VLAN segmentation for business networks
A guest on office WiFi should not have the same access as an employee working with a server. We organise the network into logical segments, define permitted communication and check that essential business services still work.
Request a network review
The problem with one network for everything
When computers, guest phones, cameras, printers and servers share a network, controlling access becomes difficult. VLANs provide logical separation, but a VLAN label alone is not enough: rules between segments determine what is actually allowed.
NBG TEAM plans office network segmentation in Belgrade and New Belgrade around the way your business operates. The aim is to limit access while preserving approved applications, printing and other required services.
Devices and communication requirements
- Employee, guest, server and specialist-device groups.
- Equipment support for VLANs, tagged ports and WiFi network mapping.
- IP addressing, DHCP, DNS and routing between segments.
- Services that must remain reachable between particular groups.
- A change window, pilot group and configuration rollback plan.
The review covers managed switches, the router or firewall and access points. If required functions are missing, we prepare a hardware recommendation. We first establish what the existing equipment can support rather than replacing the entire system by default.
From access plan to testing
Rules before rollout
We agree who needs the server, who needs printing and what guests are allowed to use. Some device-discovery functions may not work across network boundaries, so the actual workflow needs to be checked in advance.
Staged implementation
Changes are introduced in the agreed window. We test address assignment, internet connectivity, DNS, applications and authorised access. We also check that blocked connections are genuinely unavailable.
Documentation for the next change
Handover records network segments, port and WiFi purposes, address ranges and agreed rules. A future switch replacement or new device should not depend on someone remembering the original configuration. Exceptions, such as a contractor’s access to one device, should have an owner and a reason.
Segmentation is one part of infrastructure protection. It does not replace account management, updates or backup. For a business with several locations, rules can be coordinated with site-to-site VPN connections.
What determines the work
Device and port counts, equipment capabilities, required exceptions and application availability for testing affect timing and cost. Router and switch model numbers plus an office sketch are useful starting points. Extra cabling, new equipment and ongoing maintenance are agreed according to the findings.
For the wider service, see network infrastructure. Our IT services pricing page explains billing; the scope of this project is confirmed in a proposal.