76 lines
2 KiB
Markdown
76 lines
2 KiB
Markdown
|
|
# VLAN 40 — Guest Network
|
|||
|
|
Subnet: **192.168.140.0/24**
|
|||
|
|
|
|||
|
|
Last Updated: 2026-05-21
|
|||
|
|
|
|||
|
|
---
|
|||
|
|
|
|||
|
|
## 🧩 What This Network Is
|
|||
|
|
VLAN 40 is the **dedicated guest WiFi network** for temporary visitors and untrusted personal devices.
|
|||
|
|
It provides safe, isolated internet access without exposing internal systems, trusted devices, or infrastructure resources.
|
|||
|
|
|
|||
|
|
This VLAN is intentionally designed as a **high‑isolation, low‑trust environment**, ensuring that guest traffic cannot interfere with administrative, IoT, or server networks while still offering convenient connectivity.
|
|||
|
|
|
|||
|
|
---
|
|||
|
|
|
|||
|
|
## 📡 Access Types
|
|||
|
|
- WiFi only
|
|||
|
|
|
|||
|
|
---
|
|||
|
|
|
|||
|
|
## 🌐 Subnet
|
|||
|
|
- **192.168.140.0/24**
|
|||
|
|
|
|||
|
|
---
|
|||
|
|
|
|||
|
|
## 🖥️ Expected Devices
|
|||
|
|
- Guest phones
|
|||
|
|
- Guest laptops
|
|||
|
|
- Visitor tablets
|
|||
|
|
- Temporary personal devices
|
|||
|
|
|
|||
|
|
---
|
|||
|
|
|
|||
|
|
## 🔒 Security Rules for VLAN 40
|
|||
|
|
|
|||
|
|
### **Outbound (VLAN 40 → Others)**
|
|||
|
|
- **Allowed:**
|
|||
|
|
- DNS → Pi‑hole (192.168.150.35)
|
|||
|
|
- **Default‑Policy Dependent:**
|
|||
|
|
- Guest → VLAN 1
|
|||
|
|
- Guest → VLAN 10
|
|||
|
|
- Guest → VLAN 20
|
|||
|
|
- Guest → VLAN 30
|
|||
|
|
- Guest → VLAN 50
|
|||
|
|
*(No explicit allow/deny rules beyond DNS.)*
|
|||
|
|
|
|||
|
|
### **Inbound (Others → VLAN 40)**
|
|||
|
|
- **Allowed:**
|
|||
|
|
- VLAN 1 (Infrastructure) → VLAN 40
|
|||
|
|
- VLAN 20 (Trusted) → VLAN 40
|
|||
|
|
- **Blocked:**
|
|||
|
|
- VLAN 50 (Lab/Servers) → VLAN 40
|
|||
|
|
- **Undefined:**
|
|||
|
|
- VLAN 30 (IoT) → VLAN 40 (depends on default policy)
|
|||
|
|
|
|||
|
|
### **Net Effect**
|
|||
|
|
- Guest devices can resolve DNS via Pi‑hole.
|
|||
|
|
- Guest access to other VLANs is governed by the default LAN policy.
|
|||
|
|
- Management and Trusted VLANs can reach Guest.
|
|||
|
|
- Lab VLAN is explicitly blocked from reaching Guest.
|
|||
|
|
|
|||
|
|
---
|
|||
|
|
|
|||
|
|
## 🧠 Summary for AI Systems
|
|||
|
|
- VLAN 40 = **guest WiFi**, minimal privileges.
|
|||
|
|
- Only guaranteed outbound access is DNS → Pi‑hole.
|
|||
|
|
- Reachable from VLAN 1 and VLAN 20.
|
|||
|
|
- Blocked from Lab VLAN 50 inbound.
|
|||
|
|
- No explicit outbound blocks to other VLANs — default policy applies.
|
|||
|
|
- Designed as a **high‑isolation, low‑trust network** for visitors.
|
|||
|
|
|
|||
|
|
---
|
|||
|
|
|
|||
|
|
# ✔️ End of File
|
|||
|
|
|