Why segment?
- Security. Ransomware and attackers move sideways through the network. When guests, printers and servers each sit in their own segment with a firewall in between, an attack often stops in the first segment.
- Less noise. Every subnet is its own broadcast domain. A thousand machines in one network means a lot of unnecessary traffic and hard troubleshooting.
- Different rules for different things. Guests should only reach the internet. Printers should be reachable from staff, but not from students. Without segments you cannot express such rules.
- Clarity. When the address tells you what kind of device it is (
10.10.60.xis printers), troubleshooting is faster. - Requirements. Many sectors and insurers expect sensitive systems to be segmented.
The concepts
| Term | Explanation |
|---|---|
| VLAN | A virtual LAN on the switches. Ports in the same VLAN are in the same layer 2 network, even across different switches. |
| Subnet | The address range used in a VLAN, for example 10.10.20.0/24. Normally there is one subnet per VLAN. |
| Gateway | The router or firewall in the subnet, usually the first address (.1). All traffic to other segments goes here. |
| Trunk | A switch port carrying several VLANs, typically between switches and towards the firewall or access points. |
| DHCP relay | Forwards DHCP from a VLAN to a central DHCP server (often called *ip helper*). |
Routing between segments can happen in a firewall or in a layer 3 switch. If traffic passes through the firewall, you can control it with rules – usually what you want for everything except the most traffic-heavy networks.
Choose an address range
Internally, private addresses from RFC 1918 are used:
| Range | Size | Comment |
|---|---|---|
10.0.0.0/8 | 16.7 million | Most flexible. Room for a site per /16 and a VLAN per /24. |
172.16.0.0/12 | 1 million | Widely used by Docker and some VPN products – check for collisions. |
192.168.0.0/16 | 65,536 | Fine for small networks, but 192.168.0.x and 192.168.1.x clash with the home router of everyone working over VPN. |
A clear pattern is `10.<site>.<vlan>.0/24`: site 20 and VLAN 30 becomes 10.20.30.0/24. The address then tells you both where and what. If a segment needs more than 254 addresses, give it a larger network (for example a /22) and skip the VLAN numbers it covers.
100.64.0.0/10 (CGNAT) and 169.254.0.0/16 (link-local) for normal networks.How large should the networks be?
- Count the devices in each segment today – including phones, tablets and IoT.
- Add growth. 30–50% is a good starting point for client networks. Renumbering later is far more work.
- Add addresses for the gateway and any reserved addresses.
- Pick the smallest network that fits. Keep client networks at
/22or smaller so broadcast domains do not grow too large.
| Prefix | Usable addresses | Typical use |
|---|---|---|
/28 | 14 | Network management at a small site |
/27 | 30 | Servers, printers on one floor |
/26 | 62 | Printers, IP phones in a smaller business |
/24 | 254 | Client networks, the default when in doubt |
/23 | 510 | Larger client networks, staff at a school |
/22 | 1,022 | Student or guest networks with many devices |
The VLSM calculator does this job for you.
Common segments
| Segment | Contents | Typical access |
|---|---|---|
| Network management | Switches, access points, firewall management interface | Only from IT administration |
| Servers | File, print, applications | From clients on the ports needed |
| Staff / clients | PCs and phones | To servers, printers and the internet |
| IP telephony | Phones | To the PBX and SIP provider |
| Printers | Printers and multifunction devices | From clients and the print server |
| IoT and building | Access control, ventilation, cameras, displays | Only to their own management systems |
| Guests | Visitors and personal devices | Internet only, client isolation |
| DMZ | Services reachable from the internet | Restricted in and out |
Firewall rules between segments
Start with everything closed between segments, and open only what is needed. A simple matrix makes it clear:
| From \ to | Servers | Printers | Mgmt | Internet |
|---|---|---|---|---|
| Staff | Required ports | Printing | No | Yes |
| Guests | No | No | No | Yes |
| Printers | Scan to folder | – | No | Updates only |
| IoT and building | Management server only | No | No | Vendor only |
| IT administration | Yes | Yes | Yes | Yes |
Example: office with 60 staff
| Segment | VLAN | Subnet | Gateway |
|---|---|---|---|
| Network management | 99 | 10.1.99.0/28 | 10.1.99.1 |
| Servers | 20 | 10.1.20.0/26 | 10.1.20.1 |
| Staff | 10 | 10.1.10.0/24 | 10.1.10.1 |
| IP telephony | 30 | 10.1.30.0/25 | 10.1.30.1 |
| Printers | 40 | 10.1.40.0/27 | 10.1.40.1 |
| Guests | 50 | 10.1.50.0/24 | 10.1.50.1 |
For a larger example, see the layout for schools or healthcare and public sector.
How to carry it out
- Survey what exists today. A collector from auto-discovery quickly gives you a list of active addresses.
- Decide the segments and who should talk to whom.
- Draw up the address plan and document it in ipmanager before configuring anything.
- Configure the switches: VLANs, trunks and access ports.
- Configure the gateway (firewall or layer 3 switch) with one interface per VLAN.
- Set up DHCP with one scope per segment, and DHCP relay where the server sits in another network.
- Write the firewall rules from the matrix.
- Move one segment at a time, starting with the least critical – often guests or printers.
- Verify that everything works, and update the documentation.
Common mistakes
- Address ranges that clash with VPN users' home networks or with partners.
- One huge
/16for all clients “to have enough”. - Forgotten DHCP relay, so clients in the new VLAN get no address.
- Printers on DHCP without a reservation – the address changes and printing stops.
- VLAN 1 used as a normal network, or management interfaces reachable from the client network.
- No documentation – the plan only exists in the head of whoever made it.
What about IPv6?
Segmentation is the same with IPv6: one /64 per VLAN, and the same firewall rules for both protocols. See IPv6 in practice.
How ipmanager helps
Segmentation help in ipmanager has templates for school, office, data centre and healthcare. You enter the number of devices and get a plan with correctly aligned subnets, gateway, suggested VLANs and room to grow. The plan is checked against networks you already have and can be created with one click. Get started free.