Key takeaways

  • Network design should reflect the number of users, the building, applications and availability requirements.
  • Wired connections provide predictability and Wi-Fi provides mobility — both segments should form part of one plan.
  • The guest network, IoT devices and critical systems should be logically separated.
  • WPA3 or properly configured WPA2-Enterprise do not replace segmentation, updates and access control.
  • Good monitoring reveals not only a loss of internet connectivity, but also congestion, errors and coverage problems.

Why does the network matter?

Wi-Fi problems often look like application failures: video conferences cut out, files copy slowly and the ERP system responds with a delay. Without a coverage map, load information and documentation, it is difficult to tell whether the problem lies with the connection, firewall, switch, radio interference or the application itself.

The network is also a security boundary. Guest devices, cameras, printers and IoT should not have the same access as servers and employees' computers.

What components make up a network?

Cabling and switches

Cabling, patch panels and switches create a stable wired layer. PoE can power access points and telephones through a single cable.

Router and firewall

The firewall controls traffic between the internet, VLANs and remote access. It should be kept up to date, with its configuration backed up and its status monitored.

Access points

The placement of Wi-Fi access points should follow from measurements and the building's construction, not merely the number of rooms.

Controller and monitoring

Central management simplifies updates, roaming, channel analysis and congestion detection.

How should you assess the current situation?

  • Is there an up-to-date diagram of connections, VLANs and addressing?
  • Do we know the number of devices and their bandwidth requirements?
  • Does the Wi-Fi have dead zones, interference or overloaded access points?
  • Is the guest network separated from business resources?
  • Do cameras, printers and IoT have a separate segment?
  • Is device administration protected by MFA and restricted from the internet?
  • Are router and switch configurations backed up?
  • Do we know how the business operates after a connection failure?

VLANs and separate Wi-Fi for guests

A VLAN logically separates traffic on shared infrastructure. An example design may include networks for employees, servers, guests, voice devices, cameras and management. A VLAN alone is not a complete safeguard, however — firewall rules must define which traffic is permitted.

Guests should receive a separate SSID with internet-only access. It is worth limiting speed, the number of connections and the duration of access, but excessive restrictions should not impede work without first checking the actual requirements.

VPN and secure remote working

A VPN creates an encrypted connection between a user and the business, or links entire locations. Remote access should be limited to required resources, protected by MFA and monitored. A site-to-site VPN suits permanent connections between branches, while users working from home require separate policies and accounts.

A VPN does not replace device controls or secure application configuration. Before implementation, establish who needs access, to what, and how it will be revoked after a role change.

How do you secure the network?

  • Use WPA3 or, where that is not possible, properly configured WPA2-Enterprise.
  • Separate employee, guest, camera and IoT networks.
  • Keep the firewall, switches, access points and controller up to date.
  • Restrict administrative access and do not expose management panels unnecessarily.
  • Enable logging and alerts, and back up configurations.
  • Establish a backup connection or a procedure for operating after a failure.

Common mistakes

Designing Wi-Fi without measurements

The number of access points does not guarantee coverage. Walls, interference and user density require testing in the actual building.

One network for everything

Computers, guests, cameras and IoT devices in one segment increase the consequences of any device being compromised.

No documentation

Without descriptions of ports, VLANs and addressing, every failure lasts longer and expansion carries greater risk.

What determines the cost?

Cost is affected by the building's area and layout, the number of users, required coverage, existing cabling, the number of access points, PoE switches, the firewall, a backup connection, monitoring and the number of locations. Future updates, controller licences, servicing and the time required for diagnosis should also be included.

Step-by-step action plan

  1. Gather requirements. List users, devices, applications, locations and critical services.
  2. Inspect the building. Map cabling, obstacles, interference and installation points.
  3. Design the segmentation. Define VLANs, addressing and traffic-flow rules between them.
  4. Select equipment. Account for bandwidth, PoE, redundancy, management and expansion potential.
  5. Run a pilot. Test coverage, roaming, load, the VPN and guest network.
  6. Document the environment. Record the diagram, configuration, administrative access and failure procedure.

Checklist

  • We know the number of users and devices.
  • The network has an up-to-date diagram and addressing plan.
  • Wi-Fi has been tested throughout the building.
  • Guests are separated from business resources.
  • Cameras and IoT have restricted access.
  • Device administration is protected.
  • Configurations are backed up.
  • There is a plan for operating after an internet failure.

What can the business do itself?

You can start by listing devices, photographing the current cabling, recording users' problems and checking who has administrative access. It is also worth verifying and separating the guest network and preparing a configuration backup before making changes.

When is specialist support needed?

Support is useful when designing Wi-Fi for a larger area, changing addressing and VLANs, linking branches, implementing a VPN, migrating firewalls and whenever a network failure brings the business to a halt.

Frequently asked questions

Do I need separate Wi-Fi for guests?

Yes, if people from outside the business use the network. A separate SSID and VLAN restrict access to computers, servers and printers.

Does a VLAN make sense in a small business?

Yes. Even a simple division between employees, guests and auxiliary devices organises traffic and limits the consequences of an incident.

Does a VPN always slow down the connection?

A VPN may reduce bandwidth, but the impact depends on the connection, hardware, encryption and load. A well-chosen configuration remains sufficient for most offices.

Do more Wi-Fi access points always mean better coverage?

No. Too many access points can increase interference. Placement should follow from measurements and planned load.

Is WPA3 sufficient to secure a network?

No. Segmentation, updates, restricted administration, monitoring and appropriate access policies are also required.

Related service

Do you need to design, organise or secure your business network?

Explore network design and modernisation

Read also

Business server roomsPower, cabling, cooling and backups.Essential IT securityBusiness accounts, devices and data.IT infrastructure monitoringAlerts and responding to problems.