How should a factory network be redesigned? Segmenting office, production and server networks with VLANs and firewalls
A factory network should not rely only on different IP subnets. Define office, production, server, wireless and management boundaries, then enforce required access with VLANs, routing, firewall policy and ACLs while preserving rollback paths.
A factory network should not rely only on different IP subnets. For this case, first verify office, production, server and management network boundaries and VLAN and Layer-3 gateway placement, then use least-privilege firewall access between zones to decide whether remediation is needed.
Define the target state
For this network and security-boundary case, establish the failure boundary with office, production, server and management network boundaries and VLAN, then continue to least-privilege firewall access between zones. Capture the current state, incident time and one known-good comparison before changing production configuration.
Boundaries to confirm before design
| Check | Why it matters | Recommended action |
|---|---|---|
| 01 · office, production, server and management network boundaries | Verify office, production, server and management network boundaries on the affected path using logs, counters or state information rather than relying only on the configured rule. | Record the current value, evidence source and timestamp for office, production, server and management network boundaries. If adjustment is required, change one condition only and retain the original setting for rollback. |
| 02 · VLAN and Layer-3 gateway placement | Verify VLAN and Layer-3 gateway placement on the affected path using logs, counters or state information rather than relying only on the configured rule. | Check VLAN and Layer-3 gateway placement read-only and save the result. If it differs from the baseline, correlate it with the incident time and recent changes before remediation. |
| 03 · least-privilege firewall access between zones | Verify least-privilege firewall access between zones on the affected path using logs, counters or state information rather than relying only on the configured rule. | Compare least-privilege firewall access between zones with a known-good peer, the log timeline and the real application path; confirm whether it is causal before changing production. |
| 04 · switch ACL responsibility boundary | Review the current state, related logs and recent changes for switch ACL responsibility boundary, then align them with the incident timeline before deciding whether a change is required. | Record the current value, evidence source and timestamp for switch ACL responsibility boundary. If adjustment is required, change one condition only and retain the original setting for rollback. |
| 05 · administrative entry points and jump-host path | Review the current state, related logs and recent changes for administrative entry points and jump-host path, then align them with the incident timeline before deciding whether a change is required. | Check administrative entry points and jump-host path read-only and save the result. If it differs from the baseline, correlate it with the incident time and recent changes before remediation. |
| 06 · failure rollback and temporary-access process | Review the current state, related logs and recent changes for failure rollback and temporary-access process, then align them with the incident timeline before deciding whether a change is required. | Compare failure rollback and temporary-access process with a known-good peer, the log timeline and the real application path; confirm whether it is causal before changing production. |
Recommended implementation controls
- Start with read-only evidence. Check office, production, server and management network boundaries and VLAN and Layer-3 gateway placement before changing configuration.
- If the first checks are normal, continue with least-privilege firewall access between zones and switch ACL responsibility boundary, keeping evidence tied to the incident time.
- Change configuration only when the evidence explains the symptom. For administrative entry points and jump-host path, preserve the original value and define the rollback trigger before adjustment.
- Validate failure rollback and temporary-access process in a controlled scope before expanding to production users or traffic.
Phased implementation
- Validate the complete user or application workflow; do not stop at the single status of office, production, server and management network boundaries.
- Recheck administrative entry points and jump-host path and failure rollback and temporary-access process after the change and confirm that no new bypass, permission expansion or secondary error has appeared.
- Archive evidence from office, production, server and management network boundaries through failure rollback and temporary-access process, together with before/after configuration, business validation and the rollback point.
Acceptance criteria
- Changing office, production, server and management network boundaries and VLAN at the same time, which makes the original cause impossible to prove.
- Treating a normal result for least-privilege firewall access between zones as proof that ACL and the rest of the business path are healthy.
- Leaving a temporary exception related to administrative entry points and jump-host path or failure rollback and temporary-access process in production without an owner, expiry time and rollback note.
Related questions
Where should I start with “How should a factory network be redesigned? Segmenting office, production and server networks with VLANs and firewalls”?
Start with office, production, server and management network boundaries and VLAN and Layer-3 gateway placement; they establish the first useful troubleshooting boundary without changing production state.
What should be checked after the first layer looks normal?
Continue with least-privilege firewall access between zones and switch ACL responsibility boundary, then correlate the result with the incident time and the actual user or application path.
What should be retained after the change?
Keep evidence for administrative entry points and jump-host path and failure rollback and temporary-access process, plus the original configuration, validation result, observation notes and rollback point.
Need an assessment for your actual environment?
Share the current topology, device models, system versions, symptoms, impact, maintenance windows and available configuration/backup information. We can first assess risk, scope and rollback needs, then define remote, on-site or project work.
