# VLAN 40 — Guest Network Subnet: **192.168.140.0/24** Last Updated: 2026-05-21 --- ## 🧩 What This Network Is VLAN 40 is the **dedicated guest WiFi network** for temporary visitors and untrusted personal devices. It provides safe, isolated internet access without exposing internal systems, trusted devices, or infrastructure resources. This VLAN is intentionally designed as a **high‑isolation, low‑trust environment**, ensuring that guest traffic cannot interfere with administrative, IoT, or server networks while still offering convenient connectivity. --- ## 📡 Access Types - WiFi only --- ## 🌐 Subnet - **192.168.140.0/24** --- ## 🖥️ Expected Devices - Guest phones - Guest laptops - Visitor tablets - Temporary personal devices --- ## 🔒 Security Rules for VLAN 40 ### **Outbound (VLAN 40 → Others)** - **Allowed:** - DNS → Pi‑hole (192.168.150.35) - **Default‑Policy Dependent:** - Guest → VLAN 1 - Guest → VLAN 10 - Guest → VLAN 20 - Guest → VLAN 30 - Guest → VLAN 50 *(No explicit allow/deny rules beyond DNS.)* ### **Inbound (Others → VLAN 40)** - **Allowed:** - VLAN 1 (Infrastructure) → VLAN 40 - VLAN 20 (Trusted) → VLAN 40 - **Blocked:** - VLAN 50 (Lab/Servers) → VLAN 40 - **Undefined:** - VLAN 30 (IoT) → VLAN 40 (depends on default policy) ### **Net Effect** - Guest devices can resolve DNS via Pi‑hole. - Guest access to other VLANs is governed by the default LAN policy. - Management and Trusted VLANs can reach Guest. - Lab VLAN is explicitly blocked from reaching Guest. --- ## 🧠 Summary for AI Systems - VLAN 40 = **guest WiFi**, minimal privileges. - Only guaranteed outbound access is DNS → Pi‑hole. - Reachable from VLAN 1 and VLAN 20. - Blocked from Lab VLAN 50 inbound. - No explicit outbound blocks to other VLANs — default policy applies. - Designed as a **high‑isolation, low‑trust network** for visitors. --- # ✔️ End of File