Segment the Network Without Extra Hardware
802.1Q VLAN tagging creates isolated broadcast domains for production, guest, and IoT traffic - each with its own firewall policy - on the interfaces you already have.
Anatomy of a VLAN
Six fields describe every segment - create it once and assign interfaces to it as your network grows.
Each VLAN Gets Its Own Policy
Creating a VLAN is only half the job - Firecradle enforces independent firewall rules per segment, so guest and IoT traffic can be walled off from production while inter-VLAN routing between trusted segments stays fully policy-controlled. Group interfaces together so a firewall rule can target an entire VLAN, or a whole client's segment, by name instead of by address.
VLANs on a Bonded Interface
Trunk a VLAN over a bonded pair of physical interfaces - active-backup or 802.3ad/LACP - for link redundancy or added throughput, without changing a single VLAN setting. The VLAN configuration stays identical whether it rides on one NIC or a bonded group of them.
Segment the Easy Way
Splitting a network is normally fiddly work. Firecradle turns the common jobs into one click, and lets you say exactly which devices are allowed in.
Real-World Use Cases
Isolating a Guest Wi-Fi Network
Challenge: A retail office wants to offer guest Wi-Fi without giving visitors any path to internal file shares or point-of-sale systems.
Segmenting an MSP's Multi-Client Traffic
Challenge: An MSP hosts network gear for several small clients on shared infrastructure and needs strict separation between them.