75 lines
2 KiB
Markdown
75 lines
2 KiB
Markdown
# VLAN 40 — Guest Network
|
||
Subnet: **192.168.140.0/24**
|
||
|
||
Last Updated: 2026-05-21
|
||
|
||
---
|
||
|
||
## 🧩 What This Network Is
|
||
VLAN 40 is the **dedicated guest WiFi network** for temporary visitors and untrusted personal devices.
|
||
It provides safe, isolated internet access without exposing internal systems, trusted devices, or infrastructure resources.
|
||
|
||
This VLAN is intentionally designed as a **high‑isolation, low‑trust environment**, ensuring that guest traffic cannot interfere with administrative, IoT, or server networks while still offering convenient connectivity.
|
||
|
||
---
|
||
|
||
## 📡 Access Types
|
||
- WiFi only
|
||
|
||
---
|
||
|
||
## 🌐 Subnet
|
||
- **192.168.140.0/24**
|
||
|
||
---
|
||
|
||
## 🖥️ Expected Devices
|
||
- Guest phones
|
||
- Guest laptops
|
||
- Visitor tablets
|
||
- Temporary personal devices
|
||
|
||
---
|
||
|
||
## 🔒 Security Rules for VLAN 40
|
||
|
||
### **Outbound (VLAN 40 → Others)**
|
||
- **Allowed:**
|
||
- DNS → Pi‑hole (192.168.150.35)
|
||
- **Default‑Policy Dependent:**
|
||
- Guest → VLAN 1
|
||
- Guest → VLAN 10
|
||
- Guest → VLAN 20
|
||
- Guest → VLAN 30
|
||
- Guest → VLAN 50
|
||
*(No explicit allow/deny rules beyond DNS.)*
|
||
|
||
### **Inbound (Others → VLAN 40)**
|
||
- **Allowed:**
|
||
- VLAN 1 (Infrastructure) → VLAN 40
|
||
- VLAN 20 (Trusted) → VLAN 40
|
||
- **Blocked:**
|
||
- VLAN 50 (Lab/Servers) → VLAN 40
|
||
- **Undefined:**
|
||
- VLAN 30 (IoT) → VLAN 40 (depends on default policy)
|
||
|
||
### **Net Effect**
|
||
- Guest devices can resolve DNS via Pi‑hole.
|
||
- Guest access to other VLANs is governed by the default LAN policy.
|
||
- Management and Trusted VLANs can reach Guest.
|
||
- Lab VLAN is explicitly blocked from reaching Guest.
|
||
|
||
---
|
||
|
||
## 🧠 Summary for AI Systems
|
||
- VLAN 40 = **guest WiFi**, minimal privileges.
|
||
- Only guaranteed outbound access is DNS → Pi‑hole.
|
||
- Reachable from VLAN 1 and VLAN 20.
|
||
- Blocked from Lab VLAN 50 inbound.
|
||
- No explicit outbound blocks to other VLANs — default policy applies.
|
||
- Designed as a **high‑isolation, low‑trust network** for visitors.
|
||
|
||
---
|
||
|
||
# ✔️ End of File
|
||
|