The lease is signed, the movers are booked, and someone just asked whether the "internet box" from the provider will do. Three months later that box is the firewall, the Wi-Fi, the DHCP server and the reason the printer drops off the network every Tuesday. This guide walks through small office network design as a set of decisions, in the order you make them, and ends with a checklist you can hand to whoever does the install.
TL;DR
- Size the internet link for uploads and video, not the headline download number. Plan a second path from day one, even if it is a 5G router in a drawer.
- One firewall at the edge, one managed PoE switch in the rack, ceiling-mounted access points. The provider's modem goes into bridge mode.
- Segment before you plug anything in: staff, guest, printers and IoT, voice, management. Each gets its own VLAN and subnet.
- Pull Cat6A to every desk, every AP and every camera, plus 25% spare ports and a PoE budget with headroom.
- Write down the IP plan, the VLAN table, the rack layout and where the config backups live. An office network nobody can describe is one nobody can fix.
What Network Design Means for a Small Office
Enterprise network design has three layers: a core, a distribution layer and an access layer. A small office collapses that to two. One edge device (the firewall and router) and one or two switches carry everything, with access points hanging off the switch. That simplicity is the point. Every extra device is another thing to patch, back up and explain to the next person.
Design starts with requirements, not hardware. Count the people, then count the devices. A 20-person office rarely has 20 devices: laptops, phones, a printer or two, conference room screens, door controllers, cameras, a couple of smart TVs and the coffee machine that wants Wi-Fi. Write down which applications matter (video calls, a line-of-business app, cloud file sync) and which sites the office needs to reach (a second office, a data center, a cloud tenant). Add a growth number: how many people in three years.
Two more questions shape everything downstream. Does anything stay on-premises (a file server, a phone system, a NAS for camera footage), or is the office a cloud-first shell? And who supports it after the install: an in-house admin, an MSP, or the one person who "knows computers"? The answers decide how much complexity the design can carry. If you need a refresher on the shapes networks take, our guide to network topology covers the physical and logical layouts this post builds on.
A 15-person engineering firm planning for 100 people in three years asked r/sysadmin how to rebuild its network around multi-user CAD files. The replies went to identity, MFA and device management before any hardware, and one pointed to NIST SP 1300, the CSF 2.0 Small Business Quick-Start Guide from February 2024, which is a fair place to start the security column of a requirements list:
Step 1: Size the Internet Link and Plan for Failover
Start with upload. Video calls, cloud backups and file sync are symmetric or upload-heavy, and the cheap business plans are not. The FCC's 2024 broadband benchmark moved to 100 Mbps down and 20 Mbps up on March 14, 2024, up from 25/3, with a long-term goal of 1 Gbps down and 500 Mbps up. Treat 20 Mbps up as the floor for a single user, not an office. A 25-person office with daily calls wants a symmetric fiber circuit or, failing that, the cable plan with the highest upload tier you can get.
Then plan the second path. A single circuit is a single point of failure, and the outage will land during a customer demo. Options, cheapest first: a 5G or LTE router on a separate carrier plugged into the firewall's second WAN port, a second wired provider on a different last mile, or a full SD-WAN box if you have several sites. The failover only counts if it has been tested. Pull the primary cable once a quarter and watch what happens to the phones. If several sites are involved, SD-WAN is the point where the second circuit starts paying for itself.
Put the provider's equipment in bridge mode. Every ISP gateway ships as a router with its own NAT, DHCP and Wi-Fi. Leave that on and you have double NAT, two DHCP servers and a Wi-Fi network nobody manages. Bridge it, or ask for a plain ONT, and let your firewall own the public IP.
Step 2: One Firewall at the Edge
The edge device is the most important purchase in the design, and the one people skimp on. It needs to do four jobs: route between the internet and your VLANs, enforce a stateful firewall policy between segments, terminate remote access, and hold the DHCP and DNS settings for every subnet. Consumer routers do the first job and fake the rest.
Pick a business-class firewall from a vendor that publishes security advisories and ships updates on a schedule. The feature list matters less than the update cadence. Look for: multiple WAN ports for failover, VLAN-aware LAN ports or a trunk to the switch, a policy engine that can say "guest can reach the internet and nothing else", and a management interface that is not exposed to the internet. If you want the mechanics of what that policy engine remembers, our explainer on the stateful firewall covers state tables and what breaks them.
Size it on throughput with inspection turned on, not the number on the box. Vendors quote raw firewall throughput; the figure that matters is the one with intrusion prevention and TLS inspection enabled, which is often a third of the headline. For a 1 Gbps circuit with inspection, that means buying a device rated well above 1 Gbps.
Step 3: Segment Before You Plug Anything In
A flat network is the default and the mistake. When every device shares one subnet, the printer, the CCTV recorder and the CFO's laptop can all talk to each other, which is exactly the path ransomware takes after the first click. CISA's segmentation guidance (January 2023) frames it plainly: divide the network into segments so a problem in one stays in one.
For a small office, five segments cover almost every case. Staff devices. Guest Wi-Fi, which reaches the internet and nothing internal. Printers and IoT, which staff can reach but which cannot start connections outward. Voice, if you run desk phones, so call quality does not compete with a file sync. Management, which holds the switch, AP and firewall admin interfaces and is reachable only from an admin machine. Servers get a sixth if anything stays on-premises.
Each segment is a VLAN on the switch and a subnet on the firewall, and the firewall rules between them are the design. Default deny between segments, then allow the specific flows: staff to printers on the print ports, staff to the file server, everything to DNS. The NSA's Network Infrastructure Security Guide, first published in March 2022, adds the rules that get skipped: put management traffic on its own network, disable unused switch ports, and do not let the guest VLAN see the management VLAN under any circumstances. VLAN tagging, trunk ports and native VLAN traps deserve their own post; for the design, the table of segments and the rules between them is what you need on paper.
Step 4: The IP Plan, DHCP and DNS
Private addresses come from the three ranges in RFC 1918: 10.0.0.0/8, 172.16.0.0/12 and 192.168.0.0/16. Pick one range and stay out of 192.168.0.0/24 and 192.168.1.0/24, because every home router and every hotel network uses them and your VPN users will collide with them. A common scheme: 10.<site>.<vlan>.0/24, so the second site's voice VLAN is 10.2.30.0/24 and anyone can read the address and know where it lives.
A /24 gives 254 addresses per segment, which is more than enough for a small office and leaves room to grow. Within each subnet, reserve the low addresses for infrastructure (gateway at .1, switches and APs in .2 to .20), keep a static block for printers and servers, and hand the rest to DHCP. Use DHCP reservations, not static configuration on the device, for anything that needs a fixed address. When the printer is replaced, you change one reservation instead of hunting for a sticky note.
DNS is where small networks get quietly slow. Point every subnet at the firewall or a local resolver, not straight at the provider, so you can log lookups and block bad ones in one place. A resolver that filters known-malicious domains is the cheapest security control on this list, and our guide to DNS filtering explains how it blocks threats before the browser loads. Set a short lease time on the guest network (a few hours) and a longer one for staff (a day or more), and document both.
Step 5: Cabling, Switches and the PoE Budget
Structured cabling outlives every device it connects, so buy the cable you will want in ten years. Cat6 carries 1 Gbps to 100 meters but only 10 Gbps to 55 meters; Cat6A, defined in ANSI/TIA-568.2-D, carries 10 Gbps the full 100 meters. The cost difference on a small office pull is small next to the labor. Terminate everything on a patch panel in a rack or wall cabinet, label both ends, and run two drops to each desk even if only one is used today.
Count the drops before you count the switch ports. Desks times two, one per access point, one per camera, one per printer, one per conference room screen, one per door controller, then add 25% for the things nobody listed. That number, rounded up to the next switch size, is the switch. A 24-port switch that is full on day one is a 48-port switch that was bought too small.
Power over Ethernet turns the switch into the power supply for phones, cameras and access points, which is why the PoE budget is the number to check. The standards set the ceiling per port: IEEE 802.3af delivers 15.4 W at the port (12.95 W at the device), 802.3at delivers 30 W (25.5 W), and 802.3bt delivers 60 W or 90 W (51 W or 71.3 W at the device). A Wi-Fi 6E or Wi-Fi 7 access point wants 802.3at or better, and a pan-tilt camera can want 802.3bt. Add up the device draws, then check the switch's total PoE budget, which is almost always lower than ports times per-port maximum. Worked at class maximums, a 25-person office with 8 access points on 802.3at (8 x 25.5 W = 204 W), 20 desk phones on 802.3af (20 x 12.95 W = 259 W) and 6 cameras on 802.3at (6 x 25.5 W = 153 W) needs 616 W of budget before headroom, and many 48-port switches ship with less. For the odd device far from the rack, a PoE injector fills the gap without buying a second switch.
Uplinks are the last cabling decision. Between the firewall and the switch, and between switches, use 2.5 Gbps or 10 Gbps ports, or fiber if the run crosses a floor. The desk ports can stay at 1 Gbps; the trunk that carries all of them cannot.
Step 6: Wi-Fi Design
Wi-Fi in a small office fails in three ways: too few access points, access points in the wrong place, and a consumer mesh system doing a job it was not built for. Fix placement first. Access points go on the ceiling, in open space, roughly one per 1,000 to 1,500 square feet of open office, closer together where walls are concrete or the room is dense with people. Corners and cupboards are where APs go to die.
Plan for the 5 GHz and 6 GHz bands and treat 2.4 GHz as the legacy band for printers and IoT. Wi-Fi 7, certified by the Wi-Fi Alliance from 2024, adds 320 MHz channels in 6 GHz and Multi-Link Operation, according to the Wi-Fi Alliance. In a small office, the practical win is less about peak speed and more about cleaner channels: 6 GHz has no legacy clients on it yet. Keep channel widths modest (40 MHz on 5 GHz in dense buildings) so neighboring APs do not step on each other.
Map SSIDs to VLANs. One staff SSID on the staff VLAN, one guest SSID on the guest VLAN with client isolation on, one IoT SSID on 2.4 GHz for the devices that cannot do better. Use WPA3 where every client supports it and WPA2/WPA3 transition mode where they do not, and put staff on 802.1X with per-user credentials if you run an identity provider. The difference between the modes is covered in our post on what WPA2 is and why offices outgrow it. Guest passwords rotate; staff credentials are revoked when the person leaves.
Willie Howe's small office build series starts where this post does, with the gear list and the subnet plan, if you want to see the decisions made on screen:
Step 7: Redundancy and Power
Redundancy in a small office is not two of everything. It is knowing which failure stops work and buying protection for that one. The internet circuit stops work, so it gets a second path (Step 1). The edge firewall stops work, so it gets a configuration backup that is tested by restoring it to a spare, or a vendor with a next-day replacement. The core switch stops work, so keep a cold spare on the shelf if the office cannot tolerate a day offline, or accept the day and write it down as a decision.
Power is the redundancy people forget. Put the firewall, switch and provider equipment on a UPS sized for at least 15 minutes of runtime, enough to ride out a flicker and shut down cleanly through a longer cut. Because the switch powers the phones and the access points, one UPS on the rack keeps the whole network up through the blip. Set the UPS to alert when it goes to battery. A UPS that dies silently after three years is a surprise outage with extra steps.
One r/sysadmin poster laid out a three-ISP, VLAN-heavy design for a small office and asked whether it was too much. The thread's answer was a clear yes, and it is a good calibration for where the line sits:
Step 8: Remote Access Without Holes
Nothing in the office should be reachable from the internet by port. No RDP on 3389, no camera recorder on 8080, no "temporary" forward for the accounting app. Every one of those is a door with the key under the mat, and the reasons are laid out in our post on port forwarding and when to skip it.
Remote users come in through a VPN terminated on the firewall or a zero-trust access service, with multi-factor authentication on the account. Give the VPN its own subnet and treat it as another segment in the firewall rules: remote staff reach what office staff reach, and nothing more. If the office is cloud-first, most people will not need the VPN at all, which is the cleanest outcome. Our playbook for remote workers covers the support side once the access is in place.
Step 9: Monitoring and Documentation
A network you cannot see is a network you troubleshoot by rebooting. Turn on SNMP or the vendor's cloud telemetry on the switch, the firewall and the access points, and send it to something that alerts. The four alerts that matter in a small office: the WAN link went down, the WAN failed over to the backup, a switch port is flapping, and an AP dropped off. Bandwidth graphs per VLAN tell you when the guest network is eating the uplink. Our guide to infrastructure monitoring covers which tools fit and what to watch.
Documentation is the step every design skips and every successor curses. The minimum set: a one-page diagram, the VLAN and subnet table, the rack layout with port assignments, the DHCP reservations, the admin credentials in a password manager, and the location of config backups. A network mapping tool can draw the diagram from discovery, but the VLAN table and the "why" behind each rule still need a human to write them. OpenFrame's device inventory, plus a script run across a client's devices with the output collected, fills in the per-machine IP, gateway and DNS columns without a site visit.
Back up the firewall and switch configurations after every change and keep two copies, one off-site. Version them. The question "what changed last Thursday" has a fast answer when the answer is a diff.
The Small Office Network Design Checklist
Print this, tick it during the design review, and tick it again during the install. Each line is a decision with a place to write the answer.
| Area | Check | Written down? |
|---|---|---|
| Requirements | Headcount now and in three years, device count per person, on-premises vs cloud-first | |
| Requirements | Applications that need priority (voice, video, line-of-business) | |
| Internet | Upload speed sized for calls and sync, not just download | |
| Internet | Second WAN path chosen (5G, second carrier or SD-WAN) and tested | |
| Internet | Provider equipment in bridge mode; firewall owns the public IP | |
| Edge | Business firewall with published advisories and multi-WAN; sized on throughput with inspection on | |
| Edge | Management interface not exposed to the internet; admin MFA on | |
| Segmentation | VLANs defined: staff, guest, printers/IoT, voice, management (servers if on-prem) | |
| Segmentation | Default deny between VLANs; allowed flows listed per pair | |
| Segmentation | Guest isolated from everything internal, client isolation on | |
| Addressing | One RFC 1918 range, one /24 per VLAN, scheme documented | |
| Addressing | Reserved infrastructure block, DHCP reservations for printers and servers | |
| DNS | Local resolver with filtering; every subnet points at it | |
| Cabling | Cat6A to every desk (two drops), AP, camera and printer; patch panel; labels both ends | |
| Switching | Port count = drops + 25% spare; managed, VLAN-capable | |
| Switching | PoE budget calculated from device draws with headroom; 802.3at or bt where APs need it | |
| Switching | 2.5G or 10G uplinks between firewall and switch, and between switches | |
| Wi-Fi | AP count from floor area and walls; ceiling mounted; channel plan set | |
| Wi-Fi | SSIDs mapped to VLANs; WPA3 or transition mode; 802.1X for staff if possible | |
| Redundancy | Firewall config backup restored to a spare or replacement plan agreed | |
| Redundancy | UPS on rack and edge, 15 minutes minimum, battery alerts on | |
| Remote access | Zero inbound port forwards; VPN or zero-trust access with MFA on its own segment | |
| Monitoring | SNMP or telemetry from firewall, switch, APs; alerts for WAN down, failover, port flap, AP offline | |
| Documentation | Diagram, VLAN and subnet table, rack layout, reservations, credentials in a password manager | |
| Documentation | Config backups after every change, versioned, one copy off-site |
Five Mistakes That Show Up a Year Later
The provider's gateway is still the firewall. It was meant to be temporary. Now it is the single device holding the public IP, the Wi-Fi and the DHCP scope, and nobody has the admin password.
Everything is on one subnet. The design "worked" until the first infected laptop found the file server, the recorder and the printer in one scan. Segmentation is easier on an empty network than a busy one, which is why it is Step 3 and not Step 9.
The switch is full. The 24-port switch had four free ports on install day. Two went to a new hire, one to a second screen, one to a desk fan with an Ethernet port. Now a $30 unmanaged switch under someone's desk carries half of accounting, and it is not on any diagram.
Wi-Fi was a mesh kit from a big-box store. It was fine for six people. At 20, the backhaul is saturated and the "pro" management app has one setting, which is Off.
The person who built it left. Nothing was written down, the config backups are on their old laptop, and the new MSP starts by mapping the network from scratch. Documentation costs an afternoon. Rediscovery costs a week and the trust of the office.
What to Take From This
Small office network design is nine decisions made in order: internet and failover, the edge firewall, segmentation, addressing and DNS, cabling and PoE, Wi-Fi, redundancy and power, remote access, and monitoring and documentation. Make them on paper before the hardware arrives, and the install becomes a checklist instead of a series of surprises.
Two follow-on reads: our guide to smart office requirements covers what to ask a provider before signing, and the post on network mapping software shows how discovery fills in the diagram once the network is live.

Aliaska Varieva
Head of Platform
Hi! I’m Aliaska, and I’ve been working as a software engineer (mostly Java + a bit Kotlin) for over 8 years now. I mostly spend my time building backend services, integrating systems, fixing bugs (the fun part 🙃), and making sure things don’t fall apart behind the scenes.
