How should a factory network be redesigned? Segmenting office, production and server networks with VLANs and firewalls
A factory network should not rely only on different IP subnets. Define office, production, server, wireless and management boundaries, then enforce required access with VLANs, routing, firewall policy and ACLs while preserving rollback paths.
1. Start with business boundaries, not hardware
During expansion or office relocation, extending one large subnet is easy but creates long-term problems: broadcast scope, address conflicts, office endpoints reaching production devices directly and server rules that are difficult to tighten. Define office, production, server, wireless, guest and management boundaries first.
2. A practical segmentation model
- Office endpoints stay in office VLANs and reach only required ERP, file, print, directory and internet services.
- Production endpoints use separate VLANs and reach MES/ERP or file services only through required destinations and ports.
- Servers sit in dedicated subnets with policy based on source, destination and service.
- Wireless, guest and infrastructure-management traffic can be further separated as scale requires.
3. Divide responsibilities between the core and firewall
Core switches handle VLANs, routing and simple infrastructure ACLs. Firewalls are better for security-zone boundaries, auditable controls and application-port policy. Avoid duplicating complex rules across multiple devices.
4. Prepare a cutover and rollback checklist
Back up switch, firewall and wireless configuration. Record uplinks, optics, VLANs, trunks, gateways, STP, DHCP, static addresses and critical application ports. Pilot a low-risk area first, then migrate office, production and server access in controlled stages.
5. Validate both allowed and denied paths
Test office-to-server, production-to-application, AD/DNS/DHCP, print, file share, internet and remote administration. Also test traffic that should be blocked. Update topology, VLAN/IP tables, port maps, firewall policy and configuration backups.
Frequently asked questions
Are different IP subnets enough to isolate office and production?
No. Subnets define addressing; routing, firewall policy or ACLs determine whether traffic is actually allowed between them.
Must all inter-VLAN traffic pass through a firewall?
Not always. Use the firewall where security-zone separation and auditability matter most; lower-risk internal VLANs can use Layer-3 switching and ACLs when appropriate.
Need an assessment for your actual environment?
Share the current topology, device models, system versions, symptoms, impact, maintenance windows and available configuration/backup information. We can first assess risk, scope and rollback needs, then define remote, on-site or project work.
