Network segmentation in a small company: how many VLANs is too many
A single flat network is simple until the first incident. Five segments are enough for most organisations, provided that policy stands between them and not just a VLAN number.
The network is the layer everything else stands on, and yet it is usually designed once and not revisited for years. I write about segmentation that limits the impact of an incident, about DNS as a single point of failure, about firewalls between segments, and about link redundancy in organisations that have no dedicated network team.
A single flat network is simple until the first incident. Five segments are enough for most organisations, provided that policy stands between them and not just a VLAN number.
The ticket says „the network is down”, and the network is fine. Name resolution is not. Where DNS hides single points of failure, and how to design it so that the failure of one element goes unnoticed.
The second link is often bought, plugged in and never tested. How to design the switchover so that it works on the day of the outage, and what will not switch by itself even with a perfect configuration.
Older applications, printers and scripts send mail to port 25 with no encryption and no authentication. A cloud mail service will not accept that. One internal relay solves the problem better than twenty exceptions.