Network Segmentation: A Field Guide for Multi-Department Sites
VLANs, guest Wi-Fi, IoT, and clinical/admin separation explained for operators who aren't network engineers, but are responsible when something leaks.
Flat networks, everything on one LAN, are easy until they're catastrophic. One compromised laptop can browse file shares, printers, and cameras because nothing is walled off.
Segmentation divides traffic so departments, guests, and devices only reach what they need.
Common segments for SMB sites
| VLAN / Segment | Typical users/devices | Access |
|---|---|---|
| Corporate | Staff laptops, servers | Full internal resources per role |
| Clinical / secure | Workstations with sensitive apps | Restricted servers only |
| Guest | Visitors, families | Internet only |
| IoT / cameras | Security cams, badges, HVAC | No internet outbound unless required; no corporate access |
| VoIP | Phones | Priority QoS; limited east-west |
Not every site needs all five, but guest on corporate is the pattern we retire most often.
Design principles
Default deny between segments, allow only specific ports/services
Document every firewall rule with business owner
Name VLANs clearly, future you will thank present you
Test from each segment quarterly, penetration isn't required; ping and browse tests suffice
Wireless matters
Guest SSID must map to guest VLAN, not isolated only by password on the same broadcast domain. Meraki, UniFi, and enterprise APs all support this; consumer gear often doesn't.
When segmentation fails
- Overly complex rules nobody maintains → "temporary" allow-all rule added in 2023 still there
- Vendor requiring flat network, push back or isolate vendor gear in dedicated segment
- No monitoring, segments drift as devices move
Project vs. operational
Initial segmentation is a project. Maintaining it is operations, new devices assigned correctly, rules reviewed when apps change.
Precipice designs and manages segmented networks for single and multi-site operators. Discuss your site.