VLAN segmentation for business networks

A guest on office WiFi should not have the same access as an employee working with a server. We organise the network into logical segments, define permitted communication and check that essential business services still work.

Request a network review
Illustration of business network equipment and network segmentation

The problem with one network for everything

When computers, guest phones, cameras, printers and servers share a network, controlling access becomes difficult. VLANs provide logical separation, but a VLAN label alone is not enough: rules between segments determine what is actually allowed.

NBG TEAM plans office network segmentation in Belgrade and New Belgrade around the way your business operates. The aim is to limit access while preserving approved applications, printing and other required services.

Devices and communication requirements

  • Employee, guest, server and specialist-device groups.
  • Equipment support for VLANs, tagged ports and WiFi network mapping.
  • IP addressing, DHCP, DNS and routing between segments.
  • Services that must remain reachable between particular groups.
  • A change window, pilot group and configuration rollback plan.

The review covers managed switches, the router or firewall and access points. If required functions are missing, we prepare a hardware recommendation. We first establish what the existing equipment can support rather than replacing the entire system by default.

From access plan to testing

Rules before rollout

We agree who needs the server, who needs printing and what guests are allowed to use. Some device-discovery functions may not work across network boundaries, so the actual workflow needs to be checked in advance.

Staged implementation

Changes are introduced in the agreed window. We test address assignment, internet connectivity, DNS, applications and authorised access. We also check that blocked connections are genuinely unavailable.

Documentation for the next change

Handover records network segments, port and WiFi purposes, address ranges and agreed rules. A future switch replacement or new device should not depend on someone remembering the original configuration. Exceptions, such as a contractor’s access to one device, should have an owner and a reason.

Segmentation is one part of infrastructure protection. It does not replace account management, updates or backup. For a business with several locations, rules can be coordinated with site-to-site VPN connections.

What determines the work

Device and port counts, equipment capabilities, required exceptions and application availability for testing affect timing and cost. Router and switch model numbers plus an office sketch are useful starting points. Extra cabling, new equipment and ongoing maintenance are agreed according to the findings.

For the wider service, see network infrastructure. Our IT services pricing page explains billing; the scope of this project is confirmed in a proposal.

Questions about this service

Is a different WiFi name enough?
Not necessarily. Different network names can still connect to the same local network. We check segment mapping, isolation and access rules.
Will VLANs slow down the network?
Performance depends on equipment and routing between segments. We review device capacity and required traffic, particularly large file transfers between networks.
Can a guest print without accessing all computers?
If the equipment and printing method support it, access can be restricted to the required service. We check the actual model rather than opening a whole segment for one printer.