Designing a Business Network That Scales: VLANs, Switching and Wireless
Share
Most small business networks are not designed. They accumulate. A router from the internet provider, a cheap switch added when the ports ran out, an access point someone bought at a retail store, a second switch daisy-chained off the first. It works until it doesn't, and by then nobody knows what is plugged into what. This guide covers how to build a network that scales — aimed at IT managers and technically confident business owners.
Start with a document, not a purchase order
Before buying anything, write down:
- Device count today and in three years. Include everything with an IP address: computers, phones, printers, cameras, access points, POS terminals, building management, sensors.
- Physical layout. Where the cabling terminates, where power is, where the comms cabinet is or should be.
- Traffic patterns. What talks to what. Is your traffic mostly out to the internet, or is there heavy internal traffic to a local server or NAS?
- Availability requirements. What breaks the business if it stops.
This document is your design brief and, later, your troubleshooting reference. Businesses that skip it end up buying hardware twice.
Segment the network
A flat network — everything on one subnet, everything able to talk to everything — is the root cause of most performance and security problems in small business networks.
VLANs let you carve one physical network into several logical ones. A sensible small business segmentation:
- VLAN 10 – Staff. Laptops, desktops, staff devices.
- VLAN 20 – Voice. IP phones, prioritised for quality of service.
- VLAN 30 – Servers and storage. If you have any onsite.
- VLAN 40 – Point of sale and payments. Tightly restricted, minimal outbound access.
- VLAN 50 – IoT and building systems. Cameras, door controllers, smart devices, printers. These are frequently insecure and rarely patched.
- VLAN 60 – Guest. Internet only, isolated from everything internal, client isolation enabled.
- VLAN 99 – Management. Switch, access point and firewall management interfaces, reachable only from specific admin devices.
Two rules make this worth the effort: deny between segments by default, then open only the specific flows you need. And put management on its own segment — if an attacker on the guest network can reach your switch's admin page, the segmentation achieved nothing.
The payoff is concrete. A compromised camera cannot reach your accounts machine. A customer on guest WiFi cannot scan your file server. A broadcast storm on one segment does not take down the whole site.
Address planning
Give each VLAN its own subnet, and be generous. Address space costs nothing; renumbering later costs a weekend.
Within each subnet, split the range deliberately: a block reserved for static assignments (gateways, switches, servers, printers), a block for DHCP reservations, and the remainder for the general DHCP pool. Avoid the overused 192.168.0.0/24 and 192.168.1.0/24 — they collide constantly with home networks when staff connect via VPN from home.
Choose hardware by role
Firewall / router
The internet provider's modem-router should be in bridge mode with a proper firewall behind it. Size it by throughput with security services enabled, not by the marketing number. Requirements: multiple WAN ports or a USB/SIM option for failover, VLAN support, site-to-site VPN, and remote access VPN.
Switching
Managed switches, not unmanaged. Unmanaged switches cannot do VLANs, cannot be monitored, and give you no visibility when something goes wrong. Specify:
- PoE for access points, IP phones and cameras — and budget the PoE power, not just the port count. PoE+ devices draw considerably more than legacy PoE.
- Uplink capacity. If access switches connect at 1 Gb and there are twenty of them feeding a core switch over a single 1 Gb link, that link is your bottleneck. Use 10 Gb uplinks or link aggregation.
- Port count with headroom. Plan for roughly 30–50% growth. Running out of ports is how daisy-chained switch sprawl starts.
Wireless
Access points with wired backhaul, centrally managed, all broadcasting the same network names with proper roaming between them. Map coverage to the building rather than to available power points. Support the VLANs you defined — a guest SSID mapped to the guest VLAN, a staff SSID to the staff VLAN.
Cable properly, once
Cabling outlives every other component in the network. Cat6 or Cat6A to every desk and every access point location, terminated into a patch panel in a proper rack, labelled at both ends, and certified after installation.
Run more cables than you need while the ceiling is open. The marginal cost of an extra run during installation is trivial; the cost of pulling one later is a day of labour and a mess.
Build in resilience
Decide which failures you are willing to absorb and which you are not:
- Internet failover. A second service on different infrastructure — a 5G service is a good complement to fixed-line, since a cable cut does not affect it.
- Power protection. A UPS on the comms cabinet at minimum. Network gear draws little power and a modest UPS carries it through the brief outages that make up most power events.
- Spares. A cold spare switch and access point on the shelf turn a multi-day outage into a one-hour one.
Full redundancy — dual firewalls, stacked core switches, dual uplinks — is rarely justified below a certain size. Be honest about what an hour of downtime actually costs before buying it.
Quality of service
If you run VoIP or heavy video conferencing, configure QoS. Voice traffic should be prioritised end to end. Without it, a single large upload can degrade every call in the building. This is a configuration task, not a hardware purchase, and it is routinely skipped.
Monitoring and documentation
You cannot manage what you cannot see. At minimum, monitor device availability, interface errors and utilisation, PoE budget, WAN latency and packet loss, and configuration changes. Alert on the things that predict failure, not just the things that have already failed.
Documentation should live somewhere accessible and stay current:
- Network diagram, logical and physical
- VLAN and IP allocation table
- Device inventory with model, serial, firmware, location and warranty
- Cable and patch panel schedules
- Firewall rule set with a stated reason for each rule
- Credentials in a proper password manager
The firewall rule justification matters more than it sounds. Undocumented rules never get removed, because nobody dares. Over years, that produces a rule set nobody understands and everybody is afraid of.
A note on scaling to multiple sites
When a second location appears, resist replicating the first site's design independently. Plan a consistent addressing scheme across sites from the start, use the same hardware family so configurations and spares are interchangeable, and connect sites with a site-to-site VPN or SD-WAN overlay. Standardisation is what makes a two-site network manageable and a five-site network possible.
Do it in the right order
- Document requirements and draw the target design
- Plan addressing and VLANs on paper
- Install and certify cabling
- Deploy and configure switching
- Deploy firewall and configure inter-VLAN policy
- Deploy wireless and map SSIDs to VLANs
- Migrate devices segment by segment, out of hours
- Configure monitoring, then verify against the original requirements
Real IT Consulting designs and builds business networks across the Gold Coast, Brisbane, Logan, Pimpama and Sydney — from single-office cleanups to multi-site rollouts. Call 0489 940 359 to discuss your site.