Home Support Blog

Network Segmentation: Plan VLANs and IP Subnets for Campus Networks

Release date:2026-09-14

"Can we just use one 192.168.1.0/24 for the whole company?" That question shows up constantly when an integrator or a small business first pulls cable. The person asking only wants "plug in and ping works" — they have not thought about the cameras turning into a slideshow three months later, a guest phone sniffing the finance PC, or discovering there are no addresses left when a branch VPN needs to be added. Network segmentation — giving each business function its own VLAN and IP subnet — is how you build rooms and install access control instead of leaving one open hall.

KEY TAKEAWAYS
  • One flat /24 saves planning but also removes four safeguards: broadcast control, security boundary, enforceable policy, and room to grow.

  • A /24 holds 254 hosts, but keep real usage under ~80% — size a domain by function, not by "how many addresses exist."

  • "One VLAN, one subnet" keeps Layer 2 isolation and Layer 3 addressing aligned, so faults map to a specific room instead of a building-wide broadcast storm.

  • Put the gateway on a Layer 3 switch SVI, keep a separate management VLAN, and reserve 10–20% headroom per segment.

What goes wrong with one /24 for everything

192.168.1.0/24 gives 254 usable addresses. Dump the whole company in and you skip planning — but you also skip four layers of insurance:

  • Broadcast domain out of control. 254 devices in one Layer 2 domain means ARP, DHCP, and multicast packets flood everywhere. When camera streams climb or APs multiply, broadcast volume can peg the switch CPU and the whole network randomly stutters or occasionally fails to hand out a DHCP address.

  • Security boundary disappears. Office PCs, finance machines, cameras, and guest phones in the same Layer 2 mean ARP spoofing, lateral scanning, and unauthorized access sit behind "a trust that should never have existed." One compromised host can move sideways across the entire network.

  • Policy cannot land. Rate limits, ACLs, and auditing all apply at the "whole segment" grain — you cannot express "camera domain only reaches the NVR, guest domain only reaches the internet, office domain reaches finance."

  • Scaling means starting over. The day you add a VPN branch, enable IPv6 dual-stack, or split office from production, a single /24 cannot be cut — you tear it down and re-number every deployed device.

    image

/24 /25 /26 — how big should one domain be

The mask decides how many hosts a subnet holds. As a rule of thumb, never fill it:

MaskUsable hostsFitsEngineering ceiling
/24254Single-building office, single service domainActually use ≤ 200
/25126Camera zone, single weak-current well≤ 100 cameras
/2662Access control, AP management, small IoT domain≤ 50

Experience: keep subnet utilization under 80% to leave room for growth; cut cameras at "≤ 100 per subnet" to avoid single-domain broadcast overload.

One VLAN, one subnet

Engineering convention says "one VLAN, one subnet" — make Layer 2 isolation (VLAN) and Layer 3 addressing (subnet / mask) a one-to-one map, so troubleshooting never has the two layers disagreeing:

  • VLAN 10 = 192.168.10.0/24 (office)

  • VLAN 20 = 192.168.20.0/24 (surveillance)

  • VLAN 30 = 192.168.30.0/24 (guest)

The switch uses VLANs for Layer 2 isolation and subnets / masks for Layer 3 addressing. Cross-VLAN traffic must pass through Layer 3 (the core switch or router SVI), and that is exactly where ACLs, rate limits, and auditing attach.

Campus planning example

Below is the standard cut for a ~200-person campus. VLAN ID, subnet, use, and gateway all line up — copy it and fill in the blanks:

VLAN IDSubnetUseDevicesGatewayKey constraint
10192.168.10.0/24Office wired~150192.168.10.1L3 switch SVI
20192.168.20.0/24Surveillance IPC≤ 100192.168.20.1≤ 100 cams, prevent broadcast
30192.168.30.0/24Guest Wi-Fidynamic192.168.30.1ACL denies intranet, internet only
40192.168.40.0/24Wireless office~80192.168.40.1Same policy as VLAN 10
99192.168.99.0/24Device managementswitches / OLT192.168.99.1Independent management domain, no business traffic

imageWhere the gateway lives

  • Mid / large campus: a Layer 3 industrial switch raises an SVI per VLAN as the gateway, forwarding at wire speed so cross-domain traffic does not detour through a router. Rayin industrial switches support Layer 3 routing and VLAN division for exactly this role.

  • Small scenario: router-on-a-stick can cope, but bandwidth is capped by the uplink port — add cameras and it becomes the bottleneck.

How to reserve addresses

  • The management VLAN (VLAN 99 in the example) is reserved solely for the switches / OLT themselves, physically isolated from business IPs, so an operations channel is never washed away by a business-traffic storm.

  • Leave 10–20% headroom per segment; do not chain addresses from .1 straight to .254 with no gap.

  • Large campuses use discontiguous blocks (e.g. 10.10.x.0) to enable route summarization, so the core only needs a few aggregate routes.

Note: Network segmentation is the structure; the access edge is where it bites. Pair it with port isolation so a device in one VLAN still cannot probe its neighbors, and with 802.1X so only credentialed devices enter at all.

Anti-pattern vs correct

ItemAnti-pattern (one /24 for all)Correct (split by function)
Broadcast domainWhole company in one /24Split by function, /24 ~ /26
VLAN–subnetMultiple subnets mixed in one VLANOne VLAN, one subnet
GatewayCameras and office share a gatewayEach VLAN independent SVI
Management addressMixed with business IPIndependent management VLAN

FAQ

How many cameras actually fit in a /24?

Theoretically 254, but engineering practice caps it at ≤ 100 to prevent broadcast overload and limit single-point failure spread.

Must VLAN and subnet be strictly one-to-one?

Not forced, but one-to-one is the clearest and easiest to troubleshoot — it is the recommended convention.

How do I isolate the guest network safely?

An independent VLAN plus an independent subnet, with an ACL that denies access to internal segments and permits only the internet egress.

Is the gateway usually .1?

Convention puts the gateway at .1 or .254; keep it consistent across the whole site. The example uses .1.

The subnet is full — how do I expand?

Prefer adding a new VLAN / subnet so existing addresses stay untouched. As a temporary fix you can widen the mask (/24 → /23) to double space, but that disturbs already-deployed hosts.

Conclusion

Subnet planning is fundamentally "build rooms and set access control." Segment by business function, align VLAN and subnet one-to-one, put the gateway on a Layer 3 switch, and keep the management address independent — then when something breaks you locate a specific room, not a building full of roaming broadcasts. Rayin industrial switches support the Layer 3 routing and VLAN division this design needs; see the Rayin website for more network solutions.

Related Reading

About the author: Sara — Sara is a Customer Manager at Rayin with over 10 years of experience in the communications field. In her free time, she enjoys badminton and swimming.

Connect with Sara on LinkedIn


About Rayin: Shenzhen Rayin Technology Co., Ltd. — Company Profile

Get A Quote

You have agreed to this website’s《Privacy Policy》