Flamingo Raises $4.5M Seed Round

Skip to content

The lease is signed, the movers are booked, and someone just asked whether the "internet box" from the provider will do. Three months later that box is the firewall, the Wi-Fi, the DHCP server and the reason the printer drops off the network every Tuesday. This guide walks through small office network design as a set of decisions, in the order you make them, and ends with a checklist you can hand to whoever does the install.

TL;DR

  • Size the internet link for uploads and video, not the headline download number. Plan a second path from day one, even if it is a 5G router in a drawer.
  • One firewall at the edge, one managed PoE switch in the rack, ceiling-mounted access points. The provider's modem goes into bridge mode.
  • Segment before you plug anything in: staff, guest, printers and IoT, voice, management. Each gets its own VLAN and subnet.
  • Pull Cat6A to every desk, every AP and every camera, plus 25% spare ports and a PoE budget with headroom.
  • Write down the IP plan, the VLAN table, the rack layout and where the config backups live. An office network nobody can describe is one nobody can fix.

What Network Design Means for a Small Office

Enterprise network design has three layers: a core, a distribution layer and an access layer. A small office collapses that to two. One edge device (the firewall and router) and one or two switches carry everything, with access points hanging off the switch. That simplicity is the point. Every extra device is another thing to patch, back up and explain to the next person.

Design starts with requirements, not hardware. Count the people, then count the devices. A 20-person office rarely has 20 devices: laptops, phones, a printer or two, conference room screens, door controllers, cameras, a couple of smart TVs and the coffee machine that wants Wi-Fi. Write down which applications matter (video calls, a line-of-business app, cloud file sync) and which sites the office needs to reach (a second office, a data center, a cloud tenant). Add a growth number: how many people in three years.

Two more questions shape everything downstream. Does anything stay on-premises (a file server, a phone system, a NAS for camera footage), or is the office a cloud-first shell? And who supports it after the install: an in-house admin, an MSP, or the one person who "knows computers"? The answers decide how much complexity the design can carry. If you need a refresher on the shapes networks take, our guide to network topology covers the physical and logical layouts this post builds on.

A 15-person engineering firm planning for 100 people in three years asked r/sysadmin how to rebuild its network around multi-user CAD files. The replies went to identity, MFA and device management before any hardware, and one pointed to NIST SP 1300, the CSF 2.0 Small Business Quick-Start Guide from February 2024, which is a fair place to start the security column of a requirements list:

Start with upload. Video calls, cloud backups and file sync are symmetric or upload-heavy, and the cheap business plans are not. The FCC's 2024 broadband benchmark moved to 100 Mbps down and 20 Mbps up on March 14, 2024, up from 25/3, with a long-term goal of 1 Gbps down and 500 Mbps up. Treat 20 Mbps up as the floor for a single user, not an office. A 25-person office with daily calls wants a symmetric fiber circuit or, failing that, the cable plan with the highest upload tier you can get.

Then plan the second path. A single circuit is a single point of failure, and the outage will land during a customer demo. Options, cheapest first: a 5G or LTE router on a separate carrier plugged into the firewall's second WAN port, a second wired provider on a different last mile, or a full SD-WAN box if you have several sites. The failover only counts if it has been tested. Pull the primary cable once a quarter and watch what happens to the phones. If several sites are involved, SD-WAN is the point where the second circuit starts paying for itself.

Put the provider's equipment in bridge mode. Every ISP gateway ships as a router with its own NAT, DHCP and Wi-Fi. Leave that on and you have double NAT, two DHCP servers and a Wi-Fi network nobody manages. Bridge it, or ask for a plain ONT, and let your firewall own the public IP.

Step 2: One Firewall at the Edge

The edge device is the most important purchase in the design, and the one people skimp on. It needs to do four jobs: route between the internet and your VLANs, enforce a stateful firewall policy between segments, terminate remote access, and hold the DHCP and DNS settings for every subnet. Consumer routers do the first job and fake the rest.

Pick a business-class firewall from a vendor that publishes security advisories and ships updates on a schedule. The feature list matters less than the update cadence. Look for: multiple WAN ports for failover, VLAN-aware LAN ports or a trunk to the switch, a policy engine that can say "guest can reach the internet and nothing else", and a management interface that is not exposed to the internet. If you want the mechanics of what that policy engine remembers, our explainer on the stateful firewall covers state tables and what breaks them.

Size it on throughput with inspection turned on, not the number on the box. Vendors quote raw firewall throughput; the figure that matters is the one with intrusion prevention and TLS inspection enabled, which is often a third of the headline. For a 1 Gbps circuit with inspection, that means buying a device rated well above 1 Gbps.

Step 3: Segment Before You Plug Anything In

A flat network is the default and the mistake. When every device shares one subnet, the printer, the CCTV recorder and the CFO's laptop can all talk to each other, which is exactly the path ransomware takes after the first click. CISA's segmentation guidance (January 2023) frames it plainly: divide the network into segments so a problem in one stays in one.

For a small office, five segments cover almost every case. Staff devices. Guest Wi-Fi, which reaches the internet and nothing internal. Printers and IoT, which staff can reach but which cannot start connections outward. Voice, if you run desk phones, so call quality does not compete with a file sync. Management, which holds the switch, AP and firewall admin interfaces and is reachable only from an admin machine. Servers get a sixth if anything stays on-premises.

Each segment is a VLAN on the switch and a subnet on the firewall, and the firewall rules between them are the design. Default deny between segments, then allow the specific flows: staff to printers on the print ports, staff to the file server, everything to DNS. The NSA's Network Infrastructure Security Guide, first published in March 2022, adds the rules that get skipped: put management traffic on its own network, disable unused switch ports, and do not let the guest VLAN see the management VLAN under any circumstances. VLAN tagging, trunk ports and native VLAN traps deserve their own post; for the design, the table of segments and the rules between them is what you need on paper.

Step 4: The IP Plan, DHCP and DNS

Private addresses come from the three ranges in RFC 1918: 10.0.0.0/8, 172.16.0.0/12 and 192.168.0.0/16. Pick one range and stay out of 192.168.0.0/24 and 192.168.1.0/24, because every home router and every hotel network uses them and your VPN users will collide with them. A common scheme: 10.<site>.<vlan>.0/24, so the second site's voice VLAN is 10.2.30.0/24 and anyone can read the address and know where it lives.

A /24 gives 254 addresses per segment, which is more than enough for a small office and leaves room to grow. Within each subnet, reserve the low addresses for infrastructure (gateway at .1, switches and APs in .2 to .20), keep a static block for printers and servers, and hand the rest to DHCP. Use DHCP reservations, not static configuration on the device, for anything that needs a fixed address. When the printer is replaced, you change one reservation instead of hunting for a sticky note.

DNS is where small networks get quietly slow. Point every subnet at the firewall or a local resolver, not straight at the provider, so you can log lookups and block bad ones in one place. A resolver that filters known-malicious domains is the cheapest security control on this list, and our guide to DNS filtering explains how it blocks threats before the browser loads. Set a short lease time on the guest network (a few hours) and a longer one for staff (a day or more), and document both.

Step 5: Cabling, Switches and the PoE Budget

Structured cabling outlives every device it connects, so buy the cable you will want in ten years. Cat6 carries 1 Gbps to 100 meters but only 10 Gbps to 55 meters; Cat6A, defined in ANSI/TIA-568.2-D, carries 10 Gbps the full 100 meters. The cost difference on a small office pull is small next to the labor. Terminate everything on a patch panel in a rack or wall cabinet, label both ends, and run two drops to each desk even if only one is used today.

Count the drops before you count the switch ports. Desks times two, one per access point, one per camera, one per printer, one per conference room screen, one per door controller, then add 25% for the things nobody listed. That number, rounded up to the next switch size, is the switch. A 24-port switch that is full on day one is a 48-port switch that was bought too small.

Power over Ethernet turns the switch into the power supply for phones, cameras and access points, which is why the PoE budget is the number to check. The standards set the ceiling per port: IEEE 802.3af delivers 15.4 W at the port (12.95 W at the device), 802.3at delivers 30 W (25.5 W), and 802.3bt delivers 60 W or 90 W (51 W or 71.3 W at the device). A Wi-Fi 6E or Wi-Fi 7 access point wants 802.3at or better, and a pan-tilt camera can want 802.3bt. Add up the device draws, then check the switch's total PoE budget, which is almost always lower than ports times per-port maximum. Worked at class maximums, a 25-person office with 8 access points on 802.3at (8 x 25.5 W = 204 W), 20 desk phones on 802.3af (20 x 12.95 W = 259 W) and 6 cameras on 802.3at (6 x 25.5 W = 153 W) needs 616 W of budget before headroom, and many 48-port switches ship with less. For the odd device far from the rack, a PoE injector fills the gap without buying a second switch.

Uplinks are the last cabling decision. Between the firewall and the switch, and between switches, use 2.5 Gbps or 10 Gbps ports, or fiber if the run crosses a floor. The desk ports can stay at 1 Gbps; the trunk that carries all of them cannot.

Step 6: Wi-Fi Design

Wi-Fi in a small office fails in three ways: too few access points, access points in the wrong place, and a consumer mesh system doing a job it was not built for. Fix placement first. Access points go on the ceiling, in open space, roughly one per 1,000 to 1,500 square feet of open office, closer together where walls are concrete or the room is dense with people. Corners and cupboards are where APs go to die.

Plan for the 5 GHz and 6 GHz bands and treat 2.4 GHz as the legacy band for printers and IoT. Wi-Fi 7, certified by the Wi-Fi Alliance from 2024, adds 320 MHz channels in 6 GHz and Multi-Link Operation, according to the Wi-Fi Alliance. In a small office, the practical win is less about peak speed and more about cleaner channels: 6 GHz has no legacy clients on it yet. Keep channel widths modest (40 MHz on 5 GHz in dense buildings) so neighboring APs do not step on each other.

Map SSIDs to VLANs. One staff SSID on the staff VLAN, one guest SSID on the guest VLAN with client isolation on, one IoT SSID on 2.4 GHz for the devices that cannot do better. Use WPA3 where every client supports it and WPA2/WPA3 transition mode where they do not, and put staff on 802.1X with per-user credentials if you run an identity provider. The difference between the modes is covered in our post on what WPA2 is and why offices outgrow it. Guest passwords rotate; staff credentials are revoked when the person leaves.

Willie Howe's small office build series starts where this post does, with the gear list and the subnet plan, if you want to see the decisions made on screen:

Step 7: Redundancy and Power

Redundancy in a small office is not two of everything. It is knowing which failure stops work and buying protection for that one. The internet circuit stops work, so it gets a second path (Step 1). The edge firewall stops work, so it gets a configuration backup that is tested by restoring it to a spare, or a vendor with a next-day replacement. The core switch stops work, so keep a cold spare on the shelf if the office cannot tolerate a day offline, or accept the day and write it down as a decision.

Power is the redundancy people forget. Put the firewall, switch and provider equipment on a UPS sized for at least 15 minutes of runtime, enough to ride out a flicker and shut down cleanly through a longer cut. Because the switch powers the phones and the access points, one UPS on the rack keeps the whole network up through the blip. Set the UPS to alert when it goes to battery. A UPS that dies silently after three years is a surprise outage with extra steps.

One r/sysadmin poster laid out a three-ISP, VLAN-heavy design for a small office and asked whether it was too much. The thread's answer was a clear yes, and it is a good calibration for where the line sits:

Step 8: Remote Access Without Holes

Nothing in the office should be reachable from the internet by port. No RDP on 3389, no camera recorder on 8080, no "temporary" forward for the accounting app. Every one of those is a door with the key under the mat, and the reasons are laid out in our post on port forwarding and when to skip it.

Remote users come in through a VPN terminated on the firewall or a zero-trust access service, with multi-factor authentication on the account. Give the VPN its own subnet and treat it as another segment in the firewall rules: remote staff reach what office staff reach, and nothing more. If the office is cloud-first, most people will not need the VPN at all, which is the cleanest outcome. Our playbook for remote workers covers the support side once the access is in place.

Step 9: Monitoring and Documentation

A network you cannot see is a network you troubleshoot by rebooting. Turn on SNMP or the vendor's cloud telemetry on the switch, the firewall and the access points, and send it to something that alerts. The four alerts that matter in a small office: the WAN link went down, the WAN failed over to the backup, a switch port is flapping, and an AP dropped off. Bandwidth graphs per VLAN tell you when the guest network is eating the uplink. Our guide to infrastructure monitoring covers which tools fit and what to watch.

Documentation is the step every design skips and every successor curses. The minimum set: a one-page diagram, the VLAN and subnet table, the rack layout with port assignments, the DHCP reservations, the admin credentials in a password manager, and the location of config backups. A network mapping tool can draw the diagram from discovery, but the VLAN table and the "why" behind each rule still need a human to write them. OpenFrame's device inventory, plus a script run across a client's devices with the output collected, fills in the per-machine IP, gateway and DNS columns without a site visit.

Back up the firewall and switch configurations after every change and keep two copies, one off-site. Version them. The question "what changed last Thursday" has a fast answer when the answer is a diff.

The Small Office Network Design Checklist

Print this, tick it during the design review, and tick it again during the install. Each line is a decision with a place to write the answer.

AreaCheckWritten down?
RequirementsHeadcount now and in three years, device count per person, on-premises vs cloud-first
RequirementsApplications that need priority (voice, video, line-of-business)
InternetUpload speed sized for calls and sync, not just download
InternetSecond WAN path chosen (5G, second carrier or SD-WAN) and tested
InternetProvider equipment in bridge mode; firewall owns the public IP
EdgeBusiness firewall with published advisories and multi-WAN; sized on throughput with inspection on
EdgeManagement interface not exposed to the internet; admin MFA on
SegmentationVLANs defined: staff, guest, printers/IoT, voice, management (servers if on-prem)
SegmentationDefault deny between VLANs; allowed flows listed per pair
SegmentationGuest isolated from everything internal, client isolation on
AddressingOne RFC 1918 range, one /24 per VLAN, scheme documented
AddressingReserved infrastructure block, DHCP reservations for printers and servers
DNSLocal resolver with filtering; every subnet points at it
CablingCat6A to every desk (two drops), AP, camera and printer; patch panel; labels both ends
SwitchingPort count = drops + 25% spare; managed, VLAN-capable
SwitchingPoE budget calculated from device draws with headroom; 802.3at or bt where APs need it
Switching2.5G or 10G uplinks between firewall and switch, and between switches
Wi-FiAP count from floor area and walls; ceiling mounted; channel plan set
Wi-FiSSIDs mapped to VLANs; WPA3 or transition mode; 802.1X for staff if possible
RedundancyFirewall config backup restored to a spare or replacement plan agreed
RedundancyUPS on rack and edge, 15 minutes minimum, battery alerts on
Remote accessZero inbound port forwards; VPN or zero-trust access with MFA on its own segment
MonitoringSNMP or telemetry from firewall, switch, APs; alerts for WAN down, failover, port flap, AP offline
DocumentationDiagram, VLAN and subnet table, rack layout, reservations, credentials in a password manager
DocumentationConfig backups after every change, versioned, one copy off-site

Five Mistakes That Show Up a Year Later

The provider's gateway is still the firewall. It was meant to be temporary. Now it is the single device holding the public IP, the Wi-Fi and the DHCP scope, and nobody has the admin password.

Everything is on one subnet. The design "worked" until the first infected laptop found the file server, the recorder and the printer in one scan. Segmentation is easier on an empty network than a busy one, which is why it is Step 3 and not Step 9.

The switch is full. The 24-port switch had four free ports on install day. Two went to a new hire, one to a second screen, one to a desk fan with an Ethernet port. Now a $30 unmanaged switch under someone's desk carries half of accounting, and it is not on any diagram.

Wi-Fi was a mesh kit from a big-box store. It was fine for six people. At 20, the backhaul is saturated and the "pro" management app has one setting, which is Off.

The person who built it left. Nothing was written down, the config backups are on their old laptop, and the new MSP starts by mapping the network from scratch. Documentation costs an afternoon. Rediscovery costs a week and the trust of the office.

What to Take From This

Small office network design is nine decisions made in order: internet and failover, the edge firewall, segmentation, addressing and DNS, cabling and PoE, Wi-Fi, redundancy and power, remote access, and monitoring and documentation. Make them on paper before the hardware arrives, and the install becomes a checklist instead of a series of surprises.

Two follow-on reads: our guide to smart office requirements covers what to ask a provider before signing, and the post on network mapping software shows how discovery fills in the diagram once the network is live.

Aliaska Varieva

Aliaska Varieva

Head of Platform

Hi! I’m Aliaska, and I’ve been working as a software engineer (mostly Java + a bit Kotlin) for over 8 years now. I mostly spend my time building backend services, integrating systems, fixing bugs (the fun part 🙃), and making sure things don’t fall apart behind the scenes.

Related Content

Blog Posts

Product Releases

Podcasts

Webinars

Case Studies

Events

Onboarding Guides

Frequently Asked Questions

About OpenFrame

In the cloud, on US soil. Your data stays stateside.
OpenFrame isn't built to plug into your stack. It replaces it. Instead of duct-taping a dozen tools together (RMM, MDM, SIEM, patching, remote access, each its own login and bill), we bundle it into one unified platform: RMM, MDM, monitoring, automation, remote access, patch management, security monitoring, and ticketing, plus built-in AI copilots. So "does it integrate with X?" usually means: you won't need X anymore.
Most platforms give you one piece and expect you to bolt the rest on. OpenFrame unifies the whole stack in one place, with AI copilots built in. Fewer logins, fewer bills, less duct tape.

MSP AI Agents

On a five-person desk, reported deployments show $78,000 to $130,000 in annual direct labor savings, roughly 30% fewer escalations, and 15% to 20% better SLA compliance. Broader MSP adoption data adds ticket handling time cut by 45% and five to 12 points of margin, all from reclaimed capacity rather than headcount cuts.
Five covers almost every small office: staff, guest, printers and IoT, voice, and management. Add a sixth for servers if anything stays on-premises. Each is a VLAN on the switch and a /24 subnet on the firewall, with default deny between them and specific allowed flows written down.
For 1 Gbps to the desk, yes, to the full 100 meters. Cat6 only carries 10 Gbps to 55 meters, while Cat6A carries it the full 100 meters under ANSI/TIA-568.2-D. Because cabling outlives every device it connects and the labor is the main cost, pull Cat6A to every desk, access point and camera.
You need a business firewall. The ISP gateway routes, but it cannot enforce default-deny rules between VLANs, terminate VPN with MFA, or keep its management page off the internet. Put the provider box in bridge mode and let the firewall own the public IP, the DHCP scopes and DNS.
Plan roughly one ceiling-mounted access point per 1,000 to 1,500 square feet of open office, closer together where walls are concrete or rooms are dense with people. Count by floor area and walls, not by headcount, and wire every AP to the PoE switch rather than relying on wireless mesh backhaul.
It is the total power a switch can supply across all its ports, which is almost always less than ports times the per-port maximum. Add up the device draws at their IEEE class: 802.3af phones at 12.95 W, 802.3at access points and cameras at 25.5 W, 802.3bt devices at 51 W or 71.3 W. Add 20% headroom and buy a switch whose total budget exceeds that figure.
Yes, because a single circuit is the one failure that stops all work. The cheapest second path is a 5G or LTE router on a different carrier plugged into the firewall's second WAN port. It only counts if it has been tested, so pull the primary cable once a quarter and confirm phones and calls survive the failover.