VLAN Planner
Add your network segments and get a real VLAN plan — VLAN IDs, recommended subnet sizes, and optional CIDR allocations. Calculated in your browser, no account required.
VLAN Planner
Everything below is calculated instantly in your browser as you add segments — nothing is submitted or stored.
IT KORR
VLAN Planner
Build a logical VLAN segmentation plan — calculated entirely in your browser.
| VLAN | Purpose | Hosts | Recommended Subnet | CIDR | Segmentation Notes |
|---|---|---|---|---|---|
| VLAN 10 | Corporate Users | 150 | /24 | 10.0.0.0/24 | Full internal routing — corporate endpoints and servers. |
| VLAN 20 | Servers | 50 | /26 | 10.0.2.0/26 | Full internal routing — corporate endpoints and servers. |
| VLAN 30 | Voice | 80 | /25 | 10.0.1.0/25 | Full internal routing — corporate endpoints and servers. |
| VLAN 40 | Guest Wi-Fi | 100 | /25 | 10.0.1.128/25 | Isolate from internal networks — guest/public segments should reach the internet only, never internal VLANs. |
| VLAN 50 | IoT / Cameras | 40 | /26 | 10.0.2.64/26 | Limited routing — allow only required destinations (e.g. IoT to its controller, management to infrastructure). |
| VLAN 60 | Management | 20 | /27 | 10.0.2.128/27 | Limited routing — allow only required destinations (e.g. IoT to its controller, management to infrastructure). |
This is a logical design starting point — it does not configure switches, deploy VLANs, generate vendor-specific CLI, or guarantee security. Validate trunk/access port assignments, inter-VLAN routing rules, and ACLs against your actual switch and firewall platform before implementation.
What The Inputs Mean
What Shapes Your Generated Plan
Segments and Host Counts
Each segment you add — guest, VoIP, IoT, servers, management, or your own — gets a VLAN ID and a subnet size calculated from its host count.
Trust Classification
Marking a segment Trusted, Restricted, or Untrusted attaches segmentation notes on how it should relate to inter-VLAN routing and access control.
Understanding Your Results
A Logical Design Starting Point
This plan gives you real VLAN ID assignments, calculated subnet sizes, and optional CIDR allocations to start from — it does not configure switches, deploy VLANs, generate vendor-specific CLI, or guarantee security on its own. Your network team still needs to implement trunk/access port assignments, inter-VLAN routing rules, and ACLs on your actual switch and firewall platform.
FAQ
Common Questions
How many VLANs does a typical business network need?
It depends on the traffic types present, but most small-to-midsize environments benefit from at least a corporate data VLAN, a guest VLAN, a voice VLAN if using VoIP, an IoT VLAN, a server VLAN, and a dedicated management VLAN for device administration. This tool tailors the specific segments to your environment.
Is VLAN segmentation the same as a security boundary?
Not by itself. VLANs separate broadcast domains, but the segmentation only becomes a real security boundary once inter-VLAN routing and access control rules are explicitly defined — unrestricted routing between VLANs provides organizational tidiness without meaningfully limiting how far a compromise can spread.
Does this tool generate VLAN IDs and subnet assignments?
Yes. For each segment you add, it assigns a VLAN ID (auto-generated or your own preferred ID, with duplicate and reserved-ID detection) and calculates a recommended subnet size from your host count — optionally including a real CIDR allocation from a parent network you specify. It does not generate a network diagram or vendor-specific switch configuration.
What happens if I request a VLAN ID that's already used or reserved?
The tool flags it immediately — it will not silently overwrite your specified ID or assign a duplicate. Reserved IDs (such as 1, 1002-1005, and 4095) are called out because most switch platforms treat them specially or reserve them by default.
Related Guidance
The full guide behind this tool.
Evaluate your broader network documentation, resilience, and firewall hygiene.
Plan the addressing scheme to pair with your VLAN segments.
Get hands-on help implementing the segmentation plan this tool recommends.
Operational Support
Need help implementing a segmented network?
IT KORR can help you design and deploy the VLAN architecture an audit or insurer expects to see.
No commitment required — we respond within one business day.