Network segmentation: a practical guide

A flat network where everything can talk to everything is easy to set up – and hard to secure and troubleshoot. This guide shows how to split the network into sensible segments, without needing to be a network specialist.

Why segment?

  • Security. Ransomware and attackers move sideways through the network. When guests, printers and servers each sit in their own segment with a firewall in between, an attack often stops in the first segment.
  • Less noise. Every subnet is its own broadcast domain. A thousand machines in one network means a lot of unnecessary traffic and hard troubleshooting.
  • Different rules for different things. Guests should only reach the internet. Printers should be reachable from staff, but not from students. Without segments you cannot express such rules.
  • Clarity. When the address tells you what kind of device it is (10.10.60.x is printers), troubleshooting is faster.
  • Requirements. Many sectors and insurers expect sensitive systems to be segmented.

The concepts

TermExplanation
VLANA virtual LAN on the switches. Ports in the same VLAN are in the same layer 2 network, even across different switches.
SubnetThe address range used in a VLAN, for example 10.10.20.0/24. Normally there is one subnet per VLAN.
GatewayThe router or firewall in the subnet, usually the first address (.1). All traffic to other segments goes here.
TrunkA switch port carrying several VLANs, typically between switches and towards the firewall or access points.
DHCP relayForwards DHCP from a VLAN to a central DHCP server (often called *ip helper*).

Routing between segments can happen in a firewall or in a layer 3 switch. If traffic passes through the firewall, you can control it with rules – usually what you want for everything except the most traffic-heavy networks.

Choose an address range

Internally, private addresses from RFC 1918 are used:

RangeSizeComment
10.0.0.0/816.7 millionMost flexible. Room for a site per /16 and a VLAN per /24.
172.16.0.0/121 millionWidely used by Docker and some VPN products – check for collisions.
192.168.0.0/1665,536Fine for small networks, but 192.168.0.x and 192.168.1.x clash with the home router of everyone working over VPN.

A clear pattern is `10.<site>.<vlan>.0/24`: site 20 and VLAN 30 becomes 10.20.30.0/24. The address then tells you both where and what. If a segment needs more than 254 addresses, give it a larger network (for example a /22) and skip the VLAN numbers it covers.

Avoid public addresses you do not own, and avoid 100.64.0.0/10 (CGNAT) and 169.254.0.0/16 (link-local) for normal networks.

How large should the networks be?

  1. Count the devices in each segment today – including phones, tablets and IoT.
  2. Add growth. 30–50% is a good starting point for client networks. Renumbering later is far more work.
  3. Add addresses for the gateway and any reserved addresses.
  4. Pick the smallest network that fits. Keep client networks at /22 or smaller so broadcast domains do not grow too large.
PrefixUsable addressesTypical use
/2814Network management at a small site
/2730Servers, printers on one floor
/2662Printers, IP phones in a smaller business
/24254Client networks, the default when in doubt
/23510Larger client networks, staff at a school
/221,022Student or guest networks with many devices

The VLSM calculator does this job for you.

Common segments

SegmentContentsTypical access
Network managementSwitches, access points, firewall management interfaceOnly from IT administration
ServersFile, print, applicationsFrom clients on the ports needed
Staff / clientsPCs and phonesTo servers, printers and the internet
IP telephonyPhonesTo the PBX and SIP provider
PrintersPrinters and multifunction devicesFrom clients and the print server
IoT and buildingAccess control, ventilation, cameras, displaysOnly to their own management systems
GuestsVisitors and personal devicesInternet only, client isolation
DMZServices reachable from the internetRestricted in and out

Firewall rules between segments

Start with everything closed between segments, and open only what is needed. A simple matrix makes it clear:

From \ toServersPrintersMgmtInternet
StaffRequired portsPrintingNoYes
GuestsNoNoNoYes
PrintersScan to folder–NoUpdates only
IoT and buildingManagement server onlyNoNoVendor only
IT administrationYesYesYesYes

Example: office with 60 staff

SegmentVLANSubnetGateway
Network management9910.1.99.0/2810.1.99.1
Servers2010.1.20.0/2610.1.20.1
Staff1010.1.10.0/2410.1.10.1
IP telephony3010.1.30.0/2510.1.30.1
Printers4010.1.40.0/2710.1.40.1
Guests5010.1.50.0/2410.1.50.1

For a larger example, see the layout for schools or healthcare and public sector.

How to carry it out

  1. Survey what exists today. A collector from auto-discovery quickly gives you a list of active addresses.
  2. Decide the segments and who should talk to whom.
  3. Draw up the address plan and document it in ipmanager before configuring anything.
  4. Configure the switches: VLANs, trunks and access ports.
  5. Configure the gateway (firewall or layer 3 switch) with one interface per VLAN.
  6. Set up DHCP with one scope per segment, and DHCP relay where the server sits in another network.
  7. Write the firewall rules from the matrix.
  8. Move one segment at a time, starting with the least critical – often guests or printers.
  9. Verify that everything works, and update the documentation.

Common mistakes

  • Address ranges that clash with VPN users' home networks or with partners.
  • One huge /16 for all clients “to have enough”.
  • Forgotten DHCP relay, so clients in the new VLAN get no address.
  • Printers on DHCP without a reservation – the address changes and printing stops.
  • VLAN 1 used as a normal network, or management interfaces reachable from the client network.
  • No documentation – the plan only exists in the head of whoever made it.

What about IPv6?

Segmentation is the same with IPv6: one /64 per VLAN, and the same firewall rules for both protocols. See IPv6 in practice.

How ipmanager helps

Segmentation help in ipmanager has templates for school, office, data centre and healthcare. You enter the number of devices and get a plan with correctly aligned subnets, gateway, suggested VLANs and room to grow. The plan is checked against networks you already have and can be created with one click. Get started free.

Get your IP addresses under control today

Free for up to 100 IP addresses. Sign-in details by email immediately, no credit card.