Network Architecture, VLAN & LAN

3. Network Architecture Standards

The recommended architecture separates POS traffic from guest, office, IoT, and management traffic. All inter-VLAN access should be explicitly permitted, logged where feasible, and denied by default.

Figure 1. Reference topology for segmented POS connectivity with mirrored primary and backup WAN policy.

3.1 Core Design Requirements

  • Stateful firewall controls must govern POS traffic entering or leaving the POS VLAN.

  • Guest networks must not route to POS, payment, management, or back-office systems.

  • Network devices should have management access restricted to authorized administration sources.

  • Document IP ranges, DHCP reservations, device ownership, and dependency owners before acceptance testing.

4. VLAN Segmentation Standards

Figure 2. Recommended logical segmentation for store networks.

VLAN Typical systems Routing posture Notes
POS Registers, KDS, receipt printers, local POS services Least privilege Primary business-critical segment.
Payment PIN pads, payment controllers where separated PCI-controlled Use only where architecture requires or compliance owner mandates separation.
Office Back-office PCs, managers' workstations Restricted Permit only required access to POS admin services.
Guest Guest Wi-Fi clients Internet only No internal routing.
IoT Cameras, sensors, signage Restricted Prevent lateral movement into POS.
Management Switches, firewall, APs, monitoring Admin only Restrict to named admin sources and log access.

5. LAN Requirements and Performance

Component Minimum expectation Recommended standard Evidence
Switching Managed switching Gigabit access ports with monitored uplinks Switch inventory and port map
Cabling Cat5e Cat6 or better for new installs Cable certification or installer signoff
Wireless Business-class APs Separate SSIDs mapped to VLANs SSID/VLAN map and RF validation
DHCP Documented scopes Reservations for infrastructure and static-critical devices DHCP scope export
Monitoring Basic reachability Circuit, firewall, switch, and POS endpoint health alerts Monitoring dashboard or alert policy

5.1 LAN Performance Targets

Metric Target Customer validation method
Switch ports 1 Gbps where device supports it Switch port status export
Packet loss Near zero on LAN paths Ping or monitoring sample during operating hours
Latency to gateway Low single-digit milliseconds Gateway ping sample
Address capacity At least 25 percent free DHCP capacity DHCP utilization review