors accordingly.

enable
configure terminal
! Create VLANs
vlan 10
 name Management
exit
vlan 20
 name Staff
exit
vlan 30
 name Guest
exit
vlan 40
 name IoT
exit
! Assign ports – assume ports 1‑4 are for staff workstations,
! 5‑6 for IoT, 7 for the uplink to the router, 8 for a management PC.
interface range GigabitEthernet0/1-4
 switchport mode access
 switchport access vlan 20
exit
interface range GigabitEthernet0/5-6
 switchport mode access
 switchport access vlan 40
exit
interface GigabitEthernet0/7
 switchport mode trunk
 switchport trunk allowed vlan 10,20,30,40
exit
interface GigabitEthernet0/8
 switchport mode access
 switchport access vlan 10
 exit
! Save configuration
write memory

If you’re using a Netgear or TP‑Link switch, the same concepts apply but the CLI commands differ; refer to the vendor’s manual for “VLAN ID”, “Untagged/Tagged” settings, and “PVID”.

Step 3: Set Up Inter‑VLAN Routing on the Router/Firewall

Without routing, devices on different VLANs cannot talk to each other or reach the internet. Below is a pfSense example; similar steps exist on Cisco ISR (using interface vlanX) or Ubiquiti EdgeOS.

# Assume the router’s physical interface is em0 and connects to switch port 7 (trunk)
# Create VLAN interfaces
set interfaces ethernet eth0 vif 10 description "Management"
set interfaces ethernet eth0 vif 20 description "Staff"
set interfaces ethernet eth0 vif 30 description "Guest"
set interfaces ethernet eth0 vif 40 description "IoT"

# Assign IP addresses
set interfaces ethernet eth0 vif 10 address 192.168.10.1/24
set interfaces ethernet eth0 vif 20 address 192.168.20.1/24
set interfaces ethernet eth0 vif 30 address 192.168.30.1/24
set interfaces ethernet eth0 vif 40 address 192.168.40.1/24

# Enable DHCP for each VLAN (optional but recommended)
set service dhcp-server shared-network-name Management subnet 192.168.10.0/24 default-router 192.168.10.1
set service dhcp-server shared-network-name Management subnet 192.168.10.0/24 range 192.168.10.100 192.168.10.200
# Repeat for Staff, Guest, IoT...

# Commit and save
commit
save

On a Cisco router, you would use:

interface GigabitEthernet0/0.10
 encapsulation dot1Q 10
 ip address 192.168.10.1 255.255.255.0
interface GigabitEthernet0/0.20
 encapsulation dot1Q 20
 ip address 192.168.20.1 255.255.255.0
! ... repeat for other VLANs
ip routing

Make sure ip routing (or the equivalent) is enabled; otherwise the router will act as a Layer‑2 bridge only.

Step 4: Verify Connectivity and Test Isolation

Connect a laptop to a staff port (VLAN 20). It should receive an IP from 192.168.20.0/24 and be able to ping the router’s 192.168.20.1 address. Then try pinging 192.168.10.1 (Management). If you haven’t added firewall rules yet, the ping will fail, confirming isolation.

On the Linux test server, you can also use tcpdump to watch tagged frames:

sudo tcpdump -i eth0 -e vlan 20

This shows that frames leaving the server are correctly tagged with VLAN 20.

Step 5: Harden the Environment with Firewall Rules

Now that the VLANs are isolated, decide which traffic should be allowed. A typical small business permits:

  • Staff ↔ Management (for printer access, internal services).
  • Guest ↔ Internet only.
  • IoT ↔ Internet only, but block inbound from other VLANs.

In pfSense, navigate to Firewall → Rules → [VLAN interface] and create rules such as:

# Allow staff to reach management services (HTTP, SMB)
Action: Pass
Interface: VLAN20
Source: VLAN20 net
Destination: VLAN10 net
Destination Port: 80,443,445
# Allow all VLANs to reach WAN
Action: Pass
Interface: VLAN10/VLAN20/VLAN30/VLAN40
Source: any
Destination: any
Destination Port: any
# Block inter‑VLAN traffic not explicitly allowed
Action: Block
Interface: VLAN10/VLAN20/VLAN30/VLAN40
Source: any
Destination: any

Remember to place “Allow” rules above the generic “Block” rule; pfSense processes rules top‑down.

Common Mistakes to Avoid

1 Forgetting the trunk port configuration. If the uplink to the router is set as an access port, VLAN tags will be stripped, and the router will see only the native VLAN. Double‑check that the port is in trunk mode and that the allowed VLAN list includes every VLAN you created.

2 Using overlapping IP subnets. Assigning the same subnet to two different VLANs creates routing ambiguities and can cause ARP storms. Keep each VLAN on a distinct /24 (or appropriate) network.

3 Neglecting native VLAN consistency. Cisco defaults the native VLAN to 1. If you leave native VLAN 1 on the trunk but never configure it, untagged traffic may be dropped or end up in the wrong VLAN. Either change the native VLAN to an unused ID or ensure VLAN 1 is deliberately used.

4 Leaving DHCP disabled on a new VLAN. Devices will fall back to APIPA (169.254.x.x) and appear disconnected. Add DHCP scopes or configure static IPs before plugging in end devices.

5 Over‑permissive firewall rules. A “allow all” rule on a guest VLAN defeats the purpose of segmentation. Start with a deny‑all default and open only the ports you truly need.

Tips and Tricks

Use descriptive VLAN names. Most switches let you name VLANs (e.g., name Staff). This makes troubleshooting much faster when you run show vlan brief.

Document the VLAN‑to‑subnet mapping. Keep a simple spreadsheet that lists VLAN ID, name, IP subnet, purpose, and associated ports. It becomes a reference for future expansions.

Leverage port‑based authentication. If your switch supports 802.1X, you can require devices to authenticate before they’re placed into a VLAN, adding an extra security layer.

Test with a single device first. Before rolling out VLAN 40 (IoT) to dozens of cameras, connect one camera and verify it receives the correct IP and can reach the cloud service.

Backup configurations. After you finish, export the switch and router configs. In Cisco IOS, write memory saves the running config; on pfSense, use Diagnostics → Backup & Restore.

Frequently Asked Questions

Do I need a Layer‑3 switch if I already have a router?

No. A router (or firewall) that supports sub‑interfaces can perform inter‑VLAN routing. A Layer‑3 switch is useful when you want routing inside the switch fabric for lower latency, but it’s optional for a small business.

Can I use the same VLAN ID on multiple switches?

Yes, as long as the switches are connected via trunk links that carry those VLAN IDs. Consistency across the network ensures devices stay in the same logical segment.

What if my ISP’s modem/router only has one LAN port?

Place the ISP device in “bridge” mode and let your dedicated router handle all VLANs. If bridge mode isn’t possible, connect the ISP router to a LAN port on your managed switch, but treat that port as a separate VLAN (often called “WAN”) and avoid mixing it with internal VLAN traffic.

Conclusion

Setting up VLANs for network segmentation might sound intimidating, but with a clear plan, the right hardware, and a few carefully typed commands you can dramatically improve security and performance in a small‑business environment. By following the steps above—designing your VLAN map, configuring the switch, enabling inter‑VLAN routing, testing isolation, and hardening with firewall rules—you’ll have a robust, future‑proof network that can grow alongside your business. Remember to document everything, back up configurations, and revisit your firewall policies as new devices join the network. Happy networking!

Photo by Jakub Żerdzicki on Unsplash

Etiketlendi: