Skip to content

VLAN Design

VLAN IDNameSubnetGatewayMTUPurpose
1zrh-default-v110.1.1.0/2410.1.1.11500UniFi Devices
10zrh-mgmt-v1010.10.10.0/2410.10.10.11500Management
20zrh-san-v2010.20.20.0/24-9000Storage (isolated)
30zrh-srv-v3010.30.30.0/2410.30.30.19000Servers
40zrh-clt-v4010.40.40.0/2210.40.40.11500Clients
50zrh-dmz-v5010.50.50.0/2810.50.50.11500DMZ
60zrh-vpn-v6010.60.60.0/2410.60.60.11280VPN
Name: zrh-default-v1
Router: fw-edge-zrh-01
Zone: Internal
VLAN ID: 1
Gateway/Subnet: 10.1.1.1/24
DHCP Mode: DHCP Server
DHCP Range: 10.1.1.100 - 10.1.1.254
Allow Internet Access: Yes
Name: zrh-mgmt-v10
Router: fw-edge-zrh-01
Zone: Internal
VLAN ID: 10
Gateway/Subnet: 10.10.10.1/24
DHCP Mode: None
Domain Name: corp.microsoftlab.ch
Allow Internet Access: Yes
IGMP Snooping: Off
Name: zrh-san-v20
Network Type: VLAN Only (no router!)
VLAN ID: 20
MTU: 9000

Important: VLAN 20 has no gateway - it’s an isolated storage network.

Name: zrh-srv-v30
Router: fw-edge-zrh-01
Zone: Internal
VLAN ID: 30
Gateway/Subnet: 10.30.30.1/24
DHCP Mode: None (DHCP on srv-dc-zrh-01)
Domain Name: corp.microsoftlab.ch
MTU: 9000
Allow Internet Access: No (blocked by firewall)
Name: zrh-clt-v40
Router: fw-edge-zrh-01
Zone: Internal
VLAN ID: 40
Gateway/Subnet: 10.40.40.1/22
DHCP Mode: None (DHCP on srv-dc-zrh-01)
Domain Name: corp.microsoftlab.ch
Allow Internet Access: Yes
Name: zrh-dmz-v50
Router: fw-edge-zrh-01
Zone: DMZ
VLAN ID: 50
Gateway/Subnet: 10.50.50.1/28
DHCP Mode: None
Allow Internet Access: Yes (restricted)
Name: zrh-vpn-v60
Router: fw-edge-zrh-01
Zone: Internal
VLAN ID: 60
Gateway/Subnet: 10.60.60.1/24
DHCP Mode: None (WireGuard assigns IPs)
Allow Internet Access: Yes

All routing is handled by fw-edge-zrh-01 (UniFi Enterprise Fortress Gateway).

From \ ToMGMTSANSRVCLTDMZVPN
MGMT
SAN
SRV
CLT
DMZ
VPN