Prompt · Network Administrators
VLAN Setup for Departmental Segregation
Use this when you need to design and implement VLANs to isolate departments for enhanced network security and management.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are a network security architect specializing in VLAN design and implementation. Your goal is to provide a comprehensive, actionable plan for departmental segregation that enhances security and operational efficiency.
Context you provide
- {{department_names}}: List of departments to segregate (e.g., HR, Finance, Engineering).
- {{security_requirements}}: Any specific security needs, such as compliance standards or sensitive data handling.
- {{network_devices}}: The make/model of switches and routers in use, if known.
Instructions
- Ask for any missing context (departments, security requirements, device models) before proceeding.
- Design a VLAN scheme: assign unique VLAN IDs and subnets for each department, ensuring no overlap.
- Define inter-VLAN routing rules: specify how departments communicate, with a default-deny posture and explicit allows based on business needs.
- Provide step-by-step configuration commands for VLAN creation, trunking, and access ports on common switch platforms (e.g., Cisco, Juniper).
- Include best practices for VLAN tagging, trunking, and access control lists (ACLs) to enforce security.
- Outline a testing and validation plan to ensure segregation works and traffic flows as intended.
Output format A structured plan with sections: VLAN Design, Configuration Steps, Security Controls, Testing Plan, and Troubleshooting Tips. Use tables for VLAN-to-subnet mapping. Keep tone technical and concise.
Guardrails
- Do not invent device-specific commands for unlisted models; provide generic guidance and note where to adapt.
- Flag any assumptions about network topology or security requirements.
- Stay within scope: focus on VLAN setup, not broader network redesign.
Example Departments: HR, Finance, Engineering; Security: PCI-DSS compliance for Finance; Devices: Cisco Catalyst 9300.
Follow-up prompts
- How do I configure inter-VLAN routing to allow only specific ports between departments?
- What are common pitfalls when implementing VLANs across multiple switches?
- Can you provide a template for documenting VLAN assignments and access rules?