SOP-005: VLAN Creation and Segmentation on a Managed Switch¶
Sep 29, 2026 ยท @Lloyd
1. Document Control¶
| Field | Value |
|---|---|
| Document ID | SOP-005 |
| Version | 0.2 (Draft) |
| Owner | Lloyd Johnson, Johnson Technical Systems LLC |
| Milestone | Subnetting & VLANs |
| Review cycle | Every 6 months, or after any switch platform or IOS upgrade |
| Classification | Internal / Portfolio sample |
| Related | SOP-004 Cat6 Cable Termination; SOP-003 Network Troubleshooting Runbook |
2. Purpose and Scope¶
This SOP defines a repeatable, change-controlled process for creating VLANs and assigning switch ports. It separates user, server, voice, and management traffic into distinct broadcast domains and limits lateral movement between them.
In scope: Cisco IOS / IOS-XE managed access switches at a generic small office. Other vendors follow the same steps with their own syntax.
Out of scope: inter-VLAN routing, DHCP, and firewall rules, which live on the router or firewall. This SOP assumes the router already has a gateway interface and a DHCP scope for each VLAN in Section 3.
3. VLAN Plan¶
| VLAN | Name | Subnet | Purpose |
|---|---|---|---|
| 10 | USERS | 10.10.10.0/24 | Staff workstations |
| 20 | SERVERS | 10.10.20.0/24 | Internal servers |
| 30 | VOICE | 10.10.30.0/24 | IP phones |
| 99 | MGMT | 10.10.99.0/24 | Switch and AP management |
| 998 | NATIVE | none | Trunk native VLAN only. No access ports and no hosts |
| 999 | BLACKHOLE | none | Parking VLAN for unused ports. Never allowed on any trunk |
The native VLAN and the parking VLAN are kept separate. If unused ports were parked in the native VLAN, a device plugged into one of them would share a VLAN with untagged trunk traffic.
4. Procedure A: Change Preparation¶
- Open a change request listing the VLAN IDs, names, subnets, affected ports, rollback plan, and maintenance window. Get approval before making changes.
- Back up the current configuration with
copy running-config tftp:, or save theshow running-configoutput to the change ticket.
5. Procedure B: Configuration¶
-
Create and name the VLANs:
configure terminal vlan 10 name USERS vlan 20 name SERVERS vlan 30 name VOICE vlan 99 name MGMT vlan 998 name NATIVE vlan 999 name BLACKHOLE exit -
Assign access ports:
interface range gigabitEthernet1/0/1 - 20 switchport mode access switchport access vlan 10 switchport voice vlan 30 spanning-tree portfast spanning-tree bpduguard enable exit -
Configure the uplink trunk with an explicit allowed list and the dedicated native VLAN. On platforms that also support ISL, add
switchport trunk encapsulation dot1qbeforeswitchport mode trunk.interface gigabitEthernet1/0/48 switchport mode trunk switchport trunk native vlan 998 switchport trunk allowed vlan 10,20,30,99 switchport nonegotiate exit -
Park and shut down unused ports:
interface range gigabitEthernet1/0/21 - 47 switchport mode access switchport access vlan 999 shutdown exit -
Move switch management to VLAN 99 and restrict who can reach it. SSH must already be enabled (hostname, domain name, RSA key, and a local or AAA login). If it is not, enable it first, or
transport input sshwill cut off remote management.interface vlan 99 ip address 10.10.99.2 255.255.255.0 no shutdown exit ip default-gateway 10.10.99.1 interface vlan 1 shutdown exit ip access-list standard MGMT-ONLY permit 10.10.99.0 0.0.0.255 deny any log exit line vty 0 15 access-class MGMT-ONLY in transport input ssh exitip default-gatewayapplies to a layer 2 switch with IP routing disabled. On a layer 3 switch, use a default route instead. -
Save the configuration:
copy running-config startup-config.
6. Verification¶
-
show vlan brieflists every VLAN with the expected ports -
show interfaces trunkshows only VLANs 10, 20, 30, and 99 allowed, with native VLAN 998 -
show interfaces statusshows unused ports disabled and in VLAN 999 - A test host on a port in each VLAN receives an address in that VLAN's subnet from the router's DHCP scope
- SSH to 10.10.99.2 succeeds from a host in VLAN 99 and is refused from a host in VLAN 10
- Telnet to 10.10.99.2 is refused from every VLAN
- Before and after configs and verification output are attached to the change ticket
- The network diagram and VLAN/IP plan are updated
7. Responsible Parties¶
| Role | Responsibility |
|---|---|
| Network Administrator | Plans the VLANs, makes the change, and verifies results |
| IT Manager / Change Advisory Board | Approves the change and reviews post-change evidence |
| Security Lead | Confirms segmentation matches data-flow and access requirements |
8. Control Mapping¶
Verify each reference against the published text before changing status to Reviewed. Verify each command against the Cisco configuration guide for the specific switch model and IOS version.
| Procedure step | NIST SP 800-53 Rev 5 | AICPA SOC 2 (TSC 2017) |
|---|---|---|
| Separate VLANs by trust level (Section 3) | SC-7 Boundary Protection | CC6.1 Logical access security |
| Trunk allowed list, parked unused ports (Procedure B) | AC-4 Information Flow Enforcement | CC6.1 Logical access security |
| Management restricted to VLAN 99 over SSH only (Procedure B, step 5) | AC-3 Access Enforcement; SC-8 Transmission Confidentiality and Integrity | CC6.1 Logical access security |
| Approved change with backup and rollback (Procedure A) | CM-3 Configuration Change Control | CC8.1 Change management |
| Updated diagram and VLAN plan (Section 6) | CM-2 Baseline Configuration | CC8.1 Change management |
9. Revision History¶
| Version | Date | Change |
|---|---|---|
| 0.1 | 2026-09-29 | Initial AI-assisted draft; not yet fact-checked |
| 0.2 | 2026-10-03 | Separated the native VLAN (998) from the parking VLAN (999). Added management interface and SSH access restriction on VLAN 99. Added BPDU guard on access ports. Verification now matches the layer 2 scope. Remapped trunk controls from CC6.6 to CC6.1. Commands not yet verified on a switch |