Skip to main content
VLAN & Network Segmentation

Segment the Network Without Extra Hardware

802.1Q VLAN tagging creates isolated broadcast domains for production, guest, and IoT traffic - each with its own firewall policy - on the interfaces you already have.

๐Ÿงฉ 802.1Q tagging ยท per-VLAN firewall policy ยท guest isolation

Anatomy of a VLAN

Six fields describe every segment - create it once and assign interfaces to it as your network grows.

VLAN ID
802.1Q tag (1-4094) that identifies the segment on the wire - assign it once and every trunked switch downstream honors it.
Name & Description
Label each VLAN by purpose - Management, Production, Guest, IoT - so policy stays readable months later.
Parent Interface
Bind the VLAN to a physical port or a bonded pair (e.g. eth0.100) - no dedicated NIC required per segment.
IP Address & Netmask
Give the VLAN its own subnet, gateway, and DHCP scope, independent of every other segment on the appliance.
Isolation
Decide whether the segment can reach other VLANs at all, or whether it is walled off from the rest of the network by default.
Enable / Disable
Bring a VLAN up or down without deleting its configuration - useful for staged rollouts.

Each VLAN Gets Its Own Policy

Creating a VLAN is only half the job - Firecradle enforces independent firewall rules per segment, so guest and IoT traffic can be walled off from production while inter-VLAN routing between trusted segments stays fully policy-controlled. Group interfaces together so a firewall rule can target an entire VLAN, or a whole client's segment, by name instead of by address.

VLAN ID
Name
Interface
Subnet
Isolated
10
Management
eth0.10
10.10.0.0/24
No
20
Production
eth0.20
10.20.0.0/24
No
30
Guest
eth0.30
10.30.0.0/24
Yes
40
IoT
eth0.40
10.40.0.0/24
Yes

VLANs on a Bonded Interface

Trunk a VLAN over a bonded pair of physical interfaces - active-backup or 802.3ad/LACP - for link redundancy or added throughput, without changing a single VLAN setting. The VLAN configuration stays identical whether it rides on one NIC or a bonded group of them.

Segment the Easy Way

Splitting a network is normally fiddly work. Firecradle turns the common jobs into one click, and lets you say exactly which devices are allowed in.

Smart-device isolation
One click puts smart cameras, TVs, and plugs on their own segment. A hacked gadget cannot reach your laptop or your files.
Guest network in one click
Sets up a guest VLAN, the sign-in page, and a bandwidth cap in a single step, all walled off from your real network.
Device allow-list
Only devices you approve can join a segment. New or unknown gear is turned away at the door.

Real-World Use Cases

Isolating a Guest Wi-Fi Network

Challenge: A retail office wants to offer guest Wi-Fi without giving visitors any path to internal file shares or point-of-sale systems.

How it's handled:
โœ…Guest traffic placed on its own VLAN with a dedicated subnet
โœ…Firewall policy blocks the guest VLAN from reaching production subnets
โœ…Internet access still permitted for guests on the same segment
โœ…Production VLAN policy untouched - no shared broadcast domain risk

Segmenting an MSP's Multi-Client Traffic

Challenge: An MSP hosts network gear for several small clients on shared infrastructure and needs strict separation between them.

How it's handled:
โœ…Each client assigned a dedicated VLAN with its own firewall policy
โœ…Interface groups let the MSP target rules at a client's VLAN by name
โœ…One client's misconfiguration cannot expose another client's subnet
โœ…All VLANs managed from a single centralized dashboard

Key Advantages

โœ…No extra hardware: multiple isolated segments on the interfaces you already have
โœ…Per-VLAN firewall policy: guest, IoT, and production traffic each get independent rules
โœ…Guest isolation template ready out of the box
โœ…Interface groups let rules target a whole VLAN or client segment by name
โœ…Works over bonded interfaces for redundancy or added throughput

Isolate Traffic Without Buying More Hardware

802.1Q VLAN segmentation with per-VLAN firewall policy included in every Firecradle appliance.

No credit card required ยท Cancel anytime ยท 30-day free trial