"Can we just use one 192.168.1.0/24 for the whole company?" That question shows up constantly when an integrator or a small business first pulls cable. The person asking only wants "plug in and ping works" — they have not thought about the cameras turning into a slideshow three months later, a guest phone sniffing the finance PC, or discovering there are no addresses left when a branch VPN needs to be added. Network segmentation — giving each business function its own VLAN and IP subnet — is how you build rooms and install access control instead of leaving one open hall.
One flat /24 saves planning but also removes four safeguards: broadcast control, security boundary, enforceable policy, and room to grow.
A /24 holds 254 hosts, but keep real usage under ~80% — size a domain by function, not by "how many addresses exist."
"One VLAN, one subnet" keeps Layer 2 isolation and Layer 3 addressing aligned, so faults map to a specific room instead of a building-wide broadcast storm.
Put the gateway on a Layer 3 switch SVI, keep a separate management VLAN, and reserve 10–20% headroom per segment.
192.168.1.0/24 gives 254 usable addresses. Dump the whole company in and you skip planning — but you also skip four layers of insurance:
Broadcast domain out of control. 254 devices in one Layer 2 domain means ARP, DHCP, and multicast packets flood everywhere. When camera streams climb or APs multiply, broadcast volume can peg the switch CPU and the whole network randomly stutters or occasionally fails to hand out a DHCP address.
Security boundary disappears. Office PCs, finance machines, cameras, and guest phones in the same Layer 2 mean ARP spoofing, lateral scanning, and unauthorized access sit behind "a trust that should never have existed." One compromised host can move sideways across the entire network.
Policy cannot land. Rate limits, ACLs, and auditing all apply at the "whole segment" grain — you cannot express "camera domain only reaches the NVR, guest domain only reaches the internet, office domain reaches finance."
Scaling means starting over. The day you add a VPN branch, enable IPv6 dual-stack, or split office from production, a single /24 cannot be cut — you tear it down and re-number every deployed device.

The mask decides how many hosts a subnet holds. As a rule of thumb, never fill it:
| Mask | Usable hosts | Fits | Engineering ceiling |
|---|---|---|---|
| /24 | 254 | Single-building office, single service domain | Actually use ≤ 200 |
| /25 | 126 | Camera zone, single weak-current well | ≤ 100 cameras |
| /26 | 62 | Access control, AP management, small IoT domain | ≤ 50 |
Experience: keep subnet utilization under 80% to leave room for growth; cut cameras at "≤ 100 per subnet" to avoid single-domain broadcast overload.
Engineering convention says "one VLAN, one subnet" — make Layer 2 isolation (VLAN) and Layer 3 addressing (subnet / mask) a one-to-one map, so troubleshooting never has the two layers disagreeing:
VLAN 10 = 192.168.10.0/24 (office)
VLAN 20 = 192.168.20.0/24 (surveillance)
VLAN 30 = 192.168.30.0/24 (guest)
The switch uses VLANs for Layer 2 isolation and subnets / masks for Layer 3 addressing. Cross-VLAN traffic must pass through Layer 3 (the core switch or router SVI), and that is exactly where ACLs, rate limits, and auditing attach.
Below is the standard cut for a ~200-person campus. VLAN ID, subnet, use, and gateway all line up — copy it and fill in the blanks:
| VLAN ID | Subnet | Use | Devices | Gateway | Key constraint |
|---|---|---|---|---|---|
| 10 | 192.168.10.0/24 | Office wired | ~150 | 192.168.10.1 | L3 switch SVI |
| 20 | 192.168.20.0/24 | Surveillance IPC | ≤ 100 | 192.168.20.1 | ≤ 100 cams, prevent broadcast |
| 30 | 192.168.30.0/24 | Guest Wi-Fi | dynamic | 192.168.30.1 | ACL denies intranet, internet only |
| 40 | 192.168.40.0/24 | Wireless office | ~80 | 192.168.40.1 | Same policy as VLAN 10 |
| 99 | 192.168.99.0/24 | Device management | switches / OLT | 192.168.99.1 | Independent management domain, no business traffic |
Where the gateway livesMid / large campus: a Layer 3 industrial switch raises an SVI per VLAN as the gateway, forwarding at wire speed so cross-domain traffic does not detour through a router. Rayin industrial switches support Layer 3 routing and VLAN division for exactly this role.
Small scenario: router-on-a-stick can cope, but bandwidth is capped by the uplink port — add cameras and it becomes the bottleneck.
The management VLAN (VLAN 99 in the example) is reserved solely for the switches / OLT themselves, physically isolated from business IPs, so an operations channel is never washed away by a business-traffic storm.
Leave 10–20% headroom per segment; do not chain addresses from .1 straight to .254 with no gap.
Large campuses use discontiguous blocks (e.g. 10.10.x.0) to enable route summarization, so the core only needs a few aggregate routes.
Note: Network segmentation is the structure; the access edge is where it bites. Pair it with port isolation so a device in one VLAN still cannot probe its neighbors, and with 802.1X so only credentialed devices enter at all.
| Item | Anti-pattern (one /24 for all) | Correct (split by function) |
|---|---|---|
| Broadcast domain | Whole company in one /24 | Split by function, /24 ~ /26 |
| VLAN–subnet | Multiple subnets mixed in one VLAN | One VLAN, one subnet |
| Gateway | Cameras and office share a gateway | Each VLAN independent SVI |
| Management address | Mixed with business IP | Independent management VLAN |
How many cameras actually fit in a /24?
Theoretically 254, but engineering practice caps it at ≤ 100 to prevent broadcast overload and limit single-point failure spread.
Must VLAN and subnet be strictly one-to-one?
Not forced, but one-to-one is the clearest and easiest to troubleshoot — it is the recommended convention.
How do I isolate the guest network safely?
An independent VLAN plus an independent subnet, with an ACL that denies access to internal segments and permits only the internet egress.
Is the gateway usually .1?
Convention puts the gateway at .1 or .254; keep it consistent across the whole site. The example uses .1.
The subnet is full — how do I expand?
Prefer adding a new VLAN / subnet so existing addresses stay untouched. As a temporary fix you can widen the mask (/24 → /23) to double space, but that disturbs already-deployed hosts.
Subnet planning is fundamentally "build rooms and set access control." Segment by business function, align VLAN and subnet one-to-one, put the gateway on a Layer 3 switch, and keep the management address independent — then when something breaks you locate a specific room, not a building full of roaming broadcasts. Rayin industrial switches support the Layer 3 routing and VLAN division this design needs; see the Rayin website for more network solutions.
About the author: Sara — Sara is a Customer Manager at Rayin with over 10 years of experience in the communications field. In her free time, she enjoys badminton and swimming.
About Rayin: Shenzhen Rayin Technology Co., Ltd. — Company Profile